ABitAlarmed: GOG must look into this and explain us what's going on.
Do we remember how CD Projekt Red, the parent company of the store, got hacked? No company is fully safe. Seeing well-known Kaspersky on scans, plus this odd "Restarter.exe" all of a sudden, this is not looking great: The older installers or the newest installer after the current, none has any "Restarter.exe." Could it be there are no changelog because the malicious actor didn't have a high access to influence Steam's changelogs or affect other installers for that matter, only to change gamefiles and this installer's behavior? Who knows? What I do know is better to be safe than sorry.
For now I can only tell to keep the older offline installer on disks if you'd one unless we know more.
More Context
Old Installer: www.virustotal.com/gui/file/00e10df957337e56564cd6c0a36077de931f4530a5cf6baecb740fc924a37f31/behavior
Other old installer: www.virustotal.com/gui/file/8f146774b6d3ff0fa638870a1a3b26ff52d75c50a38b3cb42543f1b0196a56de/behavior
Other new installer: www.virustotal.com/gui/file/8c5e1be9cb8fdd843e0a25082c0717f45aeb0793ef726bd549fae2fa17674768/behavior
Restarter is part of the package, it's in (Installdir)\Binaries\Danielle\x64\Release
(You can see the files in the Steam distribution as well here:
https://steamdb.info/depot/480491/)
The SHA1 hash for Restarter in the previous GoG distribution matches the most recent Steam one and is 53b8193d884455330c49e20504358db0df72b864.
Other hash types are below:
MD5: 5f1f8e3c445c1acdbb7466e4c749bc17
SHA 256: 2bd70a7ca8775d5ed75ead1c9b0897e351abbdbfe026c3fb7da816bbf62dde2e
(Virus Total has one threat for it from MaxSecure "Trojan.Malware.300983.susgen" which is obviously b.s.)
I have not patched my Prey yet mostly due to my Baldur's Gate 3 download which may actually finish today (it stalled out overnight due to some CDN issue.)