Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

7.00.9600.16384 (winblue_rtm.130821-1623) 1.79%
7.00.9600.16384 (winblue_rtm.130821-1623) 0.05%
7.00.9600.16384 (winblue_rtm.130821-1623) 2.79%
7.00.9431.0 (winmain_bluemp.130615-1214) 0.23%
7.00.9431.0 (winmain_bluemp.130615-1214) 0.03%
7.00.9200.16384 (win8_rtm.120725-1247) 0.69%
7.00.9200.16384 (win8_rtm.120725-1247) 0.51%
7.00.9200.16384 (win8_rtm.120725-1247) 0.13%
7.00.9200.16384 (win8_rtm.120725-1247) 0.33%
7.00.9200.16384 (win8_rtm.120725-1247) 6.98%
7.00.9200.16384 (win8_rtm.120725-1247) 1.15%
7.00.9200.16384 (win8_rtm.120725-1247) 6.60%
7.00.9200.16384 (win8_rtm.120725-1247) 0.49%
7.00.8400.0 (winmain_win8rc.120518-1423) 0.08%
7.00.8400.0 (winmain_win8rc.120518-1423) 0.08%
7.00.8250.0 (winmain_win8beta.120217-1520) 0.03%
7.00.8102.0 (winmain_win8m3.110823-1455) 0.08%
7.00.7600.16385 (win7_rtm.090713-1255) 8.18%
7.00.7600.16385 (win7_rtm.090713-1255) 37.60%
7.00.7600.16385 (win7_rtm.090713-1255) 2.40%
7.00.7600.16385 (win7_rtm.090713-1255) 3.71%
7.00.7600.16385 (win7_rtm.090713-1255) 13.39%
7.00.7600.16385 (win7_rtm.090713-1255) 2.15%
7.00.7600.16385 (win7_rtm.090713-1255) 0.15%
7.00.7600.16385 (win7_rtm.090713-1255) 0.03%
View more

Relationships

Parent process
Child processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegOpenKeyExW, OpenProcessToken, InitializeAcl, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumKeyExW, InitializeSecurityDescriptor, RegQueryValueExW, AdjustTokenPrivileges, LookupPrivilegeValueW, RegLoadKeyW, RegUnLoadKeyW, SetSecurityDescriptorOwner, IsValidSid, GetLengthSid, CopySid, GetTokenInformation, AddAce, GetAce, GetAclInformation, AddAccessAllowedAce, SetServiceStatus, StartServiceCtrlDispatcherW, SetSecurityDescriptorDacl, OpenThreadToken, LookupAccountNameW, RegNotifyChangeKeyValue, RegisterServiceCtrlHandlerExW, RegEnumValueW, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, LookupAccountSidW, CreateWellKnownSid, ReportEventW, AddAccessDeniedAce, SetTokenInformation, IsValidAcl, DeregisterEventSource, RegisterEventSourceW, SetSecurityDescriptorGroup, RegisterTraceGuidsW, UnregisterTraceGuids, TraceEvent, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, ImpersonateLoggedOnUser, GetSecurityDescriptorLength, RevertToSelf, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorA, CheckTokenMembership
kernel32.dll
UnmapViewOfFile, LCMapStringW, lstrcmpW, CompareFileTime, RemoveDirectoryW, LoadLibraryW, FindNextFileW, GetCommandLineW, MapViewOfFile, GetDriveTypeW, GetVersionExW, CreateEventW, DuplicateHandle, CreateFileW, GetLocalTime, SetEvent, GetCurrentThread, WaitForSingleObject, GetSystemDefaultLCID, VerSetConditionMask, VerifyVersionInfoW, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, RtlUnwind, OutputDebugStringA, GetStartupInfoA, InterlockedCompareExchange, GetEnvironmentVariableW, CreateFileMappingW, GetLocaleInfoW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, SearchPathW, CopyFileW, ExpandEnvironmentStringsW, GetFileAttributesW, DeleteFileW, FindFirstFileW, lstrlenA, FindClose, FindResourceExW, LockResource, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, FreeLibrary, HeapSetInformation, SetPriorityClass, SetEnvironmentVariableW, CreateMutexW, InterlockedExchange, GetVersionExA, HeapSize, HeapReAlloc, HeapAlloc, Sleep, GetModuleFileNameW, lstrcmpiW, LeaveCriticalSection, EnterCriticalSection, SetLastError, GetProcessHeap, HeapFree, InterlockedDecrement, InterlockedIncrement, DeleteCriticalSection, InitializeCriticalSection, RaiseException, GetVolumeInformationW, GetCurrentProcess, GetSystemDirectoryW, GetUserDefaultLCID, GetModuleHandleW, GetModuleHandleExW, GetProcAddress, GetLastError, CloseHandle, WideCharToMultiByte, CompareStringW, lstrlenW, HeapDestroy, FormatMessageW, ReleaseMutex, OpenMutexW, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetTimeFormatW, LocalFree, GetStringTypeExW, OutputDebugStringW, CreateFileA, FlushViewOfFile, DeleteFileA, CopyFileA, CreateThread, WaitForMultipleObjects
mpr.dll
WNetGetConnectionW
msvcrt.dll
DllMain
netapi32.dll
NetShareEnum, NetApiBufferFree
ole32.dll
CoCreateInstance, CoInitializeEx, CoUninitialize, CoTaskMemAlloc, CoTaskMemRealloc, CoRevokeClassObject, CoRegisterClassObject, CoInitializeSecurity, CLSIDFromProgID, CoTaskMemFree, CoInitialize, CoImpersonateClient, CoRevertToSelf
shell32.dll
SHFileOperationW, SHGetFolderPathW
shlwapi.dll
PathSkipRootW, PathStripToRootW, PathIsUNCServerShareW, PathIsUNCServerW, PathIsUNCW, SHGetValueW, PathAddBackslashW, SHSetValueW, PathRemoveBackslashW, PathAppendW, SHDeleteKeyW, PathFileExistsW, SHStrDupW, SHCopyKeyW, SHEnumKeyExW, SHEnumValueW, SHRegGetValueW, SHDeleteValueW
user32.dll
GetKeyboardLayout, CharNextW, PeekMessageW, DispatchMessageW, MsgWaitForMultipleObjects, LoadStringW, UnregisterClassA
userenv.dll
GetUserProfileDirectoryW, GetDefaultUserProfileDirectoryW, GetProfilesDirectoryW, GetAllUsersProfileDirectoryW
wtsapi32.dll
WTSQueryUserToken, WTSFreeMemory, WTSEnumerateSessionsW

