Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '%TEMP%\zuupd.exe'
- xcuijte.exe process, Amsi.dll module
- zuupd.exe process, Amsi.dll module
- %TEMP%\golfinfo.ini
- %TEMP%\zuupd.exe
- %TEMP%\_sannuy.bat
- '%TEMP%\zuupd.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_sannuy.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\_sannuy.bat" "' (with hidden window)