***********************************************
* _ _ _ _ *
* / \ / \ / \ / \ *
* ( M | E | T | A ) *
* \_/ \_/ \_/ \_/ *
* *
* Telegram: TichanCloud| Sup(@alekseev888) *
***********************************************
ID: 22540, Name: csrss.exe, CommandLine:
===============
ID: 22080, Name: winlogon.exe, CommandLine:
===============
ID: 22872, Name: fontdrvhost.exe, CommandLine:
===============
ID: 1840, Name: dwm.exe, CommandLine:
===============
ID: 20796, Name: gameinputsvc.exe, CommandLine:
===============
ID: 17092, Name: NVDisplay.Container.exe, CommandLine:
===============
ID: 19816, Name: sihost.exe, CommandLine: sihost.exe
===============
ID: 14312, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser
%dSPUser.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\SPUser" -
r -l 3 -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\
NvContainerTelemetryApi.dll" -c
===============
ID: 7708, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup -s CDPUserSvc
===============
ID: 18176, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser
%d.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -
p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\
NvContainerTelemetryApi.dll" -c
===============
ID: 22020, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup -s WpnUserService
===============
ID: 14520, Name: LEDKeeper2.exe, CommandLine:
===============
ID: 13088, Name: taskhostw.exe, CommandLine: taskhostw.exe {222A245B-E637-4AE9-
A93F-A59CA119A75E}
===============
ID: 13060, Name: MpDlpCmd.exe, CommandLine: "C:\ProgramData\microsoft\MpDlpCmd.exe"
===============
ID: 5328, Name: explorer.exe, CommandLine: C:\WINDOWS\Explorer.EXE
===============
ID: 11644, Name: system.exe, CommandLine: "C:\Users\timph\AppData\Roaming\
Microsoft\Windows\Start Menu\Programs\windows\system.exe"
===============
ID: 25468, Name: ctfmon.exe, CommandLine:
===============
ID: 13256, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
ClipboardSvcGroup -p -s cbdhsvc
===============
ID: 17172, Name: TextInputHost.exe, CommandLine: "C:\Windows\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -
ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mca
===============
ID: 1260, Name: StartMenuExperienceHost.exe, CommandLine: "C:\Windows\SystemApps\
Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\
StartMenuExperienceHost.exe" -
ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
===============
ID: 25856, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 10960, Name: SearchApp.exe, CommandLine: "C:\WINDOWS\SystemApps\
Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -
ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
===============
ID: 9120, Name: NVIDIA Web Helper.exe, CommandLine: "C:\Program Files (x86)\NVIDIA
Corporation\NvNode\NVIDIA Web Helper.exe" index.js
===============
ID: 15904, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 20488, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 13068, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 21168, Name: PhoneExperienceHost.exe, CommandLine: "C:\Program Files\
WindowsApps\Microsoft.YourPhone_1.23022.140.0_x64__8wekyb3d8bbwe\
PhoneExperienceHost.exe" -ComServer:Background -Embedding
===============
ID: 16984, Name: DefenderSupport.exe, CommandLine: "C:\Users\timph\DefenderSupport\
DefenderSupport.exe"
===============
ID: 9404, Name: Spotify.exe, CommandLine: "C:\Users\timph\AppData\Roaming\Spotify\
Spotify.exe" --autostart --minimized
===============
ID: 25824, Name: DCv2.exe, CommandLine: "C:\Program Files\WindowsApps\9426MICRO-
STARINTERNATION.DragonCenter_2.0.130.0_x64__kzh8wxbdkxb8p\DCv2\DCv2.exe" msi-
dc:Startup
===============
ID: 22496, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 25692, Name: schtasks.exe, CommandLine: "C:\Windows\System32\schtasks.exe"
/create /sc daily /tn "DefenderSupport_Task-DAILY-21PM" /TR "%MyFile%" /ST 21:00
===============
ID: 18360, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 7820, Name: Spotify.exe, CommandLine: C:\Users\timph\AppData\Roaming\Spotify\
Spotify.exe --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --
max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\
timph\AppData\Local\Spotify\User Data\Crashpad" "--metrics-dir=C:\Users\timph\
AppData\Local\Spotify\User Data" --url=https://crashdump.spotify.com:443/ --
annotation=platform=win32 --annotation=product=spotify --
annotation=version=1.2.9.743 --initial-client-
data=0x494,0x498,0x49c,0x490,0x4a0,0x5a21c0c0,0x5a21c0d0,0x5a21c0dc
===============
ID: 10276, Name: Spotify.exe, CommandLine: "C:\Users\timph\AppData\Roaming\Spotify\
Spotify.exe" --type=gpu-process --disable-d3d11 --log-severity=disable --user-
agent-product="Chrome/111.0.5563.65 Spotify/1.2.9.743" --lang=de --user-data-
dir="C:\Users\timph\AppData\Local\Spotify\User Data" --gpu-
preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAA
AAAAAAAAAAAAAABgAAAAAAAAAGAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAACAAAAAAAAAA= --log-
file="C:\Users\timph\AppData\Roaming\Spotify\debug.log" --mojo-platform-channel-
handle=1888 --field-trial-
handle=1852,i,10331755581015812093,9632020856956973509,131072 --disable-
features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker
/prefetch:2
===============
ID: 2400, Name: Spotify.exe, CommandLine: "C:\Users\timph\AppData\Roaming\Spotify\
Spotify.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --
lang=en-US --service-sandbox-type=service --log-severity=disable --user-agent-
product="Chrome/111.0.5563.65 Spotify/1.2.9.743" --lang=de --user-data-dir="C:\
Users\timph\AppData\Local\Spotify\User Data" --log-file="C:\Users\timph\AppData\
Roaming\Spotify\debug.log" --mojo-platform-channel-handle=3492 --field-trial-
handle=1852,i,10331755581015812093,9632020856956973509,131072 --disable-
features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker
/prefetch:8
===============
ID: 9852, Name: Spotify.exe, CommandLine: "C:\Users\timph\AppData\Roaming\Spotify\
Spotify.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --
lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-
product="Chrome/111.0.5563.65 Spotify/1.2.9.743" --lang=de --user-data-dir="C:\
Users\timph\AppData\Local\Spotify\User Data" --log-file="C:\Users\timph\AppData\
Roaming\Spotify\debug.log" --mojo-platform-channel-handle=3684 --field-trial-
handle=1852,i,10331755581015812093,9632020856956973509,131072 --disable-
features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker
/prefetch:8
===============
ID: 2344, Name: Spotify.exe, CommandLine: "C:\Users\timph\AppData\Roaming\Spotify\
Spotify.exe" --type=renderer --log-severity=disable
--user-agent-product="Chrome/111.0.5563.65 Spotify/1.2.9.743" --disable-spell-
checking --user-data-dir="C:\Users\timph\AppData\Local\Spotify\User Data" --first-
renderer-process --log-file="C:\Users\timph\AppData\Roaming\Spotify\debug.log" --
lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=5 --time-ticks-at-unix-epoch=-
1681326730741959 --launch-time-ticks=493064898571 --mojo-platform-channel-
handle=3968 --field-trial-
handle=1852,i,10331755581015812093,9632020856956973509,131072 --disable-
features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker
/prefetch:1
===============
ID: 26264, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 24124, Name: Voltage.exe, CommandLine: "C:\Users\timph\AppData\Roaming\
Voltage.exe"
===============
ID: 16344, Name: nvsphelper64.exe, CommandLine:
===============
ID: 17436, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
===============
ID: 9336, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=gpu-process --field-
trial-handle=2108,13358592653460016000,18155000806854900575,131072 --disable-
features=VizDisplayCompositor --no-sandbox --log-file="C:\Users\timph\AppData\
Local\NVIDIA Corporation\NVIDIA Share\debug.log" --lang=en-US --gpu-
preferences=KAAAAAAAAACACwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\timph\AppData\Local\
NVIDIA Corporation\NVIDIA Share\debug.log" --service-request-channel-
token=1838118874820584753 --mojo-platform-channel-handle=2124 /prefetch:2
===============
ID: 19940, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --no-
sandbox --autoplay-policy=no-user-gesture-required --log-file="C:\Users\timph\
AppData\Local\NVIDIA Corporation\NVIDIA Share\debug.log" --field-trial-
handle=2108,13358592653460016000,18155000806854900575,131072 --disable-
features=VizDisplayCompositor --service-pipe-token=14263752026815034094 --lang=en-
US --log-file="C:\Users\timph\AppData\Local\NVIDIA Corporation\NVIDIA Share\
debug.log" --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-
before-activation --service-request-channel-token=14263752026815034094 --renderer-
client-id=3 --mojo-platform-channel-handle=2756 /prefetch:1
===============
ID: 25072, Name: NhNotifSys.exe, CommandLine: "C:\WINDOWS\system32\
NhNotifSys.exe" /app nahimic /wait-install
===============
ID: 1568, Name: RegAsm.exe, CommandLine: "C:\Windows\Microsoft.NET\Framework\
v4.0.30319\RegAsm.exe"
===============
ID: 13644, Name: SystemSettings.exe, CommandLine: "C:\Windows\
ImmersiveControlPanel\SystemSettings.exe" -
ServerName:microsoft.windows.immersivecontrolpanel
===============
ID: 25084, Name: ApplicationFrameHost.exe, CommandLine: C:\WINDOWS\system32\
ApplicationFrameHost.exe -Embedding
===============
ID: 13156, Name: UserOOBEBroker.exe, CommandLine: C:\Windows\System32\oobe\
UserOOBEBroker.exe -Embedding
===============
ID: 9544, Name: svchost.exe, CommandLine: C:\WINDOWS\System32\svchost.exe -k
UnistackSvcGroup
===============
ID: 14148, Name: Microsoft.Photos.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.Windows.Photos_2023.10030.7003.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe"
-ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
===============
ID: 23316, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 2992, Name: SearchApp.exe, CommandLine: "C:\WINDOWS\SystemApps\
Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -
ServerName:ShellFeedsUI.AppX88fpyyrd21w8wqe62wzsjh5agex7tf1e.mca
===============
ID: 10264, Name: dllhost.exe, CommandLine: C:\WINDOWS\system32\DllHost.exe
/Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
===============
ID: 4676, Name: BakkesMod.exe, CommandLine: "C:\Program Files\BakkesMod\
BakkesMod.exe"
===============
ID: 6248, Name: CompPkgSrv.exe, CommandLine: C:\Windows\System32\CompPkgSrv.exe -
Embedding
===============
ID: 19848, Name: RegAsm.exe, CommandLine: #cmd
===============
ID: 20008, Name: RegAsm.exe, CommandLine: #cmd
===============
ID: 15868, Name: RegAsm.exe, CommandLine: #cmd
===============
ID: 16052, Name: RegAsm.exe, CommandLine: #cmd
===============
ID: 17368, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe"
===============
ID: 10896, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\timph\
AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\timph\AppData\Local\
Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --
annotation=channel= --annotation=chromium-version=112.0.5615.121 "--
annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --
annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --
annotation=ver=112.0.1722.48 --initial-client-
data=0x110,0x114,0x118,0xec,0x124,0x7ffed67835f0,0x7ffed6783600,0x7ffed6783610
===============
ID: 19428, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=gpu-process --gpu-
preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAA
AAAAAAAAAAAAAABgAAAAAAAAAGAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-
platform-channel-handle=2056 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:2
===============
ID: 17536, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --lang=de --service-sandbox-type=none --mojo-
platform-channel-handle=2060 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:3
===============
ID: 24856, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=storage.mojom.StorageService --lang=de --service-sandbox-type=service --mojo-
platform-channel-handle=2584 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:8
===============
ID: 2736, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --extension-process --lang=de --js-flags=--
ms-user-locale=de_DE --device-scale-factor=1 --num-raster-threads=4 --enable-main-
frame-before-activation --renderer-client-id=5 --time-ticks-at-unix-epoch=-
1681326730741224 --launch-time-ticks=499194547251 --mojo-platform-channel-
handle=4992 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 4224, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --extension-process --lang=de --js-flags=--
ms-user-locale=de_DE --device-scale-factor=1 --num-raster-threads=4 --enable-main-
frame-before-activation --renderer-client-id=6 --time-ticks-at-unix-epoch=-
1681326730741224 --launch-time-ticks=499194631227 --mojo-platform-channel-
handle=5496 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 20940, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --extension-process --lang=de --js-flags=--
ms-user-locale=de_DE --device-scale-factor=1 --num-raster-threads=4 --enable-main-
frame-before-activation --renderer-client-id=7 --time-ticks-at-unix-epoch=-
1681326730741224 --launch-time-ticks=499194652744 --mojo-platform-channel-
handle=5284 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 19036, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --extension-process --lang=de --js-flags=--
ms-user-locale=de_DE --device-scale-factor=1 --num-raster-threads=4 --enable-main-
frame-before-activation --renderer-client-id=8 --time-ticks-at-unix-epoch=-
1681326730741224 --launch-time-ticks=499194705173 --mojo-platform-channel-
handle=6024 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 11456, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=proxy_resolver.mojom.ProxyResolverFactory --lang=de --service-sandbox-
type=service --mojo-platform-channel-handle=6152 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:8
===============
ID: 1304, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService
--lang=de --service-sandbox-type=audio --mojo-platform-channel-handle=7208 --field-
trial-handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:8
===============
ID: 23416, Name: Discord.exe, CommandLine: C:\Users\timph\AppData\Local\Discord\
app-1.0.9012\Discord.exe --type=crashpad-handler --user-data-dir=C:\Users\timph\
AppData\Roaming\discord /prefetch:7 --no-rate-limit --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\timph\AppData\Roaming\
discord\Crashpad --url=https://sentry.io/api/146342/minidump/?
sentry_key=384ce4413de74fe0be270abe03b2b35a "--annotation=_companyName=Discord
Inc." --annotation=_productName=Discord --annotation=_version=1.0.9012 --
annotation=plat=Win32 --annotation=prod=Electron --annotation=ver=22.3.2 --initial-
client-data=0x860,0x864,0x868,0x52c,0x86c,0x813ef78,0x813ef88,0x813ef94
===============
ID: 10392, Name: Discord.exe, CommandLine: "C:\Users\timph\AppData\Local\Discord\
app-1.0.9012\Discord.exe" --type=renderer --user-data-dir="C:\Users\timph\AppData\
Roaming\discord" --app-user-model-id=com.squirrel.Discord.Discord --app-path="C:\
Users\timph\AppData\Local\Discord\app-1.0.9012\resources\app.asar" --no-sandbox --
no-zygote --autoplay-policy=no-user-gesture-required --disable-gpu-compositing --
lang=de --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=5 --time-ticks-at-unix-epoch=-1681326730741814 --
launch-time-ticks=499275964340 --mojo-platform-channel-handle=2784 --field-trial-
handle=1900,i,7531631736964802201,11756741283630739419,131072 --disable-
features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand
/prefetch:1
===============
ID: 15028, Name: ShellExperienceHost.exe, CommandLine: "C:\Windows\SystemApps\
ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -
ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
===============
ID: 816, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 272, Name: smartscreen.exe, CommandLine: C:\Windows\System32\smartscreen.exe -
Embedding
===============
ID: 21956, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=72 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500062555716 --mojo-platform-channel-handle=10088 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 11880, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=82 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500063009425 --mojo-platform-channel-handle=10472 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 22624, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=data_decoder.mojom.DataDecoderService --lang=de --service-sandbox-type=service
--mojo-platform-channel-handle=8660 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:8
===============
ID: 7736, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=84 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500063299813 --mojo-platform-channel-handle=12896 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 4436, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=85 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500063446563 --mojo-platform-channel-handle=13444 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 3456, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=86 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500063742633 --mojo-platform-channel-handle=14068 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 10952, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=73 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500064777227 --mojo-platform-channel-handle=14240 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 18396, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=74 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500064783182 --mojo-platform-channel-handle=14136 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 21224, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=75 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500064789102 --mojo-platform-channel-handle=9748 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 6240, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=90 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500097252679 --mojo-platform-channel-handle=5076 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 13332, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=de --service-
sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-
handle=7452 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:8
===============
ID: 22672, Name: SearchProtocolHost.exe, CommandLine: "C:\WINDOWS\system32\
SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-391189439-
405378548-3552287615-100188_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-
391189439-405378548-3552287615-100188 1 -2147483646 "Software\Microsoft\Windows
Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\
ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
===============
ID: 8824, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=93 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500169746904 --mojo-platform-channel-handle=11936 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 24388, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=94 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500171161172 --mojo-platform-channel-handle=11760 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 12684, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=99 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500173816962 --mojo-platform-channel-handle=7280 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 2116, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=100 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500174345028 --mojo-platform-channel-handle=10220 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 14840, Name: msedge.exe, CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --lang=de --js-flags=--ms-user-locale=de_DE
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=101 --time-ticks-at-unix-epoch=-1681326730741224 --
launch-time-ticks=500174351765 --mojo-platform-channel-handle=4808 --field-trial-
handle=2064,i,10302994611789293866,12680555798751378188,131072 /prefetch:1
===============
ID: 21808, Name: notepad.exe, CommandLine: "C:\WINDOWS\system32\NOTEPAD.EXE" C:\
Users\timph\Downloads\READ ME!!!!!.txt
===============
ID: 26024, Name: SbieSvc.exe, CommandLine:
===============
ID: 4456, Name: SandboxieRpcSs.exe, CommandLine: "C:\Program Files\Sandboxie\
SandboxieRpcSs.exe"
===============
ID: 17736, Name: SbieCtrl.exe, CommandLine: "C:\Program Files\Sandboxie\
SbieCtrl.exe"
===============
ID: 26456, Name: SandboxieDcomLaunch.exe, CommandLine: "C:\Program Files\Sandboxie\
SandboxieDcomLaunch.exe"
===============
ID: 12732, Name: Nexus.exe, CommandLine: "C:\Users\timph\Downloads\Nexus.exe"
===============
ID: 22224, Name: Nexus.exe, CommandLine: "C:\Users\timph\Downloads\Nexus.exe"
===============
ID: 9444, Name: AppLaunch.exe, CommandLine: "C:\Windows\Microsoft.NET\Framework\
v4.0.30319\AppLaunch.exe"
===============
ID: 23816, Name: SbieSvc.exe, CommandLine: "C:\Program Files\Sandboxie\32\
SbieSvc.exe" Sandboxie_ComProxy_S-1-5-21-391189439-405378548-3552287615-
1001_DefaultBox_11_1_: