We use cookies to ensure that we give you the best experience on our website. By continuing to browse, we are assuming that you have no objection in accepting cookies. You can change your cookie settings at any time.

BullGuard Support

We’re here 24/7 to help you.


Email our support team and we'll get back to you within 24 hours.


 

 

How to remove Trojan.StealthProxy.A



THREAT NAME

Trojan.StealthProxy.A

 

CLEAN INSTRUCTIONS

1. Restart the system in Safe mode.

 

2. Go to Start>Run and type regsvr32 /u firewallx.dll then press OK.


3. Go to Start>Run and type regsvr32 /u firewallx.ocx and press OK.

 

4. Open Windows Explorer and navigate to the Windows directory.

 

5. Locate and delete the following files:


C:\Windows\proxy.exe
C:\Windows\firewallx.dll
C:\Windows\firewallx.ocx


SYMPTOMS

1. By default, the proxy runs on port 1212 so you may see this port is open.

 

2. Increased network activity.


DESCRIPTION
1. This is a SOCKS 4/5 server created in Delphi.

 

2. It is designed to run in the background in order to be as silent as possible.

 

3. By default the proxy runs on port 1212. Using the  netstat -an command should reveal the open port.


Author:
The BullGuard Team