Additional Details
Agent.BTF attempts to download an installation package from the ContraVirus webpage.
It silently installs the ContraVirus application onto the infected machine.
It adds autorun launchpoints to:
• [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Update Svc"=
• [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Updater Servc"
Malware location:
• %system32%\xpuupdate.exe