Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'empty'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'psychoware' = '<Full path to file>'
- Windows Task Manager (Taskmgr)
- %APPDATA%\microsoft\speech\files\userlexicons\sp_ddea86f022344c3187577efa92966509.dat
- '<SYSTEM32>\cmd.exe'