PID: 0, Name: [System Process], Cmdline:
PID: 4, Name: System, Cmdline:
PID: 140, Name: Secure System, Cmdline:
PID: 172, Name: Registry, Cmdline:
PID: 772, Name: smss.exe, Cmdline:
PID: 884, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=crashpad-handler
--user-data-dir=C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\Office\16.0\Wef\
webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView /prefetch:4
/pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79 --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\Cemre.Hatipoglu\AppData\
Local\Microsoft\Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\
2\EBWebView\Crashpad --metrics-dir=C:\Users\Cemre.Hatipoglu\AppData\Local\
Microsoft\Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\
EBWebView --annotation=IsOfficialBuild=1 --annotation=channel= --
annotation=chromium-version=123.0.6312.123 "--annotation=exe=C:\Program Files
(x86)\Microsoft\EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --
annotation=plat=Win64 "--annotation=prod=Edge WebView2" --
annotation=ver=123.0.2420.97 --initial-client-
data=0x188,0x18c,0x190,0x164,0x198,0x7ffe08094e48,0x7ffe08094e54,0x7ffe08094e60
PID: 1280, Name: csrss.exe, Cmdline:
PID: 1372, Name: wininit.exe, Cmdline:
PID: 1380, Name: csrss.exe, Cmdline:
PID: 1400, Name: CSFalconContainer.exe, Cmdline: /00000007
PID: 1464, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=83 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=949634412 --field-trial-
handle=8764,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=8028 /prefetch:1
PID: 1472, Name: winlogon.exe, Cmdline: winlogon.exe
PID: 1492, Name: services.exe, Cmdline:
PID: 1536, Name: LsaIso.exe, Cmdline:
PID: 1548, Name: lsass.exe, Cmdline:
PID: 1564, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s HvHost
PID: 1608, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netsvcs -
p -s BDESVC
PID: 1676, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
DcomLaunch -p
PID: 1696, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -s W32Time
PID: 1708, Name: WUDFHost.exe, Cmdline: "C:\Windows\System32\WUDFHost.exe" -
HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-b32bef83-2967-4457-8e85-a4c04bc1e060 -
SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-65c98f4c-362e-4aaa-
8d87-f754183f41cc -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-
0f624f0a-0425-4508-b985-00f12b1b62c8 -NonStateChangingEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-664f92eb-38d2-46ab-ac9f-cfdefb47872a -
LifetimeId:45f5f29a-8efe-436b-aea8-03a563a4070d -DeviceGroupId: -HostArg:0
PID: 1776, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s nsi
PID: 1796, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k RPCSS -p
PID: 1808, Name: WUDFHost.exe, Cmdline: "C:\Windows\System32\WUDFHost.exe" -
HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-d206b425-da34-4e1c-8fa2-4954bd5bb2e3 -
SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-3552a851-3c3e-4d69-
8610-8cf767cad66e -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-
b09fb4ce-4c4a-4356-afc9-6bcada055d44 -NonStateChangingEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-87896976-7c78-42e8-a3eb-f06186eda055 -
LifetimeId:d6d0ce50-6255-4fd1-8f1e-9cc0eb1bc93c -DeviceGroupId: -HostArg:0
PID: 1876, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
DcomLaunch -p -s LSM
PID: 1936, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netsvcs -
p -s NetSetupSvc
PID: 1984, Name: WUDFHost.exe, Cmdline: "C:\Windows\System32\WUDFHost.exe" -
HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-c75e7150-edac-4e11-8600-3efd144f03d2 -
SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-af7baa8d-95ee-42dd-
8db7-92f1167566b2 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-
d8bae92b-dfed-4afc-bb2b-3a32732d8ffd -NonStateChangingEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-3e2f5c1a-1d63-4f9c-a150-aad61cea43b2 -
LifetimeId:c0d87d0c-9206-4f47-9bd5-01dd1e1a4d19 -DeviceGroupId: -HostArg:0
PID: 2040, Name: dwm.exe, Cmdline: "dwm.exe"
PID: 2148, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p
PID: 2160, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s Dhcp
PID: 2184, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s TimeBrokerSvc
PID: 2196, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s NcbService
PID: 2220, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s UsoSvc
PID: 2248, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s Schedule
PID: 2276, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netprofm
-p -s netprofm
PID: 2304, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
NetworkService -p
PID: 2396, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=628 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=89504505133 --field-trial-
handle=11972,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=11400 /prefetch:1
PID: 2400, Name: cmd.exe, Cmdline: C:\Windows\system32\cmd.exe /d /s /c ""C:\
Program Files\Timus Connect\resources\service\timus-connect-service.exe" tracker"
PID: 2404, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s bthserv
PID: 2428, Name: IntelCpHDCPSvc.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\iigd_dch.inf_amd64_da775d7ecf291310\IntelCpHDCPSvc.exe
PID: 2448, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s DisplayEnhancementService
PID: 2520, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
UserProfileService -p -s ProfSvc
PID: 2552, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s hidserv
PID: 2560, Name: WUDFHost.exe, Cmdline: "C:\Windows\System32\WUDFHost.exe" -
HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-b5281648-e18c-4596-b0d8-44d4a996ba87 -
SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-dec8de91-c540-4ac8-
b268-72411ca26d45 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-
d9c6fb36-7f0b-4413-943b-aad2013199a5 -NonStateChangingEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-aff5d291-65ec-40ad-b8ed-a6b656d6e18c -
LifetimeId:def06d97-6053-4854-b0a9-a18740ab9f5b -
DeviceGroupId:WudfDefaultDevicePool -HostArg:0
PID: 2628, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
PID: 2824, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service
--noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\
Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView" --
webview-exe-name=OUTLOOK.EXE --webview-exe-version=16.0.17425.20176 --embedded-
browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear
--field-trial-handle=2132,i,1315581269799843307,13003484811696677758,262144 --
enable-
features=MojoIpcz,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleS
ignOnOSForPrimaryAccountIsShared --variations-seed-version --mojo-platform-channel-
