• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 12:31
CEST 18:31
KST 01:31
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Code S Season 1 - RO8 Preview3[ASL21] Ro8 Preview Pt2: Progenitors8Code S Season 1 - RO12 Group A: Rogue, Percival, Solar, Zoun13[ASL21] Ro8 Preview Pt1: Inheritors16[ASL21] Ro16 Preview Pt2: All Star10
Community News
Maestros of The Game 2 announcement and schedule !1Weekly Cups (April 27-May 4): Clem takes triple0RSL Revival: Season 5 - Qualifiers and Main Event12Code S Season 1 (2026) - RO12 Results12026 GSL Season 1 Qualifiers25
StarCraft 2
General
Code S Season 1 - RO8 Preview Behind the Blue - Team Liquid History Book Weekly Cups (April 27-May 4): Clem takes triple Blizzard Classic Cup @ BlizzCon 2026 - $100k prize pool Code S Season 1 (2026) - RO12 Results
Tourneys
Maestros of The Game 2 announcement and schedule ! GSL Code S Season 1 (2026) Sea Duckling Open (Global, Bronze-Diamond) RSL Revival: Season 5 - Qualifiers and Main Event Sparkling Tuna Cup - Weekly Open Tournament
Strategy
Custom Maps
[D]RTS in all its shapes and glory <3 [A] Nemrods 1/4 players
External Content
Mutation # 524 Death and Taxes The PondCast: SC2 News & Results Mutation # 523 Firewall Mutation # 522 Flip My Base
Brood War
General
Do we have a pimpest plays list? BGH Auto Balance -> http://bghmmr.eu/ (Spoiler) Asl ro8 D winner interview BW General Discussion AI Question
Tourneys
Small VOD Thread 2.0 [ASL21] Ro8 Day 4 [BSL22] RO16 Group Stage - 02 - 10 May [ASL21] Ro8 Day 3
Strategy
Simple Questions, Simple Answers Fighting Spirit mining rates What's the deal with APM & what's its true value Any training maps people recommend?
Other Games
General Games
Nintendo Switch Thread Dawn of War IV Stormgate/Frost Giant Megathread OutLive 25 (RTS Game) Daigo vs Menard Best of 10
Dota 2
The Story of Wings Gaming
League of Legends
G2 just beat GenG in First stand
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas TL Mafia Community Thread Five o'clock TL Mafia
Community
General
US Politics Mega-thread European Politico-economics QA Mega-thread The Letting Off Steam Thread Russo-Ukrainian War Thread 3D technology/software discussion
Fan Clubs
The IdrA Fan Club
Media & Entertainment
Anime Discussion Thread [Manga] One Piece [Req][Books] Good Fantasy/SciFi books
Sports
McBoner: A hockey love story 2024 - 2026 Football Thread Formula 1 Discussion
World Cup 2022
Tech Support
streaming software Strange computer issues (software) [G] How to Block Livestream Ads
TL Community
The Automated Ban List
Blogs
How EEG Data Can Predict Gam…
TrAiDoS
ramps on octagon
StaticNine
Funny Nicknames
LUCKY_NOOB
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1469 users

Starcraft: Remastered received Spyware "upgrade"?

Forum Index > BW General
Post a Reply
Mindflayer
Profile Joined December 2015
Germany10 Posts
Last Edited: 2021-04-24 23:38:13
April 24 2021 23:37 GMT
#1
Hello everyone,

so first of all, I would like to clarify that I am by far no expert in this kind of analysis. I just have some basic knowledge about whats going on in an operating system. And all I'm asking for here, is for someone to help me put things into perspective and explain to me what might be going on or what I might have misinterpreted.

What happened?
Lately, while playing Starcraft: Remastered, I recognised some unusually heavy upload activity, originating from my Computer and going towards my wifi router. It can nicely be observed within the wifi workload of the router. Download speed remains as usual.

[image loading]
Taking a look into the network activites using a monitoring tool, I found that in fact the process of Starcraft is responsible for the upload. Using the UDP protocol, it seems to send a lot of data to 37.244.54.234. Alongside with some other IP addresses, which most likely apply to the other players.
A lookup of the, by far most active, IP address unsurprisingly reveals that its a static IP address of Blizzard. (Btw. blocking that IP does not work. Starcraft just switches to another one within the 37.244.54.X range. I don't know how many excalty, but a lot of them seem to belong to Blizzard. And if I block the entire range, I am no longer able to join any games - but surprisingly still able to join Battle.Net and chat.)

The interesting part is, that the upload starts as soon as I join a game Lobby, peaks at the start of a game and starts to lower after some minutes into the game.

[image loading]
Curiosity sparked, I decided to monitor all activities of the Starcraft process for a while. After some time, there was something interesting. Right at the moment when I joined another game lobby, Starcraft.exe read in a lot of files, which it actually should not have any interest in.

The executables of Deamon Tools Lite, HP Scanning Software, WPS Office, Windows System Binaries... and so on.
And like the ones marked in the Screenshot, Starcraft.exe did not only probe the mentioned files; it completely read them in. So I am wondering, what does it do with that data? Is that normal behavior for a game executable?

Not sure about the file reading thing, but the crazy upload behavior started since the last update of Starcraft: Remastered via the Battle.Net Launcher.

Can someone help me understand?
Makaveli1
Profile Blog Joined August 2011
United States118 Posts
April 24 2021 23:50 GMT
#2
If I had to speculate, probably some sort of check to make help against people hacking on ladder. Just speculation.
Garrl
Profile Blog Joined February 2010
Scotland1978 Posts
Last Edited: 2021-04-25 17:44:25
April 25 2021 17:43 GMT
#3
Warden (Blizzard's propriety antihack) has been in BW since the remastered prepatch ((i think?) and is known to scan memory for malicious programs and send them to Blizz servers for comparison.
MeSaber
Profile Joined December 2009
Sweden1235 Posts
April 25 2021 21:20 GMT
#4
How the do you know it started since last patch? Do you analyze this frequently or have a data quota alarm?
-.-
prOxi.swAMi
Profile Blog Joined November 2004
Australia3091 Posts
April 25 2021 23:51 GMT
#5
The UDP connection you're seeing I think is just the game traffic (and the fact it is going to Blizzard is probably just because the connection is being proxied).

There's no good reason why they would do telemetry over UDP, it doesn't make sense. The TCP connections on 443 are much more likely (especially given the hostnames) to be uploading telemetry data.

This isn't Blizzard deploying or running spyware, reading executables on your machine is normal for a game that tries to prevent hacking.

Also, the numbers you're seeing are not what I would call "crazy upload behaviour" at all, not even close. I think you're jumping the gun in a big way here.
Oh no
tec27
Profile Blog Joined June 2004
United States3702 Posts
April 26 2021 00:40 GMT
#6
On April 26 2021 08:51 prOxi.swAMi wrote:
The UDP connection you're seeing I think is just the game traffic (and the fact it is going to Blizzard is probably just because the connection is being proxied).

There's no good reason why they would do telemetry over UDP, it doesn't make sense. The TCP connections on 443 are much more likely (especially given the hostnames) to be uploading telemetry data.

This isn't Blizzard deploying or running spyware, reading executables on your machine is normal for a game that tries to prevent hacking.

Also, the numbers you're seeing are not what I would call "crazy upload behaviour" at all, not even close. I think you're jumping the gun in a big way here.

Pretty much this. If you were on a turn-rate of 24 in a 2 player game and every packet was the maximum it could be without fragmentation (~1500 bytes), one would expect a send speed of 24 * 1500 / 1024 = ~35kbps, and your task manager is showing less than half that, so why exactly is that worrying?

As far as the file reads, I don't believe "Warden" is a thing any more and is not active in SC:R at all, they rely on an off-the-shelf anti-debugger and obfuscation technology now, not active protection. What those look like to me is mostly programs injecting themselves into the StarCraft process and doing initialization.

Certainly, above all else, this was not something that began in the last update. The last update only changed the ladder map pool.
Can you jam with the console cowboys in cyberspace?
Mindflayer
Profile Joined December 2015
Germany10 Posts
Last Edited: 2022-05-27 23:00:31
May 27 2022 22:45 GMT
#7
Hello everyone,

I would like to pick up on this thread once more, in the hopes that someone else might find the information useful which I discovered.

The problem I describe in my first post got way worse. In most games, the Up -and Download speed is quite low. But "sometimes" the Starcraft: Remastered process randomly starts to go apeshit. It happens, I would say, every 5th to 10th game. Almost exclusively in 3v3 or 4v4. It can happen at every point within a running game, but mostly within the first 5 or so minutes. The Starcraft process starts to download with up to 35 KiB/s and also a very high Upload-rate. Always from/to a Blizzard IP.
When it happens, in-game, the game stops immediately and I start to lag. Within the infamous 45 seconds before one can be dropped from a game, it continues maybe 3 or 4 times for a very short moment. After that, the other players cannot kick me, nor can I drop out of the game myself. (No need to mention how often I was called a hacker due to that.)

After a lot of analysis without any clear results, I started to randomly kill other processes once the problem occurred. And that's when I found the cause:
Its the ASUS ROG GameFirst V Utility, running as GameFirst_V.exe! In its description it says: "ROG GameFirst V is an exclusive Asus tool that optimizes network traffic to increase latency and speed in the game." Yeah, well done ASUS...

I didn't even know something like that was running on my PC. Otherwise it would have immediately come under my suspicion. And I still have no idea how a completely different process can manage to cause something like that to a game process like Starcraft.

Since there have been a lot of people whose games this problem has ruined so far, I would like to apologize for the inconveniences, in case one of you happens to read this post.

Have a nice weekend.
3FFA
Profile Blog Joined February 2010
United States3931 Posts
May 29 2022 17:09 GMT
#8
On May 28 2022 07:45 Mindflayer wrote:
Hello everyone,

I would like to pick up on this thread once more, in the hopes that someone else might find the information useful which I discovered.

<sic>

After a lot of analysis without any clear results, I started to randomly kill other processes once the problem occurred. And that's when I found the cause:
Its the ASUS ROG GameFirst V Utility, running as GameFirst_V.exe! In its description it says: "ROG GameFirst V is an exclusive Asus tool that optimizes network traffic to increase latency and speed in the game." Yeah, well done ASUS...

I didn't even know something like that was running on my PC. Otherwise it would have immediately come under my suspicion. And I still have no idea how a completely different process can manage to cause something like that to a game process like Starcraft.

Since there have been a lot of people whose games this problem has ruined so far, I would like to apologize for the inconveniences, in case one of you happens to read this post.

Have a nice weekend.


It's awesome that you returned with your result a whole month later once you found the cause. This makes the thread far more helpful for anyone else that may encounter similar network issues in brood war in the future!

Hopefully this marks the end of any issues you encounter
"As long as it comes from a pure place and from a honest place, you know, you can write whatever you want."
LML
Profile Blog Joined March 2007
Germany1790 Posts
May 30 2022 02:05 GMT
#9
On May 30 2022 02:09 3FFA wrote:
Show nested quote +
On May 28 2022 07:45 Mindflayer wrote:
Hello everyone,

I would like to pick up on this thread once more, in the hopes that someone else might find the information useful which I discovered.

<sic>

After a lot of analysis without any clear results, I started to randomly kill other processes once the problem occurred. And that's when I found the cause:
Its the ASUS ROG GameFirst V Utility, running as GameFirst_V.exe! In its description it says: "ROG GameFirst V is an exclusive Asus tool that optimizes network traffic to increase latency and speed in the game." Yeah, well done ASUS...

I didn't even know something like that was running on my PC. Otherwise it would have immediately come under my suspicion. And I still have no idea how a completely different process can manage to cause something like that to a game process like Starcraft.

Since there have been a lot of people whose games this problem has ruined so far, I would like to apologize for the inconveniences, in case one of you happens to read this post.

Have a nice weekend.


It's awesome that you returned with your result a whole month later once you found the cause. This makes the thread far more helpful for anyone else that may encounter similar network issues in brood war in the future!

