Техническая информация
- '<SYSTEM32>\taskkill.exe' /F /T /IM 5276
- Процесс ywmcpsd.exe, модуль ntdll.dll
- <SYSTEM32>\cmd.exe
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- <Текущая директория>\crashlog.txt
- 'localhost':49692
- 'ba####d.egmokka.com':443
- '19#.#32.210.172':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2a##############
- 'localhost':49693
- 'ba####d.egmokka.com':443
- DNS ASK ba####d.egmokka.com
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /C cmd.exe /C taskkill /F /T /IM 5276 (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C taskkill /F /T /IM 5276