Once launched, the Trojan extracts the following file from its resources to the current user's temporary directory:
%Temp%<rnd1>.vbs
where <rnd1> is a random set of numbers and letters,...
Source: http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.Agent.crbk webmaster@securelist.com ()