Virus Win32:VB-KZH In Vista system32 folder

Good morning,

Since this morning i have problems with a malware dropper avast tells me.
but i can’t find anything about it. not even a description of what it does.

can you guys tell me if this is a correct message or just a false message.

the virus name is : Win32:VB-KZH[Drp]

It’s located in c:\windows\system32\sys32aoa.exe

I tried using Spybot, though it didn’t find anything.

Please help me! :slight_smile:

Try these free adware/spyware scanners. Download, install and update.

SUPERAntiSpyware Free
Malwarebytes’ Anti-Malware

Hoi Colossus

Installeer unlocker: http://ccollomb.free.fr/unlocker/ boot vervolgens in safe mode, localiseer het geïnfecteerde bestandje (C:\WINDOWS\system32\sys32aoa.exe) En daarna verwijderen (rechts erop klikken en dan unlocker kiezen zoals op de pagina getoond)
Je kunt ook nog even een HJT logtekstje toevoegen (additional options) en dan analyseren we dat eventjes voor je, HijackThis downloaden van hier, plaatsen op je Desktop en scanfile knippen en plakken en toevoegen in je volgende posting: http://download.bleepingcomputer.com/hijackthis/HiJackThis.exe
Groetjes, surf verder veilig,

polonus

A google search for sys32aoa.exe returns zero hits, which in itself is suspicious so I would say the avast detection is good.

What action did you take (and any errors displayed) when avast detected this, move to chest, delete, no action, what ?

If you moved it to the chest (recommended) then you shouldn’t be able to find it.

If you did nothing then it is possible that the file is hidden - Ensure that you have hidden files and folders enabled and disable hide system files in Windows Explorer, Tools, Folder Options, Hidden files and folders, uncheck Hide extensions for known file types, etc. see image.