1 Rookie
•
8 Posts
2
2539
Alienware Contol Center Software is unsigned
Dell G15 5511
2 weeks ago I had issues with AWCC not working right so I fully removed it, cleared any registry keys for AWCC. Verified complete removal. Downloaded the newest version from August 11. Control center installed fine. No issues there. Next were the OC Controls for Alienware. That also installed with no issues. Rebooted laptop and NOW, when I open AWCC, EVERYTIME, i get a popup stating "Update existing components" which then shows a notification "Downloading packages" then Installing Packages. At that point, Webroot blocks a specific file "Display001VcpSrv.exe" which is located in
C:\Program Files\Alienware\Alienware FXDisplay001 Components for AWCC\
I have uploaded this file to Virustotal.com and was flagged by 23 Vendors with a high confidence of being malicious.
Virustotal Scan AWCC Component
The scary part is this In-Program update is telling you to install 2 unsigned drivers which is very suspicious. Either your AWCC update system may have been compromised or your development team has failed to digitally sign their drivers which is fairly important in trusting what you put on your PC. This is what I get when I run the update from inside of AWCC.
I have called Tech Support and they aren't capable of understanding what i'm trying to explain to them. Hopefully an employee can point me in the right direction because i'm not going to install unsigned drivers that could infect my PC and gain access to my client's data.
This is a response from another affected user but they had a different file blocked which I cannot locate on my PC.
"Mine was quarantined by Sentinel One too. One of the quarantined file was named awcc.keystrokesdetector.dll I can't think of one legit reason for AWCC to be detecting keystrokes but at the same time why would a malware writer name a DLL like that?"
Here is also a Reddit post I started where many other people are affected by the same issue but they have different antivirus. This is NOT just Webroot catching this. HELP!!!!
I have G-15 5511 if that helps any.
Please point me in the right direction!
m0rd3cai
1 Rookie
1 Rookie
•
8 Posts
0
September 11th, 2022 08:00
As of 9/9/22 Dell updated AWCC and fixed their issues with signing drivers. There is also a BIOS update available from the same date to 1.17
REQUIRES COMPLETE removal of ALL Alienware components. Reboot then use the new installer and reinstall OC components. No more Unsigned Driver issues. Issue resolved!
John harper
2 Intern
2 Intern
•
346 Posts
0
August 22nd, 2022 22:00
Make sure the computer is connected to the internet.
Browse to the Dell PC & Tablet Accessories Product Menu website.
Select the model number of your Alienware Gaming peripheral (it may be listed on the bottom of the device).
Touch or click the Drivers & downloads tab
Select the Operating System installed on your computer using the drop down menu under Operating system:.
Touch or click Download to the right of Alienware Command Center (do not close the browser window).
Depending on your browser, you will get different options. The following steps are based on using the Chrome browser.
Once the Alienware Command Center is downloaded, touch or click the file listed at the bottom of the screen to start the installation process, and follow the prompts.
Wait for the Dell Update Package window to appear the second time, and then touch or click Close.
Hope this helps,
John
m0rd3cai
1 Rookie
1 Rookie
•
8 Posts
0
August 23rd, 2022 04:00
I have uninstalled and reinstalled AWCC multiple times. That isn't the issue. The issue is I don't trust the software because your developers made a mistake or your supply chain has been compromised. There are MULTIPLE people having exactly the same issue as me. Please take 1 minute and look at the Reddit post I linked above.
This isn't a question of me being able to install the software. The issue is that you guys made a mistake and it needs to be corrected. I'm not installing an unsigned driver even if I downloaded it straight from your website. Period.
I don't understand why NO ONE understands what i'm talking about. Do you all understand how software signing works and what it means?? I have to use my laptop for work and I will NOT install unsigned ANYTHING on my laptop. This laptop will go right back to the store if this doesn't change.
I have to have that package installed to run/control my fans, it's not something I can just do without.
If your going to respond with install/uninstall directions again, just don't even post.
no_carrier
2 Posts
1
August 23rd, 2022 05:00
We are seeing the same problem in our environment with Display001VcpSrv.exe. Crowdstrike is placing the installer in quarantine based on Virustotal reports. While this might be a false positive, the unsigned driver is a serious cause of concern.
This is not an issue where anyone is having trouble downloading/installing. It is something that someone at Dell needs to further investigate.
I'd kindly request that this be escalated beyond support, possibly to whoever manages these repos, or to your IR/ID team.
m0rd3cai
1 Rookie
1 Rookie
•
8 Posts
1
August 23rd, 2022 08:00
As of 8/22/22, Dell advised they are escalating the ticket up to a higher tier so here's hoping.
no_carrier
2 Posts
0
August 23rd, 2022 10:00
That's good to hear, and gives me something to tell my customers/mgmt!
steadler
2 Intern
2 Intern
•
210 Posts
0
August 25th, 2022 18:00
Kaspersky and malwarebytes does not detect all these as infected or malware on my computer.
Display001VcpSrv.exe in the photo is listed as user added.
Yes Display001VcpSrv.exe and gamEyeApp.exe are not signed ,these are installed as a package
if you don't want those simply run the uninstaller in
C:\Program Files\Alienware\Alienware FXDisplay001 Components for AWCC\
if you want them back run the main installer (5.5.9) >> add package.
The first photo looks strange, the oc control service is no longer a separate install program it's integrated with the awcc (5.5.9) installer, it does not show a install box like that.It does no longer need a separate install. Maybe the AWCC program is an older version.
It is important to install recent updates because the digital signature certificates are dated.
Also awcc.keystrokesdetector.dll is signed and it's not detected as a problem
m0rd3cai
1 Rookie
1 Rookie
•
8 Posts
0
August 25th, 2022 22:00
How does the photo look weird? That is what pops up via the newest AWCC from Dell's site. That's what I've been trying to get Dell to realize. I updated to the newest version, rebooted after installing AWCC. THEN I was prompted to update components, which triggered said event.
What do you mean it was user added? You really having that much trouble?? The infection type is Win32.useradded? What does that have to do with anything?
Yet again, another one who doesn't understand. I wish Dell would get back to me so I can lock this thread and be done with it. Good for Kaspersky. I don't trust Kaspersky to catch anything. Even Norton was able to detect issues and stop them.
Sorry but your post doesn't make any sense. Simply running the uninstaller stops me from being able to control my fans at all so it isn't an option not to have it, hence all of the software signing.
DELL! Please respond and escalate my ticket!!
XPS_Man
5 Practitioner
5 Practitioner
•
2.4K Posts
0
August 29th, 2022 09:00
Webroot, Kaspersky both have been known to call verified apps as TROJANS. Its not Dell who will fix these. I switched to McAfee and had no issues afterwards. I have tested it on both McAfee home and Enterprise versions.
These Antivirus companies need to update their virus definitions or at least provide an option for the user to create exceptions.
m0rd3cai
1 Rookie
1 Rookie
•
8 Posts
0
August 29th, 2022 10:00
That has absolutely nothing to do with both drivers being UNSIGNED. That is the biggest problem I have right now. I'm not so worried about Display001VcpSrv being "malicious', I doubt it truly is but again, that has absolutely nothing to with the drivers.
The driver signing, however, IS Dell's problem and their responsibility. A/V detection and unsigned drivers are 2 completely different issues.