MS04-028: Trojan.Ducky A/B exploits GDI+ vulnerabilities
http://www.symantec.com/avcenter/venc/data/trojan.ducky.html
http://www.symantec.com/avcenter/venc/data/trojan.ducky.b.html
Trojan.Ducky is a downloader Trojan that exploits the Microsoft GDI+ Library JPEG Segment Length Integer Underflow vulnerability (as described in the Microsoft Security Bulletin MS04-028).