m0rd3cai

updated

4 years ago

M

m0rd3cai

1 Rookie

9 Posts

2

2939

August 17th, 2022 11:00

Alienware Contol Center Software is unsigned

2 weeks ago I had issues with AWCC not working right so I fully removed it, cleared any registry keys for AWCC. Verified complete removal. Downloaded the newest version from August 11. Control center installed fine. No issues there. Next were the OC Controls for Alienware. That also installed with no issues. Rebooted laptop and NOW, when I open AWCC, EVERYTIME, i get a popup stating "Update existing components" which then shows a notification "Downloading packages" then Installing Packages. At that point, Webroot blocks a specific file "Display001VcpSrv.exe" which is located in

C:\Program Files\Alienware\Alienware FXDisplay001 Components for AWCC\

I have uploaded this file to Virustotal.com and was flagged by 23 Vendors with a high confidence of being malicious.

Virustotal Scan AWCC Component 

The scary part is this In-Program update is telling you to install 2 unsigned drivers which is very suspicious. Either your AWCC update system may have been compromised or your development team has failed to digitally sign their drivers which is fairly important in trusting what you put on your PC. This is what I get when I run the update from inside of AWCC.

alienware.PNG

awcc-webroot.PNG

I have called Tech Support and they aren't capable of understanding what i'm trying to explain to them. Hopefully an employee can point me in the right direction because i'm not going to install unsigned drivers that could infect my PC and gain access to my client's data.

 

This is a response from another affected user but they had a different file blocked which I cannot locate on my PC.

"Mine was quarantined by Sentinel One too. One of the quarantined file was named awcc.keystrokesdetector.dll I can't think of one legit reason for AWCC to be detecting keystrokes but at the same time why would a malware writer name a DLL like that?"

 

Here is also a Reddit post I started where many other people are affected by the same issue but they have different antivirus. This is NOT just Webroot catching this. HELP!!!!

I have G-15 5511 if that helps any.

Please point me in the right direction!