The said .EXE file, which bears the icon of files related to certain applications, is also detected as TROJ_ARTIEF.D.
Upon execution, it displays a message box, which tricks a user into thinking that it is a non-malicious file.
It then drops a file in the Windows Temporary folder, also detected by Trend Micro as TROJ_ARTIEF.D.The said .DLL file is injected into a hidden Internet Explorer process.
This Trojan accesses a URL to download a file which is detected by Trend Micro as TROJ_AGENT.UEW. As a result, routines of the downloaded file may be exhibited on the system.
Technical details can be found at this Trend Micro page.
Loading Comments...