Technical Information
- <SYSTEM32>\ddraw.dll.new
- <SYSTEM32>\dllcache\ddraw.dll.new
- from <SYSTEM32>\ddraw.dll to <SYSTEM32>\ddraw1.dll
- <SYSTEM32>\dllcache\ddraw.dll.new
- '<SYSTEM32>\cmd.exe' /C takeown /f <SYSTEM32>\ddraw.dll
- '<SYSTEM32>\cmd.exe' /C icacls <SYSTEM32>\ddraw.dll /grant Administrators:F /T