Arma 3
Sybowen Apr 23, 2017 @ 7:40am
game have virus?
ever launching game windows defender founds virus ever times

The following error occurred: Error code 0x80508023. The program could not find the malware and other potentially unwanted software on this computer.

Category: Browser Modifier

Description: This program changes various Web browser settings without adequate consent.

Recommended action: Remove this software immediately.

Items:
file:C:\Windows\System32\drivers\{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gw64.sys
file:C:\Windows\System32\drivers\{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}w64.sys
< >
Showing 1-5 of 5 comments
LordCage Apr 27, 2017 @ 2:13pm 
windows defender isn't really that reliable, since its = to norton's security and no, ARMA 3 doesn't have a virus. Strange to see browser modifications occur, but you should be fine.
Sybowen Apr 27, 2017 @ 6:56pm 
i see .thx alot
Wizard Apr 28, 2017 @ 12:30am 
Hello Sybowen,
the files you've mentioned are definitely not part of the game. But given the files names I'd guess that Defender is right and there is a virus (or rather adware in this case) on your PC.
Mirudes Apr 28, 2017 @ 6:36am 
http://www.freefixer.com/library/file/%7Bbb7b7a60-f574-47c2-8a0b-4c56f2da9802%7Dgw64.sys-142369/

What is {bb7b7a60-f574-47c2-8a0b-4c56f2da9802}gw64.sys?

Vendor and version information [?]
Product name StdLib
Company name StdLib
File description StdLib
Internal name StdLib.sys
Original filename StdLib.sys
Legal copyright Copyright © 2013 StdLib
Product version 1.4.4.6
File version 1.4.4.6 built by: WinDDK


Digital signatures
This file has a valid digital signature.
Signer name AdvanceElite
Certificate issuer name VeriSign Class 3 Code Signing 2010 CA
Certificate serial number 4e2e56b75e7e0844e10d5be52cdf0e39


VirusTotal report
1 of the 55 anti-virus programs at VirusTotal detected the {bb7b7a60-f574-47c2-8a0b-4c56f2da9802}gw64.sys file. That's a 2% detection rate.




http://www.freefixer.com/library/file/%7B57f143ae-1ecd-493d-9ddb-32c45a3cecd5%7Dgw64.sys-138670/

What is {57f143ae-1ecd-493d-9ddb-32c45a3cecd5}gw64.sys?

Vendor and version information [?]
Product name StdLib
Company name StdLib
File description StdLib
Internal name StdLib.sys
Original filename StdLib.sys
Legal copyright Copyright © 2013 StdLib
Product version 1.4.3.1
File version 1.4.3.1 built by: WinDDK


Digital signatures
This file has a valid digital signature.
Signer name NetCrawl
Certificate issuer name VeriSign Class 3 Code Signing 2010 CA
Certificate serial number 3c05f8d25eb72cd5b6eb863aa0585f70



VirusTotal report

11 of the 53 anti-virus programs at VirusTotal detected the {57f143ae-1ecd-493d-9ddb-32c45a3cecd5}gw64.sys file. That's a 21% detection rate.





https://www.reasoncoresecurity.com/57f143ae-1ecd-493d-9ddb-32c45a3cecd5gt64.sys-a3d2d4848fa877d100faa5813ae0ca3d54874ab3.aspx

{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}gt64.sys

NetCrawl
Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {57f143ae-1ecd-493d-9ddb-32c45a3cecd5}gt64.sys by NetCrawl has been detected as PUP.NetCrawl. It runs as a Windows 64-bit kernel mode device driver named “{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gt64”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.

https://www.reasoncoresecurity.com/bb7b7a60-f574-47c2-8a0b-4c56f2da9802w64.sys-1d0bf684a8acd395c0551ee1f1a22b48b21a1cb2.aspx

{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}w64.sys

AdvanceElite
Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {bb7b7a60-f574-47c2-8a0b-4c56f2da9802}w64.sys by AdvanceElite has been detected as Adware.Yontoo.AdvanceElite. It runs as a Windows 64-bit kernel mode device driver named “{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}w64”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Sybowen Apr 28, 2017 @ 11:42am 
Originally posted by Wizard:
Hello Sybowen,
the files you've mentioned are definitely not part of the game. But given the files names I'd guess that Defender is right and there is a virus (or rather adware in this case) on your PC.
only launch arma3 with battle eye malware detected without battle eye no problem
< >
Showing 1-5 of 5 comments
Per page: 1530 50

Date Posted: Apr 23, 2017 @ 7:40am
Posts: 5