Solved WmiPrvSE.exe hogging processor

Nick Wright

Gadgeteer
Member
Messages
43
Location
Chester U.K.
Hi!
I have an ongoing problem with WmiPrvSE.exe, - every now and again it seems to hog the processor and maxes it out, -when I open the task manager I can see that the processor is running at 100% with WmiPrvSE.exe accounting for the lions share of that. -Its a problem because I can`t run any sort of music program or media player without it pausing in the middle of playing a track or film (it makes a horrendous noise too), its also causing problems with other applications - interrupting their operation. -I sometimes Broadcast to a server and can`t really afford to put up with this problem because its interrupting my programs. - I have had to switch to another windows 7 PC for now or at least until I can cure this problem.
Has anybody else come across this problem and is there a viable fix for it? - I understand that this is a essential windows service and is needed for the anti-virus program (defender), someone suggested to me that a wi-fi driver helper application that uses the service was known to cause this problem, but I am on a wired lan and have disabled the wi-fi, and the problem still occurs .
Anybody?
 

My Computer

System One

  • OS
    Windows 8 Poo Edition (& Windows 7 Premium)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Lenovo 2561 (& a Pavillion H.P.P6)
    CPU
    Core i5 i5-2120 / 3.3 GHz (HP= Core i3-2120)
    Motherboard
    ECS H61 MATX (HP =H61 m/Bd)
    Memory
    8,077 MB DDR3 1333Mhz SDRAM (HP= Same)
    Graphics Card(s)
    Intel HD Integrated (HP= Palit 2GB Nvidia GeForce GT 630)
    Sound Card
    Soundblaster ZxR (Hp= Realtek ALC 656 )
    Monitor(s) Displays
    Dell S2340T/Samsung SA100 (Hp= SA-100)
    Screen Resolution
    1920 x 1080( HP= Same)
    Hard Drives
    120GB SSD,2TB 7200rpm SATA II,1.5TB 7200rpm SATA II,USB2 2TB seagate SATA II, USB2 500GB Seagate SATA II, ,USB3 4TB Seagate SATA II , USB3 64GB (Readyboost) Thumb drive, microSD(a) 32GB, microSD(b) 64GB, microSD(c) 2GB in USB adapter (recovery keys),
    PSU
    240W/(500W)
    Case
    Generic Lenovo(mini Tower)
    Cooling
    Generic single fan(same)
    Keyboard
    Emprex 6310U and Lenovo SK-8861 cordless (Hp=KMO 2004 cordless)
    Mouse
    Tecknet M002 and Logitech T620 Touch mouse & Lenovo cordless (2 workstations) (HP= KMO2002 cordlesss
    Internet Speed
    100MB
    Browser
    IE11 + Firefox
    Antivirus
    Defender(PC1),McAffee(PC2),Norton 360(PC3).
    Other Info
    I have 3 Systems, this one (lenovo) & the P6 which has nearly identical specs but runs windows 7 (considerably more reliably.)
    and a Vista laptop which also has no problems -I actually LIKE vista (ooh - controversial!!)
The process WMIPrvSE.exe is a WMI Provider host. These get created when an application or script running on the machine queries WMI and causes a provider host to be spun up to satisfy the request. If you're seeing lots of activity in wmiprvse.exe processes, you have something (or some things) making heavy use of WMI on your machine.

Is there a pattern at all to when this seems to occur?
 

My Computer

System One

  • OS
    Windows 8.1 x64
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom
    CPU
    Intel Core i7 4790K @ 4.5GHz
    Motherboard
    Asus Maximus Hero VII
    Memory
    32GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX970
    Sound Card
    Realtek HD Audio
    Hard Drives
    1x Samsung 250GB SSD
    4x WD RE 2TB (RAIDZ)
    PSU
    Corsair AX760i
    Case
    Fractal Design Define R4
    Cooling
    Noctua NH-D15
Hi, thanks for answering - wasn`t sure where to ask this so thanks for moving it to the right location.