handle=2828 /prefetch:8 /pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79
PID: 2880, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s UserManager
PID: 2900, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 2908, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
InvSvcGroup -p -s InventorySvc
PID: 2928, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\
Cemre.Hatipoglu\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\Cemre.Hatipoglu\AppData\
Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\Cemre.Hatipoglu\
AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --
annotation=channel= --annotation=chromium-version=123.0.6312.123 "--
annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --
annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --
annotation=ver=123.0.2420.97 --initial-client-
data=0x1d8,0x274,0x278,0x1b4,0x280,0x7ffe08094e48,0x7ffe08094e54,0x7ffe08094e60
PID: 2984, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceNoNetworkFirewall -p
PID: 2992, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=629 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=89504642201 --field-trial-
handle=11048,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=5892 /prefetch:1
PID: 3048, Name: ipf_helper.exe, Cmdline: "C:\Windows\System32\DriverStore\
FileRepository\ipf_cpu.inf_amd64_15575ddcbffc1fc6\ipf_helper.exe"
PID: 3120, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k osprivacy
-p -s camsvc
PID: 3128, Name: ai.exe, Cmdline: "C:\Program Files\Microsoft Office\root\vfs\
ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "AFA72466-28BA-4FE6-8B87-
676BFC904DCF" "B2BEB48C-1BE7-4B70-BC89-9BA76092DA11" "7956" "C:\Program Files\
Microsoft Office\root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
PID: 3276, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=crashpad-handler
--user-data-dir=C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView
/prefetch:4 /pfhostedapp:3eacd73fa368676b0f5a859f64f7f7ea06ffa883 --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\Cemre.Hatipoglu\AppData\
Local\Packages\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\
EBWebView\Crashpad --metrics-dir=C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView --
annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-
version=123.0.6312.123 "--annotation=exe=C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --annotation=plat=Win64
"--annotation=prod=Edge WebView2" --annotation=ver=123.0.2420.97 --initial-client-
data=0x184,0x188,0x18c,0x160,0x194,0x7ffe08094e48,0x7ffe08094e54,0x7ffe08094e60
PID: 3296, Name: svchost.exe, Cmdline:
PID: 3412, Name: WUDFHost.exe, Cmdline: "C:\Windows\System32\WUDFHost.exe" -
HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-314fc9a1-f5cd-430f-8f8a-a12511423d3f -
SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-c98a2ff9-b9d2-423d-
956d-477af3b92c8b -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-
44d299cb-83ac-4b08-85da-ecb237c1306f -NonStateChangingEventPortName:\
UMDFCommunicationPorts\WUDF\HostProcess-df4522fc-e867-40e2-baea-d98ed6f73f49 -
LifetimeId:ca36ca47-9019-4b66-9a07-91ee96e30833 -DeviceGroupId: -HostArg:0
PID: 3424, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p -s EventLog
PID: 3516, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netsvcs -
p -s Themes
PID: 3524, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s SysMain
PID: 3532, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s EventSystem
PID: 3552, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k appmodel
-p -s StateRepository
PID: 3652, Name: Memory Compression, Cmdline:
PID: 3744, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s SENS
PID: 3772, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k NetSvcs -
p -s iphlpsvc
PID: 3796, Name: PhoneExperienceHost.exe, Cmdline: "C:\Program Files\WindowsApps\
Microsoft.YourPhone_1.24032.123.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe" -
Restart:{9A3598F4-560F-4B27-84DF-C8A6C1FDA639}
PID: 3844, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s AudioEndpointBuilder
PID: 3852, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s FontCache
PID: 3860, Name: AppHelperCap.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\hpcustomcapcomp.inf_amd64_bcbefa2816e7502d\x64\AppHelperCap.exe
PID: 3868, Name: DiagsCap.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\hpcustomcapcomp.inf_amd64_bcbefa2816e7502d\x64\DiagsCap.exe
PID: 3876, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s IKEEXT
PID: 3884, Name: SysInfoCap.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\hpcustomcapcomp.inf_amd64_bcbefa2816e7502d\x64\SysInfoCap.exe
PID: 3892, Name: TouchpointAnalyticsClientService.exe, Cmdline: C:\Windows\
System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_b76d40fc96db3872\x64\
TouchpointAnalyticsClientService.exe
PID: 3908, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
NetworkServiceNetworkRestricted -p -s PolicyAgent
PID: 3932, Name: NetworkCap.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\hpcustomcapcomp.inf_amd64_bcbefa2816e7502d\x64\NetworkCap.exe
PID: 4012, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --embedded-browser-
webview=1 --webview-exe-name=OUTLOOK.EXE --webview-exe-version=16.0.17425.20176 --
user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\Office\16.0\Wef\
webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView" --noerrdialogs --
embedded-browser-webview-dpi-awareness=2 --enable-
features=MojoIpcz,msSingleSignOnOSForPrimaryAccountIsShared,msAbydos,msAbydosGestur
eSupport,msAbydosHandwritingAttr --lang=en-US --accept-lang=en-US --mojo-named-
platform-channel-pipe=7956.18680.10836847306693156409
/pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79
PID: 4056, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --
lang=tr --service-sandbox-type=service --no-appcompat-clear --field-trial-
handle=2272,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=2348 /prefetch:8
PID: 4116, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
NetworkService -p
PID: 4252, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
s CertPropSvc
PID: 4288, Name: wlanext.exe, Cmdline: C:\Windows\system32\WLANExt.exe
2334800032944
PID: 4300, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netsvcs
PID: 4424, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=18 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=92262947 --field-trial-
handle=5992,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=6012 /prefetch:1
PID: 4448, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s Winmgmt
PID: 4456, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=22 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=92926477 --field-trial-
handle=3280,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=6096 /prefetch:1
