You are on page 1of 10

***********************************************

* *
* ____ _____ ____ _ ___ _ _ _____ *
* | _ \| ____| _ \| | |_ _| \ | | ____| *
* | |_) | _| | | | | | | || \| | _| *
* | _ <| |___| |_| | |___ | || |\ | |___ *
* |_| \_|_____|____/|_____|___|_| \_|_____| *
* *
* Telegram: https://t.me/REDLINESUPPORT *
***********************************************

ID: 5868, Name: csrss.exe, CommandLine:


===============
ID: 1148, Name: winlogon.exe, CommandLine:
===============
ID: 1296, Name: fontdrvhost.exe, CommandLine:
===============
ID: 5900, Name: dwm.exe, CommandLine:
===============
ID: 2460, Name: atieclxx.exe, CommandLine:
===============
ID: 1532, Name: uihost.exe, CommandLine: "C:\Program Files\McAfee\WebAdvisor\
UIHost.exe"
===============
ID: 10316, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup -s CDPUserSvc
===============
ID: 9708, Name: sihost.exe, CommandLine: sihost.exe
===============
ID: 3956, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup -s WpnUserService
===============
ID: 8848, Name: taskhostw.exe, CommandLine: taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
===============
ID: 5016, Name: explorer.exe, CommandLine: C:\WINDOWS\Explorer.EXE
===============
ID: 3916, Name: service.exe, CommandLine: C:\Users\pc\AppData\Local\Temp\
service.exe
===============
ID: 6380, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
ClipboardSvcGroup -p -s cbdhsvc
===============
ID: 8648, Name: StartMenuExperienceHost.exe, CommandLine: "C:\WINDOWS\SystemApps\
Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\
StartMenuExperienceHost.exe" -
ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
===============
ID: 11824, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 7520, Name: SearchApp.exe, CommandLine: "C:\WINDOWS\SystemApps\
Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -
ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
===============
ID: 8940, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 7964, Name: YourPhone.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.YourPhone_1.21062.150.0_x64__8wekyb3d8bbwe\YourPhone.exe" -
ServerName:App.AppX9yct9q388jvt4h7y0gn06smzkxcsnt8m.mca
===============
ID: 6768, Name: TextInputHost.exe, CommandLine: "C:\WINDOWS\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -
ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mca
===============
ID: 932, Name: ctfmon.exe, CommandLine:
===============
ID: 5300, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 10876, Name: RtkAudUService64.exe, CommandLine: "C:\Windows\System32\
DriverStore\FileRepository\realtekservice.inf_amd64_01042bb7f11c17c4\
RtkAudUService64.exe" -background
===============
ID: 2108, Name: vgtray.exe, CommandLine: "C:\Program Files\Riot Vanguard\
vgtray.exe"
===============
ID: 1040, Name: OneDrive.exe, CommandLine: "C:\Users\pc\AppData\Local\Microsoft\
OneDrive\OneDrive.exe" /background
===============
ID: 7564, Name: steam.exe, CommandLine: "C:\Program Files (x86)\Steam\steam.exe" -
silent
===============
ID: 11832, Name: TaskbarSystem.exe, CommandLine: "C:\Users\pc\AppData\Local\
Programs\Taskbar system\TaskbarSystem.exe"
===============
ID: 12180, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --restore-last-session
===============
ID: 1324, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=crashpad-handler "--
user-data-dir=C:\Users\pc\AppData\Local\Secure Browser\Secure Browser\User Data"
/prefetch:7 --monitor-self --monitor-self-argument=--type=crashpad-handler "--
monitor-self-argument=--user-data-dir=C:\Users\pc\AppData\Local\Secure Browser\
Secure Browser\User Data" --monitor-self-argument=/prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\Local\Secure
Browser\Secure Browser\User Data\Crashpad" "--metrics-dir=C:\Users\pc\AppData\
Local\Secure Browser\Secure Browser\User Data" --annotation=plat=Win32 "--
annotation=prod=Secure Browser" --annotation=ver=89.0.4389.114-devel --initial-
client-data=0x134,0x138,0x13c,0x110,0x140,0x72ecea88,0x72ecea98,0x72eceaa4
===============
ID: 1440, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=crashpad-handler "--
user-data-dir=C:\Users\pc\AppData\Local\Secure Browser\Secure Browser\User Data"
/prefetch:7 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler
"--database=C:\Users\pc\AppData\Local\Secure Browser\Secure Browser\User Data\
Crashpad" --annotation=plat=Win32 "--annotation=prod=Secure Browser" --
annotation=ver=89.0.4389.114-devel --initial-client-
data=0x238,0x23c,0x240,0x234,0x244,0x7324c0,0x7324d0,0x7324dc
===============
ID: 8568, Name: browser_assistant.exe, CommandLine: "C:\Users\pc\AppData\Local\
Programs\Opera\assistant\browser_assistant.exe"
===============
ID: 11828, Name: System.exe, CommandLine: "C:\ProgramData\Microsoft Network\
System.exe"
===============
ID: 11500, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --headless --disable-gpu --remote-debugging-port=9222
http://www.google.com.263288868798149.windows-display-service.com
===============
ID: 712, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 11076, Name: browser_assistant.exe, CommandLine: C:\Users\pc\AppData\Local\
Programs\Opera\assistant\browser_assistant.exe --type=crashpad-handler /prefetch:7
--monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\
Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\pc\
AppData\Roaming\Opera Software\Opera Stable\crash_count.txt"
--url=https://crashstats-collector.opera.com/collector/submit --
annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --
annotation=ver=77.0.4054.277 --initial-client-
data=0x280,0x284,0x288,0x25c,0x28c,0xfc34e8,0xfc34f8,0xfc3504
===============
ID: 6816, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\pc\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\pc\AppData\Local\Google\Chrome\
User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --
annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=92.0.4515.107 --
initial-client-
data=0xf0,0xf4,0xf8,0xcc,0xfc,0x7ffccaff5390,0x7ffccaff53a0,0x7ffccaff53b0
===============
ID: 11612, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=gpu-process --field-
trial-handle=1616,9023931564935911795,5603989844836402165,131072 --gpu-
preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAA
AAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIA
AAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1628 /prefetch:2
===============
ID: 3888, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --field-trial-
handle=1616,9023931564935911795,5603989844836402165,131072 --lang=en-US --service-
sandbox-type=network --mojo-platform-channel-handle=1884 /prefetch:8
===============
ID: 8352, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-
type=storage.mojom.StorageService --field-trial-
handle=1616,9023931564935911795,5603989844836402165,131072 --lang=en-US --service-
sandbox-type=utility --mojo-platform-channel-handle=2264 /prefetch:8
===============
ID: 32, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --origin-trial-disabled-features=SecurePaymentConfirmation --device-
scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --
renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=2572 /prefetch:1
===============
ID: 232, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=2580 /prefetch:1
===============
ID: 2304, Name: PWRISOVM.EXE, CommandLine: "D:\PowerISO\PWRISOVM.EXE" -startup
===============
ID: 9092, Name: schtasks.exe, CommandLine:
===============
ID: 5480, Name: conhost.exe, CommandLine:
===============
ID: 6808, Name: unsecapp.exe, CommandLine: C:\WINDOWS\system32\wbem\unsecapp.exe -
Embedding
===============
ID: 11316, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=utility --utility-sub-
type=data_decoder.mojom.DataDecoderService --field-trial-
handle=1616,9023931564935911795,5603989844836402165,131072 --lang=en-US --service-
sandbox-type=utility --mojo-platform-channel-handle=3408 /prefetch:8
===============
ID: 4832, Name: cmd.exe, CommandLine: "C:\Windows\System32\cmd.exe" /K taskkill /IM
ixternndll.exe /F && exit
===============
ID: 9320, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3564 /prefetch:1
===============
ID: 9016, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3944 /prefetch:1
===============
ID: 1672, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 11224, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3924 /prefetch:1
===============
ID: 1868, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=9 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=4672 /prefetch:1
===============
ID: 6136, Name: SecureBrowser.exe, CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\SecureBrowser.exe" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=10 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=4900 /prefetch:1
===============
ID: 3100, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=gpu-process --field-trial-
handle=1376,17144345471661145895,4856825916987237249,131072 --disable-
features=PaintHolding --headless --headless --gpu-
preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAA
AAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHA
AAADQAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=swiftshader-webgl --override-use-software-
gl-for-tests --mojo-platform-channel-handle=1440 /prefetch:2
===============
ID: 3904, Name: RadeonSoftware.exe, CommandLine: "C:\Program Files\AMD\CNext\CNext\
Radeonsoftware.exe" atlogon
===============
ID: 11208, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --field-trial-
handle=1376,17144345471661145895,4856825916987237249,131072 --disable-
features=PaintHolding --lang=en-GB --service-sandbox-type=none --use-
gl=swiftshader-webgl --headless --mojo-platform-channel-handle=1656 /prefetch:8
===============
ID: 8396, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --remote-debugging-port=9222 --allow-pre-
commit-input --field-trial-
handle=1376,17144345471661145895,4856825916987237249,131072 --disable-
features=PaintHolding --disable-databases --disable-gpu-compositing --lang=en-GB --
headless --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=4 --mojo-platform-channel-
handle=1744 /prefetch:1
===============
ID: 1308, Name: ndrXXOnkDS.exe.com, CommandLine: C:\Users\pc\AppData\Roaming\
nWbKOHRTrH\ndrXXOnkDS.exe.com
===============
ID: 10072, Name: note3dll.exe, CommandLine: NULL
===============
ID: 2776, Name: Discord.exe, CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\Discord.exe"
===============
ID: 9296, Name: Discord.exe, CommandLine: C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\Discord.exe --type=crashpad-handler --user-data-dir=C:\Users\pc\AppData\
Roaming\discord /prefetch:7 --no-rate-limit --no-upload-gzip --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\pc\AppData\Roaming\discord\
Crashpad --url=https://sentry.io/api/146342/minidump/?
sentry_key=384ce4413de74fe0be270abe03b2b35a "--annotation=_companyName=Discord
Inc." --annotation=_productName=Discord --annotation=_version=1.0.9002 --
annotation=prod=Electron --annotation=ver=9.3.5 --initial-client-
data=0x468,0x46c,0x470,0x42c,0x474,0x59c4078,0x59c4088,0x59c4094
===============
ID: 8104, Name: Discord.exe, CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\Discord.exe" --type=gpu-process --field-trial-
handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--gpu-
preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQ
AAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAA
AGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-
handle=1672 /prefetch:2
===============
ID: 5296, Name: Discord.exe, CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\Discord.exe" --type=utility --field-trial-
handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--lang=en-US --service-sandbox-type=network --mojo-platform-channel-handle=2148
/prefetch:8
===============
ID: 2328, Name: AMDRSServ.exe, CommandLine:
===============
ID: 4788, Name: amdow.exe, CommandLine:
===============
ID: 9052, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup
===============
ID: 3908, Name: Discord.exe, CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\Discord.exe" --type=renderer --autoplay-policy=no-user-gesture-required --
field-trial-handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--lang=en-US --app-user-model-id=com.squirrel.Discord.Discord --app-path="C:\Users\
pc\AppData\Local\Discord\app-1.0.9002\resources\app.asar" --no-sandbox --no-zygote
--native-window-open --preload="C:\Users\pc\AppData\Local\Discord\app-1.0.9002\
modules\discord_desktop_core-3\discord_desktop_core\core.asar\app\
mainScreenPreload.js" --context-isolation --background-color=#202225 --enable-
spellcheck --enable-websql --device-scale-factor=1 --num-raster-threads=2 --enable-
main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-
mitigations --mojo-platform-channel-handle=3212 /prefetch:1 --enable-node-leakage-
in-renderers
===============
ID: 11560, Name: Discord.exe, CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\Discord.exe" --type=utility --field-trial-
handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=2284
/prefetch:8
===============
ID: 9968, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" "-lang=en_US" "-cachedir=C:\Users\pc\AppData\
Local\Steam\htmlcache" "-steampid=7564" "-buildid=1626824053" "-steamid=0" "-
cachedir=C:\Users\pc\AppData\Local\Steam\htmlcache" "-steamuniverse=Public" "-
realm=Global" "-clientui=C:\Program Files (x86)\Steam\clientui" --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --enable-media-stream --enable-smooth-
scrolling --enable-direct-write "--log-file=C:\Program Files (x86)\Steam\logs\
cef_log.txt"
===============
ID: 7980, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 --max-
uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-
handler "--database=C:\Program Files (x86)\Steam\dumps" "--metrics-dir=C:\Users\pc\
AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --
annotation=platform=win64 --annotation=product=cefwebhelper --
annotation=version=1626824053 --initial-client-
data=0x320,0x324,0x328,0x31c,0x32c,0x7ffcaaf1bf10,0x7ffcaaf1bf20,0x7ffcaaf1bf30
===============
ID: 2652, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" --type=gpu-process --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --log-file="C:\Program Files (x86)\
Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=en-ID --
buildid=1626824053 --steamid=0 --gpu-
preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files (x86)\Steam\
logs\cef_log.txt" --service-request-channel-token=15837304811436511476 --mojo-
platform-channel-handle=1504 --ignored=" --type=renderer " /prefetch:2
===============
ID: 9728, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" --type=utility --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --lang=en-US --service-sandbox-
type=network --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-
version="Valve Steam Client" --lang=en-ID --buildid=1626824053 --steamid=0 --log-
file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --service-request-channel-
token=17744092848952728723 --mojo-platform-channel-handle=2112 /prefetch:8
===============
ID: 5920, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" --type=renderer --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --lang=en-US --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --
buildid=1626824053 --steamid=0 --device-scale-factor=1 --num-raster-threads=2 --
enable-main-frame-before-activation --service-request-channel-
token=13941704941166654488 --renderer-client-id=5 --mojo-platform-channel-
handle=2708 /prefetch:1
===============
ID: 5176, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" --type=renderer --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --lang=en-US --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --
buildid=1626824053 --steamid=0 --device-scale-factor=1 --num-raster-threads=2 --
enable-main-frame-before-activation --service-request-channel-
token=992741647707716207 --renderer-client-id=6 --mojo-platform-channel-handle=2884
/prefetch:1
===============
ID: 1604, Name: steamwebhelper.exe, CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\steamwebhelper.exe" --type=renderer --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --lang=en-US --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --
buildid=1626824053 --steamid=0 --device-scale-factor=1 --num-raster-threads=2 --
enable-main-frame-before-activation --service-request-channel-
token=6390088502695588489 --renderer-client-id=7 --mojo-platform-channel-
handle=3148 /prefetch:1
===============
ID: 6036, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe"
===============
ID: 12024, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\pc\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\pc\AppData\Local\Google\Chrome\
User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --
annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=92.0.4515.107 --
initial-client-
data=0x100,0x104,0x108,0xdc,0x10c,0x7ffccaff5390,0x7ffccaff53a0,0x7ffccaff53b0
===============
ID: 11696, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=gpu-process --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --gpu-
preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAA
AAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHA
AAADQAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1676 /prefetch:2
===============
ID: 4516, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=storage.mojom.StorageService --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
service-sandbox-type=utility --mojo-platform-channel-handle=2356 /prefetch:8
===============
ID: 6520, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --no-
v8-untrusted-code-mitigations --mojo-platform-channel-handle=2856 /prefetch:1
===============
ID: 11476, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation
--renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=2864 /prefetch:1
===============
ID: 1692, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation
--renderer-client-id=20 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3560 /prefetch:1
===============
ID: 7452, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation
--renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3892 /prefetch:1
===============
ID: 976, Name: RAVANT~1.EXE, CommandLine: c:\PROGRA~1\RAVANT~1\ui\RAVANT~1.EXE --
minimized
===============
ID: 9252, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService
--field-trial-handle=1656,12516388163607244251,14439530889134879207,131072 --
lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6020
/prefetch:8
===============
ID: 8680, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=25 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6568 /prefetch:1
===============
ID: 7032, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7084 /prefetch:1
===============
ID: 7668, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=27 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7616 /prefetch:1
===============
ID: 1212, Name: Video.UI.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.ZuneVideo_10.21061.10121.0_x64__8wekyb3d8bbwe\Video.UI.exe" -
ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
===============
ID: 11368, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7536 /prefetch:1
===============
ID: 7208, Name: RAVANT~1.EXE, CommandLine: "c:\PROGRA~1\RAVANT~1\ui\RAVANT~1.EXE"
--type=gpu-process --field-trial-
handle=2840,17100785047698794974,15755472716090712235,131072 --disable-
features=SpareRendererForSitePerProcess --gpu-
preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-
token=8663520086443559716 --mojo-platform-channel-handle=2848 --ignored=" --
type=renderer " /prefetch:2
===============
ID: 9624, Name: RAVANT~1.EXE, CommandLine: "c:\PROGRA~1\RAVANT~1\ui\RAVANT~1.EXE"
--type=utility --field-trial-
handle=2840,17100785047698794974,15755472716090712235,131072 --disable-
features=SpareRendererForSitePerProcess --lang=en-US --service-sandbox-type=network
--standard-schemes=mc --secure-schemes=mc --bypasscsp-schemes --cors-schemes --
fetch-schemes --service-worker-schemes --service-request-channel-
token=15410565051835726808 --mojo-platform-channel-handle=3184 /prefetch:8
===============
ID: 7748, Name: RAVANT~1.EXE, CommandLine: "c:\PROGRA~1\RAVANT~1\ui\RAVANT~1.EXE"
--type=renderer --field-trial-
handle=2840,17100785047698794974,15755472716090712235,131072 --disable-
features=SpareRendererForSitePerProcess --lang=en-US --standard-schemes=mc --
secure-schemes=mc --bypasscsp-schemes --cors-schemes --fetch-schemes --service-
worker-schemes --app-path="c:\PROGRA~1\RAVANT~1\ui\resources\app.asar" --enable-
sandbox --native-window-open --preload="c:\PROGRA~1\RAVANT~1\ui\resources\app.asar\
electron\preload.js" --context-isolation --background-color=#fff --device-scale-
factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-
request-channel-token=2867675478731773067 --renderer-client-id=5 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3300 /prefetch:1
===============
ID: 8204, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 6640, Name: explorer.exe, CommandLine: C:\WINDOWS\SysWOW64\explorer.exe
===============
ID: 4628, Name: explorer.exe, CommandLine: C:\WINDOWS\explorer.exe
===============
ID: 12312, Name: explorer.exe, CommandLine: C:\WINDOWS\SysWOW64\explorer.exe
===============
ID: 12352, Name: explorer.exe, CommandLine: C:\WINDOWS\explorer.exe
===============
ID: 12416, Name: explorer.exe, CommandLine: C:\WINDOWS\SysWOW64\explorer.exe
===============
ID: 12504, Name: explorer.exe, CommandLine: C:\WINDOWS\explorer.exe
===============
ID: 12572, Name: explorer.exe, CommandLine: C:\WINDOWS\SysWOW64\explorer.exe
===============
ID: 12652, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 4552, Name: UserOOBEBroker.exe, CommandLine: C:\Windows\System32\oobe\
UserOOBEBroker.exe -Embedding
===============
ID: 13268, Name: chrome.exe, CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
service-sandbox-type=none --mojo-platform-channel-handle=8768 /prefetch:8
===============
ID: 12900, Name: C8CB.exe, CommandLine: C:\Users\pc\AppData\Local\Temp\C8CB.exe
===============
ID: 12960, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 204, Name: cmd.exe, CommandLine: "C:\WINDOWS\system32\cmd" /c "C:\Users\pc\
AppData\Local\Temp\CB57.tmp\CB58.tmp\CB59.bat C:\Users\pc\AppData\Local\Temp\
C8CB.exe"
===============
ID: 3660, Name: asap.exe, CommandLine: asap.exe
===============
ID: 1468, Name: extd.exe, CommandLine: C:\Users\pc\AppData\Local\Temp\CB57.tmp\
CB58.tmp\extd.exe "/sleep" "900000" "" "" "" "" "" "" ""
===============
ID: 8800, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 748, Name: ixternndll.exe, CommandLine: -coin eth -pool eth.2miners.com:2020 -
rvram 1 -wal 0x05E050c023DDFe7Ea87e6aDd6cCa9382D60Fc31D.test1 -proto 4

You might also like