Shoutbox

Windows Live Messenger & The Registry - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Skype & Live Messenger (/forumdisplay.php?fid=10)
+----- Thread: Windows Live Messenger & The Registry (/showthread.php?tid=95941)

Windows Live Messenger & The Registry by Chrissy on 12-01-2010 at 03:21 PM

Hey There.

When you sign into Windows Live Messenger with Plus!, it adds a registry folder to

HKCU\Software\Patchou\Messenger Plus! Live\EMAIL YOU SIGNED IN WITH.

Let's say I don't have Plus! installed. Is their I way I can detect from pulling a reg file or something to detect if a certain Windows Live ID has logged in from a pc?

Cheers.


RE: Windows Live Messenger & The Registry by Chancer on 12-01-2010 at 10:40 PM

There are (or there used to be) folders with your ID number (or code?), but I don't know if you can discover what e-mail address that ID belongs or not.


RE: Windows Live Messenger & The Registry by Chrissy on 12-01-2010 at 10:42 PM

Is there nothing I can check to see of a WL ID has logged in via the specific computer?

I appreciate your help!


RE: Windows Live Messenger & The Registry by CookieRevised on 12-01-2010 at 11:17 PM

There are 3 main things to check:

1) There are the many registry keys you can check for that.
But, as with all registry keys (or the other methods below for that matter), they can be spoofed and added manually.

2) Then there are some debug logs which Messenger creates during its running (if enabled) which you can check.

3) And there are also the (sub)directories which are created per user to hold data (eg: contacts cache, dps, custom icons, etc.)

Note that many of those things will only give you the hashed Windows Live ID. This is that cryptic number like '23145678'.
Only in certain logs the actual Windows Live ID (the email) is visible.
(hence why you should never attach your debug logs of Messenger in a public forum).

And you can not derive the actual email from that hashed numeric value.