Windows 8 and 8.1 Forums


msiexec.exe running at all times

  1. #1


    Posts : 7
    Windows 8

    msiexec.exe running at all times


    Somehow msiexec.exe always starts and if I stop it, it starts again.
    The service is set as manual and the field is greyed out, so I can't change it.
    It doesn't use CPU, just sitting on the memory.

    Here are what I've tried so far with no luck.

    1. Disable system restore.
    2. Turn off fast startup.
    3. Cleaned out Temp folder.
    4. Virus and malware scan. Nothing found.
    5. Unregister and reregister Windows Installer.
    6. SFC Scan. No problem found.
    7. Clean registry using jetclean.

    Any idea? Thanks.

    BTW, I don't know if this is related: I've notice this warning.

    Log Name: ApplicationSource: Microsoft-Windows-User Profiles Service
    Date: 2/3/2013 6:29:46 PM
    Event ID: 1530
    Task Category: None
    Level: Warning
    Keywords:
    User: SYSTEM
    Computer: Desktop-PC
    Description:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.


    Code:
    DETAIL - 
     17 user registry handles leaked from \Registry\User\S-1-5-21-3241246610-606297703-3174275145-1001:
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1164 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\CA
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
    Process 1164 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\Root
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\trust
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\Disallowed
    
    
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
        <EventID>1530</EventID>
        <Version>0</Version>
        <Level>3</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2013-02-04T02:29:46.638442500Z" />
        <EventRecordID>2974</EventRecordID>
        <Correlation ActivityID="{FB126B5E-0279-0000-7E6B-12FB7902CE01}" />
        <Execution ProcessID="1164" ThreadID="1868" />
        <Channel>Application</Channel>
        <Computer>Desktop-PC</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData Name="EVENT_HIVE_LEAK">
        <Data Name="Detail">17 user registry handles leaked from \Registry\User\S-1-5-21-3241246610-606297703-3174275145-1001:
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1164 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\CA
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
    Process 1164 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Policies\Microsoft\SystemCertificates
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\Root
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\trust
    Process 1276 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3241246610-606297703-3174275145-1001\Software\Microsoft\SystemCertificates\Disallowed
    </Data>
      </EventData>
    </Event>
    Last edited by Brink; 03 Feb 2013 at 23:32. Reason: code box

      My System SpecsSystem Spec

  2. #2


    Some things maybe I might try;
    C:\Windows\System32\WSReset.exe ..resets and cleans the store cache (prompt or run)
    DISM /Online /Cleanup-Image /RestoreHealth ..repairs store = 40 minute?? (elevated prompt)
    Windows Updates. run the repair.

    Move the stuff out of download folder and reboot?

    Boot to safe mode surf or whatever for a while there. That fixed a few security related open handles for me.
      My System SpecsSystem Spec

  3. #3


    Posts : 7
    Windows 8


    Thanks mikiep for your reply.
    As you suggested, I tried WSREset.exe, DISM RestoreHealth, and moved stuff out of download folder, but msiexec.exe still loads.

    Here are a little more information.
    msiexec.exe doesn't load in safe mode, and it loads 2~3 mins after normal boot.
      My System SpecsSystem Spec

  4. #4


    Look in applications in the Event viewer 2-3 minutes after normal boot ?
    I might be unchecking a couple of different non-windows services from starting in msconfig each new boot. And looking in Process Explorer from Microsoft sysinternals.
      My System SpecsSystem Spec

  5. #5


    Posts : 7
    Windows 8


    There are three events that are associated with msiexec.exe.
    The database engine or PackageRepository.edb is triggering the msiexec.exe?
    What do I do now?? Thanks

    Code:
    msiexec (2672) Instance: The database engine (6.02.9200.0000) is starting a new instance (0).
    
    msiexec (2672) Instance: The database engine started a new instance (0). (Time=0 seconds) 
    Internal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.016, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000.
    
    msiexec (2672) Instance: The database engine attached a database (1, C:\ProgramData\Microsoft\Windows\AppRepository\PackageRepository.edb). (Time=0 seconds) 
    Internal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000. 
    Saved Cache: 1
      My System SpecsSystem Spec

msiexec.exe running at all times
Related Threads
For some reason, every program I try to install using msiexec, I get an installation that just hangs. Though, I can get past the terms and agreements and program location screen, after that there's no progression, no file copying, nothing. I only get to see is being installed... Thanks in...
Solved The first of many times in General Support
OK, I am brand new in here and will probably wear the site out by the time I am finished. After many years with Windows 7 ( A piece of cake to use) I have made the big move to windows 8 and am going around in circles. The first question is: A. Somehow I managed to unpin the desktop flag on the...
Running out of memory when running overnight. in Performance & Maintenance
First let me say, I rarely leave my 8.1 system running all night as I generally switch off before bed. On the FEW occasions I leave the system running all night I always get the "Your computer is low on memory" warning. For instance, yesterday my software RAID mirror was "Re-synchronizing"...
BSOD 1-2 times a day in BSOD Crashes and Debugging
Hi. I am getting a BSOD 1-2 times a day. It seems to happen most often when running Steam or a gaming application, but is not unique to running those types of applications. I have had the comp crash while watching a movie or even just idling. Usually when the BSOD of death shows up I get the...
I ran the software once - and pressed the button that is supposed to purge all the detected "Adware.Tracking cookie" and stuff like that, and so it should be all gone, but it runs everytime I reboot the computer and it is again showing 'how many items found' and increasing, so I'm not sure if it...
My toshiba laptop will seem to just randomly freeze up whenever it feels like, the periods between freezes can vary anywhere from 5 minutes to 3 or 4 hours so its completely random and it does not seem to happen when I'm doing a specific task, I can be watching a video, browsing the internet or...
Solved Boot Times in Performance & Maintenance
Has anyone else noticed the incredibly fast boot times? My co-worker timed it yesterday and it was 12 seconds from power on to the log on screen on my laptop. Dell Latitude D630 Core2Duo T7250 @ 2.0Ghz 4Gig DDR2 800 Kingston WD 7200RPM 320Gig Intel Graphics and Realtek Sound.
Eight Forums Android App Eight Forums IOS App Follow us on Facebook