Thanks. I have Windows 2000 server which does not have sytem restore that I know of. Can you think of any other solution?
Main Topics
Browse All TopicsSymantec Corporate detects Spyware Ardakey during its nightly scan on my server. The file is always C:\WINNT\Sys32\dllcache\sv
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
http://www.spywareremove.c
Try the manual removal option with this link
I got it again tonight. The notification from Symantec Antivirus says the threat is Spyware Ardakey
File: C:\WINNT\System32\dllcache
Location: C:\WINNT\System32\dllcache
Action Taken: Leave Alone succceeded
It looks like the antivirus program does not delete the spyware, but informs that it is present because it is a system file that looks infected and deleting it could be a problem. I'm not sure how to get rid of this.
If the keylogger is in dllcache, what can I do to remove it without damaging the system?
Try this tool, we need to look at the log afterwards also to make sure it's clean.
Please download ComboFix by sUBs:
http://download.bleep
(If it doesn't run, re-download but rename before saving to your desktop)
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepin
Thanks rpggamergirl. The research that I did tells me that svchost.exe would not be infected, but a program running svchost would be what is infected. There is a program called Process Explorer that I fond out about which will list all the processes that run svchost, much like tasklist. Have you heard of this and should I start there? Since the pc with this problem is a server, I would not want to shut it down or stop processing during the day because many people in the office are connected to it . If it is a mjor problem, the that is a different story.
Yes, I'm very familiar with Process Explorer... that is a good program that tells if that svchost.exe running is legit belonging to Microsoft and tells you what services are running under that svchost.exe process.
But some nasties also can infect modify legit system files.
Yes, that's certainly a good one to start wth your diagnostic..
Since Combofix stops internet connection while scanning(though it will resume connection also soon after) you can use other tools maybe MalwareBytes etc.
It's also weird that Symantec doesn't detect it after the scan... could also be false positive.
You could submit that file to --> http://virusscan.jotti.org
the file will be scanned by many different antivirus scanners just to check if it really is infected.
Symantec tech support was able to resolve the issue by emailing me the link to a security scan. The scan found the spyware. I need to install a later version of their corporate antivirus after I get some more room on my server. Thanks to rpggamergirl anf priceD for their help. I will split the points to each of you.
Business Accounts
Answer for Membership
by: PriceDPosted on 2009-09-04 at 14:20:41ID: 25263428
http://www.experts-exchang e.com/Secu rity/ Opera ting_Syste ms_Securit y/Windows/ Q_21020193 .html? sfQu eryTermInf o=1+kei+lo gger+remov