CyanideBlayd: I did a bit of digging and here's what I found:
The NeoEE.msi contains a binary called PAYLOAD (.exe):
PAYLOAD (.exe)
SHA256: 19943fe1b6d22d2b585d130da4808ee82485f41b96a76a69ccd3fb2c5847012d
VirusTotal: Detection ratio: 39/68
Digging more into that PAYLOAD exe, it contains more files, one of them being "New Project.res" which is really a 7zip file. There are many files inside this "New Project.res" 7zip file, but the interesting one is authtools.exe.
Authtools.exe seems to be considered bad because it tries to connect to VBOXSVR[dot]ovh[dot]net which is considered a malicious site according to some. See here (bah, I'm not allowed to post links): threatcrowd[dot]org[slash]domain.php?domain=vboxsvr[dot]ovh[dot]net as this site says "Most users have voted this as MALICIOUS"
VirusTotal shows a bunch of .exe with porn filenames (example: WhateverPorn.mpg.exe) that also connect to VBOXSVR.ovh.net.
So as much as I'd like to play Empire Earth online with friends, I can't trust this. If the author can explain why this tool is needed, or better yet, remove it, then I think the anti-virus community might not see this installer as bad.
This is my problem with it. Is anyone on here using this patch without problems?
I found out Rivatuner screws with this one and EE2 if it is closed I get good results.