first, do you know how to read
hjt logs adequately? sometimes malware can hide itself pretty well
Yes I'm pretty comfortable with reading
HJT logfiles, I've done a course on the GeeksToGo Forum a while ago as a Malware removal assister. I got to stage 5 out of the 6 practice logs, but then my son fell ill so I had to prioritise and subsequently dropped out. But I don't mind posting the logfile to you if that helps as I may be a bit rusty in detecting
There are quite a few exclamations icons, also some error icons, here goes starting with the exclamations:
System
1st Report
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 11/04/2007
Time: 12:46:55
User: N/A
Computer: POWERTRON
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
For more information, see Help and Support Center at
Events And Errors Message Center: Basic Search.
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 82 10 00 80 ......
0010: 01 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
2nd Report
Event Type: Warning
Event Source: Tcpip
Event Category: None
Event ID: 4226
Date: 11/04/2007
Time: 12:18:02
User: N/A
Computer: POWERTRON
Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
For more information, see Help and Support Center at
Events And Errors Message Center: Basic Search.
Data:
0000: 00 00 00 00 01 00 54 00 ......T.
0008: 00 00 00 00 82 10 00 80 ......
0010: 01 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
There are more exclamation icons for today but they are of a simular nature.
Here's the Error icon reports:
1st Error
Event Type: Error
Event Source: System Error
Event Category: (102)
Event ID: 1003
Date: 11/04/2007
Time: 13:05:46
User: N/A
Computer: POWERTRON
Description:
Error code 1000008e, parameter1 c0000005, parameter2 804f28da, parameter3 f0fa0930, parameter4 00000000.
For more information, see Help and Support Center at
Events And Errors Message Center: Basic Search.
Data:
0000: 53 79 73 74 65 6d 20 45 System E
0008: 72 72 6f 72 20 20 45 72 rror Er
0010: 72 6f 72 20 63 6f 64 65 ror code
0018: 20 31 30 30 30 30 30 38 1000008
0020: 65 20 20 50 61 72 61 6d e Param
0028: 65 74 65 72 73 20 63 30 eters c0
0030: 30 30 30 30 30 35 2c 20 000005,
0038: 38 30 34 66 32 38 64 61 804f28da
0040: 2c 20 66 30 66 61 30 39 , f0fa09
0048: 33 30 2c 20 30 30 30 30 30, 0000
0050: 30 30 30 30 0000
2nd Error
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 11/04/2007
Time: 13:04:49
User: N/A
Computer: POWERTRON
Description:
The MSCamSvc service failed to start due to the following error:
The system cannot find the path specified.
For more information, see Help and Support Center at
Events And Errors Message Center: Basic Search.
There are more but again they are of a simular nature.
Applications starting with the exclamation icons
1st Application report
Event Type: Warning
Event Source: Ci
Event Category: CI Service
Event ID: 4132
Date: 11/04/2007
Time: 13:12:07
User: N/A
Computer: POWERTRON
Description:
1 inconsistencies were detected in PropertyStore during recovery of catalog c:\system volume information\catalog.wci.
For more information, see Help and Support Center at
Events And Errors Message Center: Basic Search.
Error icon reports
1st error report
Event Type: Error
Event Source: Ci
Event Category: CI Service
Event ID: 4126
Date: 11/04/2007
Time: 13:12:07
User: N/A
Computer: POWERTRON
Description:
Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci. Index will be automatically restored by refiltering all documents.
For more information, see Help and Support Center at
Events And Errors Message Center: Basic Search.
Again there are quite a few of these icons, both errors and exclamations, so I've pasted one of each.
I'm a bit out of touch as to Pc repair, so any help you can give me will be greatly appreciated.
Thank you for your time.
