viewhack

What does this .msi install? Check it before you run it

Drop a Windows Installer package to see the product, its version and publisher, who signed it, every file it would put on the computer and where, the registry keys and services it adds, and every custom action that runs a program or script. It works on a Mac, Linux or a phone, where Orca and lessmsi do not run.

The file is read by this tab only. It is not uploaded, not installed and never run.

What you get

Custom action types, decoded

The CustomAction table gives each action a Type number. Its low six bits say what runs and where the code comes from; the higher bits say when and as whom. These are the numbers worth knowing (from Microsoft's Windows Installer reference, "Summary List of All Custom Action Types"):

1, 2, 5, 6: code stored inside the package
A DLL (1), an EXE (2), a JScript (5) or a VBScript (6) kept in the package's Binary table and run from a temporary copy. Most installer helpers are type 1 DLLs. The page names the Binary entry, says whether it really is a Windows DLL or program, and lets you save it to look at it on its own.
17, 18, 21, 22: a file the package has just installed
The same four kinds, but the code is one of the installed files, named by its key in the File table.
34 and 50: a command line
Type 34 runs a command line in one of the installation folders; type 50 runs whatever program a property names. Both can run anything on the computer, cmd.exe and PowerShell included.
37, 38, 53, 54: script code written into the package
JScript or VBScript text held in the table itself (37, 38) or in a property (53, 54). The page shows the first 400 characters.
19, 35, 51: no code
Show an error and stop (19), set a folder path (35), set a property (51). Harmless on their own.
+1024 and +2048: deferred, and as SYSTEM
Adding 1024 (0x400) makes an action deferred: it runs while the computer is being changed. Adding 2048 (0x800) to a deferred action makes it run as the LocalSystem account, with full control of the computer, instead of as you. So type 3074 (2 + 1024 + 2048) is an EXE from the Binary table running as SYSTEM, and 3073 the same for a DLL. 8192 (0x2000) hides the action's data from the installation log.

How it reads the package

An .msi is a small relational database inside a Microsoft compound file (the container of old .doc and .xls files). Each table is a stream whose name is packed: two characters from 0-9 A-Z a-z . _ share one UTF-16 code unit (0x3800 + a + 64 × b) behind a 0x4840 marker, so the Property table's stream is called 䡀䕙䓲䕨䜷 (U+4840 and four packed pairs) in a generic compound-file viewer. Every text value is stored once in a string pool (_StringPool lengths, _StringData bytes, in the package's code page) and referred to by number; _Tables and _Columns say which tables exist and the type of each column; rows are stored column by column, integers offset by 0x8000 or 0x80000000. viewhack decodes all of this in the page with its own code, written from Microsoft's documentation of the format.

The same data elsewhere: Orca (in the Windows SDK) and lessmsi on Windows; msiinfo and msidump from msitools on Linux; Get-AuthenticodeSignature in PowerShell for the signature.

What this cannot do

  • It does not install or run anything. It only reads the package's bytes, so nothing here can change your computer.
  • It cannot extract files from cabinets. The files themselves are packed in .cab streams inside the package (or beside it); they are listed with path, size and version, not unpacked. lessmsi or msiexec /a (an administrative install) unpacks them on Windows.
  • A signature check is not a malware scan. The signer's name says who signed, not that the package is safe. This page also does not recompute the package's hash, check the certificate chain or check revocation, so it cannot tell you that the file is unchanged since signing; Windows' Digital Signatures tab can.
  • Patches and transforms are read only partly. An .msp shows its targets, description and the transforms inside it; an .mst shows its summary and which tables it changes, since its rows are differences, not whole rows.
  • Install paths are the defaults. Folder properties set by a dialog, a command line or a custom action can change them at install time. [NAME] marks a folder decided while installing.