Sophos

Troj/Gimmiv-A

Aliases
  • TrojanSpy:Win32/Gimmiv.A
  • TrojanSpy:Win32/Gimmiv.A.dll
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 23 October 2008 19:06:59 (GMT)
Last updated 24 October 2008 21:55:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Gimmiv-A is a Trojan for the Windows platform.

When Troj/Gimmiv-A is run, the following file is dropped:

<System>\wbem\sysmgr.dll

This file is also detected as Troj/Gimmiv-A

Troj/Gimmiv-A sets the following registry entries to link the dll with svchost.exe:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
sysmgr
sysmgr

HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters
ServiceDll
<System>\wbem\sysmgr.dll

HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters
ServiceMain
ServiceMainFunc

Troj/Gimmiv-A then also creates a service with the a Service Name of "sysmgr" and a Display Name of "System Maintenance Service" to run the dropped dll on startup by running "<Root>\System32\svchost.exe -k sysmgr".

The dll includes functionality to send information about the infected computer to a remote website, including information about what anti-virus product is being run.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer