Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 23 October 2008 19:06:59 (GMT) |
| Last updated | 24 October 2008 21:55:14 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Gimmiv-A is a Trojan for the Windows platform.
When Troj/Gimmiv-A is run, the following file is dropped:
<System>\wbem\sysmgr.dll
This file is also detected as Troj/Gimmiv-A
Troj/Gimmiv-A sets the following registry entries to link the dll with svchost.exe:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
sysmgr
sysmgr
HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters
ServiceDll
<System>\wbem\sysmgr.dll
HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters
ServiceMain
ServiceMainFunc
Troj/Gimmiv-A then also creates a service with the a Service Name of "sysmgr" and a Display Name of "System Maintenance Service" to run the dropped dll on startup by running "<Root>\System32\svchost.exe -k sysmgr".
The dll includes functionality to send information about the infected computer to a remote website, including information about what anti-virus product is being run.
