PE structurePE file structure

Show functions
Import table
RegCloseKey, RegCreateKeyA, RegOpenKeyExA, RegCreateKeyExA, RegSetValueExA, RegQueryValueExA, RegDeleteValueA, RegQueryInfoKeyA, RegEnumKeyA, RegDeleteKeyA, FreeSid, RevertToSelf, AccessCheck, IsValidSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, AddAccessAllowedAce, InitializeAcl, GetLengthSid, InitializeSecurityDescriptor, AllocateAndInitializeSid, OpenProcessToken, OpenThreadToken, ImpersonateSelf, CryptReleaseContext, CryptDestroyHash, CryptCreateHash, CryptAcquireContextA, CryptHashData, CryptGetHashParam, RegOpenKeyA
Polygon, SetDIBitsToDevice, CreateCompatibleBitmap, FillRgn, CreatePolygonRgn, DPtoLP, SetStretchBltMode, SetBitmapBits, OffsetViewportOrgEx, SetDIBColorTable, SetDIBits, GetDIBits, SetViewportExtEx, GetCurrentObject, StretchDIBits, GetObjectType, GetPaletteEntries, CreatePalette, GetSystemPaletteEntries, Ellipse, GetNearestPaletteIndex, PatBlt, GetMapMode, GetViewportExtEx, GetWindowExtEx, DeleteMetaFile, SetBrushOrgEx, GetBrushOrgEx, GetEnhMetaFileHeader, GetObjectA, DeleteEnhMetaFile, SetTextAlign, CreatePatternBrush, PlayEnhMetaFile, OffsetRgn, CombineRgn, EqualRgn, CreateDIBPatternBrushPt, ExtTextOutA, CreateFontIndirectA, GetTextExtentPoint32A, GetTextExtentExPointA, GetWindowOrgEx, OffsetWindowOrgEx, CreateDCA, SetWorldTransform, SetGraphicsMode, SetRectRgn, Polyline, GetTextMetricsA, RectInRegion, GetRandomRgn, GetClipBox, CreateHalftonePalette, RealizePalette, SelectPalette, GetDIBColorTable, SetTextColor, SetBkMode, SetWindowExtEx, CloseMetaFile, GetClipRgn, CreateRectRgn, ExtSelectClipRgn, SelectClipRgn, SetBkColor, Rectangle, MoveToEx, LineTo, GetPixel, BitBlt, StretchBlt, CreateCompatibleDC, CreatePen, SelectObject, GetDeviceCaps, LPtoDP, SaveDC, SetMapMode, SetWindowOrgEx, SetViewportOrgEx, DeleteDC, RestoreDC, CreateRectRgnIndirect, CreateRoundRectRgn, GetStockObject, CreateDIBSection, CreateSolidBrush, DeleteObject
StgOpenStorageOnILockBytes, GetHGlobalFromILockBytes, OleLockRunning, CoTaskMemAlloc, CLSIDFromProgID, CoInitializeEx, CoFreeUnusedLibraries, ReleaseStgMedium, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, CoInitialize, CoUninitialize, IIDFromString, CoCreateGuid, StringFromGUID2, OleRun, RegisterDragDrop, RevokeDragDrop, DoDragDrop, CoCreateFreeThreadedMarshaler, OleSaveToStream, WriteClassStm, OleLoadFromStream, GetHGlobalFromStream, OleDuplicateData, CreateStreamOnHGlobal, CreateDataAdviseHolder, CreateOleAdviseHolder, OleRegGetMiscStatus, OleRegGetUserType, OleRegEnumVerbs, OleFlushClipboard, StringFromCLSID, CoTaskMemFree, CLSIDFromString, CoRevokeClassObject, CoCreateInstance, CoRegisterClassObject, OleUninitialize, OleInitialize, CoDisconnectObject
DragQueryPoint, DragAcceptFiles, DragFinish, SHAppBarMessage, ShellExecuteExA, SHGetMalloc, Shell_NotifyIconA, ShellExecuteA
PathFileExistsW, StrCpyNW, wnsprintfW, StrCatBuffA
WSAIoctl, WSAEnumNetworkEvents, WSAEventSelect, WSASocketA


Messenger by Microsoft Corporation (Signed)

Version:   8.0.0812.00
MD5:   c1ee2387ede907599ee3a6de9493f672
SHA1:   9b30cdcb3087f4c868b83020a0825feeecc38852
SHA256:   380a9b493fc27a3af528b02f036abc92ddae4e713d74ec71f93d8fce5f9bb5cf

What is msnmsgr.exe?

Windows Messenger is a client by Microsoft that is included in Windows. It has a variety of features, such as instant messaging, presence awareness, support for Session Initiation Protocol (SIP), file transfer, application sharing and whiteboarding. The software integrates with Microsoft Exchange, Microsoft Outlook, Outlook Express, and the Remote Assistance feature of Windows XP.


MsnMsgr.Exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including Windows Live Messenger published by Microsoft Corporation and RETScreen published by Ressources Naturelles Canada. The file is digitally signed by Microsoft Corporation.


File name:MsnMsgr.Exe
Publisher:Microsoft Corporation
Product name:Messenger
Typical file path:C:\Program Files\msn messenger\msnmsgr.exe
File version:8.0.0812.00
Product version:8.0.0812
Size:5.11 MB (5,354,792 bytes)
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Effective date:Tuesday, April 4, 2006
Expiration date:Thursday, October 4, 2007
Digital DNA
File packed:No
More details


Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'MsnMsgr' → "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Program Files\MSN Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 81.82%
Windows XP Professional 9.09%
Windows Vista Ultimate 9.09%

Distribution by countryDistribution by country

Germany installs about 33.33% of Messenger.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 72.73%
Toshiba 18.18%
Sahara 9.09%
