Suspicious services found, what now?

T

Tri

Hi,
This message has to be a bit lengthy, so sorry first.
I have been looking in the Computer Management -> Event
Viewer -> Application of my computer. I have found
several instances of this type of warning:
"A provider blah blah has been registered in the WMI
namespace, to use the Local System account"

One of the examples which I found on my computer is:

"Ein Anbieter Rsop Planning Mode Provider wurde im WMI-
Namespace root\RSOP registriert ohne die HostingModel-
Eigenschaft festzulegen. Dieser Anbieter wird unter dem
Konto "LocalSystem" ausgeführt. Dieses Konto verfügt über
besondere Berechtigungen und der Anbieter kann eine
Sicherheitsverletzung verursachen, wenn er
Benutzeranforderungen nicht richtig imitiert."
Sorry cause I have Windows in German. Basically you can
see the name of the service (or whatever) is Rsop
Planning Mode, which I certainly don't know.

So the question is, are these things normal? I don't feel
so. I follow the link given by windows to go to knowledge
base and support but it says it has no documents or
information to match. I started to look in Event Viewer
because my firewall was down a few days ago and I have
been trying to make sure my computer is clean now. I have
got rid of Blaster by Norton AV and quarrantired Amecisco
keylogger by using Spy Sweeper. But I don't know what is
still there.
Thanks a lot,
Tri
 
R

Roger

Sorry, but I have no answer for you. I just wanted to
find out if you got the problem solved, it sounded kinda
interesting. And have you translated the German yet?
German to Klingon perhaps?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top