***********************************************
* *
* ____ _____ ____ _ ___ _ _ _____ *
* | _ \| ____| _ \| | |_ _| \ | | ____| *
* | |_) | _| | | | | | | || \| | _| *
* | _ <| |___| |_| | |___ | || |\ | |___ *
* |_| \_|_____|____/|_____|___|_| \_|_____| *
* *
* Telegram: https://t.me/REDLINESUPPORT *
***********************************************
ID: 720, Name: csrss.exe, CommandLine:
===============
ID: 1032, Name: winlogon.exe, CommandLine:
===============
ID: 1092, Name: fontdrvhost.exe, CommandLine:
===============
ID: 1204, Name: dwm.exe, CommandLine:
===============
ID: 2820, Name: NVDisplay.Container.exe, CommandLine:
===============
ID: 3840, Name: sihost.exe, CommandLine: sihost.exe
===============
ID: 3880, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup -s CDPUserSvc
===============
ID: 3968, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup -s WpnUserService
===============
ID: 4100, Name: oCamTask.exe, CommandLine:
===============
ID: 4180, Name: itype.exe, CommandLine: "c:\Program Files\Microsoft Mouse and
Keyboard Center\itype.exe"
===============
ID: 4212, Name: taskhostw.exe, CommandLine: taskhostw.exe {222A245B-E637-4AE9-A93F-
A59CA119A75E}
===============
ID: 4248, Name: ipoint.exe, CommandLine: "c:\Program Files\Microsoft Mouse and
Keyboard Center\ipoint.exe"
===============
ID: 4584, Name: RAVBg64.exe, CommandLine:
===============
ID: 4828, Name: ctfmon.exe, CommandLine:
===============
ID: 4900, Name: igfxEM.exe, CommandLine:
"C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_33f5ee0bec51165d\
igfxEM.exe"
===============
ID: 6568, Name: explorer.exe, CommandLine: C:\Windows\Explorer.EXE
===============
ID: 7344, Name: rundll32.exe, CommandLine:
===============
ID: 7744, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
ClipboardSvcGroup -p -s cbdhsvc
===============
ID: 7436, Name: INISAFECrossWebEXSvc.exe, CommandLine:
===============
ID: 7136, Name: StartMenuExperienceHost.exe, CommandLine:
"C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Star
tMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
===============
ID: 6284, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser
%dSPUser.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\SPUser"
-r -l 3 -p 30000 -st "C:\Program Files\NVIDIA
Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
===============
ID: 8196, Name: nvcontainer.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser
%d.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3
-p 30000 -st "C:\Program Files\NVIDIA
Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
===============
ID: 8248, Name: RuntimeBroker.exe, CommandLine:
C:\Windows\System32\RuntimeBroker.exe -Embedding
===============
ID: 8704, Name: SearchUI.exe, CommandLine:
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe"
-ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
===============
ID: 8976, Name: MKCHelper.exe, CommandLine:
===============
ID: 8420, Name: RuntimeBroker.exe, CommandLine:
C:\Windows\System32\RuntimeBroker.exe -Embedding
===============
ID: 9320, Name: NVIDIA Web Helper.exe, CommandLine: "C:\Program Files (x86)\NVIDIA
Corporation\NvNode\NVIDIA Web Helper.exe" index.js
===============
ID: 9340, Name: SettingSyncHost.exe, CommandLine:
C:\Windows\system32\SettingSyncHost.exe -Embedding
===============
ID: 9616, Name: conhost.exe, CommandLine: \??\C:\Windows\system32\conhost.exe 0x4
===============
ID: 9684, Name: LockApp.exe, CommandLine:
"C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe"
-ServerName:WindowsDefaultLockScreen.AppX7y4nbzq37zn4ks9k7amqjywdat7d3j2z.mca
===============
ID: 9960, Name: RuntimeBroker.exe, CommandLine:
C:\Windows\System32\RuntimeBroker.exe -Embedding
===============
ID: 2952, Name: RuntimeBroker.exe, CommandLine:
C:\Windows\System32\RuntimeBroker.exe -Embedding
===============
ID: 12072, Name: nvsphelper64.exe, CommandLine:
===============
ID: 12080, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
===============
ID: 3100, Name: nosstarter.npe, CommandLine:
===============
ID: 12300, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=gpu-process --field-
trial-handle=1948,16873190554504961139,14030489063808805285,131072 --disable-
features=VizDisplayCompositor --no-sandbox --log-
file="C:\Users\ksf35\AppData\Local\NVIDIA Corporation\NVIDIA Share\debug.log"
--lang=en-US --gpu-
preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-
file="C:\Users\ksf35\AppData\Local\NVIDIA Corporation\NVIDIA Share\debug.log"
--service-request-channel-token=2915207576359290959 --mojo-platform-channel-
handle=2052 /prefetch:2
===============
ID: 12600, Name: NVIDIA Share.exe, CommandLine: "C:\Program Files\NVIDIA
Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --no-
sandbox --autoplay-policy=no-user-gesture-required --log-
file="C:\Users\ksf35\AppData\Local\NVIDIA Corporation\NVIDIA Share\debug.log"
--field-trial-handle=1948,16873190554504961139,14030489063808805285,131072
--disable-features=VizDisplayCompositor --service-pipe-token=2481445236653662788
--lang=en-US --log-file="C:\Users\ksf35\AppData\Local\NVIDIA Corporation\NVIDIA
Share\debug.log" --device-scale-factor=1 --num-raster-threads=4 --enable-main-
frame-before-activation --service-request-channel-token=2481445236653662788
--renderer-client-id=3 --mojo-platform-channel-handle=2624 /prefetch:1
===============
ID: 13068, Name: RtkNGUI64.exe, CommandLine: "C:\Program
Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
===============
ID: 12948, Name: RAVBg64.exe, CommandLine: "C:\Program
Files\Realtek\Audio\HDA\RAVBg64.exe" /IM
===============
ID: 12940, Name: WavesSvc64.exe, CommandLine: "C:\Program
Files\Waves\MaxxAudio\WavesSvc64.exe" -Jack
===============
ID: 11184, Name: SamsungRapidApp.exe, CommandLine: "C:\Program Files
(x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe"
===============
ID: 9704, Name: steam.exe, CommandLine: "C:\Program Files (x86)\Steam\steam.exe"
-silent
===============
ID: 13376, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" "-lang=ko_KR" "-
cachedir=C:\Users\ksf35\AppData\Local\Steam\htmlcache" "-steampid=9704" "-
buildid=1591251555" "-steamid=0" "-steamuniverse=Public" "-clientui=C:\Program
Files (x86)\Steam\clientui" --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --enable-media-stream --enable-smooth-
scrolling --enable-direct-write "--log-file=C:\Program Files
(x86)\Steam\logs\cef_log.txt"
===============
ID: 13452, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=crashpad-handler
/prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Program Files (x86)\Steam\dumps"
"--metrics-dir=C:\Users\ksf35\AppData\Local\CEF\User Data"
--url=http://crash.steampowered.com/submit --annotation=platform=win64
--annotation=product=cefwebhelper --annotation=version=1591251555 --initial-client-
data=0x2f8,0x304,0x300,0x2ec,0x308,0x7ffa39a7bed0,0x7ffa39a7bee0,0x7ffa39a7bef0
===============
ID: 13552, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=gpu-process --field-
trial-handle=1484,12847299962342253205,8743202961871750711,131072 --disable-
features=CalculateNativeWinOcclusion,MimeHandlerViewInCrossProcessFrame --log-
file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam
Client" --lang=ko-KR --buildid=1591251555 --steamid=0 --gpu-
preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --service-request-channel-token=391053022585257448
--mojo-platform-channel-handle=1596 --ignored=" --type=renderer " /prefetch:2
===============
ID: 13624, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=utility --field-trial-
handle=1484,12847299962342253205,8743202961871750711,131072 --disable-
features=CalculateNativeWinOcclusion,MimeHandlerViewInCrossProcessFrame --lang=ko
--service-sandbox-type=network --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=ko-KR
--buildid=1591251555 --steamid=0 --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --service-request-channel-token=10729686925747100984
--mojo-platform-channel-handle=1796 /prefetch:8
===============
ID: 13656, Name: FreeMmr.exe, CommandLine: "D:\FreeMmr.exe" -tray
===============
ID: 13868, Name: SamsungMagician.exe, CommandLine:
===============
ID: 14044, Name: RaiDrive.exe, CommandLine: "C:\Program
Files\OpenBoxLab\RaiDrive\RaiDrive.exe" /background
===============
ID: 936, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --log-
file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1484,12847299962342253205,8743202961871750711,131072 --disable-
features=CalculateNativeWinOcclusion,MimeHandlerViewInCrossProcessFrame --enable-
blink-features=ResizeObserver,Worklet,AudioWorklet --lang=ko --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client"
--buildid=1591251555 --steamid=0 --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --service-request-channel-
token=6521041352315877758 --renderer-client-id=5 --mojo-platform-channel-
handle=2732 /prefetch:1
===============
ID: 980, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --log-
file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1484,12847299962342253205,8743202961871750711,131072 --disable-
features=CalculateNativeWinOcclusion,MimeHandlerViewInCrossProcessFrame --enable-
blink-features=ResizeObserver,Worklet,AudioWorklet --lang=ko --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client"
--buildid=1591251555 --steamid=0 --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --service-request-channel-
token=8253509500768567261 --renderer-client-id=6 --mojo-platform-channel-
handle=2880 /prefetch:1
===============
ID: 1348, Name: steamwebhelper.exe, CommandLine: "C:\Program Files
(x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --log-
file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1484,12847299962342253205,8743202961871750711,131072 --disable-
features=CalculateNativeWinOcclusion,MimeHandlerViewInCrossProcessFrame --enable-
blink-features=ResizeObserver,Worklet,AudioWorklet --lang=ko --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client"
--buildid=1591251555 --steamid=0 --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --service-request-channel-
token=9834019713956266150 --renderer-client-id=7 --mojo-platform-channel-
handle=2640 /prefetch:1
===============
ID: 15524, Name: CompPkgSrv.exe, CommandLine: C:\Windows\System32\CompPkgSrv.exe
-Embedding
===============
ID: 13340, Name: svchost.exe, CommandLine: C:\Windows\system32\svchost.exe -k
UnistackSvcGroup
===============
ID: 6636, Name: oCam.exe, CommandLine:
===============
ID: 14340, Name: cmd.exe, CommandLine:
===============
ID: 1840, Name: conhost.exe, CommandLine:
===============
ID: 13880, Name: choice.exe, CommandLine:
===============
ID: 12156, Name: cmd.exe, CommandLine:
===============
ID: 14552, Name: conhost.exe, CommandLine:
===============
ID: 1492, Name: choice.exe, CommandLine:
===============
ID: 13416, Name: cmd.exe, CommandLine:
===============
ID: 10832, Name: conhost.exe, CommandLine:
===============
ID: 5164, Name: choice.exe, CommandLine:
===============
ID: 12884, Name: csrss.exe, CommandLine:
===============
ID: 14668, Name: cmd.exe, CommandLine:
===============
ID: 2672, Name: conhost.exe, CommandLine:
===============
ID: 6080, Name: choice.exe, CommandLine:
===============
ID: 2032, Name: chrome.exe, CommandLine:
===============
ID: 10040, Name: chrome.exe, CommandLine:
===============
ID: 15296, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --gpu-
preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQ
AAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAA
AGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-
handle=1676 /prefetch:2
===============
ID: 15712, Name: chrome.exe, CommandLine:
===============
ID: 3140, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --extension-
process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3512 /prefetch:1
===============
ID: 12840, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --extension-
process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3808 /prefetch:1
===============
ID: 10848, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --extension-
process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=4072 /prefetch:1
===============
ID: 10216, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --extension-
process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=4196 /prefetch:1
===============
ID: 5696, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --enable-
auto-reload --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=16 --no-v8-untrusted-code-mitigations
--mojo-platform-channel-handle=5324 /prefetch:1
===============
ID: 12456, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --enable-
auto-reload --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-
before-activation --renderer-client-id=17 --no-v8-untrusted-code-mitigations
--mojo-platform-channel-handle=6552 /prefetch:1
===============
ID: 7496, Name: chrome.exe, CommandLine: "C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-
handle=1616,5612979557816890788,15681301574662558842,131072 --lang=ko --extension-
process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=4
--enable-main-frame-before-activation --renderer-client-id=28 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=7096 /prefetch:1
===============
ID: 13084, Name: explorer.exe, CommandLine: C:\Windows\SysWOW64\explorer.exe
===============
ID: 14360, Name: explorer.exe, CommandLine: C:\Windows\explorer.exe
===============
ID: 1868, Name: explorer.exe, CommandLine: C:\Windows\SysWOW64\explorer.exe
===============
ID: 4012, Name: AddInProcess32.exe, CommandLine:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
===============
ID: 10488, Name: explorer.exe, CommandLine: C:\Windows\explorer.exe
===============
ID: 12228, Name: explorer.exe, CommandLine: C:\Windows\SysWOW64\explorer.exe
===============
ID: 15648, Name: explorer.exe, CommandLine: C:\Windows\explorer.exe
===============
ID: 3064, Name: explorer.exe, CommandLine: C:\Windows\SysWOW64\explorer.exe
===============
ID: 14964, Name: RegSvcs.exe, CommandLine: "{path}"