You are on page 1of 5

***********************************************

* *
* ____ _____ ____ _ ___ _ _ _____ *
* | _ \| ____| _ \| | |_ _| \ | | ____| *
* | |_) | _| | | | | | | || \| | _| *
* | _ <| |___| |_| | |___ | || |\ | |___ *
* |_| \_|_____|____/|_____|___|_| \_|_____| *
* *
* Telegram: https://t.me/REDLINESUPPORT *
***********************************************

ID: 788, Name: csrss.exe, CommandLine:


===============
ID: 968, Name: winlogon.exe, CommandLine: winlogon.exe
===============
ID: 544, Name: fontdrvhost.exe, CommandLine: "fontdrvhost.exe"
===============
ID: 1124, Name: dwm.exe, CommandLine: "dwm.exe"
===============
ID: 4088, Name: sihost.exe, CommandLine: sihost.exe
===============
ID: 3876, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup
===============
ID: 3000, Name: taskhostw.exe, CommandLine: taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
===============
ID: 4284, Name: ctfmon.exe, CommandLine: "ctfmon.exe"
===============
ID: 4348, Name: explorer.exe, CommandLine: C:\Windows\Explorer.EXE
===============
ID: 4672, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
ClipboardSvcGroup -p
===============
ID: 4956, Name: ChsIME.exe, CommandLine: C:\Windows\System32\InputMethod\CHS\
ChsIME.exe -Embedding
===============
ID: 5020, Name: StartMenuExperienceHost.exe, CommandLine: "C:\Windows\SystemApps\
Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\
StartMenuExperienceHost.exe" -
ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
===============
ID: 5104, Name: NVIDIA Web Helper.exe, CommandLine: "C:\Program Files (x86)\NVIDIA
Corporation\NvNode\NVIDIA Web Helper.exe" index.js
===============
ID: 1204, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 4468, Name: conhost.exe, CommandLine: \??\C:\Windows\system32\conhost.exe 0x4
===============
ID: 1060, Name: SearchApp.exe, CommandLine: "C:\Windows\SystemApps\
Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -
ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
===============
ID: 5220, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 5640, Name: ASCTray.exe, CommandLine: "C:\Program Files (x86)\IObit\Advanced
SystemCare Ultimate\ASCTray.exe" /Auto
===============
ID: 5812, Name: PdaNetPC.exe, CommandLine: "C:\Program Files (x86)\PdaNet for
Android\PdaNetPC.exe"
===============
ID: 2676, Name: rundll32.exe, CommandLine: rundll32.exe "c:\program files\nvidia
corporation\nvstreamsrv\rxdiag.dll" RxDiagSetRuntimeMessagePump
===============
ID: 5776, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA Corporation\
NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d
"C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st
"C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
===============
ID: 6780, Name: TextInputHost.exe, CommandLine: "C:\Windows\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -
ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mca
===============
ID: 3868, Name: UninstallMonitor.exe, CommandLine: "C:\Program Files (x86)\IObit\
IObit Uninstaller\UninstallMonitor.exe" /srvupt
===============
ID: 1936, Name: SettingSyncHost.exe, CommandLine: C:\Windows\system32\
SettingSyncHost.exe -Embedding
===============
ID: 3436, Name: hvk.exe, CommandLine: "C:\Program Files\HotVirtualKeyboard\hvk.exe"
-WAITINGFORCLOSE
===============
ID: 1812, Name: hvkcm64.exe, CommandLine: "C:\Program Files\HotVirtualKeyboard\
hvkcm64.exe"
===============
ID: 3144, Name: dllhost.exe, CommandLine: C:\Windows\system32\DllHost.exe
/Processid:{49F171DD-B51A-40D3-9A6C-52D674CC729D}
===============
ID: 5296, Name: ShellExperienceHost.exe, CommandLine: "C:\Windows\SystemApps\
ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -
ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
===============
ID: 4592, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 4584, Name: conhost.exe, CommandLine: \??\C:\Windows\system32\conhost.exe 0x4
===============
ID: 5464, Name: cmd.exe, CommandLine: C:\Windows\system32\cmd.exe /c arnatic_4.exe
===============
ID: 1920, Name: cmd.exe, CommandLine: C:\Windows\system32\cmd.exe /c arnatic_6.exe
===============
ID: 3080, Name: cmd.exe, CommandLine: C:\Windows\system32\cmd.exe /c arnatic_8.exe
===============
ID: 4624, Name: arnatic_4.exe, CommandLine: arnatic_4.exe
===============
ID: 1784, Name: arnatic_6.exe, CommandLine: arnatic_6.exe
===============
ID: 2220, Name: arnatic_8.exe, CommandLine: arnatic_8.exe
