• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 02:06
CEST 08:06
KST 15:06
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 1 - Final Week6[ASL19] Finals Recap: Standing Tall12HomeStory Cup 27 - Info & Preview18Classic wins Code S Season 2 (2025)16Code S RO4 & Finals Preview: herO, Rogue, Classic, GuMiho0
Community News
Esports World Cup 2025 - Brackets Revealed11Weekly Cups (July 7-13): Classic continues to roll4Team TLMC #5 - Submission extension3Firefly given lifetime ban by ESIC following match-fixing investigation17$25,000 Streamerzone StarCraft Pro Series announced7
StarCraft 2
General
Esports World Cup 2025 - Brackets Revealed Who will win EWC 2025? RSL Revival patreon money discussion thread The GOAT ranking of GOAT rankings Weekly Cups (July 7-13): Classic continues to roll
Tourneys
FEL Cracov 2025 (July 27) - $8000 live event RSL: Revival, a new crowdfunded tournament series $5,100+ SEL Season 2 Championship (SC: Evo) WardiTV Mondays Sparkling Tuna Cup - Weekly Open Tournament
Strategy
How did i lose this ZvP, whats the proper response Simple Questions Simple Answers
Custom Maps
External Content
Mutation # 482 Wheel of Misfortune Mutation # 481 Fear and Lava Mutation # 480 Moths to the Flame Mutation # 479 Worn Out Welcome
Brood War
General
Flash Announces (and Retracts) Hiatus From ASL BW General Discussion BGH Auto Balance -> http://bghmmr.eu/ Starcraft in widescreen A cwal.gg Extension - Easily keep track of anyone
Tourneys
[Megathread] Daily Proleagues Cosmonarchy Pro Showmatches CSL Xiamen International Invitational [BSL20] Non-Korean Championship 4x BSL + 4x China
Strategy
Simple Questions, Simple Answers I am doing this better than progamers do.
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread Path of Exile CCLP - Command & Conquer League Project The PlayStation 5
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Stop Killing Games - European Citizens Initiative Summer Games Done Quick 2025! Things Aren’t Peaceful in Palestine
Fan Clubs
SKT1 Classic Fan Club! Maru Fan Club
Media & Entertainment
[Manga] One Piece Movie Discussion! Anime Discussion Thread [\m/] Heavy Metal Thread
Sports
Formula 1 Discussion TeamLiquid Health and Fitness Initiative For 2023 2024 - 2025 Football Thread NBA General Discussion NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Men Take Risks, Women Win Ga…
TrAiDoS
momentary artworks from des…
tankgirl
from making sc maps to makin…
Husyelt
StarCraft improvement
iopq
Trip to the Zoo
micronesia
Customize Sidebar...

Website Feedback

Closed Threads



Active: 690 users

Starcraft: Remastered received Spyware "upgrade"?

Forum Index > BW General
Post a Reply
Mindflayer
Profile Joined December 2015
Germany10 Posts
Last Edited: 2021-04-24 23:38:13
April 24 2021 23:37 GMT
#1
Hello everyone,

so first of all, I would like to clarify that I am by far no expert in this kind of analysis. I just have some basic knowledge about whats going on in an operating system. And all I'm asking for here, is for someone to help me put things into perspective and explain to me what might be going on or what I might have misinterpreted.

What happened?
Lately, while playing Starcraft: Remastered, I recognised some unusually heavy upload activity, originating from my Computer and going towards my wifi router. It can nicely be observed within the wifi workload of the router. Download speed remains as usual.

[image loading]
Taking a look into the network activites using a monitoring tool, I found that in fact the process of Starcraft is responsible for the upload. Using the UDP protocol, it seems to send a lot of data to 37.244.54.234. Alongside with some other IP addresses, which most likely apply to the other players.
A lookup of the, by far most active, IP address unsurprisingly reveals that its a static IP address of Blizzard. (Btw. blocking that IP does not work. Starcraft just switches to another one within the 37.244.54.X range. I don't know how many excalty, but a lot of them seem to belong to Blizzard. And if I block the entire range, I am no longer able to join any games - but surprisingly still able to join Battle.Net and chat.)

The interesting part is, that the upload starts as soon as I join a game Lobby, peaks at the start of a game and starts to lower after some minutes into the game.

[image loading]
Curiosity sparked, I decided to monitor all activities of the Starcraft process for a while. After some time, there was something interesting. Right at the moment when I joined another game lobby, Starcraft.exe read in a lot of files, which it actually should not have any interest in.

The executables of Deamon Tools Lite, HP Scanning Software, WPS Office, Windows System Binaries... and so on.
And like the ones marked in the Screenshot, Starcraft.exe did not only probe the mentioned files; it completely read them in. So I am wondering, what does it do with that data? Is that normal behavior for a game executable?

Not sure about the file reading thing, but the crazy upload behavior started since the last update of Starcraft: Remastered via the Battle.Net Launcher.

Can someone help me understand?
Makaveli1
Profile Blog Joined August 2011
United States118 Posts
April 24 2021 23:50 GMT
#2
If I had to speculate, probably some sort of check to make help against people hacking on ladder. Just speculation.
Garrl
Profile Blog Joined February 2010
Scotland1972 Posts
Last Edited: 2021-04-25 17:44:25
April 25 2021 17:43 GMT
#3
Warden (Blizzard's propriety antihack) has been in BW since the remastered prepatch ((i think?) and is known to scan memory for malicious programs and send them to Blizz servers for comparison.
MeSaber
Profile Joined December 2009
Sweden1235 Posts
April 25 2021 21:20 GMT
#4
How the do you know it started since last patch? Do you analyze this frequently or have a data quota alarm?
-.-
prOxi.swAMi
Profile Blog Joined November 2004
Australia3091 Posts
April 25 2021 23:51 GMT
#5
The UDP connection you're seeing I think is just the game traffic (and the fact it is going to Blizzard is probably just because the connection is being proxied).

There's no good reason why they would do telemetry over UDP, it doesn't make sense. The TCP connections on 443 are much more likely (especially given the hostnames) to be uploading telemetry data.

This isn't Blizzard deploying or running spyware, reading executables on your machine is normal for a game that tries to prevent hacking.

Also, the numbers you're seeing are not what I would call "crazy upload behaviour" at all, not even close. I think you're jumping the gun in a big way here.
Oh no
tec27
Profile Blog Joined June 2004
United States3696 Posts
April 26 2021 00:40 GMT
#6
On April 26 2021 08:51 prOxi.swAMi wrote:
The UDP connection you're seeing I think is just the game traffic (and the fact it is going to Blizzard is probably just because the connection is being proxied).

There's no good reason why they would do telemetry over UDP, it doesn't make sense. The TCP connections on 443 are much more likely (especially given the hostnames) to be uploading telemetry data.

This isn't Blizzard deploying or running spyware, reading executables on your machine is normal for a game that tries to prevent hacking.

Also, the numbers you're seeing are not what I would call "crazy upload behaviour" at all, not even close. I think you're jumping the gun in a big way here.

Pretty much this. If you were on a turn-rate of 24 in a 2 player game and every packet was the maximum it could be without fragmentation (~1500 bytes), one would expect a send speed of 24 * 1500 / 1024 = ~35kbps, and your task manager is showing less than half that, so why exactly is that worrying?

As far as the file reads, I don't believe "Warden" is a thing any more and is not active in SC:R at all, they rely on an off-the-shelf anti-debugger and obfuscation technology now, not active protection. What those look like to me is mostly programs injecting themselves into the StarCraft process and doing initialization.

Certainly, above all else, this was not something that began in the last update. The last update only changed the ladder map pool.
Can you jam with the console cowboys in cyberspace?
Mindflayer
Profile Joined December 2015
Germany10 Posts
Last Edited: 2022-05-27 23:00:31
May 27 2022 22:45 GMT
#7
Hello everyone,

I would like to pick up on this thread once more, in the hopes that someone else might find the information useful which I discovered.

The problem I describe in my first post got way worse. In most games, the Up -and Download speed is quite low. But "sometimes" the Starcraft: Remastered process randomly starts to go apeshit. It happens, I would say, every 5th to 10th game. Almost exclusively in 3v3 or 4v4. It can happen at every point within a running game, but mostly within the first 5 or so minutes. The Starcraft process starts to download with up to 35 KiB/s and also a very high Upload-rate. Always from/to a Blizzard IP.
When it happens, in-game, the game stops immediately and I start to lag. Within the infamous 45 seconds before one can be dropped from a game, it continues maybe 3 or 4 times for a very short moment. After that, the other players cannot kick me, nor can I drop out of the game myself. (No need to mention how often I was called a hacker due to that.)

After a lot of analysis without any clear results, I started to randomly kill other processes once the problem occurred. And that's when I found the cause:
Its the ASUS ROG GameFirst V Utility, running as GameFirst_V.exe! In its description it says: "ROG GameFirst V is an exclusive Asus tool that optimizes network traffic to increase latency and speed in the game." Yeah, well done ASUS...

I didn't even know something like that was running on my PC. Otherwise it would have immediately come under my suspicion. And I still have no idea how a completely different process can manage to cause something like that to a game process like Starcraft.

Since there have been a lot of people whose games this problem has ruined so far, I would like to apologize for the inconveniences, in case one of you happens to read this post.

Have a nice weekend.
3FFA
Profile Blog Joined February 2010
United States3931 Posts
May 29 2022 17:09 GMT
#8
On May 28 2022 07:45 Mindflayer wrote:
Hello everyone,

I would like to pick up on this thread once more, in the hopes that someone else might find the information useful which I discovered.

<sic>

After a lot of analysis without any clear results, I started to randomly kill other processes once the problem occurred. And that's when I found the cause:
Its the ASUS ROG GameFirst V Utility, running as GameFirst_V.exe! In its description it says: "ROG GameFirst V is an exclusive Asus tool that optimizes network traffic to increase latency and speed in the game." Yeah, well done ASUS...

