It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
when downloading Starfleet Command on Gog Galaxy
continually berated with popup from Avast!
Infection: Win32:Evo-gen [Susp]
Process: D:\Gamer Clients\GalaxyClient\GalaxyClient.exe

URL:
http://cdn.gog.com/content-system/v1/depots/1429172763/windows/39708869/main.bin?1223fb43868c5f174d699ac95a3ffcf6a00368cfaceda6ffd3c8c9908251d5190c1beb9b3ee45dcdd058bc7c91296e8033438e5c5af2b40c0d7a987f7fd3aa766f62a04cab806879e75580eb422bb7dc0da19dee78aa0e84fd

this happened only when the download got to 99% just before installing was to be initiated.
I just recently purchased this game but do not know if this is a false or true so I put the source URL down, please verify for me, this was purchased only a few days ago!
This question / problem has been solved by qwixterimage
False positive, GoG would never place a virus.

Avast is paranoid shit, anyway. Remove it completely.
avatar
Plokite_Wolf: False positive, GoG would never place a virus.

Avast is paranoid shit, anyway. Remove it completely.
a bit extreme wouldn't you say. I won't remove Avast when I could merely disable it. Also, I am not implying that GOG would put anything on anyone's computer! Merely that some URLs can get hijacked by the best of companies or webmasters. I would send this malware for analysis, but it was blocked, not quarentined, and I am not chancing a pitch and toss and allowing the pass and getting on my PC until I get a few more opinions and maybe one of GOG's site admins' advice., I just recovered from the last infection from a place called "nexus" legit also, competently run site also, as well, but shit happens.
Post edited December 02, 2015 by neosapian
avatar
neosapian: I won't remove Avast when I could merely disable it.
You'll find out that Avast, as well as most other modern antivirus programs, will cripple any attempts to do anything that doesn't involve Microsoft's or the antivirus' developer's programs. I've changed several in the past two years alone. There's a paradoxical occurence with antivirus programs - the more "popular" they are (especially AVG), the more paranoid and inefficient they are, with maybe the exception of Malwarebytes' Anti-Malware.
avatar
neosapian: Merely that some URLs can get hijacked by the best of companies or webmasters.
That would imply that someone managed to hijack GoG's elaborate system and attach malicious code to a file type that has no less than hundreds of megabytes, often dozens of gigabytes.
avatar
neosapian: and I am not chancing a pitch and toss and allowing the pass and getting on my PC until I get a few more opinions and maybe one of GOG's site admins' advice., I just recovered from the last infection from a place called "nexus" legit also, competently run site also, as well, but shit happens.
You can open a support ticket in the GoG Tech Support section, but do not expect any answer different to that it's a false positive.
I have avast, and I added the gog galaxy client directory and the gog install games directory to my exclusion list because the stupid false positives. In avast, you cannot say ignore and keep, which is why I had to add those directories to the exclusion list.
avatar
qwixter: I have avast, and I added the gog galaxy client directory and the gog install games directory to my exclusion list because the stupid false positives. In avast, you cannot say ignore and keep, which is why I had to add those directories to the exclusion list.
Avast does not alarm me of any strange actrvity from GalaxyClient.exe unless I try and install Starfleet Command from the Client.
avatar
neosapian: I won't remove Avast when I could merely disable it.
avatar
Plokite_Wolf: You'll find out that Avast, as well as most other modern antivirus programs, will cripple any attempts to do anything that doesn't involve Microsoft's or the antivirus' developer's programs. I've changed several in the past two years alone. There's a paradoxical occurence with antivirus programs - the more "popular" they are (especially AVG), the more paranoid and inefficient they are, with maybe the exception of Malwarebytes' Anti-Malware.

they are excessively paranoid, Kaspersky even worse like a Den Mother Hen to every user, no AV is perfect, or even close, but sometimes the positives are right.
avatar
neosapian: Merely that some URLs can get hijacked by the best of companies or webmasters.
avatar
Plokite_Wolf: That would imply that someone managed to hijack GoG's elaborate system and attach malicious code to a file type that has no less than hundreds of megabytes, often dozens of gigabytes.

it only seems to affect the startup.exe file(in this case GalaxyClient) I have had other games own start up(seemingly) affected as well. Wing Commander V WC5.exe(or something like that, don't remember the exact name) and caused my ethernet drivers to be crippled after I removed WC5.exe manually with the "delete" command. this is not normal for removing a file, only thing it should have done was cripple the game, not my ethernet. I could not get online had to get my DVD-ROM for the old drivers for my network card to work again.
avatar
neosapian: and I am not chancing a pitch and toss and allowing the pass and getting on my PC until I get a few more opinions and maybe one of GOG's site admins' advice., I just recovered from the last infection from a place called "nexus" legit also, competently run site also, as well, but shit happens.
avatar
Plokite_Wolf: You can open a support ticket in the GoG Tech Support section, but do not expect any answer different to that it's a false positive.
probably, but I am also going to get a second opinion by downloading the game to another PC with another virus scanner, maybe that will tell me another story. If so, I will just remove it from that PC and reinstall it here on my Avast one, but I will open a ticket if McCaffe or ESET says the same. anyhow, which AV do you recommend?
Post edited December 04, 2015 by neosapian
ok
I've decided I'd like this post closed
after doing much research I have found that all of you guys are absolutely correct. Avast [Susp] it is "pointing the finger" at a suspicious looking innocent, so to speak. I don't know about Wing Commander V(another topic I posted elsewhere)
but I do know that Starfleet Command is clean.) thanks anyway and as for the tip about excluding Galaxy.exe I will take that in to consideration, qwixter, and I also appreicate your input, Plokite_Wolf.