Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'EsetNupForward' = '"<Current directory>\EsetNupForward.exe"'
- '%WINDIR%\syswow64\taskkill.exe' /f /im "EsetNupForward.exe"
- %TEMP%\esetnupforward\forwarder.log
- <Current directory>\config.ini
- %TEMP%\{ec9bd85a-84dc-413f-a226-73bacee650dc}.png
- %LOCALAPPDATA%\microsoft\windows\explorer\notifyicon\microsoft.explorer.notification.{3403519e-27fc-875a-373e-bdf19a52e880}.png
- <Current directory>\update\update_new.exe
- %TEMP%\{bc65855b-1b7a-4d65-9523-53f5e27af469}.png
- <Current directory>\update\update_batch_2968.bat
- nul
- %TEMP%\{ec9bd85a-84dc-413f-a226-73bacee650dc}.png
- %TEMP%\{bc65855b-1b7a-4d65-9523-53f5e27af469}.png
- from <Full path to file> to <Current directory>\esetnupforward.exe
- 'vc#2.cn':80
- '<DNS_SERVER>':53
- http://do##.vc52.cn/NupForward/update/EsetNupForward.exe
- DNS ASK vc#2.cn
- DNS ASK do##.vc52.cn
- ClassName: 'Edit' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Current directory>\esetnupforwa...
- '%WINDIR%\syswow64\cmd.exe' /c "<Current directory>\update\update_batch_2968.bat"
- '%WINDIR%\syswow64\chcp.com' 936
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 3
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 2