Security watchers have discovered a Trojan that uses built-in Windows functionality to overwrite security software and compromise systems.
The malware - which poses as an antivirus update - uses Windows input method editor (IME) to inject a system, technology that normally creates a means for users to enter characters not supported with their input device. For example, PC users with a 'Western' keyboard would take advantage of the technology to input Chinese or Japanese characters.
Story @ The register
Write up @ Websense