HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
To get rid of it, enter serial codes from this list (there is different version of the malware with the same GUI):
ãíèëîçóá
êàðòîôàí
õðåíîâèùå
Run MBAM to remove the infection.
About Malwares, Rogues, Scarewares, SmitfraudFix