Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

16.4.3522.0110 0.37%
16.4.3508.0205 1.47%
16.4.3505.0912 12.87%
15.4.3555.0308 17.65%
15.4.3538.0513 3.68%
15.4.3508.1109 0.37%
15.4.3502.0922 1.10%
14.0.8117.0416 0.37%
14.0.8117.0416 28.31%
14.0.8117.0416 8.09%
14.0.8117.0416 0.37%
14.0.8117.0416 2.57%
14.0.8117.0416 4.78%
14.0.8117.0416 2.57%
14.0.8117.0416 0.37%
14.0.8117.0416 0.37%
14.0.8117.0416 0.37%
14.0.8117.0416 1.84%
14.0.8117.0416 1.10%
14.0.8117.0416 0.37%
14.0.8089.0726 7.35%
14.0.8089.0726 0.37%
14.0.8089.0726 0.37%
14.0.8089.0726 1.10%
14.0.8050.1202 1.84%

Relationships

Parent processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegEnumKeyExW, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, FreeSid, CheckTokenMembership, AllocateAndInitializeSid, TraceEvent, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, ConvertStringSecurityDescriptorToSecurityDescriptorW, MakeAbsoluteSD, RegDeleteKeyA, CryptReleaseContext, CryptDestroyHash, CryptCreateHash, CryptAcquireContextW, CryptHashData, CryptGetHashParam, QueryServiceStatusEx, CloseServiceHandle, OpenServiceW, OpenSCManagerW, CryptDestroyKey, CryptDeriveKey, CryptEncrypt, CryptDecrypt, RevertToSelf, AccessCheck, IsValidSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, AddAccessAllowedAce, InitializeAcl, GetLengthSid, InitializeSecurityDescriptor, OpenProcessToken, OpenThreadToken, ImpersonateSelf, RegDeleteValueW, RegGetValueW, GetTokenInformation, RegOpenCurrentUser
comctl32.dll
ImageList_Create, ImageList_AddMasked, ImageList_Destroy, ImageList_GetIcon
crypt32.dll
CertFreeCertificateContext, CertGetNameStringW, CertVerifyCertificateChainPolicy
gdi32.dll
StretchBlt, CreateRoundRectRgn, CombineRgn, GetRgnBox, GetTextMetricsW, EnumFontFamiliesExW, GetClipRgn, CreateRectRgn, ExtSelectClipRgn, SelectClipRgn, SetStretchBltMode, PatBlt, LPtoDP, SetMapMode, SetViewportOrgEx, CreateDCW, CreateMetaFileW, SaveDC, SetWindowOrgEx, SetWindowExtEx, RestoreDC, CloseMetaFile, DeleteMetaFile, CreateRectRgnIndirect, CreatePen, LineTo, MoveToEx, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, GetStockObject, GetDeviceCaps, CreateFontIndirectW, GetObjectW, SetBkMode, SetTextColor, SelectObject, DeleteDC, SetBkColor, ExtTextOutW, DeleteObject, CreateSolidBrush
gdiplus.dll
GdipGetImageGraphicsContext, GdipDrawImageI, GdipDrawImageRectI, GdipCloneImage, GdipBitmapGetPixel, GdipCreateBitmapFromResource, GdipCreateBitmapFromScan0, GdipGetImageHeight, GdipCreateImageAttributes, GdipDisposeImageAttributes, GdipDeleteBrush, GdipGetImageWidth, GdipDisposeImage, GdipDeleteGraphics, GdipFree, GdipAlloc, GdipCreatePen1, GdipCreateBitmapFromFile, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromStream, GdipCreateBitmapFromStreamICM, GdipCreateSolidFill, GdipSetPenDashStyle, GdipCreateFromHDC, GdipDrawRectangle, GdipFillRectangle, GdipDrawImageRectRect, GdipCloneBrush, GdipCreateStringFormat, GdipDeleteStringFormat, GdipCreateFontFamilyFromName, GdipDeleteFontFamily, GdipDeleteFont, GdipBitmapSetPixel, GdipCreateLineBrushFromRectI, GdipSetStringFormatAlign, GdipSetStringFormatLineAlign, GdipResetWorldTransform, GdipTranslateWorldTransform, GdipDrawLineI, GdipDrawRectangleI, GdipFillRectangleI, GdipDrawString, GdipCreateFont, GdipSaveImageToFile, GdipSaveImageToStream, GdipBitmapLockBits, GdipBitmapUnlockBits, GdipDrawImageRect, GdipDeletePen, GdipCreateBitmapFromGdiDib, GdipGetImageThumbnail, GdipGetImageDecoders, GdipGetImageDecodersSize, GdipReleaseDC, GdipGetDC, GdipCreateHBITMAPFromBitmap
imm32.dll
ImmGetContext, ImmGetCompositionStringW, ImmSetConversionStatus, ImmGetConversionStatus, ImmAssociateContext, ImmReleaseContext
iphlpapi.dll
GetIfEntry, NotifyRouteChange, GetAdaptersInfo, GetIpAddrTable, GetIpForwardTable, GetIpNetTable
kernel32.dll
DllMain
livenattrav.dll
CreateP2PUPnPNatManagerInternal, GetLiveEchoClient
livetransport.dll
CreateObjectStoreService, CreateTransportService
