The project is GUI with nothing other than its own FORM.
There was some IP traffic
192.229.211.108:80 (TCP) // google says belongs to Edgecast Inc (content/storage/cache)
20.99.133.109:443 (TCP) // google says belongs to Microsoft
20.99.185.48:443 (TCP)
20.99.186.246:443 (TCP)
23.216.147.64:443 (TCP) // google says belongs to virustotal
The IP are similar, but like I told, I'm pretty sure that these communications are triggered by Windows and not by the program (this also happens for an empty Delphi application).
My doubts were about the switch "-install" and the others, but like @marcov says should be the TotalVirus logic's the try those.
Bye