This is from a Windows XP Pro aplication log file
I did not set it up
It was done in the background
It was done by remote
No alarms or messages were made just this:
Event Type: Warning
Event Source: WinMgmt
Event Category: None
Event ID: 5603
Date: 3/22/2008
Time: 7:43:38 PM
User: NT AUTHORITY\SYSTEM
Computer: TIM
Description:
A provider, Rsop Planning Mode Provider, has been registered in the WMI
namespace, root\RSOP, but did not specify the HostingModel property. This
provider will be run using the LocalSystem account. This account is
privileged and the provider may cause a security violation if it does not
correctly impersonate user requests. Ensure that provider has been reviewed
for security behavior and update the HostingModel property of the provider
registration to an account with the least privileges possible for the
required functionality.
He copies: My Documents, all web pages, contacts, and trash. The remote
user collects the data from a database on the machine, and you never it's
going on unless you notice 20 UDP packets go through your network for no
reason.