msacm32.dll
acmStreamSize, acmFormatSuggest, acmMetrics, acmStreamPrepareHeader, acmStreamConvert, acmStreamUnprepareHeader, acmStreamClose, acmStreamOpen
msvcr110.dll
DllMain
msvcr80.dll
DllMain
msvcr90.dll
DllMain
netapi32.dll
NetApiBufferFree, NetServerGetInfo
ole32.dll
CreateILockBytesOnHGlobal, WriteClassStm, OleSetClipboard, RevokeDragDrop, GetHGlobalFromStream, CoTaskMemFree, CreateDataAdviseHolder, OleSaveToStream, CoCreateFreeThreadedMarshaler, StringFromCLSID, ReadClassStm, StgOpenStorageOnILockBytes, OleRun, StgCreateDocfileOnILockBytes, CoCreateInstance, CoSuspendClassObjects, CoCreateGuid, CoInitializeEx, CoUninitialize, CoGetInterfaceAndReleaseStream, CoMarshalInterThreadInterfaceInStream, CoAllowSetForegroundWindow, CoInitializeSecurity, OleUninitialize, CoRegisterClassObject, OleInitialize, CoRevokeClassObject, CoFreeUnusedLibraries, CLSIDFromString, CoSetProxyBlanket, CoInitialize, ReleaseStgMedium, StringFromGUID2, CreateStreamOnHGlobal, CLSIDFromProgID, OleLockRunning, CoTaskMemAlloc, OleRegEnumVerbs, OleRegGetUserType, OleRegGetMiscStatus, CreateOleAdviseHolder, CoWaitForMultipleHandles, IIDFromString, PropVariantClear, CoResumeClassObjects
presenceim.dll
CreatePlatformService, ParseAndSetMSNPPolicy
rpcrt4.dll
UuidFromStringA
setupapi.dll
SetupDiGetClassDevsExW, SetupDiEnumDeviceInfo, SetupDiGetDeviceRegistryPropertyW, SetupDiDestroyDeviceInfoList
shareanything.dll
ShareAnythingRegisterBehaviors
shell32.dll
SHGetFolderPathW, ShellExecuteW, ShellExecuteA, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetMalloc, DragQueryFileW, SHFileOperationW, SHGetFileInfoW, ExtractIconExW, Shell_NotifyIconA, Shell_NotifyIconW, SHAppBarMessage, ShellExecuteExW, SHCreateDirectoryExW, SHGetFolderPathAndSubDirW, SHGetSpecialFolderPathW, SHQueryUserNotificationState, CommandLineToArgvW, SHGetKnownFolderPath
shlwapi.dll
UrlGetPartW, PathFindExtensionW, PathUnquoteSpacesW, PathRemoveArgsW, PathGetArgsW, PathAppendW, StrCmpIW, SHGetValueW, PathRemoveExtensionW, PathStripPathW, PathGetCharTypeW, PathIsDirectoryW, PathFileExistsW, SHCreateStreamOnFileW, PathRemoveFileSpecW, StrCmpNIA, StrStrIA, PathIsDirectoryEmptyW, PathFindFileNameW, UrlCombineW, StrRChrW, SHCreateStreamOnFileEx, StrStrIW, PathAddExtensionW, SHStrDupW
urlmon.dll
ObtainUserAgentString, CreateURLMonikerEx
user32.dll
DllMain
usp10.dll
ScriptItemize, ScriptBreak
uxcontacts.dll
DllMain, UXContactsUnInitProcess, TerminateUXContacts, InitializeUXContacts, UXContactsInitProcess
uxcore.dll
DllMain
uxctl.dll
UxControlsInitProcess, UxControlsCreateObject
uxtheme.dll
IsThemeActive
version.dll
VerQueryValueA, GetFileVersionInfoSizeW, GetFileVersionInfoW, GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueW
wer.dll
WerReportSetParameter, WerReportCloseHandle, WerReportCreate, WerReportAddFile, WerReportSubmit
wininet.dll
InternetSetOptionA, InternetSetOptionW, InternetQueryOptionW, InternetInitializeAutoProxyDll, GetUrlCacheEntryInfoW, InternetGetConnectedStateExW, InternetCloseHandle, InternetSetStatusCallbackA, InternetQueryOptionA, InternetOpenA, InternetWriteFile, HttpEndRequestA, InternetReadFile, InternetQueryDataAvailable, InternetConnectA, HttpOpenRequestA, HttpAddRequestHeadersA, HttpQueryInfoA, InternetCrackUrlA, HttpSendRequestExA, InternetCrackUrlW, InternetCanonicalizeUrlW, InternetGetLastResponseInfoW
winmm.dll
waveInGetNumDevs, waveOutGetNumDevs
wldlog.dll
RetailLoggingFlush, RetailLoggingGetMemoryLog, RetailLoggingDirtyFlushLogs, UninitializeLogging, UninitializeModule, InitializeLogging, InitializeModule, RetailLoggingGetPath, GetZoneLevel, IsRetailLoggingEnabled, SetRetailLogging, ZoneLoggingEnabled, LogOutput
wlidux.dll
WlidUxCreateObject
ws2_32.dll
WSAIoctl, getnameinfo, WSCEnumProtocols, WSCGetProviderPath, WSACloseEvent, WSACreateEvent, freeaddrinfo, getaddrinfo
wtsapi32.dll
WTSRegisterSessionNotification, WTSUnRegisterSessionNotification, WTSQuerySessionInformationW, WTSFreeMemory

msnmsgr.exe

Windows Live Messenger by Microsoft Corporation (Signed)

Remove msnmsgr.exe
Version:   16.4.3505.0912
MD5:   2614f722ed8763eb692fb249ea713554
SHA1:   9d0c8bd9b3717cb7d20620e98e08d46cedb46799
SHA256:   1eed1c2b0a3d24fb87336076640922835ef3740638b619b03b841b13b5ff8698

What is msnmsgr.exe?

Windows Live Messenger (formerly named MSN Messenger) is an instant messaging client. Windows Live Messenger uses the Microsoft Notification Protocol (MSNP) over TCP (and optionally over HTTP to deal with proxies) to connect to Microsoft Messenger service

Overview

msnmsgr.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including Windows Live Essentials published by Microsoft Corporation, Podstawowe programy Windows Live from Microsoft Corporation and Podstawowe programy Windows Live by Microsoft Corporation.

DetailsDetails

File name:msnmsgr.exe
Publisher:Microsoft Corporation
Product name:Windows Live Messenger
Typical file path:C:\Program Files\windows live\messenger\msnmsgr.exe
File version:16.4.3505.0912
Size:4.07 MB (4,272,640 bytes)
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Monday, March 7, 2011
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 8.0
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Microsoft Corporation
10% remove
Windows Live Essentials is a suite of freeware applications by Microsoft that aims to offer integrated and bundled e-mail, instant messaging, photo-sharing, blog publishing, and security services. Essentials programs are designed to integrate well with each other, with Microsoft Windows, and with other Microsoft web-based services such as SkyDrive and Outlook.com, so that they operate as a seamless whole.
Microsoft Corporation
8% remove
Windows Live is the former collective brand name for a set of services and software products from Microsoft; part of their software plus services platform. A majority of these services are Web applications, accessible from a browser, but there are also client-side binary applications that require installation. There are three ways in which Windows Live services are offered: Windows Essentials applications, web services, and mobile servi...
Microsoft Corporation
9% remove
Windows Live "is a way to extend the Windows user experience". Windows Vista provides a link in its user interface to download Windows Live Messenger, and Windows 7 saw the removal of applications such as Windows Mail, Windows Photo Gallery and Windows Movie Maker and replaced with the Windows Essentials suite, a software package that allows the downloading and installation of similar offerings from Windows Live. Windows Live offers int...
Microsoft Corporation
2% remove
Windows Live Messenger is an instant messaging client connects to Microsoft Messenger service. Microsoft announced that Windows Live Messenger will be retired in favor of Skype. Windows Live Messenger's album viewer is based on Windows Photo Gallery and provides users a photo viewing experience for photo albums shared via SkyDrive and Facebook.

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'msnmsgr' → "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program\Windows Live\Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Programas\Windows Live\Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'
  • Firewall exception for 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'
Network connections
Access through an approved Windows firewall exception
  • [TCP] 65.55.5.231:80
  • [TCP] LB260.PARS.COTENDO.net (94.127.75.180:80)
  • [TCP] 65.55.121.232:80
  • [UDP] listens on port 9

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01133995%
    0.028634%
    Kernel CPU:0.00466631%
    0.013761%
    User CPU:0.00667364%
    0.014873%
    Kernel CPU time:24,705,546 ms/min
    100,923,805ms/min
    CPU cycles:1,073,276/sec
    17,470,203/sec
    Context switches:164/sec
    284/sec
    Memory
    Private memory:63.94 MB
    21.59 MB
    Private (maximum):44.78 MB
    Private (minimum):16.27 MB
    Non-paged memory:63.94 MB
    21.59 MB
    Virtual memory:295.91 MB
    140.96 MB
    Virtual memory (peak):308.66 MB
    169.69 MB
    Working set:25.58 MB
    18.61 MB
    Working set (peak):62.3 MB
    37.95 MB
    Page faults:660,585/min
    2,039/min
    I/O
    I/O read transfer:2.18 KB/sec
    1.02 MB/min
    I/O read operations:3/sec
    343/min
    I/O write transfer:1.3 KB/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:6.04 KB/sec
    448.09 KB/min
    I/O other operations:120/sec
    1,671/min
    Resource allocations
    Threads:37
    12
    Handles:837
    600
    GUI GDI count:117
    103
    GUI GDI peak:143
    142
    GUI USER count:113
    49
    GUI USER peak:135
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command lines:
    • "C:\Program Files\windows live\messenger\msnmsgr.exe" /background
    • "C:\Program Files\windows live\messenger\msnmsgr.exe"
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    msnmsgr.exe (main module)
    Total CPU:0.37410742%
    0.272967%
    Kernel CPU:0.02718463%
    0.107585%
    User CPU:0.34692280%
    0.165382%
    CPU cycles:11,099,629/sec
    5,741,424/sec
    Context switches:13/sec
    79/sec
    Memory:4.07 MB
    1.16 MB
    mshtml.dll (Windows Internet Explorer by Microsoft)
    Total CPU:0.00926389%
    Kernel CPU:0.00559426%
    User CPU:0.00366963%
    CPU cycles:1,535,840/sec
    Context switches:56/sec
    Memory:13.69 MB
    ntdll.dll
    Total CPU:0.00757938%
    Kernel CPU:0.00453979%
    User CPU:0.00303960%
    CPU cycles:266,786/sec
    Context switches:1/sec
    Memory:1.66 MB
    UXCore.dll
    Total CPU:0.00339195%
    Kernel CPU:0.00080176%
    User CPU:0.00259019%
    CPU cycles:84,435/sec
    Memory:2.49 MB
    wlidux.dll
    Total CPU:0.00204307%
    Kernel CPU:0.00041538%
    User CPU:0.00162769%
    CPU cycles:51,935/sec
    Memory:2.7 MB
    MSVCR90.dll
    Total CPU:0.00173796%
    Kernel CPU:0.00131194%
    User CPU:0.00042602%
    CPU cycles:35,042/sec
    Memory:652 KB
    LivePlatform.dll
    Total CPU:0.00099203%
    Kernel CPU:0.00044470%
    User CPU:0.00054732%
    CPU cycles:41,808/sec
    Memory:1.03 MB
    WININET.dll
    Total CPU:0.00035598%
    Kernel CPU:0.00015256%
    User CPU:0.00020342%
    CPU cycles:7,528/sec
    Memory:1.72 MB
    MSVCR110.dll
    Total CPU:0.00023085%
    Kernel CPU:0.00005130%
    User CPU:0.00017955%
    CPU cycles:3,298/sec
    Memory:840 KB
    ole32.dll
    Total CPU:0.00013182%
    Kernel CPU:0.00002565%
    User CPU:0.00010617%
    CPU cycles:6,386/sec
    Memory:1.36 MB
    msvcrt.dll (Windows NT CRT DLL by Microsoft)
    Total CPU:0.00005132%
    Kernel CPU:0.00005132%
    User CPU:0.00000000%
    CPU cycles:1,326/sec
    Memory:688 KB
    mswsock.dll
    Total CPU:0.00004535%
    Kernel CPU:0.00002543%
    User CPU:0.00001992%
    CPU cycles:1,340/sec
    Memory:240 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 49.00%
    Windows 7 Home Premium 18.00%
    Windows 7 Ultimate 14.50%
    Windows 7 Professional 3.50%
    Windows Vista Home Premium 3.00%
    Windows 8.1 1.50%
    Windows Vista Business 1.50%
    Windows 8 Pro 1.50%
    Windows 7 Starter 1.50%
    Windows 8 1.50%
    Windows 7 Enterprise 1.00%
    Windows 7 Home Basic 1.00%
    Windows Seven Black Edition 1.00%
    Windows Vista™ Home Premium 0.50%
    Windows 8 Enterprise 0.50%
    Windows 8 Pro with Media Center 0.50%

    Distribution by countryDistribution by country

    United States installs about 24.87% of Windows Live Messenger.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Hewlett-Packard 14.84%
    Dell 12.50%
    ASUS 10.94%
    Acer 10.16%
    Gateway 9.38%
    Toshiba 7.81%
    American Megatrends 7.81%
    Sony 7.81%
    Intel 6.25%
    GIGABYTE 4.69%
    Samsung 3.13%
    Lenovo 1.56%
    MSI 1.56%
    Sahara 1.56%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE