Author Topic: Self Defense false positive - "gdrv64.sys"  (Read 13000 times)

0 Members and 1 Guest are viewing this topic.

Offline Conn0rG

  • Newbie
  • *
  • Posts: 2
Re: Self Defense false positive - "gdrv64.sys"
« Reply #15 on: April 10, 2020, 08:55:10 PM »
I'm also having this issue too.

Cannot seem to find any fix for this so really hoping Avast can get this sorted soon.

Offline HuJohner

  • Newbie
  • *
  • Posts: 2
Re: Self Defense false positive - "gdrv64.sys"
« Reply #16 on: April 11, 2020, 06:33:50 PM »
I had this problem too but since today it seems to have been resolved. Can anyone else confirm?

EDIT: It is back don't know why it didn't happen for a bit.
« Last Edit: April 16, 2020, 12:06:04 PM by HuJohner »

Offline netimagus

  • Newbie
  • *
  • Posts: 4
Re: Self Defense false positive - "gdrv64.sys"
« Reply #17 on: April 12, 2020, 08:13:37 PM »
I had this problem too but since today it seems to have been resolved. Can anyone else confirm?
The problem is still here for me. I forced avast updating to be sure i've the last version. I tried to reinstall Gigabyte App Center utility and i've still messages ang blockage when i launch the utility.

My avast versions are :
- Viral database : 12 april 2020 at 19:32 (ver. 200411-0)
- Antivirus application : 1 april 2020 9:55 (ver 20.2.2401 - version 20.2.5130.568)


Offline Tronmkiheda@seznam.cz

  • Newbie
  • *
  • Posts: 6
Re: Self Defense false positive - "gdrv64.sys"
« Reply #18 on: April 13, 2020, 07:40:17 AM »
Good morning,

same problem here.
The file is essential to run "Gigabyte easy tune" application, that runs on background. It gets shut down during start of the computer and it is not possible to start it manually.
Please, solve it. It is obvious that the same problem will have everybody that runs Gigabyte based system and has this app installed.
Thank you.

Offline RoyC

  • Newbie
  • *
  • Posts: 19
Re: Self Defense false positive - "gdrv64.sys"
« Reply #19 on: April 13, 2020, 08:07:14 AM »
I am having the same problem.

Is there any solution yet?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Self Defense false positive - "gdrv64.sys"
« Reply #20 on: April 13, 2020, 08:54:12 AM »
Hi guys, I forwarded it...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Conn0rG

  • Newbie
  • *
  • Posts: 2
Re: Self Defense false positive - "gdrv64.sys"
« Reply #21 on: April 13, 2020, 12:23:43 PM »
I think for me this started after the product update on 1st April.

I know this probably isn't recommended but I did a System Restore on my PC to the end of March so that it was still running the previous update. I've had no issues since doing this and I'm trying to avoid updating it again until this has been fixed.

Offline Spec8472

  • Avast team
  • Sr. Member
  • *
  • Posts: 297
Re: Self Defense false positive - "gdrv64.sys"
« Reply #22 on: April 14, 2020, 09:15:59 AM »
Hi guys,

this is not a false positive, gdrv.sys/gdrv64.sys of version 5.2.3790.1830 is blocked from load, as it has known vulnerability inside, which is already used to remove security software: https://news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/. Please update Gigabyte software to get fixed gdrv driver, they have fixed version already (with name gdrv2.sys). The name of blocked driver file can be different.

Offline RoyC

  • Newbie
  • *
  • Posts: 19
Re: Self Defense false positive - "gdrv64.sys"
« Reply #23 on: April 14, 2020, 10:52:47 AM »
Thanks for the update.

Unfortunately, I am unable to find any updated version on Gigabyte website, other than the one installed on my PC, and that one still has a problem with this file.

