Posted by Stefan Kanthak on Dec 21
Hi @ll,
the executable installer [°] of ESET’s NOD32 antivirus,
eset_nod32_antivirus_live_installer_.exe, loads and executes
(at least) the rogue/bogus/malicious Cabinet.dll and DbgHelp.dll
eventually found in the directory it is started from [‘] (the
“application directory”).
For software downloaded with a web browser this is typically the
“Downloads” directory: see
<…