File details
File name: wermgr.exe
Name: Windows Problem Reporting
Description: Microsoft® Windows® Operating System
Version: 6.0.6000.16386 (vista_rtm.061101-2205)
Product version: 6.0.6000.16386
Size: 60.5 KB
Original file name: WerMgr
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0015039479%
Privileged CPU:
0.0000832556%

User CPU:
0.00142069223259%

Privileged CPU time: 109.38 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
1,578,916,131
CPU cycle count /min: 723,578
 | Memory utilization averages |
Committed memory:
61.45 MB
Peak committed memory: 62.02 MB
Paged memory:
3.49 MB
Peak paged memory: 3.53 MB
Paged system memory:
114.35 KB
Non-paged system memory: 4.98 KB
Working set memory:
6 MB
Peak working set memory: 7.8 MB
Min working set memory: 5.95 MB
Private memory:
3.49 MB
Page faults:
2,106
Page faults /min: 1
 | Process I/O averages |
Total read operations:
3
Read operations /min: 1
Total read transfer: 16.13 KB
Read transfer /min: 8 Bytes
Total write operations:
1
Write operations /min: 1
Total write transfer: 116 Bytes
Write transfer /min: 0 Bytes
Total other operations:
699
Other operations /min: 1
Total other transfer: 6.83 KB
Other Transfer /min: 3 Bytes
 | GUI Object Averages |
GDI objects:
46
USER objects:
29
Resources
Handle count average: 137
Thread count average: 4
Thread resource averages
wer.dll

Total CPU: 0.000095435450%
Privileged CPU: 0.000035788294%
User CPU: 0.000059647156%
CPU Cycle count /sec: 10,915
Module memory size: 884 KB
Total CPU: 0.000023858852%
Privileged CPU: 0.000011929426%
User CPU: 0.000011929426%
CPU Cycle count /sec: 607
Module memory size: 72 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 32-bit
Parent Process
Process Command
"C:\Windows\system32\wermgr.exe" "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report128d8c3a"
Scheduled task details
Name: QueueReporting
Command: \Microsoft\Windows\Windows Error Reporting\QueueReporting
Scheduled tasks startup details
Name: \Microsoft\Windows\Windows Error Reporting\QueueReporting
Image hashes
MD5: 2c8d466741833d6ca430da2b07bcb16a
SHA-1: fadaed3719b612f4f03ca719b36a5a2937fcb705
SHA-256: 55b6216cab9d24ee3d05ec359ee16d608edc106bf720693d6cb4e0b6457d8351
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.97408
File packed: No
Import Table
advapi32.dll

GetLengthSid
CheckTokenMembership
AllocateAndInitializeSid
DuplicateToken
OpenProcessToken
RegGetValueW
CopySid
IsValidSid
FreeSid
ConvertSidToStringSidW
RegQueryValueExW
ImpersonateLoggedOnUser
CreateProcessAsUserW
RevertToSelf
GetTokenInformation
TraceMessage
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegDeleteValueW
RegOpenKeyExW
kernel32.dll

InterlockedExchange
Sleep
InterlockedCompareExchange
GetStartupInfoA
SetUnhandledExceptionFilter
GetModuleHandleA
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnmapViewOfFile
CloseHandle
CreateProcessW
SetEvent
GetLastError
MapViewOfFile
CreateMutexW
Wow64RevertWow64FsRedirection
GetSystemDirectoryW
Wow64DisableWow64FsRedirection
IsWow64Process
GlobalFree
GetCommandLineW
HeapSetInformation
GetApplicationRecoveryCallback
DeleteFileW
OpenProcess
GetSystemDefaultLCID
InterlockedIncrement
lstrlenW
InterlockedDecrement
CreateEventW
LocalFree
OutputDebugStringA
GetProcAddress
GetModuleHandleW
OpenMutexW
ReadProcessMemory
UnhandledExceptionFilter
WaitForSingleObject
LoadLibraryExW
FreeLibrary
OpenFileMappingW
ClosePrivateNamespace
CreateFileMappingW
GetProcessHeap
HeapAlloc
OpenPrivateNamespaceW
HeapFree
msvcrt.dll
ntdll.dll

NtQueryInformationToken
RtlFreeSid
NtClose
NtAlpcConnectPort
RtlAllocateAndInitializeSid
RtlInitUnicodeString
NtQueryInformationProcess
RtlDeleteBoundaryDescriptor
RtlAddSIDToBoundaryDescriptor
RtlImageNtHeaderEx
RtlCreateBoundaryDescriptor
RtlCreateServiceSid
NtAlpcSendWaitReceivePort
ole32.dll

StringFromGUID2
CoInitialize
CoCreateInstance
CoCreateGuid
CoInitializeEx
CoUninitialize
CoRegisterClassObject
CoRevokeClassObject
shell32.dll

CommandLineToArgvW
ShellExecuteExW
user32.dll

CloseDesktop
CloseWindowStation
GetUserObjectInformationW
GetThreadDesktop
GetProcessWindowStation
version.dll

GetFileVersionInfoW
GetFileVersionInfoSizeW
VerQueryValueW
wer.dll

WerReportCloseHandle
WerpSetReportInformation
WerpAddRegisteredDataToReport
WerpSetCallBack
WerReportAddDump
WerpEnumerateStoreStart
WerpEnumerateStoreNext
WerpGetCustomerWatsonData
WerReportCreate
WerReportSetParameter
WerReportSubmit
WerpGetResponseId
WerpSetCustomerWatsonData
WerpGetReportInformation
WerpOpenMachineQueue
WerpSubmitReportFromStore
WerpOpenUserQueue
WerpCloseStore
WerpShowNXNotification
WerpIsTransportAvailable
WerpLoadReport
WerpGetReportType
wevtapi.dll

EvtNext
EvtClose
EvtRender
EvtCreateRenderContext
EvtQuery