Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System Relog' = '%ALLUSERSPROFILE%\<File name>.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\system relog.url
- %WINDIR%\syswow64\attrib.exe
- from <Full path to file> to %ALLUSERSPROFILE%\<File name>.exe
- '%WINDIR%\syswow64\attrib.exe'