***********************************************
* *
* ____ _____ ____ _ ___ _ _ _____ *
* | _ \| ____| _ \| | |_ _| \ | | ____| *
* | |_) | _| | | | | | | || \| | _| *
* | _ <| |___| |_| | |___ | || |\ | |___ *
* |_| \_|_____|____/|_____|___|_| \_|_____| *
* *
* Telegram: https://t.me/REDLINESUPPORT *
***********************************************
ID: 784, Name: csrss.exe, CommandLine:
===============
ID: 1056, Name: winlogon.exe, CommandLine: winlogon.exe
===============
ID: 1144, Name: fontdrvhost.exe, CommandLine: "fontdrvhost.exe"
===============
ID: 1244, Name: dwm.exe, CommandLine: "dwm.exe"
===============
ID: 2932, Name: rundll32.exe, CommandLine: rundll32.exe "c:\program files\nvidia
corporation\nvstreamsrv\rxdiag.dll" RxDiagSetRuntimeMessagePump
===============
ID: 6988, Name: NVDisplay.Container.exe, CommandLine: "C:\WINDOWS\System32\
DriverStore\FileRepository\nvami.inf_amd64_e1c005a6713cc50a\Display.NvContainer\
NVDisplay.Container.exe" -f %ProgramData%\NVIDIA\DisplaySessionContainer%d.log -d
C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_e1c005a6713cc50a\
Display.NvContainer\plugins\Session -r -l 3 -p 30000 -cfg
NVDisplay.ContainerLocalSystem\Session -c
===============
ID: 7140, Name: HControl.exe, CommandLine: "C:\Program Files (x86)\ASUS\ATK
Package\ATK Hotkey\HControl.exe"
===============
ID: 672, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA Corporation\
NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%dSPUser.log"
-d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\SPUser" -r -l 3 -p
30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\
NvContainerTelemetryApi.dll" -c
===============
ID: 2968, Name: sihost.exe, CommandLine: sihost.exe
===============
ID: 2352, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA Corporation\
NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d
"C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st
"C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
===============
ID: 1172, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup -s CDPUserSvc
===============
ID: 3792, Name: igfxEM.exe, CommandLine: "C:\WINDOWS\System32\DriverStore\
FileRepository\cui_dch.inf_amd64_559285e7cb5ac63e\igfxEM.exe"
===============
ID: 7316, Name: taskhostw.exe, CommandLine: taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
===============
ID: 7608, Name: ctfmon.exe, CommandLine: "ctfmon.exe"
===============
ID: 7212, Name: DMedia.exe, CommandLine: "C:\Program Files (x86)\ASUS\ATK Package\
ATK Media\DMedia.exe"
===============
ID: 7216, Name: ATKOSD2.exe, CommandLine: "C:\Program Files (x86)\ASUS\ATK Package\
ATKOSD2\ATKOSD2.exe"
===============
ID: 7704, Name: explorer.exe, CommandLine: C:\WINDOWS\Explorer.EXE
===============
ID: 9024, Name: NVIDIA Web Helper.exe, CommandLine: "C:\Program Files (x86)\NVIDIA
Corporation\NvNode\NVIDIA Web Helper.exe" index.js
===============
ID: 9132, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 8780, Name: AsusTPLoader.exe, CommandLine: "C:\Program Files (x86)\ASUS\ASUS
Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
===============
ID: 9992, Name: nvsphelper64.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\ShadowPlay\nvsphelper64.exe"
===============
ID: 10012, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
===============
ID: 9336, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=gpu-process --field-
trial-handle=2056,15171620840285390251,1521768407602960392,131072 --disable-
features=VizDisplayCompositor --no-sandbox --log-file="C:\Users\mosta\AppData\
Local\NVIDIA Corporation\NVIDIA Share\debug.log" --lang=en-US --gpu-
preferences=KAAAAAAAAACACwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\mosta\AppData\Local\
NVIDIA Corporation\NVIDIA Share\debug.log" --service-request-channel-
token=1244681038870697557 --mojo-platform-channel-handle=2068 /prefetch:2
===============
ID: 7816, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --no-
sandbox --autoplay-policy=no-user-gesture-required --log-file="C:\Users\mosta\
AppData\Local\NVIDIA Corporation\NVIDIA Share\debug.log" --field-trial-
handle=2056,15171620840285390251,1521768407602960392,131072 --disable-
features=VizDisplayCompositor --service-pipe-token=3549400927279552408 --lang=en-US
--log-file="C:\Users\mosta\AppData\Local\NVIDIA Corporation\NVIDIA Share\debug.log"
--device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-
activation --service-request-channel-token=3549400927279552408 --renderer-client-
id=3 --mojo-platform-channel-handle=2780 /prefetch:1
===============
ID: 9944, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
ClipboardSvcGroup -p -s cbdhsvc
===============
ID: 10568, Name: SearchHost.exe, CommandLine: "C:\WINDOWS\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe" -
ServerName:CortanaUI.AppXstmwaab17q5s3y22tp6apqz7a45vwv65.mca
===============
ID: 10620, Name: StartMenuExperienceHost.exe, CommandLine: "C:\Windows\SystemApps\
Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\
StartMenuExperienceHost.exe" -
ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
===============
ID: 10756, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 10852, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UdkSvcGroup -s UdkUserSvc
===============
ID: 10868, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 11204, Name: dllhost.exe, CommandLine: C:\WINDOWS\system32\DllHost.exe
/Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
===============
ID: 11628, Name: AsusTPHelper.exe, CommandLine: "C:\Program Files (x86)\ASUS\ASUS
Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
===============
ID: 2400, Name: TextInputHost.exe, CommandLine: "C:\WINDOWS\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -
ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca
===============
ID: 3700, Name: SecurityHealthSystray.exe, CommandLine: "C:\Windows\System32\
SecurityHealthSystray.exe"
===============
ID: 11336, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
LocalService -p -s NPSMSvc
===============
ID: 12348, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --no-startup-window /prefetch:5
===============
ID: 12464, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\mosta\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\mosta\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\mosta\AppData\Local\Google\
Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel=
--annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=92.0.4515.107 --
initial-client-
data=0xf4,0xf8,0xfc,0xd0,0x100,0x7ffb69c75390,0x7ffb69c753a0,0x7ffb69c753b0
===============
ID: 12604, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=gpu-process --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --gpu-
preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAA
AAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHA
AAADQAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1840 /prefetch:2
===============
ID: 12616, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=network.mojom.NetworkService --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --service-
sandbox-type=none --mojo-platform-channel-handle=2112 /prefetch:8
===============
ID: 12700, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=storage.mojom.StorageService --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --service-
sandbox-type=utility --mojo-platform-channel-handle=2232 /prefetch:8
===============
ID: 12920, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=18 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3148 /prefetch:1
===============
ID: 12932, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3136 /prefetch:1
===============
ID: 12984, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3836 /prefetch:1
===============
ID: 13044, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=4764 /prefetch:1
===============
ID: 13112, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4996
/prefetch:1
===============
ID: 13132, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5096
/prefetch:1
===============
ID: 13200, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5296
/prefetch:1
===============
ID: 6576, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4924
/prefetch:1
===============
ID: 13396, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5620
/prefetch:1
===============
ID: 13440, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5664
/prefetch:1
===============
ID: 13584, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=16 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5316
/prefetch:1
===============
ID: 14232, Name: CAudioFilterAgent64.exe, CommandLine: "C:\Program Files\Conexant\
cAudioFilterAgent\cAudioFilterAgent64.exe"
===============
ID: 14720, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=25 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=8316 /prefetch:1
===============
ID: 14824, Name: SmartAudio.exe, CommandLine: "C:\Program Files\Conexant\SAII\
SmartAudio.exe" /c
===============
ID: 15260, Name: swch_go_service.exe, CommandLine: "C:\Users\mosta\AppData\Local\
Programs\safe-watch\resources\app\swch_go_service\swch_go_service.exe"
===============
ID: 15320, Name: BingSvc.exe, CommandLine: "C:\Users\mosta\AppData\Local\Microsoft\
BingSvc\BingSvc.exe"
===============
ID: 14700, Name: Cortana.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.549981C3F5F10_3.2106.14307.0_x64__8wekyb3d8bbwe\Cortana.exe" -
ServerName:App.AppX2y379sjp88wjq1y80217mddj3fargf2y.mca
===============
ID: 12232, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 14876, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
AarSvcGroup -p -s AarSvc
===============
ID: 12020, Name: hid.exe, CommandLine: "C:\Program Files (x86)\ASUS Gaming Mouse\
hid.exe"
===============
ID: 6664, Name: ApplicationFrameHost.exe, CommandLine: C:\WINDOWS\system32\
ApplicationFrameHost.exe -Embedding
===============
ID: 13996, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup
===============
ID: 14792, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService
--field-trial-handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-
US --service-sandbox-type=audio --mojo-platform-channel-handle=9100 /prefetch:8
===============
ID: 8472, Name: MiniSearchHost.exe, CommandLine: "C:\WINDOWS\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy\MiniSearchHost.exe" -
ServerName:MiniSearchUI.AppXj3y73at8fy1htwztzxs68sxx1v7cksp7.mca
===============
ID: 6872, Name: Microsoft.Photos.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.Windows.Photos_2021.21060.9012.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe"
-ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
===============
ID: 4780, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 14428, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --extension-
process --origin-trial-disabled-features=SecurePaymentConfirmation --device-scale-
factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-
client-id=217 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=5152 /prefetch:1
===============
ID: 6524, Name: dllhost.exe, CommandLine: C:\WINDOWS\system32\DllHost.exe
/Processid:{7EAD5C10-8B3F-11E6-AE22-56B6B6499611}
===============
ID: 664, Name: AsusTPCenter.exe, CommandLine: "C:\Program Files (x86)\ASUS\ASUS
Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
===============
ID: 5936, Name: OneDrive.exe, CommandLine: /updateInstalled /background
===============
ID: 12360, Name: Zoom.exe, CommandLine: "C:\Program Files (x86)\Zoom\bin\Zoom.exe"
===============
ID: 11944, Name: AppVShNotify.exe, CommandLine: "C:\Program Files\Common Files\
Microsoft Shared\ClickToRun\AppVShNotify.exe"
===============
ID: 7080, Name: dllhost.exe, CommandLine: "C:\WINDOWS\system32\DllHost.exe"
/Processid:{9F156763-7844-4DC4-B2B1-901F640F5155}
===============
ID: 3516, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
UnistackSvcGroup -s WpnUserService
===============
ID: 7012, Name: Zoom.exe, CommandLine: "C:\Program Files (x86)\Zoom\bin\Zoom.exe"
--action=preload --runaszvideo=TRUE --useroption=5067099428880384 --
useroption2=1170935903118426176 --useroption3=2306055214963326977 --
useroption4=8594169856 --useroption5=4 --userroomoption=0 --userroomoption2=0 --
haszoomim=1
===============
ID: 11604, Name: Video.UI.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.ZuneVideo_10.21061.10121.0_x64__8wekyb3d8bbwe\Video.UI.exe" -
ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
===============
ID: 7264, Name: ShellExperienceHost.exe, CommandLine: "C:\WINDOWS\SystemApps\
ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -
ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
===============
ID: 6880, Name: RuntimeBroker.exe, CommandLine: C:\Windows\System32\
RuntimeBroker.exe -Embedding
===============
ID: 10140, Name: SystemSettingsBroker.exe, CommandLine: C:\Windows\System32\
SystemSettingsBroker.exe -Embedding
===============
ID: 6964, Name: MoNotificationUx.exe, CommandLine: %systemroot%\system32\
MoNotificationUx.exe /NotificationType Reboot_Engaged /FormFactor Passive /Timeout
0
===============
ID: 5100, Name: hpwuschd2.exe, CommandLine: "C:\Program Files (x86)\Hp\HP Software
Update\hpwuschd2.exe"
===============
ID: 13388, Name: explorer.exe, CommandLine: C:\WINDOWS\explorer.exe /factory,
{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
===============
ID: 14432, Name: explorer.exe, CommandLine: C:\WINDOWS\explorer.exe /factory,
{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
===============
ID: 1684, Name: explorer.exe, CommandLine: C:\WINDOWS\explorer.exe /factory,
{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
===============
ID: 16328, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=utility --utility-sub-
type=proxy_resolver.mojom.ProxyResolverFactory --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --service-
sandbox-type=proxy_resolver --mojo-platform-channel-handle=9104 /prefetch:8
===============
ID: 16448, Name: dllhost.exe, CommandLine: C:\WINDOWS\system32\DllHost.exe
/Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
===============
ID: 12192, Name: smartscreen.exe, CommandLine: C:\Windows\System32\smartscreen.exe
-Embedding
===============
ID: 7416, Name: dllhost.exe, CommandLine: "C:\WINDOWS\SysWOW64\DllHost.exe"
/Processid:{776DBC8D-7347-478C-8D71-791E12EF49D8}
===============
ID: 11792, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=1371 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6328 /prefetch:1
===============
ID: 1524, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=1399 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=9224 /prefetch:1
===============
ID: 11552, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=1408 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6076 /prefetch:1
===============
ID: 2956, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=1415 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=11492 /prefetch:1
===============
ID: 16852, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=1417 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5268 /prefetch:1
===============
ID: 300, Name: Notepad.exe, CommandLine: "C:\Program Files\WindowsApps\
Microsoft.WindowsNotepad_10.2103.6.0_x64__8wekyb3d8bbwe\Notepad\Notepad.exe" "C:\
Users\mosta\Downloads\60ff28_IDM-Crack-639-B\IDM-Crack-639-Build-2-With-Serial-Key-
Free-Download-2021\60ff28bdd25b760ff28-Passw0rd.txt"
===============
ID: 10864, Name: WinRAR.exe, CommandLine: "C:\Program Files\WinRAR\WinRAR.exe" "C:\
Users\mosta\Downloads\60ff28_IDM-Crack-639-B\IDM-Crack-639-Build-2-With-Serial-Key-
Free-Download-2021\60ff28bdd25b760ff28_setup_v18.2.9.zip"
===============
ID: 16388, Name: chrome.exe, CommandLine: "C:\Program Files\Google\Chrome\
Application\chrome.exe" --type=renderer --field-trial-
handle=1700,297503350405970506,3489991870065636420,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=1425 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=9200 /prefetch:1
===============
ID: 8248, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 17372, Name: cmd.exe, CommandLine: C:\WINDOWS\system32\cmd.exe /c sahiba_5.exe
===============
ID: 11488, Name: cmd.exe, CommandLine: C:\WINDOWS\system32\cmd.exe /c sahiba_6.exe
===============
ID: 10880, Name: cmd.exe, CommandLine: C:\WINDOWS\system32\cmd.exe /c sahiba_7.exe
===============
ID: 16332, Name: sahiba_6.exe, CommandLine: sahiba_6.exe
===============
ID: 13404, Name: sahiba_5.exe, CommandLine: sahiba_5.exe
===============
ID: 14072, Name: sahiba_7.exe, CommandLine: sahiba_7.exe
===============
ID: 2264, Name: cmd.exe, CommandLine: "C:\Windows\System32\cmd.exe" /c cmd <
Compatto.rtf
===============
ID: 15976, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 12544, Name: cmd.exe, CommandLine: cmd
===============
ID: 7428, Name: PING.EXE, CommandLine: ping 127.0.0.1 -n 30
===============
ID: 3388, Name: Triste.exe.com, CommandLine: C:\Users\mosta\AppData\Local\Temp\
7ZipSfx.000\Triste.exe.com n
===============
ID: 2632, Name: 4851165.exe, CommandLine: "C:\Users\mosta\AppData\Roaming\
4851165.exe"
===============
ID: 17120, Name: WinHoster.exe, CommandLine: "C:\Users\mosta\AppData\Roaming\
WinHost\WinHoster.exe"
===============
ID: 11980, Name: 8061694.exe, CommandLine: "C:\Users\mosta\AppData\Roaming\
8061694.exe"
===============
ID: 7500, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 5636, Name: svchost.exe, CommandLine: C:\WINDOWS\system32\svchost.exe -k
SystemNetworkService
===============
ID: 16796, Name: 4136060.exe, CommandLine: "C:\Users\mosta\AppData\Roaming\
4136060.exe"
===============
ID: 12804, Name: v2Rh7PZeW8Pg8SzOtuJmRzb_.exe, CommandLine: "C:\Users\mosta\
Documents\v2Rh7PZeW8Pg8SzOtuJmRzb_.exe"
===============
ID: 10288, Name: 3pTNzHztRTxfN77vUdLzI91V.exe, CommandLine: C:\Users\mosta\
Documents\3pTNzHztRTxfN77vUdLzI91V.exe
===============
ID: 1572, Name: rC2_jszp8oufbMPI6jYe6xv4.exe, CommandLine: "C:\Users\mosta\
Documents\rC2_jszp8oufbMPI6jYe6xv4.exe"
===============
ID: 1416, Name: conhost.exe, CommandLine: \??\C:\WINDOWS\system32\conhost.exe 0x4
===============
ID: 2164, Name: rC2_jszp8oufbMPI6jYe6xv4.exe, CommandLine: C:\Users\mosta\
Documents\rC2_jszp8oufbMPI6jYe6xv4.exe
===============
ID: 15192, Name: 4851165.exe, CommandLine: "C:\Users\mosta\AppData\Roaming\
4851165.exe"
===============
ID: 7116, Name: WerFault.exe, CommandLine: C:\WINDOWS\system32\WerFault.exe -u -p
2632 -s 2240