What does this .msi install? Check it before you run it
Drop a Windows Installer package to see the product, its version and publisher, who signed it, every file it would put on the computer and where, the registry keys and services it adds, and every custom action that runs a program or script. It works on a Mac, Linux or a phone, where Orca and lessmsi do not run.
The file is read by this tab only. It is not uploaded, not installed and never run.
What you get
- The product: ProductName, ProductVersion, Manufacturer, ProductCode and UpgradeCode from the Property table, and ALLUSERS in words: per-user, per-machine (needs administrator rights) or whichever the person installing can do.
- The signature: the name and organisation on the signing certificate, who issued it, the serial number, the validity dates and the signing time, from the package's
\x05DigitalSignaturestream. A package without one is called unsigned, plainly. - Custom actions, in words: each one that runs a program, a DLL or a script, where that code comes from (stored inside the package, installed by it, or a command line), when it runs, and whether it runs as you or as the SYSTEM account.
- Every file with its install path (the Directory, Component and File tables joined), size and version, and which cabinet holds it; the registry values it writes; the Windows services it installs, with start type and account.
- Summary information: author, creation date, platform (x86, x64, ARM64), languages, the tool that built it and the package code. And every table of the database as a grid you can save as CSV.
Custom action types, decoded
The CustomAction table gives each action a Type number. Its low six bits say what runs and where the code comes from; the higher bits say when and as whom. These are the numbers worth knowing (from Microsoft's Windows Installer reference, "Summary List of All Custom Action Types"):
- 1, 2, 5, 6: code stored inside the package
- A DLL (1), an EXE (2), a JScript (5) or a VBScript (6) kept in the package's Binary table and run from a temporary copy. Most installer helpers are type 1 DLLs. The page names the Binary entry, says whether it really is a Windows DLL or program, and lets you save it to look at it on its own.
- 17, 18, 21, 22: a file the package has just installed
- The same four kinds, but the code is one of the installed files, named by its key in the File table.
- 34 and 50: a command line
- Type 34 runs a command line in one of the installation folders; type 50 runs whatever program a property names. Both can run anything on the computer, cmd.exe and PowerShell included.
- 37, 38, 53, 54: script code written into the package
- JScript or VBScript text held in the table itself (37, 38) or in a property (53, 54). The page shows the first 400 characters.
- 19, 35, 51: no code
- Show an error and stop (19), set a folder path (35), set a property (51). Harmless on their own.
- +1024 and +2048: deferred, and as SYSTEM
- Adding 1024 (0x400) makes an action deferred: it runs while the computer is being changed. Adding 2048 (0x800) to a deferred action makes it run as the LocalSystem account, with full control of the computer, instead of as you. So type 3074 (2 + 1024 + 2048) is an EXE from the Binary table running as SYSTEM, and 3073 the same for a DLL. 8192 (0x2000) hides the action's data from the installation log.
How it reads the package
An .msi is a small relational database inside a Microsoft compound file (the container of old .doc and .xls files). Each table is a stream whose name is packed: two characters from 0-9 A-Z a-z . _ share one UTF-16 code unit (0x3800 + a + 64 × b) behind a 0x4840 marker, so the Property table's stream is called 䡀䕙䓲䕨䜷 (U+4840 and four packed pairs) in a generic compound-file viewer. Every text value is stored once in a string pool (_StringPool lengths, _StringData bytes, in the package's code page) and referred to by number; _Tables and _Columns say which tables exist and the type of each column; rows are stored column by column, integers offset by 0x8000 or 0x80000000. viewhack decodes all of this in the page with its own code, written from Microsoft's documentation of the format.
The same data elsewhere: Orca (in the Windows SDK) and lessmsi on Windows; msiinfo and msidump from msitools on Linux; Get-AuthenticodeSignature in PowerShell for the signature.
What this cannot do
- It does not install or run anything. It only reads the package's bytes, so nothing here can change your computer.
- It cannot extract files from cabinets. The files themselves are packed in .cab streams inside the package (or beside it); they are listed with path, size and version, not unpacked. lessmsi or
msiexec /a(an administrative install) unpacks them on Windows. - A signature check is not a malware scan. The signer's name says who signed, not that the package is safe. This page also does not recompute the package's hash, check the certificate chain or check revocation, so it cannot tell you that the file is unchanged since signing; Windows' Digital Signatures tab can.
- Patches and transforms are read only partly. An .msp shows its targets, description and the transforms inside it; an .mst shows its summary and which tables it changes, since its rows are differences, not whole rows.
- Install paths are the defaults. Folder properties set by a dialog, a command line or a custom action can change them at install time. [NAME] marks a folder decided while installing.