Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

11,5,0,0228 8.33%
11,5,0,0152 8.33%
11,0,0,1751 8.33%
10,0,0,1102 8.33%
10,0,0,525 8.33%
9,0,0,2160 16.67%
9,0,0,2152 8.33%
9,0,0,2128 8.33%
9,0,0,2034 8.33%
9,0,0,797 8.33%
8,1,0,244 8.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, ReportEventA, DeregisterEventSource, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyW, RegEnumKeyExW, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegisterEventSourceA
comctl32.dll
ImageList_Draw, CreateToolbarEx, CreateStatusWindowW, ImageList_GetIconSize, ImageList_EndDrag, ImageList_DragMove, ImageList_DragEnter, ImageList_DragLeave, ImageList_GetImageCount, ImageList_AddMasked, ImageList_ReplaceIcon, _TrackMouseEvent, InitCommonControlsEx, ImageList_Create, ImageList_Add, ImageList_Destroy, ImageList_BeginDrag
comdlg32.dll
ChooseFontW, GetOpenFileNameW, GetSaveFileNameW, PrintDlgW, ChooseColorW
crypt32.dll
CryptMsgClose, CertCloseStore, CertFreeCertificateContext, CertGetNameStringW, CertGetEnhancedKeyUsage, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject
gdi32.dll
SaveDC, CreateBitmap, PatBlt, SetBkColor, MoveToEx, LineTo, CreatePen, SetTextColor, GetStockObject, GetObjectW, CreateSolidBrush, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, DeleteDC, GetDeviceCaps, DeleteObject, CreateRoundRectRgn, EnumFontFamiliesExW, RoundRect, SetROP2, LPtoDP, GetTextExtentPoint32W, GetTextFaceW, GetTextMetricsW, CreateFontIndirectW, SetBkMode, ExtTextOutW, TextOutW, CreatePatternBrush, GetBkColor, GetBkMode, Rectangle, FillRgn, CombineRgn, CreateRectRgn, StretchBlt, CreateFontW, EndDoc, EndPage, StartPage, StartDocW, GetTextExtentPointW, FrameRgn, RestoreDC, SelectClipRgn, CreatePolygonRgn
imm32.dll
ImmReleaseContext, ImmGetContext, ImmAssociateContext, ImmGetCompositionStringW
kernel32.dll
GetLocaleInfoA, VirtualAlloc, GetThreadLocale, IsProcessorFeaturePresent, GetProcessHeap, GetStartupInfoW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualFree, SetFileTime, IsDebuggerPresent, QueryPerformanceCounter, FlushConsoleInputBuffer, GetStdHandle, GetFileType, GetVersion, InitializeCriticalSectionAndSpinCount, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, HeapCreate, WritePrivateProfileStringA, Beep, CreateMutexW, ReleaseMutex, GetCurrentProcessId, WritePrivateProfileSectionW, GetSystemTimeAsFileTime, GetPrivateProfileStringA, GetSystemTime, GetCPInfoExW, GetACP, GetVersionExA, SetErrorMode, CreateProcessW, GetExitCodeProcess, TerminateProcess, LoadLibraryA, lstrcpyW, GetTimeFormatW, GetDateFormatW, lstrcmpA, GetTempFileNameW, CompareFileTime, MoveFileW, RemoveDirectoryW, GetSystemDirectoryW, GetWindowsDirectoryW, GetSystemWindowsDirectoryW, GetFileAttributesExW, CreateFileA, DosDateTimeToFileTime, LocalFileTimeToFileTime, LoadLibraryW, CreateSemaphoreW, LoadLibraryExW, FreeLibrary, InterlockedExchange, ResumeThread, OutputDebugStringW, CreateThread, WaitForMultipleObjects, ExitThread, TerminateThread, WritePrivateProfileStringW, InterlockedCompareExchange, FormatMessageW, WaitForSingleObject, InterlockedIncrement, GetLocalTime, SetEvent, ResetEvent, GlobalDeleteAtom, GlobalAddAtomW, GetTickCount, FindFirstFileW, FindNextFileW, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, lstrcmpiW, EnterCriticalSection, LeaveCriticalSection, GetLastError, SetLastError, lstrlenW, FlushInstructionCache, GetCurrentProcess, lstrcmpW, MulDiv, GetModuleFileNameW, GlobalUnlock, GlobalLock, GlobalAlloc, RaiseException, GetCurrentThreadId, MultiByteToWideChar, InterlockedDecrement, DeleteCriticalSection, lstrlenA, InitializeCriticalSection, CreateDirectoryA, GetFileAttributesA, FileTimeToDosDateTime, FileTimeToLocalFileTime, GetTempFileNameA, GetTempPathA, SetFileAttributesA, WideCharToMultiByte, GetShortPathNameW, GlobalMemoryStatus, CloseHandle, CreateFileW, lstrcpynW, GetPrivateProfileStringW, GlobalFree, GlobalHandle, WriteFile, SetFilePointer, SetEndOfFile, lstrcpynA, DeleteFileW, SetFileAttributesW, GetFileAttributesW, CreateDirectoryW, GetComputerNameW, LocalFree, LocalAlloc, CopyFileW, GetProcAddress, GetModuleHandleW, GetPrivateProfileIntW, GetTempPathW, GetVersionExW, GetSystemInfo, ReadFile, GetFileSize, FileTimeToSystemTime, GetFileTime, Sleep, CreateEventW, FindClose
msimg32.dll
AlphaBlend, GradientFill
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoCreateInstance, CLSIDFromString, CoTaskMemAlloc, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, StringFromCLSID, CoReleaseMarshalData, CoMarshalInterface, CoUnmarshalInterface, CoUninitialize, CoInitialize, CoRevokeClassObject, CoRegisterClassObject, CoCreateGuid, OleRun, DoDragDrop, ReleaseStgMedium, CoGetMalloc, RegisterDragDrop, RevokeDragDrop, CoSetProxyBlanket, CoInitializeSecurity, OleGetClipboard, CLSIDFromProgID, CoGetClassObject, OleLockRunning, CoTaskMemFree, StringFromGUID2, CoTaskMemRealloc
secur32.dll
GetUserNameExW
shell32.dll
SHGetFileInfoW, ShellExecuteExW, SHGetPathFromIDListW, DragQueryFileW, DragAcceptFiles, SHFileOperationW, SHAppBarMessage, ShellExecuteW, Shell_NotifyIconW, SHGetMalloc, SHBrowseForFolderW, SHGetFolderPathW
shlwapi.dll
UrlCreateFromPathW, PathRemoveExtensionW, PathFileExistsW, StrToIntW, PathIsURLW, PathFindExtensionW, PathCanonicalizeW, PathAppendW, PathIsRelativeW, UrlIsW, SHDeleteKeyW, PathFindFileNameW, wnsprintfW, PathCombineW, StrCpyNW, UrlEscapeW, StrCmpNIW, StrCmpNA, StrCmpNW, PathStripPathW
urlmon.dll
CreateURLMonikerEx
user32.dll
DllMain
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
wininet.dll
InternetSetOptionW, InternetGetCookieW, InternetCloseHandle, HttpQueryInfoW, HttpSendRequestW, HttpOpenRequestW, InternetConnectW, InternetOpenW, InternetCrackUrlW, InternetSetCookieW, InternetGetConnectedStateExW
winmm.dll
PlaySoundW, timeGetTime
wintrust.dll
WinVerifyTrust
ylog.dll
ylog_debug

yahoomessenger.exe

Yahoo! Messenger by Yahoo! Inc. (Signed)

Remove yahoomessenger.exe
Version:   10,0,0,1102
MD5:   1b07ea92c5848259e2ef128f39223219
SHA1:   7da56acf56ff837b9bcae31ee63f73644cd44b1e
SHA256:   952d9089db2710a21ccea10be8e0c7b65f869a1df1865f49deef4a772f792f7f

Overview

yahoomessenger.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including Yahoo! Messenger published by Yahoo! Inc. and Yahoo!7 Messenger published by Yahoo! Inc.. The file is digitally signed by Yahoo! Inc. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:yahoomessenger.exe
Publisher:Yahoo! Inc.
Product name:Yahoo! Messenger
Typical file path:C:\Program Files\yahoo!\messenger\yahoomessenger.exe
File version:10,0,0,1102
Size:5 MB (5,244,216 bytes)
Build date:11/10/2009 6:36 PM
Certificate
Issued to:Yahoo! Inc.
Authority (CA):VeriSign
Expiration date:Thursday, September 3, 2009
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Yahoo! Inc.
7% remove
Yahoo! Messenger (YIM) is an ad-supported instant messaging client and protocol by Yahoo!. Yahoo! Messenger is provided free of charge and can be downloaded and used with a generic "Yahoo! ID" which also allows access to other Yahoo! services, such as Yahoo! Mail, where users can be automatically notified when they receive new email.
Yahoo! Inc.
3% remove
Just sign into Yahoo! Mail to enjoy the same Yahoo! Messenger for the Web service you know and love. Yahoo! Messenger within Yahoo! Mail also allows you to chat with your Facebook and Windows Live friends without requiring any installation. Send text messages in real-time to your friends on Yahoo! 7 or Windows Live™ Messenger. Share photos from your desktop or Flickr, then discuss them over IM while you and a friend view them together....

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Yahoo! Pager' → "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
  • 'Messenger (Yahoo!)' → "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 41.67%
Microsoft Windows XP 25.00%
Windows Vista Home Basic 8.33%
Windows 8 Single Language 8.33%
Windows 7 Starter 8.33%
Windows Vista Home Premium 8.33%

Distribution by countryDistribution by country

United States installs about 33.33% of Yahoo! Messenger.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
Sony 13.33%
Toshiba 13.33%
Gateway 13.33%
GIGABYTE 6.67%
Hewlett-Packard 6.67%
American Megatrends 6.67%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE