***********************************************
* _ _ _ _ *
* / \ / \ / \ / \ *
* ( M | E | T | A ) *
* \_/ \_/ \_/ \_/ *
* *
* Telegram: [Link] *
***********************************************
ID: 3688, Name: [Link], CommandLine:
===============
ID: 4272, Name: [Link], CommandLine: C:\Windows\System32\[Link] -
SpecialSession
===============
ID: 4724, Name: [Link], CommandLine: -hiberboot
===============
ID: 9392, Name: [Link], CommandLine: "C:\Program Files\NVIDIA Corporation\
Display\[Link]"
===============
ID: 984, Name: [Link], CommandLine: C:\Windows\system32\[Link] -session
===============
ID: 6412, Name: [Link], CommandLine: "C:\Program Files (x86)\Norton Security\
Engine\[Link]\[Link]" /c /a /s UserSession2
===============
ID: 5528, Name: [Link], CommandLine: [Link]
===============
ID: 2052, Name: [Link], CommandLine: "C:\Program Files (x86)\Auslogics\
Auslogics BoostSpeed\[Link]" -UseTray
===============
ID: 6908, Name: [Link], CommandLine: "C:\Program Files\Realtek\Audio\HDA\
[Link]" -s
===============
ID: 9528, Name: [Link], CommandLine: "C:\Program Files\ESET\ESET Security\
[Link]" /hide
===============
ID: 4368, Name: [Link], CommandLine: "C:\Program Files (x86)\EPSON Software\
Epson Printer Connection Checker\[Link]"
===============
ID: 5840, Name: [Link], CommandLine: "C:\Program Files (x86)\
Sony\Xperia Companion\[Link]"
===============
ID: 9584, Name: [Link], CommandLine: C:\Windows\[Link] 8192
===============
ID: 9776, Name: E_YATIYXE.EXE, CommandLine: "C:\Windows\System32\spool\drivers\
x64\3\E_YATIYXE.EXE" /EPT "EPLTarget\P0000000000000001" /M "L3210 Series"
===============
ID: 9972, Name: [Link], CommandLine: "C:\Program Files (x86)\
CyberLink\PowerDVD12\Kernel\DMR\[Link]"
===============
ID: 5036, Name: [Link], CommandLine: "C:\Program Files (x86)\
CyberLink\PowerDVD12\[Link]"
===============
ID: 3952, Name: [Link], CommandLine: "C:\MSI\MSIRegister\[Link]"
===============
ID: 3172, Name: Super [Link], CommandLine: "C:\Program Files (x86)\MSI\Super
Charger\Super [Link]"
===============
ID: 9836, Name: [Link], CommandLine: "C:\Program Files (x86)\Winamp\
[Link]"
===============
ID: 6252, Name: [Link], CommandLine: "C:\Program Files (x86)\EPSON Software\
FAX Utility\[Link]"
===============
ID: 6992, Name: [Link], CommandLine: "C:\Program Files (x86)\EPSON
Software\Event Manager\[Link]"
===============
ID: 3052, Name: [Link], CommandLine: "C:\Program Files (x86)\Real\
RealPlayer\Update\[Link]" -osboot
===============
ID: 6916, Name: [Link], CommandLine: "C:\Program Files (x86)\Real\
RealPlayer\RPDS\Bin\[Link]"
===============
ID: 4564, Name: [Link], CommandLine: "C:\program files (x86)\real\
realplayer\[Link]"
===============
ID: 8668, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]"
===============
ID: 5496, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=crashpad-handler "--user-data-dir=C:\Users\MCC\
AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-
annotation=ptype=crashpad-handler "--database=C:\Users\MCC\AppData\Local\Google\
Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\MCC\AppData\Local\Google\Chrome\
User Data" --url=[Link] --annotation=channel= --
annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=109.0.5414.129 --
initial-client-
data=0xa4,0xa8,0xac,0x80,0xb0,0x7ff9273f6b58,0x7ff9273f6b68,0x7ff9273f6b78
===============
ID: 9384, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=gpu-process --gpu-
preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAA
AAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAA
AOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-
handle=1312 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:2
===============
ID: 5336, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --lang=es --service-sandbox-type=none --mojo-
platform-channel-handle=1560 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:8
===============
ID: 9564, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-
type=[Link] --lang=es --service-sandbox-type=service --mojo-
platform-channel-handle=1772 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:8
===============
ID: 6452, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --extension-process --lang=es --device-
scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --
renderer-client-id=5 --time-ticks-at-unix-epoch=-1679512287393023 --launch-time-
ticks=2399506657837 --mojo-platform-channel-handle=3248 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 6772, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=12 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2399512116209 --
mojo-platform-channel-handle=4944 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 1888, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=utility --utility-sub-type=[Link]
--lang=es --service-sandbox-type=audio --mojo-platform-channel-handle=4300 --field-
trial-handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:8
===============
ID: 9096, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=28 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2399630753798 --
mojo-platform-channel-handle=2568 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 6996, Name: [Link], CommandLine: C:\Windows\System32\
[Link] -Embedding
===============
ID: 3528, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=164 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2407453908845 --
mojo-platform-channel-handle=7628 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 10184, Name: [Link], CommandLine: /restart
===============
ID: 940, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=177 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2417668757176 --
mojo-platform-channel-handle=7408 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 4120, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=192 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2419838172886 --
mojo-platform-channel-handle=7636 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 5672, Name: [Link], CommandLine: C:\Windows\system32\[Link]
/Processid:{53362C64-A296-4F2D-A2F8-FD984D08340B}
===============
ID: 3276, Name: [Link], CommandLine: "C:\Users\MCC\Pictures\
Minor Policy\[Link]"
===============
ID: 5776, Name: [Link], CommandLine: C:\Users\MCC\AppData\Local\Temp\
[Link]\[Link]
===============
ID: 6912, Name: [Link], CommandLine: C:\Users\MCC\AppData\Local\Temp\
[Link]\[Link]
===============
ID: 8900, Name: [Link], CommandLine: C:\Users\MCC\AppData\Local\Temp\
[Link]\[Link]
===============
ID: 988, Name: [Link], CommandLine: C:\Users\MCC\AppData\Local\Temp\
[Link]\[Link]
===============
ID: 7676, Name: [Link], CommandLine: C:\Users\MCC\AppData\Local\Temp\
[Link]\[Link]
===============
ID: 10192, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=206 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2420291456859 --
mojo-platform-channel-handle=7252 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 7776, Name: [Link], CommandLine: "C:\Users\MCC\AppData\Roaming\hxdQf5\
[Link]"
===============
ID: 1428, Name: [Link], CommandLine: "C:\\Windows\\[Link]\\
Framework\\v4.0.30319\\[Link]"
===============
ID: 1400, Name: [Link], CommandLine: "C:\Users\MCC\AppData\Roaming\
telemetry\[Link]"
===============
ID: 6816, Name: YfrgZHCXmzhzN9_odiPXYqB2.exe, CommandLine: "C:\Users\MCC\Pictures\
Minor Policy\YfrgZHCXmzhzN9_odiPXYqB2.exe"
===============
ID: 6284, Name: [Link], CommandLine: "C:\\Windows\\[Link]\\
Framework\\v4.0.30319\\[Link]"
===============
ID: 3228, Name: [Link], CommandLine: .\[Link]
===============
ID: 6488, Name: [Link], CommandLine: "C:\Program Files (x86)\Google\Chrome\
Application\[Link]" --type=renderer --lang=es --device-scale-factor=1 --num-
raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=207 --
time-ticks-at-unix-epoch=-1679512287393023 --launch-time-ticks=2420562225579 --
mojo-platform-channel-handle=6780 --field-trial-
handle=1352,i,9396411294573025354,10866420090067150848,131072 /prefetch:1
===============
ID: 6548, Name: [Link], CommandLine: .\[Link] /S /site_id "525403"
===============
ID: 10436, Name: [Link], CommandLine: [Link]
===============
ID: 10704, Name: [Link], CommandLine: [Link] /h /shared Global\
3098c9e679824149a9eb8cf87f94f9a1 /t 9068 /p 8668
===============
ID: 10848, Name: [Link], CommandLine: "C:\Windows\System32\
WindowsPowerShell\v1.0\[Link]" -WindowStyle Hidden -EncodedCommand
cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZAB
lAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==
===============
ID: 11216, Name: [Link], CommandLine: C:\Windows\rss\[Link]
===============
ID: 11508, Name: [Link], CommandLine: C:\Users\MCC\AppData\Local\Temp\csrss\
injector\[Link] [Link] C:\Users\MCC\AppData\Local\Temp\csrss\injector\
[Link]
===============
ID: 11524, Name: [Link], CommandLine: \??\C:\Windows\system32\[Link] 0x4
===============
ID: 11628, Name: [Link], CommandLine: "C:\Users\MCC\AppData\Local\Temp\csrss\
[Link]"
===============
ID: 11752, Name: [Link], CommandLine: \??\C:\Windows\system32\[Link] 0x4