Prepare!

Lee Harvey's Zombie Hit Parade

Time Warner customer? Dell owner? They might be spying on you...

, , , ,

Note: If you're not a Time Warner cable (RoadRunner rr.com service) customer, then you can ignore this post.

If you ever went through Time Warner's Road Runner Medic download+install for Windows, then you most likely have this Windows NT service process running:

   sprtsvc.exe

(To check: goto Start> Run... taskmgr, Processes tab)

So what is sprtsvc.exe? Well, luckily, it registers itself under your Services (Start> Run... services.msc) as "SupportSoft Sprocket Service". Searching the web doesn't reveal much information on it, so I decided to poke around...to which I found this folder:

C:\Documents and Settings\All Users\Application Data\SupportSoft\medicsp2\

...which contains log files, xml config files, ini files, zip files, etc. I highly recommend that you examine the contents (and modified date/time frequency) of these files (esp. the log files) and judge for yourself.

Personally, it seems Time Warner logs all running processes, network info, hardware info, operating system info and patches, and installed programs, during every system startup, then submits it to http:\\medic.rr.com\global\ over an unencrypted, raw HTTP connection. In addition, the service seems to use Microsoft's BITS to download additional data in the background, unbeknownst to users.

Therefore, I have stopped "SupportSoft Sprocket Service" in services.msc, and set its Startup type to "Manual", instead of "Automatic".

I'll keep monitoring this, and if I discover anything else, I'll update this post. Stay tuned...

Nice new security tool: Mandiant Red CurtainUserJS fix for ASUS Product Comparison page

Comments

rid243 Friday, December 28, 2007 6:35:28 PM

I've got the exact same thing except mine's for dell support center... is your computer a dell?

Lee HarveyLee_Harvey Friday, December 28, 2007 7:41:32 PM

Nope. Mine's a custom build.

Most likely the same support software, though. Still a PITA.

dragonfly5711 Thursday, February 14, 2008 1:16:46 AM

I've got it too and it seems to be for dell too.

C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter

path to executeable C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter

Have you found anymore on this? It seems like a legit setup but it uses port80...???monkey

Lee HarveyLee_Harvey Thursday, February 14, 2008 3:57:52 PM

I suspect Dell is using the same support snooper as Time Warner. Since I don't need third-party tech support, I manually disabled that "SupportSoft Sprocket Service" in services.msc, rebooted, and everything seems fine now (no exposure/disclosure).

I'll update the title of this blog entry to include Dell.

Thanks for the feedback.

CilantroCilantro5000 Wednesday, September 22, 2010 9:50:00 PM

This might be an old thread, but I'd like to add that my none Dell laptop also has this service magically appear one day. I did some googling and thought maybe it was attached to Avira antivirus. Then I noticed in the service name in MSCONFIG (verizonDM). Which raised an eyebrow or two. Apparently Supportsoft is used by several telecommunication companies. This worries me and @ the same time makes me feel glad that I periodically check my services!

Write a comment

New comments have been disabled for this post.