Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.17031 (winblue_gdr.140221-1952) 14.29%
6.3.9600.16384 (winblue_rtm.130821-1623) 8.57%
6.3.9431.0 (winmain_bluemp.130615-1214) 2.86%
6.2.9200.16613 (win8_gdr.130515-1513) 17.14%
6.2.9200.16455 (win8_gdr.121109-1506) 42.86%
6.2.9200.16455 (win8_gdr.121109-1506) 2.86%
6.2.9200.16384 (win8_rtm.120725-1247) 8.57%
6.2.8400.0 (winmain_win8rc.120518-1423) 2.86%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, RegCloseKey, RegQueryValueExW, ConvertStringSidToSidW, CheckTokenMembership
kernel32.dll
Sleep, CreateDirectoryW, GetFileAttributesExW, LocalFree, TryEnterCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, GetModuleFileNameW, MoveFileExW, GetSystemTime, GetEnvironmentVariableW, GetWindowsDirectoryW, FindClose, DeleteFileW, FindNextFileW, CompareFileTime, FindFirstFileW, OutputDebugStringA, TerminateProcess, UnhandledExceptionFilter, GetTickCount, GetSystemTimeAsFileTime, GetCurrentThreadId, WaitForSingleObject, ResetEvent, GetCurrentProcess, DuplicateHandle, OpenProcess, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, GetSystemDirectoryW, FreeLibrary, GetProcAddress, LoadLibraryW, HeapSetInformation, CreateEventW, CloseHandle, SetEvent, GetLastError, WaitForMultipleObjects, GetCurrentProcessId, InterlockedExchange, InterlockedCompareExchange, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter
msvcrt.dll
DllMain
ole32.dll
CoSuspendClassObjects, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoCreateInstance, CoDisconnectContext, CoRevokeClassObject, CoResumeClassObjects, CoRegisterClassObject, CoGetMalloc

TiWorker.exe

Windows Modules Installer Worker by Microsoft

Remove TiWorker.exe
Version:   6.3.9600.16384 (winblue_rtm.130821-1623)
MD5:   b0f39bcb8a7b81e0a78d66210cb7f832
SHA1:   32f7e75039199a36b4fddd72d7871a47e8518f14

Overview

tiworker.exe executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges) typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). and is compiled as a 64 bit program.

DetailsDetails

File name:tiworker.exe
Publisher:Microsoft Corporation
Product name:Windows Modules Installer Worker
Description:Microsoft® Windows® Operating System
Typical file path:C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16384_none_622908ad510eb05b\tiworker.exe
File version:6.3.9600.16384 (winblue_rtm.130821-1623)
Product version:6.3.9600.16384
Size:186 KB (190,464 bytes)
Build date:8/22/2013 11:50 AM
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.07026472%
0.028634%
Kernel CPU:0.02345834%
0.013761%
User CPU:0.04680638%
0.014873%
Kernel CPU time:21 ms/min
100,923,805ms/min
Context switches:35/sec
284/sec
Memory
Private memory:2.28 MB
21.59 MB
Private (maximum):8.12 MB
Private (minimum):8.09 MB
Non-paged memory:2.28 MB
21.59 MB
Virtual memory:47.63 MB
140.96 MB
Virtual memory (peak):50.14 MB
169.69 MB
Working set:7.05 MB
18.61 MB
Working set (peak):8.65 MB
37.95 MB
Resource allocations
Threads:3
12
Handles:134
600

BehaviorsProcess properties

Platform:64-bit
Command line:C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_fa1dc1539b4180d8\tiworker.exe -embedding
Owner:SYSTEM
Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

ResourcesThreads

Averages
 
ntdll.dll
Total CPU:0.19704506%
0.272967%
Kernel CPU:0.02189390%
0.107585%
User CPU:0.17515116%
0.165382%
CPU cycles:5,849,117/sec
5,741,424/sec
Context switches:31/sec
79/sec
Memory:1.66 MB
1.16 MB
TiWorker.exe (main module)
Total CPU:0.06524649%
Kernel CPU:0.06524649%
User CPU:0.00000000%
CPU cycles:1,481,659/sec
Context switches:2/sec
Memory:204 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 37.14%
Windows 8 Pro 20.00%
Windows 8.1 14.29%
Windows 8 Pro with Media Center 8.57%
Windows 8.1 Pro with Media Center 2.86%
Windows 8.1 Enterprise 2.86%
Windows 8.1 Pro 2.86%
Windows 8.1 Pro Preview 2.86%
Windows 8 Single Language 2.86%
Windows 8 Enterprise 2.86%
Windows 8 Release Preview 2.86%

Distribution by countryDistribution by country

United States installs about 54.29% of Windows Modules Installer Worker.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 25.81%
Toshiba 19.35%
Sony 12.90%
Dell 12.90%
Acer 9.68%
Hewlett-Packard 9.68%
Intel 6.45%
Samsung 3.23%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE