Thursday, January 6, 2011

How to Remove My Disk (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
My Disk is a rogue hard drive defragmentation application that displays fake error messages and reports false system threats to make you think that there is something wrong with your computer. This fake scanner is from the same family as Memory Fixer, HDD Fix, and HDD Low. My Disk is distributed through the use of Trojans and fake online ads/scanners. Once installed, it will display fake error messages saying that your hard drive is missing or that your private data is at risk. The rogue program will block other programs on your computer and hide your desktop icons. Your desktop background may become black as you were in safe mode. My Disk will report eleven critical errors on your computer. It will fix some of the errors and prompt you to pay for a full version of the program to fix remaining problems. This program is a typical rip-off rogue. You shouldn't purchase it. It won't make your computer run faster and it won't fix any problems because the only real problem is My Disk itself. If you got hit with this rogue disk defragmenter, please follow the removal instructions below to remove My Disk and related malware from your computer for free. Please note that this rogue can come bundled with other malware, usually rootkits. It is very important to scan your computer with trusted anti-malware software. If you have any questions about this malware, please leave a comment. Good luck and be safe online!



Fake hard drive error messages:
Low Disk Space
You are running very low disk space on Local Disk (C:).

Critical Error
A critical error has occurred while indexing data stored on hard drive. System restart required.




Fake error notifications from Windows taskbar:


Critical Error
Damaged hard drive clusters detected. Private data is at risk.



My Disk removal instructions:

1. Download Process Explorer. (click the link and wait for few seconds, download will begin automatically)
2. End My Disk processes, e.g. ickxYGkrqlBhAe.exe or He9HV84YiCjyAX.exe.



3. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


My Disk removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


My Disk associated files and registry values:

Files:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\My Disk.lnk
  • %UsersProfile%\Start Menu\Programs\My Disk\
  • %UsersProfile%\Start Menu\Programs\My Disk\My Disk.lnk
  • %UsersProfile%\Start Menu\Programs\My Disk\Uninstall My Disk.lnk
%AllUsersProfile% refers to:
C:\Documents and Settings\All Users (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Roaming (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

How to Remove PC Security 2011 (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
PC Security 2011 is a rogue anti-virus application that pretends to scan your computer for Trojans, spyware and other malware and then deliberately reports false system security threats to make you think that your computer is infected. It chooses files randomly and states that they are infected with Conficker.B and Zafi.B trojans, Sality.AM virus and some other malware. In order to get rid of these non-existent viruses, you're prompted to pay for a full license of PC Security 2011. Please do not fall victim to this fake antivirus scam. It gives a false sense of security and won't protect your computer against any type of malicious software. If you find that you have this rogue program on your computer, please follow the steps in the removal guide below to remove PC Security 2011 and related malware from your computer with free anti-malware software from trusted companies.



Scammers use Trojans, fake online scanners and infected websites to distribute their bogus anti-virus scanner. They also use online ads to try to distribute fake security software via the sites of legitimate Web publishers. PC Security 2011 may be promoted on popular social networks too. When PC Security 2011 is running, it will display fake security warnings and other misleading pop-ups saying that your computer is now attacked by spyware and other malware. It may also state that Trojans can steal your sensitive information and even delete important files. The warnings issued by this program are all fake.
Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.





One of the USB devices attacheted to this computer has been spreading Spam.Bot Virus. Please fix it immediately.
What is more, PC Security 2011 may block other programs on your computer and hijack Internet Explorer. Such rogue security applications redirect users to entirely unrelated websites full of online Ads, adult content and misleading software. The rogue program can come bundled with rootkits. We've received a sample which came with a rootkit from the TDSS family. You can choose to remove PC Security 2011 manually but be advised that there might be other malware on your computer. That's why we strongly recommend you to use anti-malware applications to remove all infections from your computer. Otherwise, the rogue program may come back after a few days or hours. Or scammers may drop new fake antivirus scanners onto your computer.

Without a doubt, PC Security 2011 is a rogue application that uses misleading methods to steal money from unsuspecting users. Do not pay for this simulated malware removal. If you did pay, contact your credit card company and dispute the charges or change your credit card number, as it's now in questionable hands. Then get rid of PC Security 2011 malware. If you have any questions about this rogue program, pleas leave a comment. Helpful comments are welcome too. You should also inform your friends and associates about this threat. Good luck and be safe online!


PC Security 2011 removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


PC Security 2011 removal instructions using Process Explorer (in Normal mode):

1. Download Process Explorer and end PC Security 2011 process:
  • PC2011.exe
2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


PC Security 2011 associated files and registry values:

Files:

In Windows XP:
  • C:\Documents and Settings\[UserName]\Application Data\PC Security 2011
  • C:\Documents and Settings\[UserName]\Application Data\Uninstall_Security
  • C:\Documents and Settings\[UserName]\Start Menu\Programs\Startup\PC2011.lnk
  • C:\Program Files\PC Security 2011
  • C:\Program Files\PC Security 2011\PC2011.exe
In Windows Vista/7:
  • C:\Users\[UserName]\AppData\Roaming\\PC Security 2011
  • C:\Users\[UserName]\AppData\Roaming\Uninstall_Security
  • C:\Program Files\PC Security 2011
  • C:\Program Files\PC Security 2011\PC2011.exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PC Security 2011
  • HKEY_CURRENT_USER\Software\PC Security 2011
Share this information with other people:

Wednesday, January 5, 2011

How to Remove Memory Fixer (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Memory Fixer is a piece of malware that comes in the form of a disk defragmenter program. It pretends to scan your computer for system errors and malcode and reports that there is an issue with your computer, even though your computer is perfectly fine. Memory Fixer states that it has found numerous hard drive and Windows registry errors (flaged as critical to scare users) and then offers remediation in exchange of payment. The rogue applications displays legitimate looking but fake error messages to further scare you into thinking that there is something wrong with your computer. Furthermore, it blocks other programs and system utilities and hijacks Internet Explorer. Besides, it can come bundled with other malware that may cause even more problems. Memory Fixer itself is very annoying but not dangerous. It can't delete your files or steal sensitive information. Anyway, if you have this rogue program on your computer then you should obviously remove it. Please follow the removal instructions below to remove Memory Fixer and related malware from your computer with the help of free and reliable anti-malware software. As always, helpful comments and questions are welcome. Good luck and be safe online!

Similar rogues: HDD Fix, Quick Defrag, HDD Low.




Memory Fixer removal instructions:

1. Download Process Explorer. (click the link and wait for few seconds, download will begin automatically)
2. End Memory Fixer processes, e.g. kdrGhdgOFGdlerg.exe or ufGhvHde.exe.



3. Download TDSSKiller (free utility from Kaspersky Lab) and run it. Remove TDSS rootkit if exist.



4. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Memory Fixer removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Memory Fixer associated files and registry values:

Files:
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS]
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].dll
  • %AllUsersProfile%\Application Data\[SET OF RANDOM CHARACTERS].exe
  • %UsersProfile%\Desktop\Memory Fixer.lnk
  • %UsersProfile%\Start Menu\Programs\Memory Fixer\
  • %UsersProfile%\Start Menu\Programs\Memory Fixer\Memory Fixer.lnk
  • %UsersProfile%\Start Menu\Programs\Memory Fixer\Uninstall Memory Fixer.lnk
%AllUsersProfile% refers to:
C:\Documents and Settings\All Users (in Windows 2000/XP)
C:\Users\[UserName]\AppData\Roaming (in Windows Vista & Windows 7)

Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[SET OF RANDOM CHARACTERS].exe"
Share this information with other people:

How to Remove AntiVirus System 2011 (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
AntiVirus System 2011 is a rogue security program that performs a fake system scan and reports non-existent malware and viruses on your computer. It launches pop-up windows with fake or simulated detection of viruses, e.g. Trojans, worms and other malicious software. It may report up to 500 infected files on your computer. In other words, AntiVirus System 2011 provides no security and generates misleading security alerts to make you think that your computer in infected with some sort of malware. As a typical scareware, it will prompt you to pay for a full version of the program to remove the infections and to protect your computer against new threats. Do not fall victim to this scam. If you have accidentally ended up with this rogue security program then please follow the removal instructions below to remove AntiVirus System 2011 and related malware for free using legitimate anti-malware software.



AntiVirus System 2011 relies on social engineering in order to install itself onto victim's computer. It is mainly promoted via Trojans, fake online scanners and infected websites. The rogue may come bundled with other malware as well. When AntiVirus System 2011 is running, it will display many fake security warnings saying that malicious software may damage your computer and compromise your privacy. It will display legitimate looking windows security center pop-ups and notifications from Windows task bar.