Hopefully this marks the end of any issues you encounter


A whole month.. and a whole year, too :D
LML
Please log in or register to reply.
Live Events Refresh
OSC
13:00
King of the Hill #247
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Hui .302
Reynor 245
BRAT_OK 2
StarCraft: Brood War
Calm 4537
Bisu 2392
Sea 2140
EffOrt 736
Horang2 434
Light 342
BeSt 333
Rush 241
Snow 236
Hyuk 201
[ Show more ]
actioN 178
hero 118
Soma 102
Mind 67
Sea.KH 65
Hyun 50
PianO 50
Trikslyr43
Killer 42
Pusan 34
sorry 29
Aegong 29
Backho 29
Rock 25
soO 23
Hm[arnc] 23
Bale 23
Terrorterran 21
Sacsri 16
IntoTheRainbow 14
JulyZerg 13
scan(afreeca) 9
Dota 2
Gorgc5291
qojqva2166
420jenkins343
monkeys_forever281
Counter-Strike
fl0m1460
ceh9429
byalli414
adren_tv160
kRYSTAL_33
Heroes of the Storm
XaKoH 111
Other Games
Grubby2532
FrodaN1325
hiko1268
B2W.Neo1031
Liquid`RaSZi967
Beastyqt802
Livibee133
Mew2King104
QueenE82
RotterdaM80
KnowMe63
Organizations
Other Games
gamesdonequick5206
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
[ Show 15 non-featured ]
StarCraft 2
• StrangeGG 79
• LUISG 34
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• WagamamaTV455
League of Legends
• TFBlade1412
Other Games
• Shiphtur265
Upcoming Events
Replay Cast
7h 29m
Escore
17h 29m
The PondCast
17h 29m
WardiTV Invitational
18h 29m
Zoun vs Ryung
Lambo vs ShoWTimE
Big Brain Bouts
23h 29m
Fjant vs Bly
Serral vs Shameless
OSC
1d 5h
Replay Cast
1d 7h
CranKy Ducklings
1d 17h
RSL Revival
1d 17h
SHIN vs Bunny
ByuN vs Shameless
WardiTV Invitational
1d 18h
Krystianer vs TriGGeR
Cure vs Rogue
[ Show More ]
uThermal 2v2 Circuit
1d 22h
BSL
2 days
Artosis vs TerrOr
spx vs StRyKeR
Replay Cast
2 days
Sparkling Tuna Cup
2 days
RSL Revival
2 days
Cure vs Zoun
Clem vs Lambo
WardiTV Invitational
2 days
BSL
3 days
Dewalt vs DragOn
Aether vs Jimin
GSL
3 days
Afreeca Starleague
3 days
Soma vs Leta
Wardi Open
3 days
Monday Night Weeklies
3 days
OSC
4 days
CranKy Ducklings
4 days
Afreeca Starleague
4 days
Light vs Flash
Replay Cast
5 days
Replay Cast
6 days
The PondCast
6 days
Liquipedia Results

Completed

Proleague 2026-05-05
WardiTV TLMC #16
Nations Cup 2026

Ongoing

BSL Season 22
ASL Season 21
CSL 2026 SPRING (S20)
IPSL Spring 2026
KCM Race Survival 2026 Season 2
Acropolis #4
SCTL 2026 Spring
RSL Revival: Season 5
2026 GSL S1
BLAST Rivals Spring 2026
IEM Rio 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals
ESL Pro League S23 Stage 1&2
PGL Cluj-Napoca 2026

Upcoming

Escore Tournament S2: W6
KK 2v2 League Season 1
BSL 22 Non-Korean Championship
YSL S3
Escore Tournament S2: W7
Escore Tournament S2: W8
CSLAN 4
Kung Fu Cup 2026 Grand Finals
HSC XXIX
uThermal 2v2 2026 Main Event
Maestros of the Game 2
2026 GSL S2
Stake Ranked Episode 3
XSE Pro League 2026
IEM Cologne Major 2026
Stake Ranked Episode 2
CS Asia Championships 2026
IEM Atlanta 2026
Asian Champions League 2026
PGL Astana 2026
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.