How to Remove a Kryptik Trojan

By Tim Mammadov

i Comstock/Comstock/Getty Images

The Kryptik trojan opens the "back door" of your computer to hackers once it infects a PC. The trojan is programmed to run at every start-up, giving the hackers who originated the program access to your hard drive. In addition, this trojan can re-create itself, making it hard to remove it completely. Delete this dangerous parasite to prevent personal data theft and computer damage.

End System Processes

Step 1

Press the "Ctrl," "Shift" and "Esc" keys at the same time to start the Task Manager.

Step 2

Click the "Processes" tab in the Task Manager's window.

Step 3

Select "defender32.exe" from the list of the processes and click "End Process" at the bottom of the window.

Step 4

Repeat Step 3 for "bqsy.exe," "CcEvtSvc.exe," "seres.exe" and "svcst.exe."

Step 5

Close the Task Manager.

Remove Registry Entries

Step 1

Go to the "Start" menu, type "Regedit" in the "Start Search" box and hit "Enter" to start the Registry Editor.

Step 2

Click the "Edit" file menu option in the Registry Editor's window, select "Find," type the following registry string in the search field and hit "Enter":

mserv

Delete all search results.

Step 3

Repeat Step 2 for the following registry entries:

bqsy RUNNING PROGRAMsvcst.exe RUNNING PROGRAMfndn8vq.exe RUNNING PROGRAMsetup.exe 0472FB67-09DD-4E92-8262-1BFC16CDB075 055E73DE-D97D-40B7-A20C-75A5C75248A7

Step 4

Close the Registry Editor.

Unregister DLL

Step 1

Go to the "Start" menu, type "cmd" in the Start Search box and hit "Enter" to start the command line window.

Step 2

Type "regsvr32 /u iehelpmod.dll" in the command line window and hit "Enter" to unregister the DLL.

Step 3

Close the command line window.

Find and Delete Files

Step 1

Go to the "Start" menu, type "defender32.exe" in the "Start Search" box and hit "Enter." Delete all search results.

Step 2

Repeat Step 1 for "bqsy.exe," "CcEvtSvc.exe," "seres.exe," "svcst.exe" and "iehelpmod.dll."

Step 3

Restart your computer.

×