PID: 4520, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p
PID: 4616, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s TextInputManagementService
PID: 4732, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p
PID: 4780, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p
PID: 4812, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netsvcs -
p -s ShellHWDetection
PID: 4936, Name: spoolsv.exe, Cmdline: C:\Windows\System32\spoolsv.exe
PID: 5012, Name: unsecapp.exe, Cmdline: C:\Windows\system32\wbem\unsecapp.exe -
Embedding
PID: 5140, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--field-trial-handle=2268,i,14303424895933633058,5885765820107907296,262144 --
variations-seed-version --mojo-platform-channel-handle=2304 /prefetch:2
PID: 5180, Name: conhost.exe, Cmdline: \??\C:\Windows\system32\conhost.exe 0x4
PID: 5236, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
NetworkService -p -s LanmanWorkstation
PID: 5248, Name: WmiPrvSE.exe, Cmdline: C:\Windows\system32\wbem\wmiprvse.exe
PID: 5264, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
DevicesFlow -s DevicesFlowUserSvc
PID: 5368, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceNoNetwork -p
PID: 5380, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k utcsvc -p
PID: 5392, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalServiceNoNetwork -p -s DPS
PID: 5432, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s DispBrokerDesktopSvc
PID: 5460, Name: ipfsvc.exe, Cmdline: "C:\Windows\System32\DriverStore\
FileRepository\dtt_sw.inf_amd64_12a05294eb98ea3c\ipfsvc.exe"
PID: 5472, Name: HotKeyServiceUWP.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\hpqkbsoftwarecompnent.inf_amd64_6c234fdd160946fe\
HotKeyServiceUWP.exe
PID: 5488, Name: fontdrvhost.exe, Cmdline: "fontdrvhost.exe"
PID: 5508, Name: CSFalconService.exe, Cmdline:
PID: 5528, Name: fontdrvhost.exe, Cmdline: "fontdrvhost.exe"
PID: 5676, Name: IntelAudioService.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\intcoed.inf_amd64_6f0a892deb241071\\AS\\IAS\\IntelAudioService.exe
PID: 5704, Name: jhi_service.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
PID: 5716, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s WwanSvc
PID: 5736, Name: MicrosoftSearchInBing.exe, Cmdline: "C:\Program Files (x86)\
Microsoft\Microsoft Search in Bing\MicrosoftSearchInBing.exe"
PID: 5748, Name: PanGPS.exe, Cmdline: "C:\Program Files\Palo Alto Networks\
GlobalProtect\PanGPS.exe"
PID: 5776, Name: ipf_uf.exe, Cmdline: "C:\Windows\System32\DriverStore\
FileRepository\ipf_cpu.inf_amd64_15575ddcbffc1fc6\ipf_uf.exe"
PID: 5804, Name: SECOMN64.exe, Cmdline: "C:\Windows\System32\SECOMN64.exe"
PID: 5844, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s LanmanServer
PID: 5888, Name: HpSfuService.exe, Cmdline: C:\Windows\Firmware\HpSfuService.exe
PID: 5928, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s TrkWks
PID: 5936, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s WpnService
PID: 5960, Name: WMIRegistrationService.exe, Cmdline: C:\Windows\System32\
DriverStore\FileRepository\mewmiprov.inf_amd64_ab7d4ea1d12c01d4\
WMIRegistrationService.exe
PID: 5968, Name: RtkAudUService64.exe, Cmdline: "C:\Windows\System32\DriverStore\
FileRepository\realtekservice.inf_amd64_285c9fb6a6c4e645\RtkAudUService64.exe"
PID: 6132, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k netsvcs -
p
PID: 6216, Name: LanWlanWwanSwitchingServiceUWP.exe, Cmdline: C:\Windows\System32\
DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_6c234fdd160946fe\
LanWlanWwanSwitchingServiceUWP.exe
PID: 6316, Name: LockApp.exe, Cmdline: "C:\Windows\SystemApps\
Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe" -
ServerName:WindowsDefaultLockScreen.AppX7y4nbzq37zn4ks9k7amqjywdat7d3j2z.mca
PID: 6356, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=renderer --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\
Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView" --
webview-exe-name=OUTLOOK.EXE --webview-exe-version=16.0.17425.20176 --embedded-
browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear
--lang=en-US --device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=6 --js-flags="--harmony-weak-refs-with-
cleanup-some --expose-gc --ms-user-locale=tr-TR" --time-ticks-at-unix-epoch=-
1713248930907302 --launch-time-ticks=4119178625 --field-trial-
handle=4068,i,1315581269799843307,13003484811696677758,262144 --enable-
features=MojoIpcz,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleS
ignOnOSForPrimaryAccountIsShared --variations-seed-version --mojo-platform-channel-
handle=3960 /pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79 /prefetch:1
PID: 6476, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Cemre.Hatipoglu\
AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\Cemre.Hatipoglu\AppData\
Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Cemre.Hatipoglu\
AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report
--annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --
annotation=ver=123.0.6312.123 --initial-client-
data=0x188,0x18c,0x190,0x164,0x194,0x7ffddca0cc40,0x7ffddca0cc4c,0x7ffddca0cc58
PID: 6620, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=asset_store.mojom.AssetStoreService --lang=tr --service-sandbox-
type=asset_store_service --no-appcompat-clear --field-trial-
handle=4328,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=5136 /prefetch:8
PID: 6836, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -p -s lmhosts
PID: 6872, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s WdiSystemHost
PID: 6904, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalServiceNetworkRestricted -s RmSvc
PID: 7236, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --embedded-browser-
webview=1 --webview-exe-name=Widgets.exe --webview-exe-version=424.1301.2920.0 --
user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView" --
noerrdialogs --disk-cache-size=52428800 --edge-webview-is-background --enable-
features=MojoIpcz,msWebView2TreatAppSuspendAsDeviceSuspend,UseNativeThreadPool,UseB
ackgroundNativeThreadPool --lang=tr-TR --accept-lang=tr-TR --mojo-named-platform-
channel-pipe=11116.10324.12949968738762630402
/pfhostedapp:3eacd73fa368676b0f5a859f64f7f7ea06ffa883
PID: 7316, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
WbioSvcGroup -s WbioSrvc
PID: 7496, Name: sihost.exe, Cmdline: sihost.exe
PID: 7572, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 7856, Name: GoogleCrashHandler64.exe, Cmdline: "C:\Program Files (x86)\Google\
Update\1.3.36.372\GoogleCrashHandler64.exe"
PID: 7872, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs -
p -s TokenBroker
PID: 7940, Name: RtkAudUService64.exe, Cmdline: "C:\Windows\System32\DriverStore\
FileRepository\realtekservice.inf_amd64_285c9fb6a6c4e645\RtkAudUService64.exe" -
admin
PID: 7956, Name: OUTLOOK.EXE, Cmdline: "C:\Program Files\Microsoft Office\root\
Office16\OUTLOOK.EXE" /restore
PID: 8268, Name: backgroundTaskHost.exe, Cmdline: "C:\Windows\system32\
backgroundTaskHost.exe" -ServerName:App.AppXfkd8mejksk4ancwf4vtyhmkvtzn1jcbs.mca
PID: 8328, Name: CSFalconContainer.exe, Cmdline:
PID: 8536, Name: GoogleCrashHandler.exe, Cmdline: "C:\Program Files (x86)\Google\
Update\1.3.36.372\GoogleCrashHandler.exe"
PID: 8604, Name: PanGPA.exe, Cmdline: "C:\Program Files\Palo Alto Networks\
GlobalProtect\PanGPA.exe"
PID: 8720, Name: CSFalconContainer.exe, Cmdline:
PID: 8736, Name: FileCoAuth.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\AppData\Local\
Microsoft\OneDrive\24.055.0317.0002\FileCoAuth.exe" -Embedding
PID: 8948, Name: taskhostw.exe, Cmdline: taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
PID: 9084, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s CDPSvc
PID: 9304, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s DeviceAssociationService
PID: 9356, Name: OfficeClickToRun.exe, Cmdline: "C:\Program Files\Common Files\
Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
PID: 9360, Name: SecurityHealthService.exe, Cmdline:
PID: 9420, Name: backgroundTaskHost.exe, Cmdline: "C:\Windows\system32\
backgroundTaskHost.exe" -
ServerName:Global.DesktopSpotlight.AppXz2j21w56bgxkgsjhtn7zkjsepq96erz2.mca
PID: 9500, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=renderer --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView" --
webview-exe-name=Widgets.exe --webview-exe-version=424.1301.2920.0 --embedded-
browser-webview=1 --no-appcompat-clear --lang=tr --device-scale-factor=1.5 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --js-
flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=tr_TR" --
time-ticks-at-unix-epoch=-1713248930912803 --launch-time-ticks=217250154 --field-
trial-handle=3508,i,7808203864710389820,3900566111316760007,262144 --enable-
features=MojoIpcz,UseBackgroundNativeThreadPool,UseNativeThreadPool,msWebView2Treat
AppSuspendAsDeviceSuspend --variations-seed-version --mojo-platform-channel-
handle=3524 /pfhostedapp:3eacd73fa368676b0f5a859f64f7f7ea06ffa883 /prefetch:1
PID: 9816, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s webthreatdefusersvc
PID: 9880, Name: AggregatorHost.exe, Cmdline: AggregatorHost.exe
PID: 9916, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
WebThreatDefense -p -s webthreatdefsvc
PID: 9952, Name: HPAudioControl_19H1.exe, Cmdline: "C:\Program Files\WindowsApps\
RealtekSemiconductorCorp.HPAudioControl_2.47.308.0_x64__dt26b99r8h8gj\
HPAudioControl_19H1.exe" -ServerName:App.AppX576jqc5ts1hneh16q91rxcnqxvwrgg4a.mca
PID: 9972, Name: CSFalconContainer.exe, Cmdline:
PID: 10008, Name: WmiPrvSE.exe, Cmdline: C:\Windows\system32\wbem\wmiprvse.exe
PID: 10064, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup -s WpnUserService
PID: 10088, Name: explorer.exe, Cmdline: C:\Windows\Explorer.EXE
PID: 10092, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup -s CDPUserSvc
PID: 10100, Name: Timus Connect.exe, Cmdline: "C:\Program Files\Timus Connect\Timus
Connect.exe"
PID: 10120, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceAndNoImpersonation -p -s SSDPSRV
PID: 10348, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --embedded-browser-
webview=1 --webview-exe-name=ms-teams.exe --webview-exe-
version=24060.2623.2790.8046 --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\
Local\Packages\MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --
noerrdialogs --embedded-browser-webview-dpi-awareness=2 --autoplay-policy=no-user-
gesture-required --disable-background-timer-throttling --disable-
features=msEnhancedTrackingPreventionEnabled,V8Maglev,msFloatyMode,msFloatyShouldHo
norIndiaHoldout,msWebOOUI --enable-
features=MojoIpcz,msSingleSignOnOSForPrimaryAccountIsShared,PartitionedCookies,Shar
edArrayBuffer,ThirdPartyStoragePartitioning,msAbydos,msAbydosGestureSupport,msAbydo
sHandwritingAttr,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream
--isolate-origins=https://[*.]microsoft.com,https://[*.]sharepoint.com,https://
[*.]sharepointonline.com,https://mesh-hearts-teams.azurewebsites.net,https://
[*.]meshxp.net,https://res-sdf.cdn.office.net,https://res.cdn.office.net,https://
copilot.teams.cloud.microsoft,https://local.copilot.teams.office.com --lang=tr-TR
--accept-lang=tr-TR --mojo-named-platform-channel-
pipe=15860.16044.12402219145394797070
/pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6
PID: 10380, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs
-p -s Appinfo
PID: 10596, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
ClipboardSvcGroup -p -s cbdhsvc
PID: 10800, Name: RtkAudUService64.exe, Cmdline: "C:\Windows\System32\DriverStore\
FileRepository\realtekservice.inf_amd64_285c9fb6a6c4e645\RtkAudUService64.exe" -
background
PID: 10812, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=tr --js-
flags=--ms-user-locale=tr_TR --device-scale-factor=1.5 --num-raster-threads=4 --
enable-main-frame-before-activation --renderer-client-id=8 --time-ticks-at-unix-
epoch=-1713248926589593 --launch-time-ticks=89357511100 --field-trial-
handle=5496,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=5640 /prefetch:1
PID: 10892, Name: ApplicationFrameHost.exe, Cmdline: C:\Windows\system32\
ApplicationFrameHost.exe -Embedding
PID: 10916, Name: SearchHost.exe, Cmdline: "C:\Windows\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe" -
ServerName:CortanaUI.AppXstmwaab17q5s3y22tp6apqz7a45vwv65.mca
PID: 10940, Name: StartMenuExperienceHost.exe, Cmdline: "C:\Windows\SystemApps\
Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\
StartMenuExperienceHost.exe" -
ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
PID: 11036, Name: Microsoft.Notes.exe, Cmdline: "C:\Program Files\WindowsApps\
Microsoft.MicrosoftStickyNotes_6.0.2.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe" -
ServerName:App.AppX495fygk72hjw82j58ny5h3nr8hpsd8vs.mca
PID: 11116, Name: Widgets.exe, Cmdline: "C:\Program Files\WindowsApps\
MicrosoftWindows.Client.WebExperience_424.1301.450.0_x64__cw5n1h2txyewy\Dashboard\
Widgets.exe" -ServerName:Microsoft.Windows.DashboardServer
PID: 11212, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 11340, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 11440, Name: Timus Connect.exe, Cmdline: "C:\Program Files\Timus Connect\Timus
Connect.exe" --type=gpu-process --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\
Roaming\Timus Connect" --gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--mojo-platform-channel-handle=1680 --field-trial-
handle=1696,i,8075542629063631105,6453845123940461168,262144 --disable-
features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSu
ggestionsOnlyOnDemand /prefetch:2
PID: 11448, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 11576, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
UdkSvcGroup -s UdkUserSvc
PID: 11920, Name: dllhost.exe, Cmdline: C:\Windows\system32\DllHost.exe /Processid:
{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
PID: 12352, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs
-p -s wlidsvc
PID: 12616, Name: dllhost.exe, Cmdline: C:\Windows\system32\DllHost.exe /Processid:
{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
PID: 12628, Name: SecurityHealthSystray.exe, Cmdline: "C:\Windows\System32\
SecurityHealthSystray.exe"
PID: 12656, Name: svchost.exe, Cmdline:
PID: 12672, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s SstpSvc
PID: 12784, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s NPSMSvc
PID: 12848, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=gpu-process --no-appcompat-clear --gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--field-trial-handle=1920,i,9582548629418647418,7580602879395158567,262144 --
variations-seed-version=20240415-180155.222000 --mojo-platform-channel-
handle=1720 /prefetch:2
PID: 12860, Name: ctfmon.exe, Cmdline: "ctfmon.exe"
PID: 12944, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\
Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView" --
webview-exe-name=OUTLOOK.EXE --webview-exe-version=16.0.17425.20176 --embedded-
browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear
--field-trial-handle=1960,i,1315581269799843307,13003484811696677758,262144 --
enable-
features=MojoIpcz,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleS
ignOnOSForPrimaryAccountIsShared --variations-seed-version --mojo-platform-channel-
handle=2548 /prefetch:3 /pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79
PID: 13060, Name: WmiPrvSE.exe, Cmdline: C:\Windows\system32\wbem\wmiprvse.exe
PID: 13064, Name: WidgetService.exe, Cmdline: "C:\Program Files\WindowsApps\
MicrosoftWindows.Client.WebExperience_424.1301.450.0_x64__cw5n1h2txyewy\Dashboard\
widgetservice.exe" -RegisterProcessAsComServer -Embedding
PID: 13192, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=renderer --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --
autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --
lang=tr --device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=14 --js-flags="--harmony-weak-refs-with-
cleanup-some --expose-gc --ms-user-locale=tr-TR" --time-ticks-at-unix-epoch=-
1713248930905692 --launch-time-ticks=89356098061 --field-trial-
handle=4612,i,15592129286464569165,6851996636257069291,262144 --enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=4544
/pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6 /prefetch:1
PID: 13544, Name: slack.exe, Cmdline: --process-start-args --startup
PID: 13744, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 13824, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService
--lang=tr --service-sandbox-type=audio --no-appcompat-clear --field-trial-
handle=6796,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=6752 /prefetch:8
PID: 13920, Name: OneDrive.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\AppData\Local\
Microsoft\OneDrive\OneDrive.exe" /background
PID: 14272, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --flag-switches-begin --flag-switches-end
PID: 14832, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 14840, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs
-p -s gpsvc
PID: 15016, Name: SystemSettingsBroker.exe, Cmdline: C:\Windows\System32\
SystemSettingsBroker.exe -Embedding
PID: 15056, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=tr --js-
flags=--ms-user-locale=tr_TR --device-scale-factor=1.5 --num-raster-threads=4 --
enable-main-frame-before-activation --renderer-client-id=12 --time-ticks-at-unix-
epoch=-1713248926589593 --launch-time-ticks=89357916514 --field-trial-
handle=6208,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=5472 /prefetch:1
PID: 15300, Name: svchost.exe, Cmdline:
PID: 15320, Name: audiodg.exe, Cmdline: C:\Windows\system32\AUDIODG.EXE
0x00000000000004F0
PID: 15444, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalSystemNetworkRestricted -p -s PcaSvc
PID: 15448, Name: slack.exe, Cmdline: C:\Users\Cemre.Hatipoglu\AppData\Local\slack\
app-4.37.101\slack.exe --type=crashpad-handler --user-data-dir=C:\Users\
Cemre.Hatipoglu\AppData\Roaming\Slack /prefetch:4 --no-upload-gzip --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\Cemre.Hatipoglu\AppData\
Roaming\Slack\Crashpad
--url=https://slack.com/apps/sentryproxy/api/5277886/minidump/?
sentry_key=fd30fe469dbf4aec9db40548e5acf91e --annotation=_productName=Slack --
annotation=_version=4.37.101 --annotation=plat=Win64 --annotation=prod=Electron "--
annotation=sentry___initialScope={\"release\":\"
[email protected]\",\"environment\":\"
production\",\"user\":{\"id\":\"77652fc2-10e6-4d52-8296-69985e7c22de\"},\"tags\":
{\"uuid\":\"77652fc2-10e6-4d52-8296-69985e7c22de\"}}" --annotation=ver=29.1.6 --
initial-client-
data=0x4b8,0x4bc,0x4c0,0x47c,0x4c4,0x7ff7d6b3d8c0,0x7ff7d6b3d8cc,0x7ff7d6b3d8d8
PID: 15536, Name: slack.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\AppData\Local\
slack\app-4.37.101\slack.exe" --type=gpu-process --enable-logging --user-data-
dir="C:\Users\Cemre.Hatipoglu\AppData\Roaming\Slack" --gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--enable-logging --log-file="C:\Users\Cemre.Hatipoglu\AppData\Roaming\Slack\logs\
default\electron_debug.log" --mojo-platform-channel-handle=1716 --field-trial-
handle=1724,i,1006956497298078404,8017062832800715534,262144 --enable-
features=kWebSQLAccess --disable-
features=AllowAggressiveThrottlingWithWebSocket,CalculateNativeWinOcclusion,Hardwar
eMediaKeyHandling,IntensiveWakeUpThrottling,LogJsConsoleMessages,RequestInitiatorSi
teLockEnfocement,SpareRendererForSitePerProcess,WebRTCPipeWireCapturer,WebRtcHideLo
calIpsWithMdns,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --
variations-seed-version /prefetch:2
PID: 15572, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceAndNoImpersonation -p -s QWAVE
PID: 15576, Name: slack.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\AppData\Local\
slack\app-4.37.101\slack.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --lang=tr --service-sandbox-type=none --enable-
logging --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Roaming\Slack" --
standard-schemes=app,slack-webapp-dev --enable-sandbox --secure-schemes=app,slack-
webapp-dev --bypasscsp-schemes=slack-webapp-dev --cors-schemes=slack-webapp-dev --
fetch-schemes=slack-webapp-dev --service-worker-schemes=slack-webapp-dev --enable-
logging --log-file="C:\Users\Cemre.Hatipoglu\AppData\Roaming\Slack\logs\default\
electron_debug.log" --mojo-platform-channel-handle=1980 --field-trial-
handle=1724,i,1006956497298078404,8017062832800715534,262144 --enable-
features=kWebSQLAccess --disable-
features=AllowAggressiveThrottlingWithWebSocket,CalculateNativeWinOcclusion,Hardwar
eMediaKeyHandling,IntensiveWakeUpThrottling,LogJsConsoleMessages,RequestInitiatorSi
teLockEnfocement,SpareRendererForSitePerProcess,WebRTCPipeWireCapturer,WebRtcHideLo
calIpsWithMdns,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --
variations-seed-version /prefetch:3
PID: 15680, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=tr --js-
flags=--ms-user-locale=tr_TR --device-scale-factor=1.5 --num-raster-threads=4 --
enable-main-frame-before-activation --renderer-client-id=9 --time-ticks-at-unix-
epoch=-1713248926589593 --launch-time-ticks=89357483238 --field-trial-
handle=5468,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=5484 /prefetch:1
PID: 15732, Name: smartscreen.exe, Cmdline: C:\Windows\System32\smartscreen.exe -
Embedding
PID: 15860, Name: ms-teams.exe, Cmdline: "C:\Program Files\WindowsApps\
MSTeams_24060.2623.2790.8046_x64__8wekyb3d8bbwe\ms-teams.exe" msteams:system-
initiated
PID: 15916, Name: slack.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\AppData\Local\
slack\app-4.37.101\slack.exe" --type=renderer --user-data-dir="C:\Users\
Cemre.Hatipoglu\AppData\Roaming\Slack" --standard-schemes=app,slack-webapp-dev --
enable-sandbox --secure-schemes=app,slack-webapp-dev --bypasscsp-schemes=slack-
webapp-dev --cors-schemes=slack-webapp-dev --fetch-schemes=slack-webapp-dev --
service-worker-schemes=slack-webapp-dev --app-user-model-
id=com.squirrel.slack.slack --app-path="C:\Users\Cemre.Hatipoglu\AppData\Local\
slack\app-4.37.101\resources\app.asar" --enable-sandbox --enable-blink-
features=ExperimentalJSProfiler --disable-blink-features --autoplay-policy=no-user-
gesture-required --enable-logging --force-color-profile=srgb --log-file="C:\Users\
Cemre.Hatipoglu\AppData\Roaming\Slack\logs\default\electron_debug.log" --lang=tr --
device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-before-
activation --renderer-client-id=4 --time-ticks-at-unix-epoch=-1713248930908126 --
launch-time-ticks=53008297 --mojo-platform-channel-handle=2828 --field-trial-
handle=1724,i,1006956497298078404,8017062832800715534,262144 --enable-
features=kWebSQLAccess --disable-
features=AllowAggressiveThrottlingWithWebSocket,CalculateNativeWinOcclusion,Hardwar
eMediaKeyHandling,IntensiveWakeUpThrottling,LogJsConsoleMessages,RequestInitiatorSi
teLockEnfocement,SpareRendererForSitePerProcess,WebRTCPipeWireCapturer,WebRtcHideLo
calIpsWithMdns,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --
variations-seed-version --window-type=main /prefetch:1
PID: 15964, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalServiceAndNoImpersonation -s SCardSvr
PID: 16296, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=storage.mojom.StorageService --lang=tr --service-sandbox-type=service --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView" --
webview-exe-name=Widgets.exe --webview-exe-version=424.1301.2920.0 --embedded-
browser-webview=1 --no-appcompat-clear --field-trial-
handle=1968,i,7808203864710389820,3900566111316760007,262144 --enable-
features=MojoIpcz,UseBackgroundNativeThreadPool,UseNativeThreadPool,msWebView2Treat
AppSuspendAsDeviceSuspend --variations-seed-version --mojo-platform-channel-
handle=2864 /prefetch:8 /pfhostedapp:3eacd73fa368676b0f5a859f64f7f7ea06ffa883
PID: 16320, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalService -p -s LicenseManager
PID: 16328, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
LocalService -p -s PhoneSvc
PID: 16344, Name: SECOCL64.exe, Cmdline: /exit-mutex-guid={1B98C26F-B074-4A42-B2B8-
217728AA4D2C} /host-pipe-name=\\.\pipe\{FB776D23-67BF-4E4C-945A-99282F0B2BE1}
/endpoint-id={0.0.0.00000000}.{f75fe73d-76ee-4806-ab59-40a7108233cb}
PID: 16460, Name: slack.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\AppData\Local\
slack\app-4.37.101\slack.exe" --type=utility --utility-sub-
type=audio.mojom.AudioService --lang=tr --service-sandbox-type=audio --enable-
logging --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Roaming\Slack" --
standard-schemes=app,slack-webapp-dev --enable-sandbox --secure-schemes=app,slack-
webapp-dev --bypasscsp-schemes=slack-webapp-dev --cors-schemes=slack-webapp-dev --
fetch-schemes=slack-webapp-dev --service-worker-schemes=slack-webapp-dev --enable-
logging --log-file="C:\Users\Cemre.Hatipoglu\AppData\Roaming\Slack\logs\default\
electron_debug.log" --mojo-platform-channel-handle=3668 --field-trial-
handle=1724,i,1006956497298078404,8017062832800715534,262144 --enable-
features=kWebSQLAccess --disable-
features=AllowAggressiveThrottlingWithWebSocket,CalculateNativeWinOcclusion,Hardwar
eMediaKeyHandling,IntensiveWakeUpThrottling,LogJsConsoleMessages,RequestInitiatorSi
teLockEnfocement,SpareRendererForSitePerProcess,WebRTCPipeWireCapturer,WebRtcHideLo
calIpsWithMdns,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --
variations-seed-version /prefetch:8
PID: 16496, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=crashpad-handler
--user-data-dir=C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView /prefetch:4
/pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6 --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\Cemre.Hatipoglu\AppData\
Local\Packages\MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView\
Crashpad --metrics-dir=C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView --
annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-
version=123.0.6312.123 "--annotation=exe=C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --annotation=plat=Win64
"--annotation=prod=Edge WebView2" --annotation=ver=123.0.2420.97 --initial-client-
data=0x184,0x188,0x18c,0x160,0x194,0x7ffe08094e48,0x7ffe08094e54,0x7ffe08094e60
PID: 16672, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=renderer --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\
Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView" --
webview-exe-name=OUTLOOK.EXE --webview-exe-version=16.0.17425.20176 --embedded-
browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear
--lang=en-US --device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=7 --js-flags="--harmony-weak-refs-with-
cleanup-some --expose-gc --ms-user-locale=tr-TR" --time-ticks-at-unix-epoch=-
1713248930907302 --launch-time-ticks=4132965388 --field-trial-
handle=5148,i,1315581269799843307,13003484811696677758,262144 --enable-
features=MojoIpcz,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleS
ignOnOSForPrimaryAccountIsShared --variations-seed-version --mojo-platform-channel-
handle=5020 /pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79 /prefetch:1
PID: 16736, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=gpu-process --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--field-trial-handle=1752,i,15592129286464569165,6851996636257069291,262144 --
enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=1740
/prefetch:2 /pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6
PID: 16804, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=network.mojom.NetworkService --lang=tr --service-sandbox-type=none --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --field-
trial-handle=1988,i,15592129286464569165,6851996636257069291,262144 --enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=2620
/prefetch:3 /pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6
PID: 16812, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=storage.mojom.StorageService --lang=tr --service-sandbox-type=service --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --field-
trial-handle=2144,i,15592129286464569165,6851996636257069291,262144 --enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=2832
/prefetch:8 /pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6
PID: 16820, Name: Timus Connect.exe, Cmdline: "C:\Program Files\Timus Connect\Timus
Connect.exe" --type=renderer --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\
Roaming\Timus Connect" --standard-schemes=timus-connect --secure-schemes --
bypasscsp-schemes --cors-schemes --fetch-schemes --service-worker-schemes --
streaming-schemes --app-user-model-id="Timus Connect" --app-path="C:\Program Files\
Timus Connect\resources\app.asar" --no-sandbox --no-zygote --first-renderer-process
--lang=tr --device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=4 --time-ticks-at-unix-epoch=-
1713248926580637 --launch-time-ticks=85003759188 --mojo-platform-channel-
handle=2408 --field-trial-
handle=1696,i,8075542629063631105,6453845123940461168,262144 --disable-
features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSu
ggestionsOnlyOnDemand /prefetch:1
PID: 16840, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=renderer --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --
autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --
lang=tr --device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-
cleanup-some --expose-gc --ms-user-locale=tr-TR" --time-ticks-at-unix-epoch=-
1713248930905692 --launch-time-ticks=59463628 --field-trial-
handle=3456,i,15592129286464569165,6851996636257069291,262144 --enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=3472
/pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6 /prefetch:1
PID: 17044, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=renderer --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --
autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --
lang=tr --device-scale-factor=1.5 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=6 --js-flags="--harmony-weak-refs-with-
cleanup-some --expose-gc --ms-user-locale=tr-TR" --time-ticks-at-unix-epoch=-
1713248930905692 --launch-time-ticks=59863982 --field-trial-
handle=4152,i,15592129286464569165,6851996636257069291,262144 --enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=4176
/pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6 /prefetch:1
PID: 17224, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=29 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=94616604 --field-trial-
handle=6384,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=6680 /prefetch:1
PID: 17320, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s StorSvc
PID: 17368, Name: svchost.exe, Cmdline:
PID: 17416, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=network.mojom.NetworkService --lang=tr --service-sandbox-type=none --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView" --
webview-exe-name=Widgets.exe --webview-exe-version=424.1301.2920.0 --embedded-
browser-webview=1 --no-appcompat-clear --field-trial-
handle=1868,i,7808203864710389820,3900566111316760007,262144 --enable-
features=MojoIpcz,UseBackgroundNativeThreadPool,UseNativeThreadPool,msWebView2Treat
AppSuspendAsDeviceSuspend --variations-seed-version --mojo-platform-channel-
handle=2108 /prefetch:3 /pfhostedapp:3eacd73fa368676b0f5a859f64f7f7ea06ffa883
PID: 17440, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k netsvcs
-p -s lfsvc
PID: 17492, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 17740, Name: ShellExperienceHost.exe, Cmdline: "C:\Windows\SystemApps\
ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -
ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
PID: 17748, Name: SearchProtocolHost.exe, Cmdline: "C:\Windows\System32\
SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1588283499-
1822172397-622671684-2241623_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-
1588283499-1822172397-622671684-2241623 1 -2147483646 "Software\Microsoft\Windows
Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\
ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
PID: 17928, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=utility --utility-
sub-type=audio.mojom.AudioService --lang=tr --service-sandbox-type=audio --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams\EBWebView" --webview-exe-
name=ms-teams.exe --webview-exe-version=24060.2623.2790.8046 --embedded-browser-
webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear --field-
trial-handle=5156,i,15592129286464569165,6851996636257069291,262144 --enable-
features=MojoIpcz,PartitionedCookies,SharedArrayBuffer,ThirdPartyStoragePartitionin
g,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleSignOnOSForPrimar
yAccountIsShared,msWebView2CodeCache,msWebView2EnableDraggableRegions,msWebView2Tex
tureStream --disable-
features=V8Maglev,msEnhancedTrackingPreventionEnabled,msFloatyShouldHonorIndiaHoldo
ut,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=5544
/prefetch:8 /pfhostedapp:9ca2ac25137b6238f12ddb55b62c34d1e196efc6
PID: 18188, Name: dllhost.exe, Cmdline: C:\Windows\system32\DllHost.exe /Processid:
{7EAD5C10-8B3F-11E6-AE22-56B6B6499611}
PID: 18196, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --
lang=tr --service-sandbox-type=none --no-appcompat-clear --field-trial-
handle=2124,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=1960 /prefetch:3
PID: 18296, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=gpu-process --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Packages\
MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView" --
webview-exe-name=Widgets.exe --webview-exe-version=424.1301.2920.0 --embedded-
browser-webview=1 --no-appcompat-clear --gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--field-trial-handle=1800,i,7808203864710389820,3900566111316760007,262144 --
enable-
features=MojoIpcz,UseBackgroundNativeThreadPool,UseNativeThreadPool,msWebView2Treat
AppSuspendAsDeviceSuspend --variations-seed-version --mojo-platform-channel-
handle=1792 /prefetch:2 /pfhostedapp:3eacd73fa368676b0f5a859f64f7f7ea06ffa883
PID: 18512, Name: , Cmdline:
PID: 18588, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=renderer --no-appcompat-clear --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=611 --time-ticks-at-unix-epoch=-1713248930915135 --launch-time-
ticks=53001772987 --field-trial-
handle=10076,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=8564 /prefetch:1
PID: 18832, Name: svchost.exe, Cmdline: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup
PID: 18840, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 19024, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
WerSvcGroup
PID: 19192, Name: SearchProtocolHost.exe, Cmdline: "C:\Windows\System32\
SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe24_ Global\
UsGthrCtrlFltPipeMssGthrPipe24 1 -2147483646 "Software\Microsoft\Windows Search"
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\
ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
PID: 19408, Name: chrome.exe, Cmdline: "C:\Program Files\Google\Chrome\Application\
chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=tr --
service-sandbox-type=audio --no-appcompat-clear --field-trial-
handle=6400,i,9582548629418647418,7580602879395158567,262144 --variations-seed-
version=20240415-180155.222000 --mojo-platform-channel-handle=6476 /prefetch:8
PID: 19420, Name: msedgewebview2.exe, Cmdline: "C:\Program Files (x86)\Microsoft\
EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe" --type=gpu-process --
noerrdialogs --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\Local\Microsoft\
Office\16.0\Wef\webview2\a965b889-9c51-437a-a0b1-071d64d6b4a3_ADAL\2\EBWebView" --
webview-exe-name=OUTLOOK.EXE --webview-exe-version=16.0.17425.20176 --embedded-
browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --no-appcompat-clear
--gpu-
preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA==
--field-trial-handle=1684,i,1315581269799843307,13003484811696677758,262144 --
enable-
features=MojoIpcz,msAbydos,msAbydosGestureSupport,msAbydosHandwritingAttr,msSingleS
ignOnOSForPrimaryAccountIsShared --variations-seed-version --mojo-platform-channel-
handle=1736 /prefetch:2 /pfhostedapp:290e723465b9cdc08c3c5d0a63eaa88b2fea1e79
PID: 19504, Name: Timus Connect.exe, Cmdline: "C:\Program Files\Timus Connect\Timus
Connect.exe" --type=renderer --user-data-dir="C:\Users\Cemre.Hatipoglu\AppData\
Roaming\Timus Connect" --standard-schemes=timus-connect --secure-schemes --
bypasscsp-schemes --cors-schemes --fetch-schemes --service-worker-schemes --
streaming-schemes --app-user-model-id="Timus Connect" --app-path="C:\Program Files\
Timus Connect\resources\app.asar" --enable-sandbox --lang=tr --device-scale-
factor=1.5 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=5 --time-ticks-at-unix-epoch=-1713248926580637 --launch-time-
ticks=85005277049 --mojo-platform-channel-handle=3184 --field-trial-
handle=1696,i,8075542629063631105,6453845123940461168,262144 --disable-
features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSu
ggestionsOnlyOnDemand /prefetch:1
PID: 19516, Name: , Cmdline:
PID: 19792, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --no-startup-window
PID: 19940, Name: AppVShNotify.exe, Cmdline: "C:\Program Files\Common Files\
Microsoft Shared\ClickToRun\AppVShNotify.exe"
PID: 19964, Name: timus-connect-service.exe, Cmdline: "C:\Program Files\Timus
Connect\resources\service\timus-connect-service.exe"
PID: 20008, Name: SearchIndexer.exe, Cmdline: C:\Windows\system32\SearchIndexer.exe
/Embedding
PID: 20328, Name: SearchFilterHost.exe, Cmdline: "C:\Windows\System32\
SearchFilterHost.exe" 872 3608 3612 856 {7FC3863B-7471-4B10-84E3-A5C2E0330618}
PID: 20340, Name: timus-connect-service.exe, Cmdline: "C:\Program Files\Timus
Connect\resources\service\timus-connect-service.exe" tracker
PID: 20412, Name: RuntimeBroker.exe, Cmdline: C:\Windows\System32\RuntimeBroker.exe
-Embedding
PID: 20544, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --lang=tr --service-sandbox-type=none --no-
appcompat-clear --field-trial-
handle=2444,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=2552 /prefetch:3
PID: 21212, Name: timus-helper-service.exe, Cmdline: "C:\Program Files\Timus
Connect\resources\service\timus-helper-service.exe"
PID: 21568, Name: HPAudioAnalytics.exe, Cmdline: C:\Windows\System32\DriverStore\
FileRepository\hpqkbsoftwarecompnent.inf_amd64_6c234fdd160946fe\
HPAudioAnalytics.exe
PID: 21648, Name: svchost.exe, Cmdline: C:\Windows\System32\svchost.exe -k
LocalSystemNetworkRestricted -p -s DsSvc
PID: 21676, Name: conhost.exe, Cmdline: \??\C:\Windows\system32\conhost.exe 0x4
PID: 21780, Name: Timus Connect.exe, Cmdline: "C:\Program Files\Timus Connect\Timus
Connect.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --
lang=tr --service-sandbox-type=none --user-data-dir="C:\Users\Cemre.Hatipoglu\
AppData\Roaming\Timus Connect" --standard-schemes=timus-connect --secure-schemes --
bypasscsp-schemes --cors-schemes --fetch-schemes --service-worker-schemes --
streaming-schemes --mojo-platform-channel-handle=1832 --field-trial-
handle=1696,i,8075542629063631105,6453845123940461168,262144 --disable-
features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSu
ggestionsOnlyOnDemand /prefetch:8
PID: 22004, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=tr --service-
sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --field-
trial-handle=5792,i,14303424895933633058,5885765820107907296,262144 --variations-
seed-version --mojo-platform-channel-handle=1308 /prefetch:8
PID: 22164, Name: conhost.exe, Cmdline: \??\C:\Windows\system32\conhost.exe 0x4
PID: 22388, Name: Microsoft.SharePoint.exe, Cmdline: "C:\Users\Cemre.Hatipoglu\
AppData\Local\Microsoft\OneDrive\24.055.0317.0002\Microsoft.SharePoint.exe"
/silentConfig
PID: 22392, Name: backgroundTaskHost.exe, Cmdline: "C:\Windows\system32\
backgroundTaskHost.exe" -
ServerName:Microsoft.MicrosoftOfficeHub.AppX54h2e8jwdm50fj5ha8987vz1etpx7czd.mca
PID: 22408, Name: msedge.exe, Cmdline: "C:\Program Files (x86)\Microsoft\Edge\
Application\msedge.exe" --type=utility --utility-sub-
type=storage.mojom.StorageService --lang=tr --service-sandbox-type=service --no-
appcompat-clear --field-trial-
handle=2808,i,14303424895933633058,5885765820107907296,262144 --variations-seed-
version --mojo-platform-channel-handle=2816 /prefetch:8
PID: 22504, Name: SystemSettings.exe, Cmdline: "C:\Windows\ImmersiveControlPanel\
SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel