Burmec manual removal:
Kill processes:
cmd.exe, explorer.exe, msconfig.exe, regedit.exe, regwiz.exe, scanregw.exe, sfc.exe, taskmgr.exe, wscript.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe msgsrv16.com
HKEY_CLASSES_ROOT\batfile\Shell\Open\Command\(Default)=%System%\cirsx.oxc "%1" %*
HKEY_CLASSES_ROOT\comfile\Shell\Open\Command\(Default)=%System%\cirsx.oxc "%1" %*
HKEY_CLASSES_ROOT\exefile\Shell\Open\Command\(Default)=C:\Recycled\kernel.vdx "%1" %*
HKEY_CLASSES_ROOT\exefile\Shell\RunAs\Command\(Default)=%Windir%\msgsrv16.com
HKEY_CLASSES_ROOT\File\Shell\Open\Command\(Default)=%Windir%\msgsrv16.com
HKEY_CLASSES_ROOT\lnffile\Shell\Open\Command\(Default)=%System%\rpcsx.vdx
HKEY_CLASSES_ROOT\nffile\Shell\Open\Command\(Default)=%Windir%\msgsrv16.com
HKEY_CLASSES_ROOT\piffile\Shell\Open\Command\(Default)=%System%\cirsx.oxc "%1" %*
HKEY_CLASSES_ROOT\scrfile\Shell\Open\Command\(Default)=C:\Recycled\kernel.vdx "%1" %*
HKEY_CLASSES_ROOT\*\Shell\OpenAs\Command\(Default)=%Windir%\msgsrv16.com
HKEY_CLASSES_ROOT\*\shellex\OpenWith\Command\(Default)=%System%\sndvol32.oxc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Network\DisablePwdCaching=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\Disabled=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\NoRealMode=1
Delete files:cmd.exe, explorer.exe, msconfig.exe, regedit.exe, regwiz.exe, scanregw.exe, sfc.exe, taskmgr.exe, wscript.exe, command.com, minigame.com, msgsrv16.com, sndvol32.com, rpcsx.vdx, cirsx.oxc, sndvol32.oxc
Misc:Exact file location:
kernel.vdx - C:\Recycled
minigame.com, msgsrv16.com - C:\Windows or C:\Winnt
rpcsx.vdx, cirsx.oxc, sndvol32.oxc - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Files cmd.exe, explorer.exe, msconfig.exe, regedit.exe, regwiz.exe, scanregw.exe, sfc.exe, taskmgr.exe, wscript.exe, command.com and sndvol32.com can be found on removable medias, local hard disks and mapped network drives.