The Trojan launches an HTTP proxy server on TCP port 12080 on the victim machine.
The Trojan is also capable of using a special configuration program to assign a random port number for the proxy.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate the Trojan process.
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
This Trojan launches a proxy server on the victim machine without the knowledge or consent of the user. It is a Windows PE EXE file. It is 48,128 bytes in size. It is packed using UPX. The unpacked file is approximately 105KB in size. Payload

Subscribe
Hot Articles