As you may expect, AntiVirus System 2011 can not be removed as legitimate software through add/remove programs. If you attempt to remove it this way, you will get an error message saying that you do not have permission to remove AntiVirus System 2011. What is more, this fake anti-virus will block other programs on your computer. It may state that particular program is infected and has been closed because it can lead to permanent data loss and etc. By the way, AntiVirus System 2011 can not delete your pictures, documents and other files. It's a fake scanner, not a virus. Don't worry about that. Last, but not least, AntiVirus System 2011 will hijack Internet Explorer and redirect to its purchase page e.g. antivirussystem2011tech.com or entirely unrelated websites which in fact may be infected with other malware.



As you can see, AntiVirus System 2011 is a fake program that uses misleading methods to deceive users into paying for the fake removal of malware. If you have already purchased this rogue program, please contact your credit card company and state that the program is a scam and that you would like to dispute the charge. To remove AntiVirus System 2011, please follow the steps in the guide below. Questions and helpful comments are welcome. Don't forget to inform your friends and colleagues about AntiVirus System 2011. Good luck and be safe online!


AntiVirus System 2011 removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


AntiVirus System 2011 removal instructions using HijackThis or Process Explorer (in Normal mode):

1. Download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it.

2. Search for such entry in the scan results:
O4 - HKCU\..\Run: [Security Manager] C:\Documents and Settings\[User Name]\Application Data\AntiVirus System 2011\securitymanager.exe
O4 - HKCU\..\Run: [AntiVirus System 2011] "C:\Documents and Settings\[User Name]\Application Data\AntiVirus System 2011\AntiVirus_System_2011.exe" /STARTUP
O4 - HKCU\..\Run: [3jdfrl34hdrmd] C:\Documents and Settings\[User Name]\Desktop\AntiVirus_System_2011\AntiVirus System 2011\securityhelper.exe
Select all similar entries and click once on the "Fix checked" button. Close HijackThis tool.

OR you may download Process Explorer and end AntiVirus System 2011 processes:
  • AntiVirus_System_2011.exe
  • securitymanager.exe
  • securityhelper.exe
3. Download free anti-malware software from the list below and run a full system scan.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


AntiVirus System 2011 associated files and registry values:

Files:

In Windows XP:
  • C:\Documents and Settings\[UserName]\Application Data\AntiVirus System 2011\
  • C:\Documents and Settings\[UserName]\Application Data\AntiVirus System 2011\AntiVirus_System_2011.exe
  • C:\Documents and Settings\[UserName]\Application Data\AntiVirus System 2011\securitymanager.exe
  • C:\Documents and Settings\[UserName]\Application Data\AntiVirus System 2011\securityhelper.exe
In Windows Vista/7:
  • C:\Users\[UserName]\AppData\Roaming\AntiVirus System 2011\
  • C:\Users\[UserName]\AppData\Roaming\AntiVirus System 2011\AntiVirus_System_2011.exe
  • C:\Users\[UserName]\AppData\Roaming\AntiVirus System 2011\securitymanager.exe
  • C:\Users\[UserName]\AppData\Roaming\AntiVirus System 2011\securityhelper.exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011
  • HKEY_CURRENT_USER\Software\AntiVirus System 2011
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "3jdfrl34hdrmd"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Security Manager"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AntiVirus System 2011"
Share this information with other people:

Tuesday, January 4, 2011

How to Remove Palladium Pro (Uninstall Guide)

Don't Copy From This Blog...

Protected by Copyscape Plagiarism Detection
Palladium Pro is a rogue security program that pretends to be legitimate antivirus software and attempts to deceive unsuspecting PC users into paying to remove fake or simulated malware infections. Palladium Pro is a rebranded version of ThinkPoint rogue. It relies on social engineering, whereby the user is tricked into installing Trojan virus which masquerades as Microsoft Security Essentials and displays a fake security warning that uses the same fonts, colors, and layout as trusted security program. It makes false claims about having detected unknown Win32/Trojan and states that Microsoft Security Center has detected the submitted suspicious file as Trojan.Horse.Win32.PAV.64.a. Trojan then prompts the user to install Palladium Pro to solve the problem. As you may already know, profit is a primary motivation for creators of such malware. Please do not purchase Palladium Pro for any reason. If you are reading this article then your computer is probably infected with this fake program. Thankfully, we've got the removal instructions to help you to remove Palladium Pro and related malware from your computer. Please follow the removal guide below.




Thanks to rogueamp for making this video.

When you press the OK button, to allow Palladium Pro to install, the Trojan will reboot your computer to finish the installation.



After a reboot, you will see the "Palladium World's leading security solution" screen instead of your normal Windows desktop.



When you click the "Safe startup" button, the fake Palladium Pro scanner window will show up on your computer screen. The rogue will pretend to scan your computer for malware. After the fake scan, it will prompt you to buy heuristic modules to remove the threats from your computer which don't even exist. Do not fall victim to this rogue program. Furthermore, Palladium Pro will interfere with the normal operation of the computer. It will prevent you from launching other applications and block access to legitimate websites. In order to remove Palladium Pro from your computer, you will have to end its process, restore Windows explorer and scan your computer with anti-malware software. If you choose to remove the rogue program manually then you will also have to change Windows shell value in the registry; otherwise your Windows desktop will not be displayed the next time you reboot. Be advised, that the rogue may come bundled with other malicious software. That's why we strongly recommend you to use anti-malware software. For more information, please follow the removal instructions below. And, of course, if you have already purchased this bogus program, then you should contact your credit card company and dispute the charges. If you have any questions regarding Palladium Pro removal, then please leave a comment. Helpful comments are welcome as always. Good luck and be safe online!


Palladium Pro removal instructions:

1. Restart your computer. Once the "Palladium World's leading security solution" window comes press Ctrl+Alt+Delete or Ctrl+Shift+Escape. You should now see the Windows Task Manager screen as shown in the image below or a screen where you can select the Task Manager to be run.



Click on the Processes tab. Then click and highlight palladium.exe and click End Task. If it asks you "Are you sure you want to terminate the process?" click yes (or press Enter). This will close the ThinkPoint program.

2. While in Windows Task Manager, click the File -> "New Task (Run...)" from the menu on the bottom right. Type in explorer.exe and click OK. Your desktop and icons should start up as normal.



NOTE: if you got an error message "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access them", then please run this command first:

cacls "C:\Windows\explorer.exe" /G Everyone:F



A new windows will come up asking "Are you sure?" Type Y and press enter.



Now run explorer.exe again.

3. Download the following file to your Desktop: windows-shell.reg. Double-click to run it. Click "Yes" when it asks if you want to add the information to the registry. This file will fix the Windows Shell entry. This step is  important because if you won't fix this entry, then your Windows Desktop will not be displayed the next time you reboot. Once the new registry value has been added, you can delete the file from your computer.

4. Run Internet Explorer or any other browser and download free anti-malware software from the list below:
Run a full system scan and remove Palladium Pro from your computer.
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator.

5. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET NOD32 Antivirus 4.


Palladium Pro associated files and registry values:

Files:

For Windows XP users:
  • C:\Documents and Settings\[User Name]\Application Data\palladium.exe
  • C:\Documents and Settings\[User Name]\Application Data\[SET OF RANDOM CHARACTERS].bat
  • C:\Documents and Settings\[User Name]\Application Data\uid_pal
  • C:\Documents and Settings\[User Name]\Application Data\completescan_pal
  • C:\Documents and Settings\[User Name]\Application Data\install_pal
  • C:\Documents and Settings\[User Name]\Desktop\Palladium.lnk
  • C:\Documents and Settings\[User Name]\Start Menu\Programs\Palladium.lnk
  • C:\Windows\Tasks\At[random].job
For Windows Vista and Windows 7 users:
  • C:\Users\[User Name]\AppData\Roaming\palladium.exe
  • C:\Users\[User Name]\AppData\Roaming\[SET OF RANDOM CHARACTERS].bat
  • C:\Users\[User Name]\AppData\Roaming\uid_pal
  • C:\Users\[User Name]\AppData\Roaming\completescan_pal
  • C:\Users\[User Name]\AppData\Roaming\install_pal
  • C:\Users\[User Name]\Desktop\Palladium.lnk
  • C:\Users\[User Name]\Start Menu\Programs\Palladium.lnk
  • C:\Windows\Tasks\At[random].job
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell = "%AppData%\palladium.exe"
Share this information with other people:

 
//PART 2