werfault.exe
Windows Problem Reporting by Microsoft Corporation (Signed)
Version: | 6.1.7600.16385 (win7_rtm.090713-1255) |
MD5: | 5feab868caedbbd1b7a145ca8261e4aa |
SHA1: | f43f28cc5165608e6fb3794e9a3d083ca2c75f0e |
SHA256: | 08bace187a0225e10677de9aa6738a7118be3e5cad6dc45fb8d3366a61bb343c |
This is a Windows system installed file with Windows File Protection (WFP) enabled.
Overview
werfault.exe executes as a process with the local user's privileges typically within the context of its parent
svchost.exe (Host Process for Windows Services by Microsoft Corporation). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). The file is digitally signed by Microsoft Corporation. This version is designed to run on Windows 7 and is compiled as a 64 bit program.
Details
File name: | werfault.exe |
Publisher: | Microsoft Corporation |
Product name: | Windows Problem Reporting |
Description: | Microsoft® Windows® Operating System |
Typical file path: | C:\Windows\System32\werfault.exe |
Original name: | WerFault.exe.mui |
File version: | 6.1.7600.16385 (win7_rtm.090713-1255) |
Product version: | 6.1.7600.16385 |
Size: | 352 KB (360,448 bytes) |
Certificate |
Issued to: | Microsoft Corporation |
Authority (CA): | Microsoft Corporation |
Effective date: | Tuesday, April 10, 2012 |
Expiration date: | Wednesday, July 10, 2013 |
Digital DNA |
File packed: | No |
Code language: | Microsoft Visual C# / Basic .NET |
.NET CLR: | Yes |
.NET NGENed: | No |
More details
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.16959425% | |
Kernel CPU: | 0.13660840% | |
User CPU: | 0.03298586% | |
Kernel CPU time: | 1,092,162 ms/min | |
CPU cycles: | 9,199,302/sec | |
Context switches: | 34/sec | |
Memory |
Private memory: | 5.41 MB | |
Private (maximum): | 11.36 MB | |
Private (minimum): | 10.52 MB | |
Non-paged memory: | 5.41 MB | |
Virtual memory: | 95.27 MB | |
Virtual memory (peak): | 111.02 MB | |
Working set: | 10.87 MB | |
Working set (peak): | 12.12 MB | |
Page faults: | 6,320/min | |
I/O |
I/O read transfer: | 333 Bytes/sec | |
I/O read operations: | 1/sec | |
I/O write transfer: | 0 Bytes/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 26 Bytes/sec | |
I/O other operations: | 12/sec | |
Resource allocations |
Threads: | 5 | |
Handles: | 172 | |
GUI GDI count: | 64 | |
GUI GDI peak: | 78 | |
GUI USER count: | 31 | |
GUI USER peak: | 42 | |
Process properties
Integrety level: | Medium |
Platform: | 64-bit |
Command lines: |
- C:\windows\syswow64\werfault.exe -u -p 9732 -s 1404
- C:\windows\syswow64\werfault.exe -u -p 5248 -s 196
- C:\windows\syswow64\werfault.exe -u -p 10868 -s 196
- C:\windows\syswow64\werfault.exe -u -p 4608 -s 196
- C:\windows\syswow64\werfault.exe -u -p 10728 -s 196
- C:\windows\syswow64\werfault.exe -u -p 2676 -s 41464
- C:\windows\syswow64\werfault.exe -u -p 5052 -s 9020
- (11 more)
|
Owner: | User |
Parent process: | svchost.exe (Host Process for Windows Services by Microsoft Corporation) |
Threads
Averages
werui.dll |
Total CPU: | 0.07710579% | |
Kernel CPU: | 0.07009617% | |
User CPU: | 0.00700962% | |
CPU cycles: | 6,636,070/sec | |
Context switches: | 18/sec | |
Memory: | 168 KB | |
ntdll.dll |
Total CPU: | 0.03509050% | |
Kernel CPU: | 0.02105430% | |
User CPU: | 0.01403620% | |
CPU cycles: | 511,379/sec | |
Context switches: | 2/sec | |
Memory: | 1.23 MB | |
WerFault.exe (main module) |
Total CPU: | 0.00546481% | |
Kernel CPU: | 0.00370255% | |
User CPU: | 0.00176226% | |
CPU cycles: | 2,890,565/sec | |
Context switches: | 18/sec | |
Memory: | 364 KB | |
Distribution by Windows OS
OS version | distribution |
Windows 8 |
40.00% |
|
Windows 8.1 Enterprise |
20.00% |
|
Windows 8 Pro |
20.00% |
|
Windows 8 Pro with Media Center |
20.00% |
|
Distribution by country
United States installs about 40.00% of Windows Problem Reporting.
Distribution by PC manufacturer
PC Manufacturer | distribution |
American Megatrends |
100.00% |
|