How to remove Trojan.StealthProxy.A



THREAT NAME

Trojan.StealthProxy.A

 

CLEAN INSTRUCTIONS

1. Restart the system in Safe mode.

 

2. Go to Start>Run and type regsvr32 /u firewallx.dll then press OK.


3. Go to Start>Run and type regsvr32 /u firewallx.ocx and press OK.

 

4. Open Windows Explorer and navigate to the Windows directory.

 

5. Locate and delete the following files:


C:\Windows\proxy.exe
C:\Windows\firewallx.dll
C:\Windows\firewallx.ocx


SYMPTOMS

1. By default, the proxy runs on port 1212 so you may see this port is open.

 

2. Increased network activity.


DESCRIPTION
1. This is a SOCKS 4/5 server created in Delphi.

 

2. It is designed to run in the background in order to be as silent as possible.

 

3. By default the proxy runs on port 1212. Using the  netstat -an command should reveal the open port.


Author:
The BullGuard Team

Support 24/7

 


Our dedicated Support team is here for you with expert advice in English 24/7 and other languages during specific intervals.


Get help now


Upgrade / Renew

 

Already using BullGuard?


Make sure you make the most of it!


Upgrade Renew