 | |  |
|
Trojan:Win32/Enchanim
(?)
Encyclopedia entry
Updated:
Jul 09, 2012
| Published:
Feb 02, 2012
Aliases
Trojan.Win32.Menti.noix
(Kaspersky)
-
WORM_SLENFBOT.JX
(Trend Micro)
Alert Level
(?)
Severe
Antimalware protection details
Microsoft recommends that you download the
latest definitions
to get protected.
Detection last updated:
Definition: 1.151.335.0 Released: May 17, 2013
|
|
Detection initially created:
Definition: 1.119.1228.0 Released: Feb 02, 2012
|
Summary
Trojan:Win32/Enchanim
is a trojan that attempts to stop multiple security-related processes for the purpose of downloading and running other malicious code such as Worm:Win32/Gamarue.F.
Symptoms
System changes
The following system changes may indicate the presence of this malware:
- Certain security programs are disabled after running the malware
- The presence of a file named "7af3996f" in the %TEMP% folder
Technical Information (Analysis)
Trojan:Win32/Enchanim
is a trojan that attempts to stop multiple security-related processes for the purpose of downloading and running other malicious code such as Worm:Win32/Gamarue.F.
Installation
This trojan is installed by other malware and is present as a randomly named file in the Windows system folder. The malware utilizes code injection in order to hinder detection and removal. When Trojan:Win32/Enchanim executes, it inject its code into running processes, including the following, for example:
-
csrss.exe
-
explorer.exe
-
lsass.exe
-
svchost.exe
Payload
Terminates processes
Trojan:Win32/Enchanim attempts to stop the following processes, many of which are security-related:
-
cfp.exe
-
avp.exe
-
kaspersky.exe
-
op_mon.exe
-
mcafee.exe
-
mcagent.exe
-
mcshield.exe
-
mctray.exe
-
mcsvhost.exe
-
mfevtps.exe
-
mfefire.exe
-
zonealarm.exe
-
egui.exe
-
nod32.exe
-
ekrn.exe
-
nod32kui.exe
-
msseces.exe
-
spiderui.exe
-
drwagntd.exe
-
drwagnui.exe
-
spiderml.exe
-
spidernt.exe
-
avscan.exe
-
avnotify.exe
-
avgnt.exe
-
ashdisp.exe
-
AVGIDSMonitor.exe
-
avgnsx.exe
-
avgcsrvx.exe
-
avgrsx.exe
-
avgw.exe
-
avgamsvr.exe
-
avg.exe
-
avgwdsvc
-
norton.exe
-
ccsvchst.exe
-
psctrls.exe
-
pavfnsvr.exe
-
pshost.exe
-
avengine.exe
Downloads other malware
Trojan:Win32/Enchanim
may contact a remote host at 188.190.98.166 using port 80 to download other malware, such as Worm:Win32/Gamarue.F.
This trojan was also observed to contact a remote host at 31.186.102.156 using port 80.
Analysis by Jeong Mun
Prevention Recovery
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
| |
 | |  |