Threat Description



Category: Malware
Type: Worm
Platform: W32
Aliases: Glieder.I, Trojan.Win32.Glieder.i, W32/Glieder.I, TrojanDropper.Win32.Small.kv, TrojanDownloader.Win32.Agent.cj


Yet another Glieder variant has been spammed. The origin is an email message sent to many people. The message contains an attachment named FOTOS.ZIP. Inside the ZIP archive there is an HTML portion that uses a common exploit to launch an EXE file named CALC.EXE, which is also located inside the archive.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

Once the CALC.EXE file is launched it copies itself to the Windows System32 directory under the name DORIOT.EXE and adds Registry keys under:

HKLM\Software\Microsoft\CurrentVersion\Run  HKCU\Software\Microsoft\CurrentVersion\Run   

to ensure the trojan is stared upon reboot. A file named GDQFW.EXE is then dropped onto the Windows System32 directory. This file is then injected into Explorer.exe process space through process memory manipulation. The dropper terminates at this stage.

The injected code from GDQFW.EXE is active while Explorer.exe is active. It performs various tasks which include monitoring various security related update programs and terminating them; checking predefined list of URLs for a particular file and if present - downloading and executing it. It also manipulates with cached URLs on the user's machine.


F-Secure Anti-Virus detects Glieder.I starting from the following update:

Detection Type: PC
Database: 2004-09-01_01

Description Details: Tzvetan Chaliavski, August 31st, 2004
Technical Details:Alexey Podrezov, September 1st, 2004


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More