===============
ID: 4220, Name: arnatic_7.exe, CommandLine: C:\Users\AHMADF~1\AppData\Local\Temp\
7zSCAB744B7\arnatic_7.exe
===============
ID: 2260, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
SystemNetworkService
===============
ID: 4032, Name: 8671137.exe, CommandLine: "C:\Users\AHMAD FATTAL\AppData\Roaming\
8671137.exe"
===============
ID: 4944, Name: WinHoster.exe, CommandLine: "C:\Users\AHMAD FATTAL\AppData\Roaming\
WinHost\WinHoster.exe"
===============
ID: 7424, Name: J1ZxzXxJma1bQp9dP5jothuF.exe, CommandLine: "C:\Users\AHMAD FATTAL\
Documents\J1ZxzXxJma1bQp9dP5jothuF.exe"
===============
ID: 7676, Name: 5469560.exe, CommandLine: "C:\Users\AHMAD FATTAL\AppData\Roaming\
5469560.exe"
===============
ID: 7856, Name: ol3OORJcHTMO2VQZcG0OnT_B.exe, CommandLine: "C:\Users\AHMAD FATTAL\
Documents\ol3OORJcHTMO2VQZcG0OnT_B.exe"
===============
ID: 7864, Name: conhost.exe, CommandLine: \??\C:\Windows\system32\conhost.exe 0x4
===============
ID: 8012, Name: J2YTYFuJEoSys5SlKP4kWEBz.exe, CommandLine: "C:\Users\AHMAD FATTAL\
Documents\J2YTYFuJEoSys5SlKP4kWEBz.exe"
===============
ID: 8096, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe"
===============
ID: 8116, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\AHMAD
FATTAL\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\AHMAD FATTAL\AppData\Local\
Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\AHMAD FATTAL\AppData\
Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --
annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --
annotation=ver=91.0.4472.114 --initial-client-
data=0xe8,0xec,0xf0,0xc4,0xf4,0x7ffc05e54370,0x7ffc05e54380,0x7ffc05e54390
===============
ID: 3716, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=gpu-process --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --gpu-
preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAA
AAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIA
AAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1620 /prefetch:2
===============
ID: 1252, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --service-
sandbox-type=none --mojo-platform-channel-handle=1944 /prefetch:8
===============
ID: 7020, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=storage.mojom.StorageService --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --service-
sandbox-type=utility --mojo-platform-channel-handle=2284 /prefetch:8
===============
ID: 4308, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3556 /prefetch:1
===============
ID: 7236, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3816 /prefetch:1
===============
ID: 7232, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3828 /prefetch:1
===============
ID: 7280, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=2744 /prefetch:1
===============
ID: 7672, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=4100 /prefetch:1
===============
ID: 7788, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=4368 /prefetch:1
===============
ID: 7392, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation
--renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=4400 /prefetch:1
===============
ID: 6960, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=15 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4992 /prefetch:1
===============
ID: 4272, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=22 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3264 /prefetch:1
===============
ID: 6624, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=23 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3512 /prefetch:1
===============
ID: 4824, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=21 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7356 /prefetch:1
===============
ID: 7768, Name: dllhost.exe, CommandLine: C:\Windows\system32\DllHost.exe
/Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
===============
ID: 8520, Name: xOsSsGxl6_KSmYxW8cbQ2W7f.exe, CommandLine: "C:\Users\AHMAD FATTAL\
Documents\xOsSsGxl6_KSmYxW8cbQ2W7f.exe"
===============
ID: 8676, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1568,6034616673642822776,8432023747051509038,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=30 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6588 /prefetch:1
===============
ID: 9088, Name: ePvntDWSFCUK8v0SD_IiH1Xb.exe, CommandLine: "C:\Users\AHMAD FATTAL\
Documents\ePvntDWSFCUK8v0SD_IiH1Xb.exe"

You might also like