3 Apprentice

 • 

20.5K Posts

August 28th, 2007 20:00

"suspicious scripting" does not always mean that it is anything bad. We have to disable script blocking for many of the good tools that we use here.

I would not delete it at this point.
If you have the file in question scanned you will know more.

Go here: http://virusscan.jotti.org/

You may have to click on Projects (only if the homepage comes up) and then online Malware Scan to access the virus scan page.
If you are at a black page with the title "Online malware scan", you are in the right place.
Click "Browse..." and navigate to progarm files\dellsupport center\bin\sptsvc.exe
Click "Open" and then "Submit"
It will take a couple seconds and then the results should be lower on the page.
In order to help other members who may have the same problem, please copy the information from "File:" down to "Norman Virus Control" and post it in your next reply.

7 Posts

August 28th, 2007 23:00

Thank you for your suggestions. I did go to the link and had the file scanned.  No virus was found.  So that didn't do anything.  I am wondering if I can just delete the file.

3 Apprentice

 • 

20.5K Posts

August 29th, 2007 00:00

"So that didn't do anything.
It didn't give you a report that you could post here?

If no virus was found, why would you want to delete a legitimate file from Dell Support? You may need it.

3 Apprentice

 • 

20.5K Posts

August 29th, 2007 01:00

The list usually has the names of all the anti-virus vendors that have scanned the file. If nothing is found, by each it states "Found Nothing".

Try Virus Total --
http://www.virustotal.com/en/indexf.html

At the top of the page you will see:
Select file>Browse>Send
Just follow the prompts.
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

When you get the report, please post back the exact results.


Or Kaspersky:
http://www.kaspersky.com/remoteviruschk.html
Browse to the file and click "Submit".

7 Posts

August 29th, 2007 01:00

Sorry.  I should have said that it did not identify any viruses.  I had closed the window to return to your message, so I didn't have the report, but the list was empty.  It didn't contain any hits, so I either I do not understand what your want me to post, or I do not understand its value (all fields none).  I do not know that it is a leg file, or its function.  That would be helpful.  Perhaps I don't need it. This is my first post, so take it easy.I am on a steep learning curve.

7 Posts

August 30th, 2007 10:00

Thank you for your suggestion on the Virus Total.  This was the report. I will continue to do full system scans for virus with various free programs others are suggesting.  No luck yet.
 
File sprtsvc.exe received on 08.30.2007 13:28:28 (CET)

 
Result: 0/32 (0%)
 
 
Email:
Antivirus Version Last Update Result AhnLab-V3 2007.8.29.0 2007.08.30 - AntiVir 7.4.1.66 2007.08.30 - Authentium 4.93.8 2007.08.29 - Avast 4.7.1029.0 2007.08.29 - AVG 7.5.0.484 2007.08.29 - BitDefender 7.2 2007.08.30 - CAT-QuickHeal 9.00 2007.08.30 - ClamAV 0.91.2 2007.08.30 - DrWeb 4.33 2007.08.30 - eSafe 7.0.15.0 2007.08.29 - eTrust-Vet 31.1.5095 2007.08.30 - Ewido 4.0 2007.08.30 - FileAdvisor 1 2007.08.30 - Fortinet 3.11.0.0 2007.08.30 - F-Prot 4.3.2.48 2007.08.29 - F-Secure 6.70.13030.0 2007.08.30 - Ikarus T3.1.1.12 2007.08.30 - Kaspersky 4.0.2.24 2007.08.30 - McAfee 5108 2007.08.29 - Microsoft 1.2803 2007.08.30 - NOD32v2 2491 2007.08.30 - Norman 5.80.02 2007.08.30 - Panda 9.0.0.4 2007.08.29 - Prevx1 V2 2007.08.30 - Rising 19.38.32.00 2007.08.30 - Sophos 4.21.0 2007.08.30 - Sunbelt 2.2.907.0 2007.08.25 - Symantec 10 2007.08.30 - TheHacker 6.1.9.175 2007.08.30 - VBA32 3.12.2.3 2007.08.30 - VirusBuster 4.3.26:9 2007.08.29 - Webwasher-Gateway 6.0.1 2007.08.30 -

3 Apprentice

 • 

20.5K Posts

August 30th, 2007 13:00

I don't see any evidence of infection there, and even McAfee does not find anything. I believe the "suspicious scripting" simply means that McAfee's realtime script blocker does not know what to do with it, so it classifies it as "suspicious".

