Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '%TEMP%\ganyx.exe'
- ulpxhpyt.exe process, Amsi.dll module
- ganyx.exe process, Amsi.dll module
- %TEMP%\golfinfo.ini
- %TEMP%\ganyx.exe
- %TEMP%\_sannuy.bat
- '%TEMP%\ganyx.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_sannuy.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_sannuy.bat" "' (with hidden window)