Once launched, the Trojan decrypts and extracts the following file from its body to the current user's temporary directory:
%Temp%<rnd1>.tmp
where <rnd1> is a random set of numbers and...
Source: http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.dfab webmaster@securelist.com ()