Skip navigation.

Prepare!

Lee Harvey's Zombie Hit Parade

Time Warner customer? Dell owner? They might be spying on you...

, , , ,

Note: If you're not a Time Warner cable (RoadRunner rr.com service) customer, then you can ignore this post.

If you ever went through Time Warner's Road Runner Medic download+install for Windows, then you most likely have this Windows NT service process running:

   sprtsvc.exe

(To check: goto Start> Run... taskmgr, Processes tab)

So what is sprtsvc.exe? Well, luckily, it registers itself under your Services (Start> Run... services.msc) as "SupportSoft Sprocket Service". Searching the web doesn't reveal much information on it, so I decided to poke around...to which I found this folder:

C:\Documents and Settings\All Users\Application Data\SupportSoft\medicsp2\

...which contains log files, xml config files, ini files, zip files, etc. I highly recommend that you examine the contents (and modified date/time frequency) of these files (esp. the log files) and judge for yourself.

Personally, it seems Time Warner logs all running processes, network info, hardware info, operating system info and patches, and installed programs, during every system startup, then submits it to http:\\medic.rr.com\global\ over an unencrypted, raw HTTP connection. In addition, the service seems to use Microsoft's BITS to download additional data in the background, unbeknownst to users.

Therefore, I have stopped "SupportSoft Sprocket Service" in services.msc, and set its Startup type to "Manual", instead of "Automatic".

I'll keep monitoring this, and if I discover anything else, I'll update this post. Stay tuned...

Nice new security tool: Mandiant Red CurtainUserJS fix for ASUS Product Comparison page

Comments

rid243 28. December 2007, 18:35

I've got the exact same thing except mine's for dell support center... is your computer a dell?

Lee Harvey 28. December 2007, 19:41

Nope. Mine's a custom build.

Most likely the same support software, though. Still a PITA.

dragonfly5711 14. February 2008, 01:16

I've got it too and it seems to be for dell too.

C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter

path to executeable C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter

Have you found anymore on this? It seems like a legit setup but it uses port80...???monkey

Lee Harvey 14. February 2008, 15:57

I suspect Dell is using the same support snooper as Time Warner. Since I don't need third-party tech support, I manually disabled that "SupportSoft Sprocket Service" in services.msc, rebooted, and everything seems fine now (no exposure/disclosure).

I'll update the title of this blog entry to include Dell.

Thanks for the feedback.

Write a comment

You must be logged in to write a comment. If you're not a registered member, please sign up.