Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.17031 (winblue_gdr.140221-1952) 14.29%
6.3.9600.16384 (winblue_rtm.130821-1623) 8.57%
6.3.9431.0 (winmain_bluemp.130615-1214) 2.86%
6.2.9200.16613 (win8_gdr.130515-1513) 17.14%
6.2.9200.16455 (win8_gdr.121109-1506) 42.86%
6.2.9200.16455 (win8_gdr.121109-1506) 2.86%
6.2.9200.16384 (win8_rtm.120725-1247) 8.57%
6.2.8400.0 (winmain_win8rc.120518-1423) 2.86%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, RegCloseKey, RegQueryValueExW, ConvertStringSidToSidW, CheckTokenMembership
kernel32.dll
Sleep, CreateDirectoryW, GetFileAttributesExW, LocalFree, TryEnterCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, GetModuleFileNameW, MoveFileExW, GetSystemTime, GetEnvironmentVariableW, GetWindowsDirectoryW, FindClose, DeleteFileW, FindNextFileW, CompareFileTime, FindFirstFileW, OutputDebugStringA, TerminateProcess, UnhandledExceptionFilter, GetTickCount, GetSystemTimeAsFileTime, GetCurrentThreadId, WaitForSingleObject, ResetEvent, GetCurrentProcess, DuplicateHandle, OpenProcess, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, GetSystemDirectoryW, FreeLibrary, GetProcAddress, LoadLibraryW, HeapSetInformation, CreateEventW, CloseHandle, SetEvent, GetLastError, WaitForMultipleObjects, GetCurrentProcessId, InterlockedExchange, InterlockedCompareExchange, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter
msvcrt.dll
DllMain
ole32.dll
CoSuspendClassObjects, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoCreateInstance, CoDisconnectContext, CoRevokeClassObject, CoResumeClassObjects, CoRegisterClassObject, CoGetMalloc

TiWorker.exe

Windows Modules Installer Worker by Microsoft

Remove TiWorker.exe
Version:   6.2.9200.16455 (win8_gdr.121109-1506)
MD5:   1417296249f8489531ace2c11572ee2b
SHA1:   db0051955b103bdd351b7d666f1c9f148ae00cf0
SHA256:   77acaac28c5607bc85d4831360b74ff713d8e43d0f411ea2ec0352d8efbee7c1

Overview

tiworker.exe executes as a process under the SYSTEM account with extensive privileges (the system and the administrator accounts have the same file privileges) typically within the context of its parent svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is installed on Windows 8 and is compiled as a 32 bit program.

DetailsDetails

File name:tiworker.exe
Publisher:Microsoft Corporation
Product name:Windows Modules Installer Worker
Description:Microsoft® Windows® Operating System
Typical file path:C:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16384_none_622908ad510eb05b\tiworker.exe
File version:6.2.9200.16455 (win8_gdr.121109-1506)
Product version:6.2.9200.16455
Size:181.5 KB (185,856 bytes)
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.56844628%
0.028634%
Kernel CPU:0.27152043%
0.013761%
User CPU:0.29692585%
0.014873%
Context switches:65/sec
284/sec
Memory
Private memory:2.02 MB
21.59 MB
Private (maximum):7.95 MB
Private (minimum):7.9 MB
Non-paged memory:2.02 MB
21.59 MB
Virtual memory:39.56 MB
140.96 MB
Virtual memory (peak):40.07 MB
169.69 MB
Working set:7.88 MB
18.61 MB
Working set (peak):8.92 MB
37.95 MB
Resource allocations
Threads:4
12
Handles:148
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:C:\windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16455_none_062bdf1d989801d0\tiworker.exe -embedding
Owner:SYSTEM
Parent process:svchost.exe (Host Process for Windows Services by Microsoft Corporation)

ResourcesThreads

Averages
 
TiWorker.exe (main module)
CPU cycles:499,188/sec
5,741,424/sec
Memory:196 KB
1.16 MB
ntdll.dll
CPU cycles:14,873,909/sec
Context switches:14/sec
Memory:1.41 MB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8 37.14%
Windows 8 Pro 20.00%
Windows 8.1 14.29%
Windows 8 Pro with Media Center 8.57%
Windows 8.1 Pro with Media Center 2.86%
Windows 8.1 Enterprise 2.86%
Windows 8.1 Pro 2.86%
Windows 8.1 Pro Preview 2.86%
Windows 8 Single Language 2.86%
Windows 8 Enterprise 2.86%
Windows 8 Release Preview 2.86%

Distribution by countryDistribution by country

United States installs about 54.29% of Windows Modules Installer Worker.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 25.81%
Toshiba 19.35%
Sony 12.90%
Dell 12.90%
Acer 9.68%
Hewlett-Packard 9.68%
Intel 6.45%
Samsung 3.23%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE