Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System Relog' = '%PROGRAMDATA%\<File name>.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\system relog.url
- %WINDIR%\syswow64\attrib.exe
- from <Full path to file> to %PROGRAMDATA%\<File name>.exe
- '%WINDIR%\syswow64\attrib.exe'
- '%ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe' -jar "%WINDIR%\SysWOW64\attrib.exe"