Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinPackEntMon' = '%WINDIR%\STMonitor.exe'
- '%WINDIR%\STMonitor.exe'
- '%WINDIR%\STMonitor.exe' -server:172.32.2.157 -port:8090 -stealth -autorun -oldpass: -newpass:acmlab.com -moninclude:*.* -NORUN
- %WINDIR%\STMonitor.exe
- %ALLUSERSPROFILE%\Application Data\71757.G08
- '17#.#2.2.157':8090
- ClassName: 'MS_WINHELP' WindowName: '(null)'