So if I read this correctly, the idea is that the PNG fetch looks innocuous to traffic scanners but the fetcher code executes the included DLL? The PNG rendering code in the browser would just discard those bits.
In other words, you've already been compromised, but the malignant code needs more instructions to continue effectively, so it fetches what appears to be an innocuous PNG file, which carries the instructions it needs.