A few days ago, I started getting notifications on my laptop “Unauthorized Changes Blocked”. This was caused by a Windows Defender virus protection function called “Controlled Folder Access”. Controlled Folder Access was blocking OSprofileCollector.exe. There is a way to “allow an app through” for trusted apps however, I can’t seem to find any information on OSProfileCollector in the Dell Community or internet to determine if this is malware, spyware or a legitimate program.
Here are details found on Event Viewer:
C:\Program Files\Dell\SARemediation\agent\OSProfileCollector.exe has been blocked from modifying %userprofile%\Music by Controlled Folder Access.
Detection time: 2018-04-13T21:44:36.937Z
User: LAP-DELL\carl3397
Path: %userprofile%\Music
Process Name: C:\Program Files\Dell\SARemediation\agent\OSProfileCollector.exe
Signature Version: 1.265.543.0
Engine Version: 1.1.14700.5
Product Version: 4.14.17613.18039
OSprofileCollector was not listed in Programs And Features either. If this is a legitimate program, I can add it to list of trusted apps (allow through) and be rid of these annoying notifications. Any help is appreciated!
There is a legitimate program on my Windows 10 called OSProfileCollector.exe with the same file path you quote. I believe it is part of Dell Update. It is not listed in my Apps and Features either (but Dell Update is).
Windows Defender's "Controlled Folder Access" feature is meant to prevent files and folders being changed during a ransomware attack. Of course Dell Update when running will make changes to files and folders. It is likely that one of these changes was interpreted as a (false positive) attack by Windows Defender.
If your computer is otherwise behaving well, I think you can allow this app through.
I don't use Windows Defender (WD) for Win 10 as my antimalware/AV. It is disabled (but not uninstalled) automatically by my use of Malwarebytes 3 over the past 2 years. When I went into the WD settings, I found that Control Folder Access was indeed turned off, as you would expect for this module of a disabled WD. Which would explain why I did not see what you did. I am surprised that more folks did not report this glitch, given the widespread use of Dell Update. It is possible this was a false positive that was detected and corrected quickly.
As an aside, if this was a case of a false positive detection by WD, it does not change my positive opinion of WD in general. All AVs and antimalwares suffer from the occasional false positive detection, sometimes (rarely) with catastrophic results. I continue to recommend WD as an acceptable alternative to paid protection.
It is absolutely ok to use WD with Malwarebytes free. I did it for years.
As a general rule, one should avoid running 2 AVs or anti-malware programs in real-time (constantly running in the background) to avoid conflicts that actually can degrade protection. However Malwarebytes Free is an on-demand scanner that provides no real-time protection.
Hi WYn Yu I agree that this Dell Update feature is unnecessary and is probably harvesting info for uncertain purposes. No doubt buried in some EULA I agreed to I gave Dell permission to gather this (hopefully and most likely anonymous) info. I see no nefarious activity here. I have found some legitimate uses for Dell Update to solve problems on an "on demand" basis, using a manual scan, and would suggest users not uninstall it. That said, I certainly do not wish it running in the background, downloading software updates automatically that I have not vetted.
For those who wish to disable (but not uninstall) automatic Dell Updates for Win 10, the best way to go is to go into services.msc and change the status of "Dell Update" from "Automatic" to "Disabled".
1) Press the Windows + R key to open the Run window
2) Type "services.msc" (without the quotation marks) in the Open: box. Click the [OK] key.
3) In the Services Window, scroll down to Dell Update Service, and click on it. In the far left column click on "Stop the service".
4) Double click on the Dell Update Service line again, and a Dell Update Service Properties window will open.
5) In the middle of that window, click on the dropdown arrow for the Startup type box, and change "automatic" to either "manual" or "disabled". Click [OK] and close.
This should solve the irritation of recurrent notifications and nags from WD, skimming of info back to Dell, and the silent installation of potentially unwanted updates.
I'm curious if you have Control Folder Access enabled on your Dell? Did you also encounter osprofilecollector.exe being blocked and had to allow the app through?
I'm wondering why I didn't see other people post about this problem?
The question for me is -- why is Dell even reading and even modifying the data in those Controlled Folders? These folders contain personal information -- user documents, photos and such, which would be irrelevant to an "update" function/program/feature. It seems to me that Dell is intruding on their customers' privacy. I had assumed that hardware manufacturers would respect user privacy. Best to find a way to disable this "update" function. And while this and my 2 previous laptops were Dells, I will look at other brands for my next purchase.
joe53
5 Journeyman
•
5772 Posts
•
17269 Points
21661
0
Posted April 13th, 2018 21:00
Hi Carl3397, and welcome to the forum
There is a legitimate program on my Windows 10 called OSProfileCollector.exe with the same file path you quote. I believe it is part of Dell Update. It is not listed in my Apps and Features either (but Dell Update is).
Windows Defender's "Controlled Folder Access" feature is meant to prevent files and folders being changed during a ransomware attack. Of course Dell Update when running will make changes to files and folders. It is likely that one of these changes was interpreted as a (false positive) attack by Windows Defender.
If your computer is otherwise behaving well, I think you can allow this app through.