SearchIndexer.exe

Microsoft Windows Search Indexer by Microsoft

Remove SearchIndexer.exe
Version:   7.00.7600.16385 (win7_rtm.090713-1255)
MD5:   622d95520182f6d3d05310d5810ca8b3
SHA1:   3cd4818cedb6c619263085c3d27026798b867ff9
SHA256:   8162f06721e7b994933639d45beef34643db36c25ae9dd8593991f45d5c2dfcc
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is SearchIndexer.exe?

Windows Search for the desktop and the enterprise delivers fast search capabilities for files, e-mail, documents, and more, provides performance enhancements and support for enterprise-critical features, and is easy to manage and extend with customized functionality.

About SearchIndexer.exe (from Microsoft)

Windows Search provides an easy and comprehensive solution for finding and organizing the content you care about, whether it's on your PC, in an e-mail message or attachment, on a remote file share,

DetailsDetails

File name:SearchIndexer.exe
Publisher:Microsoft Corporation
Product name:Microsoft Windows Search Indexer
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\searchindexer.exe
Original name:SearchIndexer.exe.mui
File version:7.00.7600.16385 (win7_rtm.090713-1255)
Product version:7.00.7600.16385
Size:418 KB (428,032 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:6.116369
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • WSearch
  • 'WSearch' (Windows Search)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00979516%
0.028634%
Kernel CPU:0.00535879%
0.013761%
User CPU:0.00443637%
0.014873%
Kernel CPU time:8,452,169 ms/min
100,923,805ms/min
User CPU time:2 ms/min
0 ms/min
CPU cycles:918,970/sec
17,470,203/sec
Context switches:8/sec
284/sec
Memory
Private memory:27.08 MB
21.59 MB
Private (maximum):17.43 MB
Private (minimum):8.53 MB
Non-paged memory:27.08 MB
21.59 MB
Virtual memory:115.62 MB
140.96 MB
Virtual memory (peak):136.45 MB
169.69 MB
Working set:13.26 MB
18.61 MB
Working set (peak):20.42 MB
37.95 MB
Page faults:289,727/min
2,039/min
I/O
I/O read transfer:16.72 KB/sec
1.02 MB/min
I/O read operations:8/sec
343/min
I/O write transfer:126.3 KB/sec
274.99 KB/min
I/O write operations:9/sec
227/min
I/O other transfer:17.8 KB/sec
448.09 KB/min
I/O other operations:225/sec
1,671/min
Resource allocations
Threads:13
12
Handles:745
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:C:\Windows\System32\searchindexer.exe /embedding
Owner:SYSTEM
Windows Service
Service name:SYSTEM\CurrentControlSet\Services\WSearch
Display name:WSearch
Description:“Provides content indexing, property caching, and search results for files, e-mail, and other content.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
MSSRCH.DLL
Total CPU:0.05689404%
0.272967%
Kernel CPU:0.00992747%
0.107585%
User CPU:0.04696657%
0.165382%
CPU cycles:1,085,911/sec
5,741,424/sec
Context switches:1/sec
79/sec
Memory:1.35 MB
1.16 MB
ntdll.dll
Total CPU:0.03337145%
Kernel CPU:0.01626014%
User CPU:0.01711132%
CPU cycles:870,062/sec
Context switches:2/sec
Memory:1.23 MB
sechost.dll
Total CPU:0.00434951%
Kernel CPU:0.00230537%
User CPU:0.00204414%
CPU cycles:94,811/sec
Memory:100 KB
TQUERY.DLL
Total CPU:0.00108285%
Kernel CPU:0.00065094%
User CPU:0.00043192%
CPU cycles:48,178/sec
Memory:1.49 MB
SearchIndexer.exe (main module)
Total CPU:0.00094559%
Kernel CPU:0.00074298%
User CPU:0.00020260%
CPU cycles:22,936/sec
Memory:424 KB
ESENT.dll
Total CPU:0.00091178%
Kernel CPU:0.00073434%
User CPU:0.00017744%
CPU cycles:30,280/sec
Memory:1.63 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 76.42%
Windows Vista Home Premium 11.38%
Windows Vista Ultimate 6.50%
Windows Vista Home Basic 4.88%
Windows Vista Business 0.81%

Distribution by countryDistribution by country

United States installs about 64.96% of Microsoft Windows Search Indexer.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 31.67%
Gateway 13.33%
Intel 13.33%
Hewlett-Packard 12.50%
Toshiba 6.67%
American Megatrends 5.83%
Compaq 3.33%
Lenovo 3.33%
Sahara 3.33%
ASUS 3.33%
Sony 1.67%
Acer 1.67%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE