File details
File name: wermgr.exe
Name: Windows Problem Reporting
Description: Microsoft® Windows® Operating System
Version: 6.3.9600.16384 (winblue_rtm.130821-1623)
Product version: 6.3.9600.16384
Size: 140.2 KB
Original file name: WerMgr
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Scheduled task details
Name: QueueReporting
Command: \Microsoft\Windows\Windows Error Reporting\QueueReporting
Scheduled tasks startup details
Name: \Microsoft\Windows\Windows Error Reporting\QueueReporting
Image hashes
MD5: 0b93a4de6b58ad04bf91b76316339817
SHA-1: d8ae63951de2c0f730b7b2c00027c2634e8aa502
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.97408
File packed: No
Import Table
advapi32.dll

GetLengthSid
CheckTokenMembership
AllocateAndInitializeSid
DuplicateToken
OpenProcessToken
RegGetValueW
CopySid
IsValidSid
FreeSid
ConvertSidToStringSidW
RegQueryValueExW
ImpersonateLoggedOnUser
CreateProcessAsUserW
RevertToSelf
GetTokenInformation
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegDeleteValueW
RegOpenKeyExW
kernel32.dll

InterlockedExchange
Sleep
InterlockedCompareExchange
GetStartupInfoA
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnmapViewOfFile
CloseHandle
CreateProcessW
SetEvent
GetLastError
MapViewOfFile
CreateMutexW
Wow64RevertWow64FsRedirection
GetSystemDirectoryW
Wow64DisableWow64FsRedirection
IsWow64Process
GlobalFree
GetCommandLineW
HeapSetInformation
GetApplicationRecoveryCallback
DeleteFileW
OpenProcess
GetSystemDefaultLCID
InterlockedIncrement
lstrlenW
InterlockedDecrement
CreateEventW
LocalFree
OutputDebugStringA
GetProcAddress
GetModuleHandleW
OpenMutexW
ReadProcessMemory
UnhandledExceptionFilter
WaitForSingleObject
LoadLibraryExW
FreeLibrary
OpenFileMappingW
ClosePrivateNamespace
CreateFileMappingW
GetProcessHeap
HeapAlloc
OpenPrivateNamespaceW
HeapFree
msvcrt.dll
ntdll.dll

NtQueryInformationToken
RtlFreeSid
NtClose
NtAlpcConnectPort
RtlAllocateAndInitializeSid
RtlInitUnicodeString
NtQueryInformationProcess
RtlDeleteBoundaryDescriptor
RtlAddSIDToBoundaryDescriptor
RtlImageNtHeaderEx
RtlCreateBoundaryDescriptor
RtlCreateServiceSid
NtAlpcSendWaitReceivePort
ole32.dll

StringFromGUID2
CoInitialize
CoCreateInstance
CoCreateGuid
CoInitializeEx
CoUninitialize
CoRegisterClassObject
CoRevokeClassObject
shell32.dll

CommandLineToArgvW
ShellExecuteExW
user32.dll

CloseDesktop
CloseWindowStation
GetUserObjectInformationW
GetThreadDesktop
GetProcessWindowStation
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueW
wer.dll

WerReportCloseHandle
WerpSetReportInformation
WerpAddRegisteredDataToReport
WerpSetCallBack
WerReportAddDump
WerpEnumerateStoreStart
WerpEnumerateStoreNext
WerpGetCustomerWatsonData
WerReportCreate
WerReportSetParameter
WerReportSubmit
WerpGetResponseId
WerpSetCustomerWatsonData
WerpGetReportInformation
WerpOpenMachineQueue
WerpSubmitReportFromStore
WerpOpenUserQueue
WerpCloseStore
WerpShowNXNotification
WerpIsTransportAvailable
WerpLoadReport
WerpGetReportType
wevtapi.dll

EvtNext
EvtClose
EvtRender
EvtCreateRenderContext
EvtQuery