GOG.com (Good Old Games) Discussion Thread - Online video game storefront known for delivering DRM-free video games.

  • 🔧 Site instability resolved. You can report double-posts and broken attachments. For bigger issues, use the Technical Grievances thread.
    🇵🇦 Nuestro primer dominio localizado está en español en kiwifarms.pa. Our first localized domain is on Spanish on kiwifarms.pa.
  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
mfs i tought that was the real gog that was dying CORTISOL SPIKED DONT DO THAT TO ME

1742873851267539.png
 
Speaking of gog-games it seems "sus" as the zoomers say. A friend has asked me to take a look at this installer that he had:

Has a valid signature from GOG in the details tab without any misspellings and possibly a false positive of "corrupted/suspected" detection, but the behavior tab is showing this:
1781114881539.png
Looks like an obvious malware. I don't know if Virus Total somehow mixed the analysis up with some fake installer, but I advised him to stay away from the site to be safe. He then showed me a few more installer scans told him to do and some were fine, some weren't. All with the same, valid signature. This is very weird.

An example of one that seems fine:
And yes the signature looks weird, but as far as I know it's a legitimate one.
 
Speaking of gog-games it seems "sus" as the zoomers say. A friend has asked me to take a look at this installer that he had:

Has a valid signature from GOG in the details tab without any misspellings and possibly a false positive of "corrupted/suspected" detection, but the behavior tab is showing this:
Ver archivo adjunto 9127938
Looks like an obvious malware. I don't know if Virus Total somehow mixed the analysis up with some fake installer, but I advised him to stay away from the site to be safe. He then showed me a few more installer scans told him to do and some were fine, some weren't. All with the same, valid signature. This is very weird.

An example of one that seems fine:
And yes the signature looks weird, but as far as I know it's a legitimate one.
What's so suspicious about it? Only C:\Program Files\Google1584_1518742326\bin\updater.exe and C:\Windows\System32\UI0Detect.exe don't seem to belong, and these processes run often in the background in Microsoft Sysinternals.
 
What's so suspicious about it? Only C:\Program Files\Google1584_1518742326\bin\updater.exe and C:\Windows\System32\UI0Detect.exe don't seem to belong, and these processes run often in the background in Microsoft Sysinternals.
I noticed lots of weird randomly generated names for folders, exe files and tmp files which didn't match the patterns in 2nd link. The chrome folder was also weird and looked like an impersonator. But it does disappear if I untick sysinternals so it seems legit.

I decided to test another installer which had 0 detections, but the same looking behavior tab. Got a VM and scanned it with ClamAV, then extracted it with innoextract, and scanned again. It was fine.
 
I noticed lots of weird randomly generated names for folders, exe files and tmp files which didn't match the patterns in 2nd link. The chrome folder was also weird and looked like an impersonator. But it does disappear if I untick sysinternals so it seems legit.

I decided to test another installer which had 0 detections, but the same looking behavior tab. Got a VM and scanned it with ClamAV, then extracted it with innoextract, and scanned again. It was fine.
Temp files are randomly named garbage, go into your local/temp folder and you will see that. Here's a scan I got of an installer straight from the real gog website, and it has the same behaviours, gog-games should be safe.
 
Something I found out the hard way: Linux-native versions of GOG games do not have access to any achievements. AT ALL. I finally managed to grab the Mantis Claw in Hollow Knight, and then it occurred to me I never once saw a single achievement pop-up. It could be a Heroic thing, or it could also just be GOG paying lipservice to Linux users like they've been doing for however many years at this point. If I want the achievements, I either have to use the in-game tracker (genuinely excellent stuff) or run the Windows version outright. Meanwhile, I'm 99.99% sure that Steam registers achievements on all Linux versions.
 
Atrás
Top Abajo