Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malicious Software
- Worm
File Behavior
LOADER.EXE has been seen to perform the following behavior:
- Executes a Process
- Enables an In Process Object/Server - Common with DLL Injections
- Writes to another Process's Virtual Memory (Process Hijacking)
- Adds products to the system registry
- Modifies the Windows Host File which could be used to stop you visiting specific web sites by redirecting you to alternative addresses without you knowing
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Reads your outlook address book
- Registers a Dynamic Link Library File
- This process creates other processes on disk
- Injects code into other processes
- The Process is packed and/or encrypted using a software packing process
- This Process Deletes Other Processes From Disk
- Can communicate with other computer systems using HTTP protocols
- Makes outbound connections to other computers using NETBIOSOUT protocols
LOADER.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Has code inserted into its Virtual Memory space by other programs
- Registered as a Dynamic Link Library File
- Executed by Internet Explorer
- Terminated as a Process
- Copied to multiple locations on the system
- Created by processes which appear to be checking for interception by security products
Country Of Origin
The filename LOADER.EXE was first seen on May 9 2007 in the following geographical regions of the Prevx community:
- Canada on May 9 2007
- The United States on May 14 2007
- Spain on May 14 2007
- Belgium on Jun 10 2007
- Denmark on Jun 10 2007
- Thailand on Jun 27 2007
- Germany on Jan 20 2009
- Poland on Jul 7 2009
- Europe on Oct 3 2009
File Name Aliases
LOADER.EXE can also use the following file names:
- HAZAAR 2ND CHOICE.EXE
- LOADER1.6.1D.EXE
- LOADER2.EXE
- LOADER V.1.6.1D.EXE
- N1|LOADER V.1.6.1D.EXE
- M2|LOADER.EXE
- WINDOW~1.EXE
- LOADER1.6.EXE
- LOADER[1].EXE
- LLLLLLL.EXE
- JAIL LOADER.EXE
- CRACK FOR WINDOWS 7.EXE
- MESSENGERDISCOVERY/LOADER.EXE
- LOADER[n].EXE
- ADMINISTRATOR.EXE
- VENKU.EXE
- SUN.EXE
- ANIKó.EXE
- ADMIN.EXE
- C19H28O2.V7.15/LOADER.EXE
- MSASA1.EXE
- LOADER_715/LOADER.EXE
- AGBOT/LOADER.EXE
- LOADER.EXE.EXE
- SILKERRSENDER.EXE
- LOADER/LOADER.EXE
- SMSMZ2.EXE
- LOADER 175/LOADER.EXE
- بندق.EXE
- NEW FOLDER/LOADER.EXE
- PACKAGE/LOADER.EXE
- WPV141240687018.EXE
- WPV171240687018.EXE
- RENDSZERGAZDA.EXE
- GéP.EXE
- WINDOWS.EXE
- 200706271350_LOADER[1].EXE
- PC.EXE
- LOADER.EX
- LOADČER.EX
- LO
- LOďADER.EX
- WARCRA
- M4|34821058.EXE
- 30731412.EXE
- 93961608.EXE
- 16862406.EXE
- 22681459.EXE
Filesizes
The following file size has been seen:
- 5,376 bytes
- 3,541,702 bytes
- 24,576 bytes
- 318,976 bytes
- 188,416 bytes
- 221,696 bytes
- 21,026 bytes
- 401,408 bytes
- 147,456 bytes
File Type
The filename LOADER.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.