Technical Information
- <SYSTEM32>\rundll32.exe "%CommonProgramFiles%\Remoete.dll" WWWW
- <SYSTEM32>\GroupPolicy\User\Scripts\dd.ini
- <SYSTEM32>\GroupPolicy\gpt.ini
- %CommonProgramFiles%\Remoete.dll
- from <Full path to virus> to %WINDIR%\Temp\svchost.exe
- '<Private IP address>':1990