There doesn`t seem to be a regular pattern as such but I would say it does occur every 10 minutes or so on average, - in saying that, there could be a gap of 20 minutes between occurrences or just 5 minutes, it seems quite random.
I have tried disabling things like my Livedrive backup, Dropbox, Skydrive etc and running with nothing showing in the task bar to try to isolate it but so far without success. Whatever I do , it still comes back. I have also run antispyware scans in case it is a Trojan or malware. -I used Superantispyware and malwarebytes. (Nothing found).
 

My Computer

System One

  • OS
    Windows 8 Poo Edition (& Windows 7 Premium)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Lenovo 2561 (& a Pavillion H.P.P6)
    CPU
    Core i5 i5-2120 / 3.3 GHz (HP= Core i3-2120)
    Motherboard
    ECS H61 MATX (HP =H61 m/Bd)
    Memory
    8,077 MB DDR3 1333Mhz SDRAM (HP= Same)
    Graphics Card(s)
    Intel HD Integrated (HP= Palit 2GB Nvidia GeForce GT 630)
    Sound Card
    Soundblaster ZxR (Hp= Realtek ALC 656 )
    Monitor(s) Displays
    Dell S2340T/Samsung SA100 (Hp= SA-100)
    Screen Resolution
    1920 x 1080( HP= Same)
    Hard Drives
    120GB SSD,2TB 7200rpm SATA II,1.5TB 7200rpm SATA II,USB2 2TB seagate SATA II, USB2 500GB Seagate SATA II, ,USB3 4TB Seagate SATA II , USB3 64GB (Readyboost) Thumb drive, microSD(a) 32GB, microSD(b) 64GB, microSD(c) 2GB in USB adapter (recovery keys),
    PSU
    240W/(500W)
    Case
    Generic Lenovo(mini Tower)
    Cooling
    Generic single fan(same)
    Keyboard
    Emprex 6310U and Lenovo SK-8861 cordless (Hp=KMO 2004 cordless)
    Mouse
    Tecknet M002 and Logitech T620 Touch mouse & Lenovo cordless (2 workstations) (HP= KMO2002 cordlesss
    Internet Speed
    100MB
    Browser
    IE11 + Firefox
    Antivirus
    Defender(PC1),McAffee(PC2),Norton 360(PC3).
    Other Info
    I have 3 Systems, this one (lenovo) & the P6 which has nearly identical specs but runs windows 7 (considerably more reliably.)
    and a Vista laptop which also has no problems -I actually LIKE vista (ooh - controversial!!)
You can enable WMI tracing (it's not on by default) by doing the following on Win8:

  • Open Event Viewer
  • Click View > Show Analytic and Debug Logs
  • Browse to Applications and Services Logs > Microsoft > Windows > WMI-Activity
  • Right-click on both the "Debug" and "Trace" log options within this folder, and select "Enable Log" for both (the "Operational" log should already be enabled and logging generic events)

Reboot, and after the next time you see high activity in wmiprvse.exe, see if there's any activity in these two newly-enabled logs.
 

My Computer

System One

  • OS
    Windows 8.1 x64
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom
    CPU
    Intel Core i7 4790K @ 4.5GHz
    Motherboard
    Asus Maximus Hero VII
    Memory
    32GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX970
    Sound Card
    Realtek HD Audio
    Hard Drives
    1x Samsung 250GB SSD
    4x WD RE 2TB (RAIDZ)
    PSU
    Corsair AX760i
    Case
    Fractal Design Define R4
    Cooling
    Noctua NH-D15
OK, thanks -will give that a try tomorrow, - bit occupied at the moment, -one of my USB external drives is dying (different PC) and I`m transferring what I can to a new one.
Thanks for the help!
 

My Computer

System One

  • OS
    Windows 8 Poo Edition (& Windows 7 Premium)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Lenovo 2561 (& a Pavillion H.P.P6)
    CPU
    Core i5 i5-2120 / 3.3 GHz (HP= Core i3-2120)
    Motherboard
    ECS H61 MATX (HP =H61 m/Bd)
    Memory
    8,077 MB DDR3 1333Mhz SDRAM (HP= Same)
    Graphics Card(s)
    Intel HD Integrated (HP= Palit 2GB Nvidia GeForce GT 630)
    Sound Card
    Soundblaster ZxR (Hp= Realtek ALC 656 )
    Monitor(s) Displays
    Dell S2340T/Samsung SA100 (Hp= SA-100)
    Screen Resolution
    1920 x 1080( HP= Same)
    Hard Drives
    120GB SSD,2TB 7200rpm SATA II,1.5TB 7200rpm SATA II,USB2 2TB seagate SATA II, USB2 500GB Seagate SATA II, ,USB3 4TB Seagate SATA II , USB3 64GB (Readyboost) Thumb drive, microSD(a) 32GB, microSD(b) 64GB, microSD(c) 2GB in USB adapter (recovery keys),
    PSU
    240W/(500W)
    Case
    Generic Lenovo(mini Tower)
    Cooling
    Generic single fan(same)
    Keyboard
    Emprex 6310U and Lenovo SK-8861 cordless (Hp=KMO 2004 cordless)
    Mouse
    Tecknet M002 and Logitech T620 Touch mouse & Lenovo cordless (2 workstations) (HP= KMO2002 cordlesss
    Internet Speed
    100MB
    Browser
    IE11 + Firefox
    Antivirus
    Defender(PC1),McAffee(PC2),Norton 360(PC3).
    Other Info
    I have 3 Systems, this one (lenovo) & the P6 which has nearly identical specs but runs windows 7 (considerably more reliably.)
    and a Vista laptop which also has no problems -I actually LIKE vista (ooh - controversial!!)
Good luck - I'll try to keep an eye on this as I start traveling again tomorrow.
 

My Computer

System One

  • OS
    Windows 8.1 x64
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom
    CPU
    Intel Core i7 4790K @ 4.5GHz
    Motherboard
    Asus Maximus Hero VII
    Memory
    32GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX970
    Sound Card
    Realtek HD Audio
    Hard Drives
    1x Samsung 250GB SSD
    4x WD RE 2TB (RAIDZ)
    PSU
    Corsair AX760i
    Case
    Fractal Design Define R4
    Cooling
    Noctua NH-D15
OK started the logging process and almost immediately the processor started maxing out again but on examining the logs I can only see the process cimwill32.dll running at the times of the spikes

Here is an example of the log:-

Log Name: Microsoft-Windows-WMI-Activity/Operational
Source: Microsoft-Windows-WMI-Activity
Date: 12/05/2013 13:43:57
Event ID: 5857
Task Category: None
Level: Information
Keywords:
User: NETWORK SERVICE
Computer: LUNA
Description:
CIMWin32 provider started with result code 0x0. HostProcess = wmiprvse.exe; ProcessID = 4844; ProviderPath = %systemroot%\system32\wbem\cimwin32.dll
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WMI-Activity" Guid="{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}" />
<EventID>5857</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2013-05-12T12:43:57.281362300Z" />
<EventRecordID>6001</EventRecordID>
<Correlation />
<Execution ProcessID="4844" ThreadID="5072" />
<Channel>Microsoft-Windows-WMI-Activity/Operational</Channel>
<Computer>LUNA</Computer>
<Security UserID="S-1-5-20" />
</System>
<UserData>
<Operation_StartedOperational xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
<ProviderName>CIMWin32</ProviderName>
<Code>0x0</Code>
<HostProcess>wmiprvse.exe</HostProcess>
<ProcessID>4844</ProcessID>
<ProviderPath>%systemroot%\system32\wbem\cimwin32.dll</ProviderPath>
</Operation_StartedOperational>
</UserData>
</Event>

-All double dutch to me I`m afraid?
 

My Computer

System One

  • OS
    Windows 8 Poo Edition (& Windows 7 Premium)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Lenovo 2561 (& a Pavillion H.P.P6)
    CPU
    Core i5 i5-2120 / 3.3 GHz (HP= Core i3-2120)
    Motherboard
    ECS H61 MATX (HP =H61 m/Bd)
    Memory
    8,077 MB DDR3 1333Mhz SDRAM (HP= Same)
    Graphics Card(s)
    Intel HD Integrated (HP= Palit 2GB Nvidia GeForce GT 630)
    Sound Card
    Soundblaster ZxR (Hp= Realtek ALC 656 )
    Monitor(s) Displays
    Dell S2340T/Samsung SA100 (Hp= SA-100)
    Screen Resolution
    1920 x 1080( HP= Same)
    Hard Drives
    120GB SSD,2TB 7200rpm SATA II,1.5TB 7200rpm SATA II,USB2 2TB seagate SATA II, USB2 500GB Seagate SATA II, ,USB3 4TB Seagate SATA II , USB3 64GB (Readyboost) Thumb drive, microSD(a) 32GB, microSD(b) 64GB, microSD(c) 2GB in USB adapter (recovery keys),
    PSU
    240W/(500W)
    Case
    Generic Lenovo(mini Tower)
    Cooling
    Generic single fan(same)
    Keyboard
    Emprex 6310U and Lenovo SK-8861 cordless (Hp=KMO 2004 cordless)
    Mouse
    Tecknet M002 and Logitech T620 Touch mouse & Lenovo cordless (2 workstations) (HP= KMO2002 cordlesss
    Internet Speed
    100MB
    Browser
    IE11 + Firefox
    Antivirus
    Defender(PC1),McAffee(PC2),Norton 360(PC3).
    Other Info
    I have 3 Systems, this one (lenovo) & the P6 which has nearly identical specs but runs windows 7 (considerably more reliably.)
    and a Vista laptop which also has no problems -I actually LIKE vista (ooh - controversial!!)
Closing this thread. Still no wiser unfortunately. -Guess I`ll just have to put up with it.
 

My Computer

System One

  • OS
    Windows 8 Poo Edition (& Windows 7 Premium)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Lenovo 2561 (& a Pavillion H.P.P6)
    CPU
    Core i5 i5-2120 / 3.3 GHz (HP= Core i3-2120)
    Motherboard
    ECS H61 MATX (HP =H61 m/Bd)
    Memory
    8,077 MB DDR3 1333Mhz SDRAM (HP= Same)
    Graphics Card(s)
    Intel HD Integrated (HP= Palit 2GB Nvidia GeForce GT 630)
    Sound Card
    Soundblaster ZxR (Hp= Realtek ALC 656 )
    Monitor(s) Displays
    Dell S2340T/Samsung SA100 (Hp= SA-100)
    Screen Resolution
    1920 x 1080( HP= Same)
    Hard Drives
    120GB SSD,2TB 7200rpm SATA II,1.5TB 7200rpm SATA II,USB2 2TB seagate SATA II, USB2 500GB Seagate SATA II, ,USB3 4TB Seagate SATA II , USB3 64GB (Readyboost) Thumb drive, microSD(a) 32GB, microSD(b) 64GB, microSD(c) 2GB in USB adapter (recovery keys),
    PSU
    240W/(500W)
    Case
    Generic Lenovo(mini Tower)
    Cooling
    Generic single fan(same)
    Keyboard
    Emprex 6310U and Lenovo SK-8861 cordless (Hp=KMO 2004 cordless)
    Mouse
    Tecknet M002 and Logitech T620 Touch mouse & Lenovo cordless (2 workstations) (HP= KMO2002 cordlesss
    Internet Speed
    100MB
    Browser
    IE11 + Firefox
    Antivirus
    Defender(PC1),McAffee(PC2),Norton 360(PC3).
    Other Info
    I have 3 Systems, this one (lenovo) & the P6 which has nearly identical specs but runs windows 7 (considerably more reliably.)
    and a Vista laptop which also has no problems -I actually LIKE vista (ooh - controversial!!)
Sorry - been traveling without internet access off and on for the last month. I would recommend running a process monitor log along with this logging and stopping the process monitor logging (file > save) when the issue occurs. Since it's cimwin32, some process is running and querying WMI, but we don't know if it's some new process or if an existing one is doing so, but it's likely calling native classes. A process monitor log should give more insight here.
 

My Computer

System One

  • OS
    Windows 8.1 x64
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom
    CPU
    Intel Core i7 4790K @ 4.5GHz
    Motherboard
    Asus Maximus Hero VII
    Memory
    32GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX970
    Sound Card
    Realtek HD Audio
    Hard Drives
    1x Samsung 250GB SSD
    4x WD RE 2TB (RAIDZ)
    PSU
    Corsair AX760i
    Case
    Fractal Design Define R4
    Cooling
    Noctua NH-D15

My Computer

System One

  • OS
    W8.1 x64
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba Satellite C55T-A5394
    CPU
    i3
    Memory
    6GB
    Graphics Card(s)
    Intel HD 4000
    Browser
    FF
    Antivirus
    Defender
i also have this problem how can i fix it though
 

My Computer

System One

  • OS
    windows 8
    Computer type
    Laptop
    System Manufacturer/Model
    lenovo g585
    CPU
    amd e1 with radeon graphics
    Motherboard
    Lenovo 11.S9000.152 Laptop Motherboard
    Memory
    4GB DDR3
    Graphics Card(s)
    AMD Radeon™ HD 7310
    Browser
    firefox/ie10
    Antivirus
    kaspersky 2013
well this is embarasing......

when i did the logiing steps it automaticly dissapeared and k am running as goood as stock :shock:
 

My Computer

System One

  • OS
    windows 8
    Computer type
    Laptop
    System Manufacturer/Model
    lenovo g585
    CPU
    amd e1 with radeon graphics
    Motherboard
    Lenovo 11.S9000.152 Laptop Motherboard
    Memory
    4GB DDR3
    Graphics Card(s)
    AMD Radeon™ HD 7310
    Browser
    firefox/ie10
    Antivirus
    kaspersky 2013
If you're still having problems, have a look at the link in post #10 (page 1) of this thread, and also here.
 

My Computer

System One

  • OS
    W8.1 x64
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba Satellite C55T-A5394
    CPU
    i3
    Memory
    6GB
    Graphics Card(s)
    Intel HD 4000
    Browser
    FF
    Antivirus
    Defender
Log Name: Microsoft-Windows-WMI-Activity/Trace
Source: Microsoft-Windows-WMI-Activity
Date: 11/12/2013 10:57:01 PM
Event ID: 50
Task Category: None
Level: Information
Keywords:
User: SYSTEM
Computer: idea-PC
Description:
Activity Transfer
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WMI-Activity" Guid="{1418ef04-b0b4-4623-bf7e-d74ab47bbdaa}" />
<EventID>50</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2013-11-13T06:57:01.734113400Z" />
<EventRecordID>237</EventRecordID>
<Correlation ActivityID="{1782D085-F6F5-428C-BEBB-F44E890C44DF}" RelatedActivityID="{6854820B-E03D-0001-2582-54683DE0CE01}" />
<Execution ProcessID="604" ThreadID="2600" ProcessorID="1" KernelTime="4" UserTime="7" />
<Channel>Microsoft-Windows-WMI-Activity/Trace</Channel>
<Computer>idea-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
</EventData>
</Event>




this my log can anyone help my wmi is hogging 40% constintly
 

My Computer

System One

  • OS
    windows 8
    Computer type
    Laptop
    System Manufacturer/Model
    lenovo g585
    CPU
    amd e1 with radeon graphics
    Motherboard
    Lenovo 11.S9000.152 Laptop Motherboard
    Memory
    4GB DDR3
    Graphics Card(s)
    AMD Radeon™ HD 7310
    Browser
    firefox/ie10
    Antivirus
    kaspersky 2013
Hi

Not sure how to enterpret Resource Monitor and "WmiPrvSE.exe" ..... is this normal ?
I'm running w8.1
Capture.PNG

, referes (at the bottom) to a hotfix for Windows 2008 R2.
- is this valid for w8.1 ?

-------------------------------------------
Attached are logs
You can enable WMI tracing (it's not on by default) by doing the following on Win8:

  • Open Event Viewer
  • Click View > Show Analytic and Debug Logs
  • Browse to Applications and Services Logs > Microsoft > Windows > WMI-Activity
  • Right-click on both the "Debug" and "Trace" log options within this folder, and select "Enable Log" for both (the "Operational" log should already be enabled and logging generic events)

Reboot, and after the next time you see high activity in wmiprvse.exe, see if there's any activity in these two newly-enabled logs.
 

Attachments

  • Trace_.txt
    44.1 KB · Views: 201
  • Debug.txt
    9.7 KB · Views: 196
Last edited:

My Computer

System One

  • OS
    Windows 8.1
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Acer Aspire V5-5 serie
    CPU
    i5 4-serie
    Memory
    8GB RAM
    Graphics Card(s)
    AMD Radeon R7 M265 (2 GB)
    Screen Resolution
    Full HD
    Hard Drives
    1TB HDD (soon 250 SSD)
    Browser
    Crome
    Antivirus
    Avast
TZres.dll file created over and over again solved

Long story short, I've spent a day investigating the spikes my cpu made at idle (between 4% and 16%, the culprit was tzres.dll accesed by WMI trying to create a file over and over again.

Probable causes I found browsing the internet wirth their solution:

1) Windows Resources Management software - not installed on my system, an official patch exist if you're affected

2) Malware (opencandy, conduit etc...) - use an anti malware program like adwcleaner or hitman pro

3) Temporary solution with no culprit found - restart the Windows Management Instrumentation service, the bad behaviour will come back after reboot

None of these solutions satisfying me, I remembered Antivirus software use the time of your computer in their procedures to weed out malicious programs. TZres.dll dealing with timezones, I decided to investigate and VOILA, the culprit on my system is AVAST ANTIVIRUS.

Uninstalled and the spikes were gone, my cpu stays at about 2 to 3% at about 600 Mhz, perfect for my little atom tablet!

Hope this helps

PS: Installed Panda cloud antivirus and the spikes did not return! It is also supposed to be light on resources and quite effective if you believe the last AV-comparatives test AV-Comparatives Real-World Protection Test » AV-Comparatives
 

My Computer

System One

  • OS
    Win 8.1 32bit
    Computer type
    Tablet
    System Manufacturer/Model
    Asus T100TA
    CPU
    Atom Z3740
    Memory
    2 Gb
    Browser
    Chrome
    Antivirus
    Panda Cloud
Sysinternals Process Explorer is an excellent utility that can help you track down problem processes and malware. Learning how to use it is key:

https://www.youtube.com/results?search_query=process+explorer

SysInternals Pro: Understanding Process Explorer


Process monitor can be useful also, but there is much more info to wade through, as it monitors registry changes, which can eat up system resources very quickly if you let it run too long. It's general use is to fire it up and start capturing when the problem process starts, stop the capture when you think you've caught it and examine the traces.

SysInternals Pro: Understanding Process Monitor
 

My Computer

System One

  • OS
    Win7, Win8
TZres.dll file created over and over again solved

Long story short, I've spent a day investigating the spikes my cpu made at idle (between 4% and 16%, the culprit was tzres.dll accesed by WMI trying to create a file over and over again.
I know that this msg is pretty old, but I was wondering how you determined that tzrez.dll was trying to create a file over and over again.

Thx.

P.S. I too am using Panda, Avast sucks!
 

My Computer

System One

  • OS
    windows8.1
Back
Top