0% found this document useful (0 votes)
37 views10 pages

Windows Process Command Lines Overview

This document contains process information from a Windows system. It lists the process ID (PID), process name, and command line arguments for 30+ running processes including explorer.exe, chrome.exe, svchost.exe, and SecureBrowser.exe.

Uploaded by

hendry
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views10 pages

Windows Process Command Lines Overview

This document contains process information from a Windows system. It lists the process ID (PID), process name, and command line arguments for 30+ running processes including explorer.exe, chrome.exe, svchost.exe, and SecureBrowser.exe.

Uploaded by

hendry
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

***********************************************

* *
* ____ _____ ____ _ ___ _ _ _____ *
* | _ \| ____| _ \| | |_ _| \ | | ____| *
* | |_) | _| | | | | | | || \| | _| *
* | _ <| |___| |_| | |___ | || |\ | |___ *
* |_| \_|_____|____/|_____|___|_| \_|_____| *
* *
* Telegram: [Link] *
***********************************************

ID: 5868, Name: [Link], CommandLine:


===============
ID: 1148, Name: [Link], CommandLine:
===============
ID: 1296, Name: [Link], CommandLine:
===============
ID: 5900, Name: [Link], CommandLine:
===============
ID: 2460, Name: [Link], CommandLine:
===============
ID: 1532, Name: [Link], CommandLine: "C:\Program Files\McAfee\WebAdvisor\
[Link]"
===============
ID: 10316, Name: [Link], CommandLine: C:\WINDOWS\system32\[Link] -k
UnistackSvcGroup -s CDPUserSvc
===============
ID: 9708, Name: [Link], CommandLine: [Link]
===============
ID: 3956, Name: [Link], CommandLine: C:\WINDOWS\system32\[Link] -k
UnistackSvcGroup -s WpnUserService
===============
ID: 8848, Name: [Link], CommandLine: [Link] {222A245B-E637-4AE9-A93F-
A59CA119A75E}
===============
ID: 5016, Name: [Link], CommandLine: C:\WINDOWS\[Link]
===============
ID: 3916, Name: [Link], CommandLine: C:\Users\pc\AppData\Local\Temp\
[Link]
===============
ID: 6380, Name: [Link], CommandLine: C:\WINDOWS\system32\[Link] -k
ClipboardSvcGroup -p -s cbdhsvc
===============
ID: 8648, Name: [Link], CommandLine: "C:\WINDOWS\SystemApps\
[Link].StartMenuExperienceHost_cw5n1h2txyewy\
[Link]" -
ServerName:[Link]
===============
ID: 11824, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 7520, Name: [Link], CommandLine: "C:\WINDOWS\SystemApps\
[Link].Search_cw5n1h2txyewy\[Link]" -
ServerName:[Link]
===============
ID: 8940, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 7964, Name: [Link], CommandLine: "C:\Program Files\WindowsApps\
Microsoft.YourPhone_1.21062.150.0_x64__8wekyb3d8bbwe\[Link]" -
ServerName:[Link]
===============
ID: 6768, Name: [Link], CommandLine: "C:\WINDOWS\SystemApps\
[Link].CBS_cw5n1h2txyewy\InputApp\[Link]" -
ServerName:[Link]
===============
ID: 932, Name: [Link], CommandLine:
===============
ID: 5300, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 10876, Name: [Link], CommandLine: "C:\Windows\System32\
DriverStore\FileRepository\realtekservice.inf_amd64_01042bb7f11c17c4\
[Link]" -background
===============
ID: 2108, Name: [Link], CommandLine: "C:\Program Files\Riot Vanguard\
[Link]"
===============
ID: 1040, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\Microsoft\
OneDrive\[Link]" /background
===============
ID: 7564, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\[Link]" -
silent
===============
ID: 11832, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\
Programs\Taskbar system\[Link]"
===============
ID: 12180, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --restore-last-session
===============
ID: 1324, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=crashpad-handler "--
user-data-dir=C:\Users\pc\AppData\Local\Secure Browser\Secure Browser\User Data"
/prefetch:7 --monitor-self --monitor-self-argument=--type=crashpad-handler "--
monitor-self-argument=--user-data-dir=C:\Users\pc\AppData\Local\Secure Browser\
Secure Browser\User Data" --monitor-self-argument=/prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\Local\Secure
Browser\Secure Browser\User Data\Crashpad" "--metrics-dir=C:\Users\pc\AppData\
Local\Secure Browser\Secure Browser\User Data" --annotation=plat=Win32 "--
annotation=prod=Secure Browser" --annotation=ver=89.0.4389.114-devel --initial-
client-data=0x134,0x138,0x13c,0x110,0x140,0x72ecea88,0x72ecea98,0x72eceaa4
===============
ID: 1440, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=crashpad-handler "--
user-data-dir=C:\Users\pc\AppData\Local\Secure Browser\Secure Browser\User Data"
/prefetch:7 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler
"--database=C:\Users\pc\AppData\Local\Secure Browser\Secure Browser\User Data\
Crashpad" --annotation=plat=Win32 "--annotation=prod=Secure Browser" --
annotation=ver=89.0.4389.114-devel --initial-client-
data=0x238,0x23c,0x240,0x234,0x244,0x7324c0,0x7324d0,0x7324dc
===============
ID: 8568, Name: browser_assistant.exe, CommandLine: "C:\Users\pc\AppData\Local\
Programs\Opera\assistant\browser_assistant.exe"
===============
ID: 11828, Name: [Link], CommandLine: "C:\ProgramData\Microsoft Network\
[Link]"
===============
ID: 11500, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --headless --disable-gpu --remote-debugging-port=9222
[Link]
===============
ID: 712, Name: [Link], CommandLine: \??\C:\WINDOWS\system32\[Link] 0x4
===============
ID: 11076, Name: browser_assistant.exe, CommandLine: C:\Users\pc\AppData\Local\
Programs\Opera\assistant\browser_assistant.exe --type=crashpad-handler /prefetch:7
--monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\
Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\pc\
AppData\Roaming\Opera Software\Opera Stable\crash_count.txt"
--url=[Link] --
annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --
annotation=ver=77.0.4054.277 --initial-client-
data=0x280,0x284,0x288,0x25c,0x28c,0xfc34e8,0xfc34f8,0xfc3504
===============
ID: 6816, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=crashpad-handler "--user-data-dir=C:\Users\pc\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\pc\AppData\Local\Google\Chrome\
User Data" --url=[Link] --annotation=channel= --
annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=92.0.4515.107 --
initial-client-
data=0xf0,0xf4,0xf8,0xcc,0xfc,0x7ffccaff5390,0x7ffccaff53a0,0x7ffccaff53b0
===============
ID: 11612, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=gpu-process --field-
trial-handle=1616,9023931564935911795,5603989844836402165,131072 --gpu-
preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAA
AAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIA
AAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1628 /prefetch:2
===============
ID: 3888, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=utility --utility-sub-
type=[Link] --field-trial-
handle=1616,9023931564935911795,5603989844836402165,131072 --lang=en-US --service-
sandbox-type=network --mojo-platform-channel-handle=1884 /prefetch:8
===============
ID: 8352, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=utility --utility-sub-
type=[Link] --field-trial-
handle=1616,9023931564935911795,5603989844836402165,131072 --lang=en-US --service-
sandbox-type=utility --mojo-platform-channel-handle=2264 /prefetch:8
===============
ID: 32, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --origin-trial-disabled-features=SecurePaymentConfirmation --device-
scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --
renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=2572 /prefetch:1
===============
ID: 232, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=2580 /prefetch:1
===============
ID: 2304, Name: [Link], CommandLine: "D:\PowerISO\[Link]" -startup
===============
ID: 9092, Name: [Link], CommandLine:
===============
ID: 5480, Name: [Link], CommandLine:
===============
ID: 6808, Name: [Link], CommandLine: C:\WINDOWS\system32\wbem\[Link] -
Embedding
===============
ID: 11316, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=utility --utility-sub-
type=data_decoder.[Link] --field-trial-
handle=1616,9023931564935911795,5603989844836402165,131072 --lang=en-US --service-
sandbox-type=utility --mojo-platform-channel-handle=3408 /prefetch:8
===============
ID: 4832, Name: [Link], CommandLine: "C:\Windows\System32\[Link]" /K taskkill /IM
[Link] /F && exit
===============
ID: 9320, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3564 /prefetch:1
===============
ID: 9016, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3944 /prefetch:1
===============
ID: 1672, Name: [Link], CommandLine: \??\C:\WINDOWS\system32\[Link] 0x4
===============
ID: 11224, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3924 /prefetch:1
===============
ID: 1868, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=9 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=4672 /prefetch:1
===============
ID: 6136, Name: [Link], CommandLine: "C:\Program Files (x86)\Secure
Browser\Secure Browser\Application\[Link]" --type=renderer --file-url-
path-alias="/gen=C:\Program Files (x86)\Secure Browser\Secure Browser\Application\
gen" --field-trial-handle=1616,9023931564935911795,5603989844836402165,131072 --
lang=en-US --extension-process --origin-trial-disabled-
features=SecurePaymentConfirmation --device-scale-factor=1 --num-raster-threads=2
--enable-main-frame-before-activation --renderer-client-id=10 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=4900 /prefetch:1
===============
ID: 3100, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=gpu-process --field-trial-
handle=1376,17144345471661145895,4856825916987237249,131072 --disable-
features=PaintHolding --headless --headless --gpu-
preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAA
AAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHA
AAADQAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=swiftshader-webgl --override-use-software-
gl-for-tests --mojo-platform-channel-handle=1440 /prefetch:2
===============
ID: 3904, Name: [Link], CommandLine: "C:\Program Files\AMD\CNext\CNext\
[Link]" atlogon
===============
ID: 11208, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --field-trial-
handle=1376,17144345471661145895,4856825916987237249,131072 --disable-
features=PaintHolding --lang=en-GB --service-sandbox-type=none --use-
gl=swiftshader-webgl --headless --mojo-platform-channel-handle=1656 /prefetch:8
===============
ID: 8396, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --remote-debugging-port=9222 --allow-pre-
commit-input --field-trial-
handle=1376,17144345471661145895,4856825916987237249,131072 --disable-
features=PaintHolding --disable-databases --disable-gpu-compositing --lang=en-GB --
headless --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=4 --mojo-platform-channel-
handle=1744 /prefetch:1
===============
ID: 1308, Name: [Link], CommandLine: C:\Users\pc\AppData\Roaming\
nWbKOHRTrH\[Link]
===============
ID: 10072, Name: [Link], CommandLine: NULL
===============
ID: 2776, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\[Link]"
===============
ID: 9296, Name: [Link], CommandLine: C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\[Link] --type=crashpad-handler --user-data-dir=C:\Users\pc\AppData\
Roaming\discord /prefetch:7 --no-rate-limit --no-upload-gzip --monitor-self-
annotation=ptype=crashpad-handler --database=C:\Users\pc\AppData\Roaming\discord\
Crashpad --url=[Link]
sentry_key=384ce4413de74fe0be270abe03b2b35a "--annotation=_companyName=Discord
Inc." --annotation=_productName=Discord --annotation=_version=1.0.9002 --
annotation=prod=Electron --annotation=ver=9.3.5 --initial-client-
data=0x468,0x46c,0x470,0x42c,0x474,0x59c4078,0x59c4088,0x59c4094
===============
ID: 8104, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\[Link]" --type=gpu-process --field-trial-
handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--gpu-
preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQ
AAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAA
AGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-
handle=1672 /prefetch:2
===============
ID: 5296, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\[Link]" --type=utility --field-trial-
handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--lang=en-US --service-sandbox-type=network --mojo-platform-channel-handle=2148
/prefetch:8
===============
ID: 2328, Name: [Link], CommandLine:
===============
ID: 4788, Name: [Link], CommandLine:
===============
ID: 9052, Name: [Link], CommandLine: C:\WINDOWS\system32\[Link] -k
UnistackSvcGroup
===============
ID: 3908, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\[Link]" --type=renderer --autoplay-policy=no-user-gesture-required --
field-trial-handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--lang=en-US --app-user-model-id=[Link] --app-path="C:\Users\
pc\AppData\Local\Discord\app-1.0.9002\resources\[Link]" --no-sandbox --no-zygote
--native-window-open --preload="C:\Users\pc\AppData\Local\Discord\app-1.0.9002\
modules\discord_desktop_core-3\discord_desktop_core\[Link]\app\
[Link]" --context-isolation --background-color=#202225 --enable-
spellcheck --enable-websql --device-scale-factor=1 --num-raster-threads=2 --enable-
main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-
mitigations --mojo-platform-channel-handle=3212 /prefetch:1 --enable-node-leakage-
in-renderers
===============
ID: 11560, Name: [Link], CommandLine: "C:\Users\pc\AppData\Local\Discord\app-
1.0.9002\[Link]" --type=utility --field-trial-
handle=1664,11599580143400392076,17312611005654495799,131072 --enable-
features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess
--lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=2284
/prefetch:8
===============
ID: 9968, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" "-lang=en_US" "-cachedir=C:\Users\pc\AppData\
Local\Steam\htmlcache" "-steampid=7564" "-buildid=1626824053" "-steamid=0" "-
cachedir=C:\Users\pc\AppData\Local\Steam\htmlcache" "-steamuniverse=Public" "-
realm=Global" "-clientui=C:\Program Files (x86)\Steam\clientui" --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --enable-media-stream --enable-smooth-
scrolling --enable-direct-write "--log-file=C:\Program Files (x86)\Steam\logs\
cef_log.txt"
===============
ID: 7980, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" --type=crashpad-handler /prefetch:7 --max-
uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-
handler "--database=C:\Program Files (x86)\Steam\dumps" "--metrics-dir=C:\Users\pc\
AppData\Local\CEF\User Data" --url=[Link] --
annotation=platform=win64 --annotation=product=cefwebhelper --
annotation=version=1626824053 --initial-client-
data=0x320,0x324,0x328,0x31c,0x32c,0x7ffcaaf1bf10,0x7ffcaaf1bf20,0x7ffcaaf1bf30
===============
ID: 2652, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" --type=gpu-process --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --log-file="C:\Program Files (x86)\
Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=en-ID --
buildid=1626824053 --steamid=0 --gpu-
preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files (x86)\Steam\
logs\cef_log.txt" --service-request-channel-token=15837304811436511476 --mojo-
platform-channel-handle=1504 --ignored=" --type=renderer " /prefetch:2
===============
ID: 9728, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" --type=utility --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --lang=en-US --service-sandbox-
type=network --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-
version="Valve Steam Client" --lang=en-ID --buildid=1626824053 --steamid=0 --log-
file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --service-request-channel-
token=17744092848952728723 --mojo-platform-channel-handle=2112 /prefetch:8
===============
ID: 5920, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" --type=renderer --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --lang=en-US --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --
buildid=1626824053 --steamid=0 --device-scale-factor=1 --num-raster-threads=2 --
enable-main-frame-before-activation --service-request-channel-
token=13941704941166654488 --renderer-client-id=5 --mojo-platform-channel-
handle=2708 /prefetch:1
===============
ID: 5176, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" --type=renderer --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --lang=en-US --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --
buildid=1626824053 --steamid=0 --device-scale-factor=1 --num-raster-threads=2 --
enable-main-frame-before-activation --service-request-channel-
token=992741647707716207 --renderer-client-id=6 --mojo-platform-channel-handle=2884
/prefetch:1
===============
ID: 1604, Name: [Link], CommandLine: "C:\Program Files (x86)\Steam\bin\
cef\cef.win7x64\[Link]" --type=renderer --log-file="C:\Program Files
(x86)\Steam\logs\cef_log.txt" --field-trial-
handle=1532,2753257847912935875,13204773307442543732,131072 --disable-
features=MimeHandlerViewInCrossProcessFrame --enable-blink-
features=ResizeObserver,Worklet,AudioWorklet --lang=en-US --log-file="C:\Program
Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --
buildid=1626824053 --steamid=0 --device-scale-factor=1 --num-raster-threads=2 --
enable-main-frame-before-activation --service-request-channel-
token=6390088502695588489 --renderer-client-id=7 --mojo-platform-channel-
handle=3148 /prefetch:1
===============
ID: 6036, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]"
===============
ID: 12024, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=crashpad-handler "--user-data-dir=C:\Users\pc\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\pc\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\pc\AppData\Local\Google\Chrome\
User Data" --url=[Link] --annotation=channel= --
annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=92.0.4515.107 --
initial-client-
data=0x100,0x104,0x108,0xdc,0x10c,0x7ffccaff5390,0x7ffccaff53a0,0x7ffccaff53b0
===============
ID: 11696, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=gpu-process --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --gpu-
preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAA
AAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHA
AAADQAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1676 /prefetch:2
===============
ID: 4516, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
service-sandbox-type=utility --mojo-platform-channel-handle=2356 /prefetch:8
===============
ID: 6520, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --no-
v8-untrusted-code-mitigations --mojo-platform-channel-handle=2856 /prefetch:1
===============
ID: 11476, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation
--renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=2864 /prefetch:1
===============
ID: 1692, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation
--renderer-client-id=20 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3560 /prefetch:1
===============
ID: 7452, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
extension-process --origin-trial-disabled-features=SecurePaymentConfirmation --
device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation
--renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-
handle=3892 /prefetch:1
===============
ID: 976, Name: RAVANT~[Link], CommandLine: c:\PROGRA~1\RAVANT~1\ui\RAVANT~[Link] --
minimized
===============
ID: 9252, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-type=[Link]
--field-trial-handle=1656,12516388163607244251,14439530889134879207,131072 --
lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6020
/prefetch:8
===============
ID: 8680, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=25 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6568 /prefetch:1
===============
ID: 7032, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7084 /prefetch:1
===============
ID: 7668, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=27 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7616 /prefetch:1
===============
ID: 1212, Name: [Link], CommandLine: "C:\Program Files\WindowsApps\
Microsoft.ZuneVideo_10.21061.10121.0_x64__8wekyb3d8bbwe\[Link]" -
ServerName:[Link]
===============
ID: 11368, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --origin-
trial-disabled-features=SecurePaymentConfirmation --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --
no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7536 /prefetch:1
===============
ID: 7208, Name: RAVANT~[Link], CommandLine: "c:\PROGRA~1\RAVANT~1\ui\RAVANT~[Link]"
--type=gpu-process --field-trial-
handle=2840,17100785047698794974,15755472716090712235,131072 --disable-
features=SpareRendererForSitePerProcess --gpu-
preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAA
AAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAA
AAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-
token=8663520086443559716 --mojo-platform-channel-handle=2848 --ignored=" --
type=renderer " /prefetch:2
===============
ID: 9624, Name: RAVANT~[Link], CommandLine: "c:\PROGRA~1\RAVANT~1\ui\RAVANT~[Link]"
--type=utility --field-trial-
handle=2840,17100785047698794974,15755472716090712235,131072 --disable-
features=SpareRendererForSitePerProcess --lang=en-US --service-sandbox-type=network
--standard-schemes=mc --secure-schemes=mc --bypasscsp-schemes --cors-schemes --
fetch-schemes --service-worker-schemes --service-request-channel-
token=15410565051835726808 --mojo-platform-channel-handle=3184 /prefetch:8
===============
ID: 7748, Name: RAVANT~[Link], CommandLine: "c:\PROGRA~1\RAVANT~1\ui\RAVANT~[Link]"
--type=renderer --field-trial-
handle=2840,17100785047698794974,15755472716090712235,131072 --disable-
features=SpareRendererForSitePerProcess --lang=en-US --standard-schemes=mc --
secure-schemes=mc --bypasscsp-schemes --cors-schemes --fetch-schemes --service-
worker-schemes --app-path="c:\PROGRA~1\RAVANT~1\ui\resources\[Link]" --enable-
sandbox --native-window-open --preload="c:\PROGRA~1\RAVANT~1\ui\resources\[Link]\
electron\[Link]" --context-isolation --background-color=#fff --device-scale-
factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-
request-channel-token=2867675478731773067 --renderer-client-id=5 --no-v8-untrusted-
code-mitigations --mojo-platform-channel-handle=3300 /prefetch:1
===============
ID: 8204, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 6640, Name: [Link], CommandLine: C:\WINDOWS\SysWOW64\[Link]
===============
ID: 4628, Name: [Link], CommandLine: C:\WINDOWS\[Link]
===============
ID: 12312, Name: [Link], CommandLine: C:\WINDOWS\SysWOW64\[Link]
===============
ID: 12352, Name: [Link], CommandLine: C:\WINDOWS\[Link]
===============
ID: 12416, Name: [Link], CommandLine: C:\WINDOWS\SysWOW64\[Link]
===============
ID: 12504, Name: [Link], CommandLine: C:\WINDOWS\[Link]
===============
ID: 12572, Name: [Link], CommandLine: C:\WINDOWS\SysWOW64\[Link]
===============
ID: 12652, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 4552, Name: [Link], CommandLine: C:\Windows\System32\oobe\
[Link] -Embedding
===============
ID: 13268, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --field-trial-
handle=1656,12516388163607244251,14439530889134879207,131072 --lang=en-US --
service-sandbox-type=none --mojo-platform-channel-handle=8768 /prefetch:8
===============
ID: 12900, Name: [Link], CommandLine: C:\Users\pc\AppData\Local\Temp\[Link]
===============
ID: 12960, Name: [Link], CommandLine: \??\C:\WINDOWS\system32\[Link] 0x4
===============
ID: 204, Name: [Link], CommandLine: "C:\WINDOWS\system32\cmd" /c "C:\Users\pc\
AppData\Local\Temp\[Link]\[Link]\[Link] C:\Users\pc\AppData\Local\Temp\
[Link]"
===============
ID: 3660, Name: [Link], CommandLine: [Link]
===============
ID: 1468, Name: [Link], CommandLine: C:\Users\pc\AppData\Local\Temp\[Link]\
[Link]\[Link] "/sleep" "900000" "" "" "" "" "" "" ""
===============
ID: 8800, Name: [Link], CommandLine: \??\C:\WINDOWS\system32\[Link] 0x4
===============
ID: 748, Name: [Link], CommandLine: -coin eth -pool [Link] -
rvram 1 -wal 0x05E050c023DDFe7Ea87e6aDd6cCa9382D60Fc31D.test1 -proto 4

Common questions

Powered by AI

The `ctfmon.exe` process lacks specific command-line arguments in the source provided , suggesting it operates in its default state without modifications. `ctfmon.exe` is responsible for controlling the Alternative User Input Text Input Processor and the Microsoft Office Language Bar. Its typical presence without unique modification reflects normal operation for text input services in applications like Microsoft Office in Windows systems .

Field-trial handles in `SecureBrowser.exe` command lines, such as `1616,9023931564935911795,5603989844836402165,131072`, indicate that the browser is engaging in A/B testing or staged feature deployment . These unique handles likely correlate to specific configurations or experimental features being tested across different user groups, allowing developers to measure performance and user feedback before full-scale deployment .

The process `RuntimeBroker.exe` is listed multiple times and is executed from `C:\Windows\System32\` with the `-Embedding` parameter . This suggests that it functions as part of the inter-process communication framework in Windows, facilitating security and resource management for universal Windows apps . Its presence in the system directory and the embedding mode indicates its critical, system-level role in managing app permissions and ensuring that apps do not exceed their resource allocations.

The different instances of `svchost.exe` are distinguished by their command-line arguments, which specify the service groups and services they host. For example, entries like `C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc` and `-s WpnUserService` indicate that each instance manages different sets of services within Windows . This multiplexing allows for efficient resource use and management of multiple Windows services by running them under shared service host processes .

The Chrome application uses the `crashpad-handler` to manage crashes and exceptions, as indicated by several command lines specifying `--type=crashpad-handler` . This handler typically collects and processes crash reports, enabling developers to diagnose and address issues. The utility details, including the `--user-data-dir`, `--database`, and `--url` parameters, suggest that it organizes crash data and potentially uploads it to remote servers for further analysis .

The command line entry for `taskhostw.exe`, such as `taskhostw.exe {222A245B-E637-4AE9-A93F- A59CA119A75E}`, implies it serves as a host process for Dynamic-Link Library (DLL)-based services . This GUID parameter represents the hosted component, which varies depending on the service being run. `taskhostw.exe` acts as a generic host for running local server COM objects, enabling efficient service execution within the Windows architecture by improving system resource allocation and robustness .

The command line for `steamwebhelper.exe`, such as `--type=renderer --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --enable-blink-features=ResizeObserver,Worklet,AudioWorklet`, suggests it is responsible for rendering web content and interfacing with Steam's user interface through Chromium Embedded Framework (CEF). The parameters reflect its role in handling graphic and multimedia elements required for Steam's web-driven content, ensuring smooth interaction and display within the platform .

The `TextInputHost.exe` process is likely responsible for managing and facilitating user input in Windows applications. Its execution command `"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mca` indicates it operates as part of the Microsoft input services that enhance input processing for text input functionality across different applications in the Windows environment .

The presence of multiple instances of `explorer.exe`, with some executing from `C:\WINDOWS\SysWOW64\`, indicates architectural considerations for supporting both 32-bit and 64-bit processes. `SysWOW64` is a directory on 64-bit Windows systems that stores 32-bit versions of files, allowing compatibility with applications designed for 32-bit systems. Multiple instances suggest concurrent sessions or tasks performed by the user interface shell, managing different desktops or user interactions .

Analysis of the command lines from SecureBrowser.exe indicates that it runs multiple utility processes, as seen from entries in the document specifying various `--utility-sub-type` parameters, such as `data_decoder.mojom.DataDecoderService`, `network.mojom.NetworkService`, and `storage.mojom.StorageService` . These utility processes likely handle specific tasks such as data decoding, network communication, and storage operations, which are essential for the browser's functionality and efficiency.

You might also like