Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\nvddlkko] 'ImagePath' = '<DRIVERS>\xZ1rGVqvESJZ.sys'
- 'nvddlkko' <DRIVERS>\xZ1rGVqvESJZ.sys
- <DRIVERS>\xz1rgvqvesjz.sys
- <DRIVERS>\7greuufwkkdi.sys
- from <DRIVERS>\xz1rgvqvesjz.sys to <DRIVERS>\7greuufwkkdi.sys
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- ClassName: 'VALORANTUnrealWindow' WindowName: ''
- '<SYSTEM32>\cmd.exe' sc stop nvddlkko
- '<SYSTEM32>\sc.exe' stop nvddlkko
- '<SYSTEM32>\cmd.exe' sc delete nvddlkko
- '<SYSTEM32>\sc.exe' delete nvddlkko
- '<SYSTEM32>\cmd.exe' sc create nvddlkko type= kernel start= demand binPath= <DRIVERS>\xZ1rGVqvESJZ.sys
- '<SYSTEM32>\sc.exe' create nvddlkko type= kernel start= demand binPath= <DRIVERS>\xZ1rGVqvESJZ.sys
- '<SYSTEM32>\cmd.exe' sc start nvddlkko
- '<SYSTEM32>\sc.exe' start nvddlkko
- '<SYSTEM32>\cmd.exe' rename <DRIVERS>\xZ1rGVqvESJZ.sys 7gReUufwkKdI.sys