Jump to content

Malwarebytes

prinimalka.py


2 replies to this topic

#1
duaneduane

    New Member

  • Members
  • Pip
  • 9 posts
I write software for a living - I happened to have SysInternals "DebugView" up and running and I see this really odd message pop up that I cannot explain


[872] http://XXX.XXX.XXX.XXX/f/prinimalka.py/opt...21&patch=ok
[872] stuk-stuk za cmd.cgi

To keep others from Clicking the above - I have removed the IP address ...
213
155
7
24

Registered to some guy in Russia.

How, why, what... I do not know what this is or where it came from ... Makes me wonder.. what it is, and I do not know where it came from.

I"m not that familiar with "DebugView" - but I think [872] is the process id.

What i don't know is what to do - or where this is comming from.

It has repeated a few times about 20mintes part.

#2
duaneduane

    New Member

  • Members
  • Pip
  • 9 posts
found it - Left overs of Antivirus 2009 that was not removed ... on an initial scan.

#3
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States
Are you good to go then or do you still require assistance?





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us