Alert level

Trojan:Win32/Enchanim

(?)

Encyclopedia entry
Updated: Jul 09, 2012  |  Published: Feb 02, 2012

Aliases
  • Trojan.Win32.Menti.noix (Kaspersky)
  • WORM_SLENFBOT.JX (Trend Micro)

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection last updated:
Definition: 1.151.335.0
Released: May 17, 2013
Detection initially created:
Definition: 1.119.1228.0
Released: Feb 02, 2012


 

Summary

Trojan:Win32/Enchanim is a trojan that attempts to stop multiple security-related processes for the purpose of downloading and running other malicious code such as Worm:Win32/Gamarue.F.



 

Symptoms

System changes

The following system changes may indicate the presence of this malware:

  • Certain security programs are disabled after running the malware
  • The presence of a file named "7af3996f" in the %TEMP% folder


 

Technical Information (Analysis)

Trojan:Win32/Enchanim is a trojan that attempts to stop multiple security-related processes for the purpose of downloading and running other malicious code such as Worm:Win32/Gamarue.F.

Installation

This trojan is installed by other malware and is present as a randomly named file in the Windows system folder. The malware utilizes code injection in order to hinder detection and removal. When Trojan:Win32/Enchanim executes, it inject its code into running processes, including the following, for example:

  • csrss.exe
  • explorer.exe
  • lsass.exe
  • svchost.exe
Payload
Terminates processes
Trojan:Win32/Enchanim attempts to stop the following processes, many of which are security-related:
  • cfp.exe
  • avp.exe
  • kaspersky.exe
  • op_mon.exe
  • mcafee.exe
  • mcagent.exe
  • mcshield.exe
  • mctray.exe
  • mcsvhost.exe
  • mfevtps.exe
  • mfefire.exe
  • zonealarm.exe
  • egui.exe
  • nod32.exe
  • ekrn.exe
  • nod32kui.exe
  • msseces.exe
  • spiderui.exe
  • drwagntd.exe
  • drwagnui.exe
  • spiderml.exe
  • spidernt.exe
  • avscan.exe
  • avnotify.exe
  • avgnt.exe
  • ashdisp.exe
  • AVGIDSMonitor.exe
  • avgnsx.exe
  • avgcsrvx.exe
  • avgrsx.exe
  • avgw.exe
  • avgamsvr.exe
  • avg.exe
  • avgwdsvc
  • norton.exe
  • ccsvchst.exe
  • psctrls.exe
  • pavfnsvr.exe
  • pshost.exe
  • avengine.exe
Downloads other malware
Trojan:Win32/Enchanim may contact a remote host at 188.190.98.166 using port 80 to download other malware, such as Worm:Win32/Gamarue.F.
This trojan was also observed to contact a remote host at 31.186.102.156 using port 80.

Analysis by Jeong Mun



 

Prevention



 

Recovery

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

Provide feedback