The last version description is as follows:

Quote
APP Center
(Note) Support Intel 300/200/100/X299/C246 series and AMD TRX40/AM4/X399 series motherboards (support may vary by model).
(Note) Please install Microsoft .NET Framework 4.5 first before install APP Center utility.
Version :B19.1021.1
OS : Windows 10 64bit , Windows 7 32bit , Windows 7 64bit
« Last Edit: April 14, 2020, 10:54:22 AM by RoyC »

Offline Spec8472

  • Avast team
  • Sr. Member
  • *
  • Posts: 297
Re: Self Defense false positive - "gdrv64.sys"
« Reply #24 on: April 14, 2020, 11:59:03 AM »
Hi RoyC, can you please attach your GDRV.SYS driver, which is blocked? It should be present in C:\Windows\gdrv.sys. This must be some remnant of a previous installation. I have installed APP center B19.1021.1 and there is no vulnerable driver...

Thanks for the update.

Unfortunately, I am unable to find any updated version on Gigabyte website, other than the one installed on my PC, and that one still has a problem with this file.

The last version description is as follows:

Quote
APP Center
(Note) Support Intel 300/200/100/X299/C246 series and AMD TRX40/AM4/X399 series motherboards (support may vary by model).
(Note) Please install Microsoft .NET Framework 4.5 first before install APP Center utility.
Version :B19.1021.1
OS : Windows 10 64bit , Windows 7 32bit , Windows 7 64bit
« Last Edit: April 14, 2020, 01:46:33 PM by Spec8472 »

Offline Tronmkiheda@seznam.cz

  • Newbie
  • *
  • Posts: 6
Re: Self Defense false positive - "gdrv64.sys"
« Reply #25 on: April 14, 2020, 06:23:52 PM »
OK, I did as suggested, and everything seems to work properly. At least, for now.
But I have to say that I am quite unhappy with your approach. App that is installed on many computers and you simply decide to block it. Nothing else. No information why, no suggested solution, no possibility to keep the app running. Especially when the problem is vulnerability. It is not malware.
This is not what I have been paying for all those years.
Next time inform your users better before you kill their apps, that they use on every day basis.
Thanks

Offline Spec8472

  • Avast team
  • Sr. Member
  • *
  • Posts: 297
Re: Self Defense false positive - "gdrv64.sys"
« Reply #26 on: April 14, 2020, 06:36:19 PM »
Hi Tronmkiheda, thank you for your opinion. Frankly, I didn't expect so many of our users to have such obsolete driver. The certificate used to sign this driver is revoked already, so it shouldn't be loadable at all. But Windows still allow to load this (not on systems with active EFI secure boot).


Offline Scotty33

  • Newbie
  • *
  • Posts: 6
Re: Self Defense false positive - "gdrv64.sys"
« Reply #27 on: April 14, 2020, 08:24:26 PM »
hi Spec8472~

I am running an very old PC mainboard so that there is no way to get any support/patch from GigaByte.
And I do need this tool to monitor my PC healthy information.

Is it possible to release a Avast patch to let user decide to block this gdrv.sys or not?
Since it's vulnerability , I will take the risks.

gdrv.sys version in my PC: 5.00.2195.1620

Thanks.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48564
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Self Defense false positive - "gdrv64.sys"
« Reply #28 on: April 14, 2020, 08:38:43 PM »
hi Spec8472~

I am running an very old PC mainboard so that there is no way to get any support/patch from GigaByte.
And I do need this tool to monitor my PC healthy information.

Is it possible to release a Avast patch to let user decide to block this gdrv.sys or not?
Since it's vulnerability , I will take the risks.

gdrv.sys version in my PC: 5.00.2195.1620

Thanks.
It seems a bit strange to possibly compromise your system to allow something to monitor it's health?
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Scotty33

  • Newbie
  • *
  • Posts: 6
Re: Self Defense false positive - "gdrv64.sys"
« Reply #29 on: April 14, 2020, 08:44:40 PM »
hi Spec8472~

I am running an very old PC mainboard so that there is no way to get any support/patch from GigaByte.
And I do need this tool to monitor my PC healthy information.

Is it possible to release a Avast patch to let user decide to block this gdrv.sys or not?
Since it's vulnerability , I will take the risks.

gdrv.sys version in my PC: 5.00.2195.1620

Thanks.
It seems a bit strange to possibly compromise your system to allow something to monitor it's health?

well~

GigaByte provide a tiny tool called [EasyTune] , to monitor the CPU temperature or setup the CPU fan speed.
And this tool need gdrv.sys......

F.Y.I.