7 Posts

August 30th, 2007 16:00

Thank you again.  Something is going wrong however, as more messages are now appearing.  I have removed the Support Center (can always download again), but now Windows Defender cannot activate, and the windows/system32/msiexec.exe file is now reporting suspicious.  I am sending that to virus total right now for a check....I also ran I complete scan in DOS per McAfee's suggestion.  It found only one possible infection and deleleted it.  However there were a lot of files it could not open.  I wish I could have figured out how to save that report.  It was very thorough, but in dos I couldn't remember how to print the screen....In addition to these new warnings that open at start up is a VPN warning, and Real Player appeared in Start up.  It hasn't before. So I will continue to run all virus detection software I have availalble...perhaps some update has fouled up the works.
So far this AhnLab-V3 2007.8.31.0 2007.08.30 - AntiVir 7.4.1.66 2007.08.30 - Authentium 4.93.8 2007.08.29 - Avast 4.7.1029.0 2007.08.29 - BitDefender 7.2 2007.08.30 - ClamAV 0.91.2 2007.08.30 - eSafe 7.0.15.0 2007.08.29 - eTrust-Vet 31.1.5095 2007.08.30 - Ewido 4.0 2007.08.30 - FileAdvisor 1 2007.08.30 - Fortinet 3.11.0.0 2007.08.30 - F-Prot 4.3.2.48 2007.08.29 - F-Secure 6.70.13030.0 2007.08.30 - Ikarus T3.1.1.12 2007.08.30 - Kaspersky 4.0.2.24 2007.08.30 - Microsoft 1.2803 2007.08.30 - NOD32v2 2492 2007.08.30 - Norman 5.80.02 2007.08.30is the result...

7 Posts

August 30th, 2007 16:00

H
File msiexec.exe received on 08.30.2007 19:36:50 (CET)
 
Result: 0/32 (0%)
Loading server information...
wait for web response ( automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.  
Antivirus Version Last Update Result AhnLab-V3 2007.8.31.0 2007.08.30 - AntiVir 7.4.1.66 2007.08.30 - Authentium 4.93.8 2007.08.29 - Avast 4.7.1029.0 2007.08.29 - AVG 7.5.0.484 2007.08.29 - BitDefender 7.2 2007.08.30 - CAT-QuickHeal 9.00 2007.08.30 - ClamAV 0.91.2 2007.08.30 - DrWeb 4.33 2007.08.30 - eSafe 7.0.15.0 2007.08.29 - eTrust-Vet 31.1.5095 2007.08.30 - Ewido 4.0 2007.08.30 - FileAdvisor 1 2007.08.30 - Fortinet 3.11.0.0 2007.08.30 - F-Prot 4.3.2.48 2007.08.29 - F-Secure 6.70.13030.0 2007.08.30 - Ikarus T3.1.1.12 2007.08.30 - Kaspersky 4.0.2.24 2007.08.30 - McAfee 5109 2007.08.30 - Microsoft 1.2803 2007.08.30 - NOD32v2 2492 2007.08.30 - Norman 5.80.02 2007.08.30 - Panda 9.0.0.4 2007.08.29 - Prevx1 V2 2007.08.30 - Rising 19.38.32.00 2007.08.30 - Sophos 4.21.0 2007.08.30 - Sunbelt 2.2.907.0 2007.08.25 - Symantec 10 2007.08.30 - TheHacker 6.1.9.175 2007.08.30 - VBA32 3.12.2.3 2007.08.30 - VirusBuster 4.3.26:9 2007.08.30 - Webwasher-Gateway 6.0.1 2007.08.30 -Here is the rest of the report:

3 Apprentice

 • 

20.5K Posts

August 30th, 2007 16:00

It might not be a good idea to delete programs/files until you know exactly what the problem is. If you delete something that is needed for another file to execute you are going to start getting errors.

How about running CCleaner, and then download and install a clean copy of Dell Support Center? Perhaps a clean copy won't set off McAfee, and if it does, it may be McAfee with the problem. Have you checked the McAfee forums to see if anyone else with a Dell has had a similar problem? http://forums.mcafeehelp.com/

If you are going to run CCleaner, here are the instructions:
Download and scan each user profile with CCleaner:
http://www.ccleaner.com/download/builds
** Select to download the BASIC version.
1. Before first use, select Options > Advanced and UNCHECK
" Only delete files in Windows Temp folder older than 48 hours"
2. Then select the items you wish to clean up.
In the Windows Tab:
• Clean all entries in the "Internet Explorer" section except Cookies (if you want to keep those).
• Clean all the entries in the "Windows Explorer" section.
• Clean all entries in the "System" section.
• Clean all entries in the "Advanced" section.
• Clean any others that you choose.
In the Applications Tab:
• Clean all except cookies (if you want to keep those) in the Firefox/Mozilla section if you use it.
• Clean all in the Opera section if you use it.
• Clean Sun Java in the Internet Section.
• Clean any others that you choose.
3. Click the " Run Cleaner" button.
4. A pop up box will appear advising this process will permanently delete files from your system.
5. Click " OK" and it will scan and clean your system.
6. Click " exit" when done.
REBOOT.
No Events found!

Top