Additional Details
Upon execution, this trojan tries to take advantage of the following vulnerability:
• Microsoft Office Snapshot Viewer ActiveX vulnerability
If this vulnerability is present on the user's system, the malware exploits it in order to download and execute a file from the URL http://down.hs7yue.cn/[...]/ac.css. The downloaded file is detected as the malware Trojan.Win32.Agent.wnu.
The online
F-Secure Health Check can help determine whether a user's system has vulnerabilities which can be exploited, and assist in finding fixes for any vulnerabilities discovered.