New Trojan Small.DAM Warning

Andy Ramblings

  • Homepage
  • About
  • Gallery
  • Archives
  • Contact
< Power of Internet search | Snow-Wooo >

Jan 21: New Trojan Small.DAM Warning

Ok folks, Spammers and their likes have a tendency to try and get you to read e-mails. Some of you may or may not have noticed that there has been a change it the types of spam you are getting. The latest ones will try and convince you that they have some Good/oh My God terrible news about the storms that we have had over here in Europe over the past week, No this is not a weather report.

SO,  What is Small.Dam?
During the last 48hrs virus writers have been taking advantage of the winter storms in Europe to launch a new wave of attacks on computers around the globe.

This particular attack trys to get the user to "execute" a malicious file attached to an email that contains a Trojan horse.

The email and its attachment pose as information about the dreadful weather that Europe has currently been experiencing.

(Something I can personally vouch for as a roofing contractor has only just left my house after replacing tiles blown off in the strong winds!)

The Trojan is being distributed in emails with messages subjects like:

- 230 dead as storm batters Europe.
- British Muslims Genocide
- Naked teens attack home director.
- A killer at 11, he's free at 21 and kill again!
- U.S. Secretary of State Condoleezza Rice has kicked German Chancellor Angela Merkel

The email will have an attachment  that contains the Small.DAM Trojan.

The attachments may contain one of the following filenames:

- Full Clip.exe
- Full Story.exe
- Read More.exe
- Video.exe

Source

Basically, If you didn't ask for e-mails about the weather in Europe, it's most likely crap.
Obviously, below, there is more info on what the trojan does, read only if you want info on it.
If executed (clicked on) the "payload" turns the users computer into a machine that can be controlled remotely by the "hackers" from anywhere in the world!

Turning the computer into what is commonly known as a "zombie"

UK anti-virus firm Sophos reports that the malware accounts for one in every 200 emails it has monitored over the last 12 hours. Two in every three reports of malware tracked by Sophos on Friday involved reports of the Trojan.

By focusing on a topical subject like the news of storms of up to 200mph the writers of this malicious program expect users to let their guard down and open the attachment!

In doing so they can turn their computer into a machine that as the mercy of the hackers, who can use the infected machine to send out spam email or even capture the personal information of the computer owner...

For you techies reading this article Small.DAM contains an advance kernel mode driver that is dropped onto the infected computer:


%SysDir%\wincom32.sys - Kernel mode driver component
%SysDir%\peers.ini - Initialization file component



It also installs itself as a service with the name "wincom32" by creating the following registry keys:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
\wincom32]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum
\Root\LEGACY_WINCOM32]

The Second Wave Of Small.DAM

It now appears that the writers of the malicious Trojan Small.DAM, have launched a second wave of emails on the public, due to the success they have had with the first wave...

It is still the same malicious program but with new subject lines like:

- Radical Muslim drinking enemies's blood.
- Chinese missile shot down Russian satellite
- Chinese missile shot down Russian aircraft
- Chinese missile shot down USA aircraft
- Chinese missile shot down USA satellite
- Russian missile shot down USA aircraft
- Russian missile shot down USA satellite
- Russian missile shot down Chinese aircraft
- Russian missile shot down Chinese satellite
- Saddam Hussein safe and sound!
- Saddam Hussein alive!
 

DON'T GET CAUGHT OUT!

Make sure you have an up to date antivirus package on your computer - if you do not have the funds for one then do not let that be an excuse, take a look the the free version from Grisoft.com

Posted by Andy Rambling in News, News Comments: (0) Trackbacks: (0)
Defined tags for this entry: microsoft, software, warnings
Related entries by tags:
  • Windows 7 Beta 1
  • My Gigabit project
  • We all Love Powerpoint
  • Techie problems
  • Playing with Vista

Trackbacks
Trackback specific URI for this entry

No Trackbacks

Comments
Display comments as (Linear | Threaded)

No comments


Add Comment

Gravatar, Favatar, Twitter, Pavatar, Pavatar author images supported.
Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
E-Mail addresses will not be displayed and will only be used for E-Mail notifications.
:'(  :-)  :-|  :-O  :-(  8-)  :-D  :-P  ;-) 
BBCode format allowed
Standard emoticons like :-) and ;-) are converted to images.
 
 

Local Sunrise/Sunset

Today's Sunrise:07:53
Today's Sunset:15:53
Local Time:19:51

London Weather

Tags Tags,

annoyance art bush days drunk england Entertainment fun Fun Games General health Humour Jokes london me microsoft News News - UK News - USA news uk Only In America politics Software Review stupid things travel

Ramblers

• The Blair Watch Project
• My Boyfriend Is A twat
• Stop the world I wanna get off
• Elspeth
• PostSecret
• MICAH WRIGHT
• The Dilbert Blog
• Baghdad Burning
• Downing Street Says
• Nick Robinson's Newslog
• Karelian Blonde
• Rob A's (Im)personal Blog
• | The Zahir |
• Talking Points Memo:
• Michael Moore
• diamond geezer
• That's The way Life Is
• Rachel from north London
• Guy Fawkes' blog of parliamentary plots
• Beau Bo D'Or
• Blogzira
• Grumpy Old Man - Keith
• More4 News Blog
• GUYANA
• little.red.boat
• Chocs Away, Old Girl!
• File Hippo
• Live Life Then Give Life
• Tomato And Basil Sandwiches
• PUBLOG
• The Nether-World
• julianhopkins.net
• Ten Percent
• Bloggerheads: The Alisher Usmanov Affair

Search Stuff

Cluster Map

Locations of visitors to this page

Banner

Andy Ramblings
Andy Ramblings
Create your badge Foxkeh
Use OpenDNS
Trillian 4 in 1 IM
Get Trillian, the ultimate instant messenger!
A UK wide PC based TVguide
 DigiGuide, the best TV guide

Want this badge?
  Save Parliament
Powered By
 Serendipity Banner
Serendipity PHP Weblog

My Little Tag Bar

GeoURL British Blog Directory. Firefox Flicks!
Get Thunderbird! Firefox 2


Who Links Here

Enter your Email


Powered by FeedBlitz

Creative Commons License
This work is licenced under a Creative Commons Licence.

Other Pages

Archives

  • December 2019 (0)
  • November 2019 (0)
  • October 2019 (0)
  • September 2019 (0)
  • August 2019 (0)
  • Recent...
  • Older...

Great Web Hosting

* 510GB of Disk Space *
* Over 5TB transfer/Month *
» Unlimited E-mail addresses
» Unlimited E-mail Forwarding
» 1 Free Domain or Transfer
» Free Setup
» Unlimited Domains
» 1000 MySQL Database
» Active Spam Protection
And Many more features
»» All for £4.25 per Month ««
* sign up using the above link, and get 2500MB extra webspace free]

Statistics

Last entry: 2013-03-15 18:29
259 entries written
315 comments have been made
25079 visitor(s) this month
32 visitor(s) online
 

Layout by Andreas Viklund | Serendipity template by Carl