I recently had my Warcraft account hacked. I checked for keyloggers, reinstalled Vista and found nothing (NIS 2008 installed then, 2009 now).
After checking IP address patterns, i noticed that ccSvcHst.exe is trying to access an ip address in china every time I boot my computer: 61.129.72.16.
This happens both before and after the reinstallation of vista. On the reinstall, there was nothing but Norton 2008 on the system with vista, no other software.
I checked the file and the digital signature is correct, the size is correct etc.
Is this normal behaviour for this file?