I didn't even know something like that was running on my PC. Otherwise it would have immediately come under my suspicion. And I still have no idea how a completely different process can manage to cause something like that to a game process like Starcraft.

Since there have been a lot of people whose games this problem has ruined so far, I would like to apologize for the inconveniences, in case one of you happens to read this post.

Have a nice weekend.


It's awesome that you returned with your result a whole month later once you found the cause. This makes the thread far more helpful for anyone else that may encounter similar network issues in brood war in the future!

Hopefully this marks the end of any issues you encounter
"As long as it comes from a pure place and from a honest place, you know, you can write whatever you want."
LML
Profile Blog Joined March 2007
Germany1764 Posts
May 30 2022 02:05 GMT
#9
On May 30 2022 02:09 3FFA wrote:
Show nested quote +
On May 28 2022 07:45 Mindflayer wrote:
Hello everyone,

I would like to pick up on this thread once more, in the hopes that someone else might find the information useful which I discovered.

<sic>

After a lot of analysis without any clear results, I started to randomly kill other processes once the problem occurred. And that's when I found the cause:
Its the ASUS ROG GameFirst V Utility, running as GameFirst_V.exe! In its description it says: "ROG GameFirst V is an exclusive Asus tool that optimizes network traffic to increase latency and speed in the game." Yeah, well done ASUS...

I didn't even know something like that was running on my PC. Otherwise it would have immediately come under my suspicion. And I still have no idea how a completely different process can manage to cause something like that to a game process like Starcraft.

Since there have been a lot of people whose games this problem has ruined so far, I would like to apologize for the inconveniences, in case one of you happens to read this post.

Have a nice weekend.


It's awesome that you returned with your result a whole month later once you found the cause. This makes the thread far more helpful for anyone else that may encounter similar network issues in brood war in the future!

Hopefully this marks the end of any issues you encounter


A whole month.. and a whole year, too :D
LML
Please log in or register to reply.
Live Events Refresh
Next event in 9h 54m
[ Submit Event ]
Live Streams
Refresh
StarCraft: Brood War
Britney 23866
Sea 13997
Backho 206
PianO 87
Mind 62
Sacsri 44
Noble 26
Shine 25
Bale 15
NaDa 8
Dota 2
NeuroSwarm112
Counter-Strike
Stewie2K1137
Super Smash Bros
Mew2King84
Other Games
summit1g10272
hungrybox347
Trikslyr24
Organizations
Other Games
gamesdonequick2938
BasetradeTV22
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 18 non-featured ]
StarCraft 2
• Berry_CruncH353
• Light_VIP 71
• practicex 42
• OhrlRock 3
• AfreecaTV YouTube
• sooper7s
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
StarCraft: Brood War
• iopq 2
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• lizZardDota226
League of Legends
• Lourlo1336
• Stunt431
Upcoming Events
uThermal 2v2 Circuit
9h 54m
Replay Cast
17h 54m
The PondCast
1d 3h
OSC
1d 6h
WardiTV European League
1d 9h
Replay Cast
1d 17h
Epic.LAN
2 days
CranKy Ducklings
3 days
Epic.LAN
3 days
CSO Contender
3 days
[ Show More ]
BSL20 Non-Korean Champi…
3 days
Bonyth vs Sziky
Dewalt vs Hawk
Hawk vs QiaoGege
Sziky vs Dewalt
Mihu vs Bonyth
Zhanhun vs QiaoGege
QiaoGege vs Fengzi
Sparkling Tuna Cup
4 days
Online Event
4 days
BSL20 Non-Korean Champi…
4 days
Bonyth vs Zhanhun
Dewalt vs Mihu
Hawk vs Sziky
Sziky vs QiaoGege
Mihu vs Hawk
Zhanhun vs Dewalt
Fengzi vs Bonyth
Esports World Cup
6 days
ByuN vs Astrea
Lambo vs HeRoMaRinE
Clem vs TBD
Solar vs Zoun
SHIN vs Reynor
Maru vs TriGGeR
herO vs Lancer
Cure vs ShoWTimE
Liquipedia Results

Completed

CSL 17: 2025 SUMMER
RSL Revival: Season 1
Murky Cup #2

Ongoing

JPL Season 2
BSL 2v2 Season 3
Copa Latinoamericana 4
Jiahua Invitational
BSL20 Non-Korean Championship
Championship of Russia 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
BLAST Rivals Spring 2025
MESA Nomadic Masters

Upcoming

CSL Xiamen Invitational
CSL Xiamen Invitational: ShowMatche
2025 ACS Season 2
CSLPRO Last Chance 2025
CSLPRO Chat StarLAN 3
BSL Season 21
K-Championship
RSL Revival: Season 2
SEL Season 2 Championship
uThermal 2v2 Main Event
FEL Cracov 2025
Esports World Cup 2025
Underdog Cup #2
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.