Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- System Back Door
- Worm
- Malicious Software
File Behavior
MSNLOADER.EXE has been seen to perform the following behavior:
- Executes a Process
- Writes to another Process's Virtual Memory (Process Hijacking)
- The Process is packed and/or encrypted using a software packing process
- Registers a Dynamic Link Library File
- Found on infected systems and resists interrogation by security products
- Uses low level functions to hide itself from the user and from system/security processes
- Checks for the use of debuggers
- Uses DNS to retrieve the IP address for web sites
- Uses your PC to connect to Chat rooms
MSNLOADER.EXE has been the subject of the following behavior:
- Created as a process on disk
- Deleted as a process from disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Executed by Internet Explorer
- Executed from Temporary Folders
- Terminated as a Process
- Registered as a Dynamic Link Library File
- Added as a Registry auto start to load Program on Boot up
- Copied to multiple locations on the system
Country Of Origin
The filename MSNLOADER.EXE was first seen on May 22 2007 in the following geographical regions of the Prevx community:
- SPAIN on May 22 2007
- URUGUAY on Mar 28 2008
File Name Aliases
MSNLOADER.EXE can also use the following file names:
- MSN_LOADER.EXE
- MSNLOADER(À¹ƒÀ¸ŠÀ¹‰À¹€À¸›À¸´À¸”MSNÀ¸«À¸¥À¸²À¸¢À¸•À¸±À¸§).EXE
- MSNLOADER UNIVERSAL.EXE
- MSN MESSENGER 7.5 COKLU OTURUM.EXE
- MSNLOADER_EXE_1.EXE
- MSNLOADER%20UNIVERSAL[n].EXE
- MSNLOADER1.EXE
- MYPHOTO39.JPEG-SCANNEDBYMSN.COM
- MSN LOADER UNIVERSAL.EXE
- MSNLOADER[n].EXE
- ÇOKLU MSN.EXE
- ÇOKLU MSNLOADER.EXE
- 2[1].EXE
- DD238.EXE
Filesizes
The following file size has been seen:
- 4,061 bytes
- 82,432 bytes
- 3,653 bytes
- 81,408 bytes
- 161,100 bytes
File Type
The filename MSNLOADER.EXE refers to many versions of an executable program.
File Activity
One or more files with the name MSNLOADER.EXE creates, deletes, copies or moves the following files and folders:
- Creates c:\docume~1\user\locals~1\temp\9a87_appcompat.txt
- Creates c:\docume~1\user\locals~1\temp\19630.dmp
- Opens/modifes c:\autoexec.bat
Network Activity
One or more files with the name MSNLOADER.EXE performs the following network events:
- DNS Lookup125.240.182.140 01.cybernix.info
Website Activity
One or more files with the name MSNLOADER.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- TCP:125.240.182.140:9058 Port:14
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.