Now is wednesday at 21.54 my time West Europe, Since moday 23.20 I am looking at the history file of NIS (on Vista) very carefully, because moday I got some files intercepted by Norton like Gk0.exe,Gk1.exe... Gk7.exe sshnas21.dll and others in my temp directoy and in my process list. I stopped the connection to internet (unlight the modem) and started the observations of the all the enviroment. I deleted manually the processes. Delete the files in temp directory , erased the entry in the register of windows. But I find a message in Norton Hystory that I do not like: "You allowed Gk7 to access your network resources" and same for the other programs. Looking in details the "Gk7" is \user\paolo\AppData\Local\Temp\Gk7.exe with Traffic description : Outbound UDP,Port 53. This now but monday the programs were all called Daniels and not Gk0,...,GK7. So apparently the message has changed, but my concer is WHY SOMEBODY or some program CAN MAKE THIS NEW RULE . I have done absolutly nothing manually to change the rules. More if I go to the list of PROGRAM CONTROL i cannot find GK7.exe or Daniels!
Now the are a number of Messages like : "Symantec Error Reporting Submission" concerning the process ccSvcHst.
I am asking myself if I am working in a proper environment or if Norton is compromised
Could sombody help me please. Thank You very much