It drops something winrar.exe which renames itself to logon.exe and runs through HKCU\....\Run registry key. Extracted from VBC.exe payload dll attached.
					
										Attachments
			
			 pass: malware
(248.74 KiB) Downloaded 39 times
		
					
				
				
				(248.74 KiB) Downloaded 39 times
			
			 pass: malware
(414.23 KiB) Downloaded 39 times
		
								(414.23 KiB) Downloaded 39 times
Ring0 - the source of inspiration
					 						
            
