***********************************************
* *
* ____ _____ ____ _ ___ _ _ _____ *
* | _ \| ____| _ \| | |_ _| \ | | ____| *
* | |_) | _| | | | | | | || \| | _| *
* | _ <| |___| |_| | |___ | || |\ | |___ *
* |_| \_|_____|____/|_____|___|_| \_|_____| *
* *
* Telegram: [Link] *
***********************************************
ID: 9544, Name: [Link], CommandLine:
===============
ID: 6840, Name: [Link], CommandLine: C:\Windows\System32\[Link] -
SpecialSession
===============
ID: 5456, Name: [Link], CommandLine: "[Link]"
===============
ID: 13760, Name: [Link], CommandLine: "[Link]"
===============
ID: 9436, Name: [Link], CommandLine: "C:\Program Files\Alps\GlidePoint\
[Link]"
===============
ID: 3768, Name: [Link], CommandLine: C:\Windows\system32\[Link] -k
UnistackSvcGroup -s CDPUserSvc
===============
ID: 4380, Name: [Link], CommandLine: [Link]
===============
ID: 10292, Name: [Link], CommandLine: C:\Windows\system32\[Link] -k
UnistackSvcGroup -s WpnUserService
===============
ID: 6848, Name: [Link], CommandLine: [Link]
===============
ID: 12896, Name: [Link], CommandLine: [Link] {222A245B-E637-4AE9-
A93F-A59CA119A75E}
===============
ID: 5304, Name: [Link], CommandLine: "C:\Program Files\Alps\GlidePoint\
[Link]" -s{05FA8492-C047-4207-BE65-780D8591C113}
===============
ID: 4440, Name: [Link], CommandLine: C:\Windows\[Link]
===============
ID: 11764, Name: [Link], CommandLine: [Link]
===============
ID: 14020, Name: [Link], CommandLine: "[Link]"
===============
ID: 5544, Name: [Link], CommandLine: \??\C:\Windows\system32\[Link] 0x4
===============
ID: 8440, Name: [Link], CommandLine: [Link]
===============
ID: 12512, Name: [Link], CommandLine: C:\Windows\system32\[Link] -k
ClipboardSvcGroup -p -s cbdhsvc
===============
ID: 4388, Name: [Link], CommandLine: "[Link]"
===============
ID: 8688, Name: [Link], CommandLine: "C:\Windows\SystemApps\
[Link].StartMenuExperienceHost_cw5n1h2txyewy\
[Link]" -
ServerName:[Link]
===============
ID: 13852, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 12196, Name: [Link], CommandLine: "C:\Windows\SystemApps\
[Link].Search_cw5n1h2txyewy\[Link]" -
ServerName:[Link]
===============
ID: 3508, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 192, Name: [Link], CommandLine:
/QuitInfo:000000000000030C;0000000000000260;
===============
ID: 916, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 7684, Name: [Link], CommandLine: "C:\Program Files\
WindowsApps\Microsoft.YourPhone_1.22082.117.0_x64__8wekyb3d8bbwe\
[Link]" -ComServer:Background -Embedding
===============
ID: 12492, Name: [Link], CommandLine: "C:\Windows\SystemApps\
[Link].CBS_cw5n1h2txyewy\[Link]" -
ServerName:[Link]
===============
ID: 12312, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 11608, Name: [Link], CommandLine: "C:\Windows\System32\
[Link]"
===============
ID: 9740, Name: [Link], CommandLine: "C:\Windows\[Link]"
===============
ID: 10172, Name: [Link], CommandLine: C:\Windows\system32\[Link]
/Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
===============
ID: 1048, Name: [Link], CommandLine: "C:\Program Files (x86)\AnyDesk\
[Link]" --control
===============
ID: 7764, Name: [Link], CommandLine: C:\Windows\system32\[Link]
/Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
===============
ID: 2560, Name: [Link], CommandLine: C:\Windows\system32\
[Link] -Embedding
===============
ID: 11188, Name: [Link], CommandLine: C:\Windows\System32\oobe\
[Link] -Embedding
===============
ID: 4164, Name: [Link], CommandLine: C:\Windows\system32\[Link] -k
UnistackSvcGroup
===============
ID: 6980, Name: [Link], CommandLine: "C:\Program Files\WindowsApps\
5319275A.WhatsAppDesktop_2.2240.2.0_x64__cv1g1gvanyjgm\[Link]" -
ServerName:[Link]
===============
ID: 13964, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 1752, Name: [Link], CommandLine: "C:\Windows\SystemApps\
ShellExperienceHost_cw5n1h2txyewy\[Link]" -
ServerName:[Link]
===============
ID: 2576, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 3384, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --no-startup-window /prefetch:5
===============
ID: 8452, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --type=crashpad-handler "--user-data-dir=C:\Users\USER\
AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\USER\AppData\Local\
Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --
annotation=channel= --annotation=chromium-version=106.0.5249.119 "--
annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\[Link]" --
annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --
annotation=ver=106.0.1370.47 --initial-client-
data=0xb4,0xe4,0x108,0x8,0x114,0x7ff969c46e08,0x7ff969c46e18,0x7ff969c46e28
===============
ID: 10980, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --type=gpu-process --gpu-
preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAA
AAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAA
AOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-
handle=1880 --field-trial-
handle=2012,i,2776781904686220101,14516812019439838743,131072 /prefetch:2
===============
ID: 13872, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --lang=ar --service-sandbox-type=none --mojo-
platform-channel-handle=2192 --field-trial-
handle=2012,i,2776781904686220101,14516812019439838743,131072 /prefetch:3
===============
ID: 7768, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --lang=ar --service-sandbox-type=utility --mojo-
platform-channel-handle=2528 --field-trial-
handle=2012,i,2776781904686220101,14516812019439838743,131072 /prefetch:8
===============
ID: 13568, Name: [Link], CommandLine: "C:\Program Files\TeamViewer\
[Link]"
===============
ID: 7872, Name: tv_w32.exe, CommandLine: "C:\Program Files\TeamViewer\tv_w32.exe"
--action hooks --log C:\Program Files\TeamViewer\TeamViewer15_Logfile.log
===============
ID: 5104, Name: tv_x64.exe, CommandLine: "C:\Program Files\TeamViewer\tv_x64.exe"
--action hooks --log C:\Program Files\TeamViewer\TeamViewer15_Logfile.log
===============
ID: 7188, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --js-flags=--ms-user-locale=ar_SY --lang=ar --device-scale-factor=1 --num-
raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=11 --
time-ticks-at-unix-epoch=-1665764507377161 --launch-time-ticks=523514580490 --mojo-
platform-channel-handle=5292 --field-trial-
handle=2012,i,2776781904686220101,14516812019439838743,131072 /prefetch:1
===============
ID: 12204, Name: TeamViewer_Desktop.exe, CommandLine: "C:\Program Files\TeamViewer\
TeamViewer_Desktop.exe" --IPCport 5939 --Module 1
===============
ID: 10636, Name: [Link], CommandLine: "C:\Windows\SystemApps\
[Link].Search_cw5n1h2txyewy\[Link]" -
ServerName:[Link]
===============
ID: 3240, Name: [Link], CommandLine: C:\Windows\System32\[Link] -
Embedding
===============
ID: 12944, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --profile-directory="Default"
===============
ID: 6952, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=crashpad-handler "--user-data-dir=C:\Users\USER\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\USER\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\USER\AppData\Local\Google\
Chrome\User Data" --url=[Link] --annotation=channel=
--annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=106.0.5249.119 --
initial-client-
data=0x10c,0x110,0x114,0xe8,0x118,0x7ff96a219758,0x7ff96a219768,0x7ff96a219778
===============
ID: 1692, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=gpu-process --gpu-
preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAA
AAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAA
AOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-
handle=1832 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:2
===============
ID: 13608, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --lang=ar --service-sandbox-type=none --mojo-
platform-channel-handle=2244 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:8
===============
ID: 4172, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --lang=ar --service-sandbox-type=utility --mojo-
platform-channel-handle=2316 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:8
===============
ID: 9900, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=12 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524844954288 --mojo-platform-channel-
handle=5548 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 9632, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=14 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524847871061 --mojo-platform-channel-
handle=5808 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 12876, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=23 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524895289589 --mojo-platform-channel-
handle=6320 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 6700, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=24 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524897027919 --mojo-platform-channel-
handle=3188 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 3416, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=25 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524897941700 --mojo-platform-channel-
handle=3208 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 1556, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=27 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524898621515 --mojo-platform-channel-
handle=6828 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 12176, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=28 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=524898741179 --mojo-platform-channel-
handle=7016 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 1592, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-type=[Link]
--lang=ar --service-sandbox-type=audio --mojo-platform-channel-handle=7160 --field-
trial-handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:8
===============
ID: 4736, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=renderer --display-capture-permissions-policy-
allowed --lang=ar --device-scale-factor=1 --num-raster-threads=2 --enable-main-
frame-before-activation --renderer-client-id=41 --time-ticks-at-unix-epoch=-
1665764507392555 --launch-time-ticks=525008835559 --mojo-platform-channel-
handle=7652 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:1
===============
ID: 4336, Name: [Link], CommandLine: "C:\Windows\system32\
[Link]" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3462017062-
494721814-2957221631-100170_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-
3462017062-494721814-2957221631-100170 1 -2147483646 "Software\Microsoft\Windows
Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\
ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
===============
ID: 12056, Name: [Link], CommandLine: "C:\Users\USER\AppData\Local\Temp\
Rar$EXb740.26169\[Link]"
===============
ID: 8264, Name: [Link], CommandLine: "C:\Users\USER\Desktop\\مجلد جديد
[Link]"
===============
ID: 3156, Name: [Link], CommandLine: [Link] f
===============
ID: 13076, Name: [Link], CommandLine:
===============
ID: 8756, Name: [Link], CommandLine: "C:\Windows\system32\[Link]" /4
===============
ID: 8516, Name: Nuktvijioppmpfdjkrcwhoprojections_s.exe, CommandLine: "C:\Users\
USER\AppData\Local\Temp\Nuktvijioppmpfdjkrcwhoprojections_s.exe"
===============
ID: 13208, Name: SETUP_~[Link], CommandLine: C:\Users\USER\AppData\Local\Temp\
[Link]\SETUP_~[Link]
===============
ID: 14736, Name: [Link], CommandLine: "C:\Windows\System32\
WindowsPowerShell\v1.0\[Link]" -enc
UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwA1AA==
===============
ID: 14744, Name: [Link], CommandLine: \??\C:\Windows\system32\[Link] 0x4
===============
ID: 15248, Name: [Link], CommandLine: "C:\Users\USER\
Pictures\Minor Policy\[Link]"
===============
ID: 38248, Name: [Link], CommandLine: "C:\Windows\[Link]\Framework\
v4.0.30319\[Link]"
===============
ID: 60356, Name: [Link], CommandLine: C:\Windows\syswow64\[Link]
[Link],uxbqsz
===============
ID: 10928, Name: [Link], CommandLine: C:\Windows\system32\[Link] -k
WspService
===============
ID: 15220, Name: [Link], CommandLine: "C:\Windows\[Link]\Framework\
v4.0.30319\[Link]"
===============
ID: 15540, Name: [Link], CommandLine: "C:\Program Files\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=proxy_resolver.[Link] --lang=ar --service-sandbox-
type=service --mojo-platform-channel-handle=5408 --field-trial-
handle=1936,i,17225448184771347760,9821348038348839157,131072 /prefetch:8
===============
ID: 15548, Name: [Link], CommandLine: "C:\Program Files (x86)\Microsoft\Edge\
Application\[Link]" --type=utility --utility-sub-
type=proxy_resolver.[Link] --lang=ar --service-sandbox-
type=service --mojo-platform-channel-handle=5504 --field-trial-
handle=2012,i,2776781904686220101,14516812019439838743,131072 /prefetch:8
===============
ID: 15672, Name: [Link], CommandLine: C:\Windows\system32\[Link]
/Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}