File details
File name: wermgr.exe
Name: Windows Problem Reporting
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 49.5 KB
Original file name: WerMgr
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 2.0649319647%
Privileged CPU:
0.2745285271%

User CPU:
1.79040343757460%

 | Memory utilization averages |
Min working set memory: 0 Bytes
Process details
Runs as (owner): User
Windows platform: 64-bit
Process Command
"C:\Windows\system32\wermgr.exe" "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_avgwdsvc.exe_e507a6572fdde82a2fbb020c657ebe0156846e7_13341ad1"
Scheduled task details
Name: QueueReporting
Command: \Microsoft\Windows\Windows Error Reporting\QueueReporting
Scheduled tasks startup details
Name: \Microsoft\Windows\Windows Error Reporting\QueueReporting
Image hashes
MD5: 41df7355a5a907e2c1d7804ec028965d
SHA-1: 453263d230c6317eb4a2eb3aceeec1bbcf5e153d
SHA-256: 207bfec939e7c017c4704ba76172ee2c954f485ba593bc1bc8c7666e78251861
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.97408
File packed: No
Import Table
advapi32.dll

GetLengthSid
CheckTokenMembership
AllocateAndInitializeSid
DuplicateToken
OpenProcessToken
RegGetValueW
CopySid
IsValidSid
FreeSid
ConvertSidToStringSidW
RegQueryValueExW
ImpersonateLoggedOnUser
CreateProcessAsUserW
RevertToSelf
GetTokenInformation
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegDeleteValueW
RegOpenKeyExW
kernel32.dll

InterlockedExchange
Sleep
InterlockedCompareExchange
GetStartupInfoA
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnmapViewOfFile
CloseHandle
CreateProcessW
SetEvent
GetLastError
MapViewOfFile
CreateMutexW
Wow64RevertWow64FsRedirection
GetSystemDirectoryW
Wow64DisableWow64FsRedirection
IsWow64Process
GlobalFree
GetCommandLineW
HeapSetInformation
GetApplicationRecoveryCallback
DeleteFileW
OpenProcess
GetSystemDefaultLCID
InterlockedIncrement
lstrlenW
InterlockedDecrement
CreateEventW
LocalFree
OutputDebugStringA
GetProcAddress
GetModuleHandleW
OpenMutexW
ReadProcessMemory
UnhandledExceptionFilter
WaitForSingleObject
LoadLibraryExW
FreeLibrary
OpenFileMappingW
ClosePrivateNamespace
CreateFileMappingW
GetProcessHeap
HeapAlloc
OpenPrivateNamespaceW
HeapFree
msvcrt.dll
ntdll.dll

NtQueryInformationToken
RtlFreeSid
NtClose
NtAlpcConnectPort
RtlAllocateAndInitializeSid
RtlInitUnicodeString
NtQueryInformationProcess
RtlDeleteBoundaryDescriptor
RtlAddSIDToBoundaryDescriptor
RtlImageNtHeaderEx
RtlCreateBoundaryDescriptor
RtlCreateServiceSid
NtAlpcSendWaitReceivePort
ole32.dll

StringFromGUID2
CoInitialize
CoCreateInstance
CoCreateGuid
CoInitializeEx
CoUninitialize
CoRegisterClassObject
CoRevokeClassObject
shell32.dll

CommandLineToArgvW
ShellExecuteExW
user32.dll

CloseDesktop
CloseWindowStation
GetUserObjectInformationW
GetThreadDesktop
GetProcessWindowStation
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueW
wer.dll

WerReportCloseHandle
WerpSetReportInformation
WerpAddRegisteredDataToReport
WerpSetCallBack
WerReportAddDump
WerpEnumerateStoreStart
WerpEnumerateStoreNext
WerpGetCustomerWatsonData
WerReportCreate
WerReportSetParameter
WerReportSubmit
WerpGetResponseId
WerpSetCustomerWatsonData
WerpGetReportInformation
WerpOpenMachineQueue
WerpSubmitReportFromStore
WerpOpenUserQueue
WerpCloseStore
WerpShowNXNotification
WerpIsTransportAvailable
WerpLoadReport
WerpGetReportType
wevtapi.dll

EvtNext
EvtClose
EvtRender
EvtCreateRenderContext
EvtQuery