Win32:Malware-gen False Positive?

Hello,
So I decided to mod a game. A popular mod that i wanted was The Rise of the White Wolf:
http://www.nexusmods.com/witcher/mods/669/?. The mod is legit and the comments were all positive. But on downloading it, avast! told me it was infected with win32:malware-gen and locked it in the chest.

After searching on Google, nobody has had this problem with the mod and some people have had infected files turn up to be false positive and completely safe.

What should i do? Should i put it in the exclusion list of scan and install the mod or forget about it?

When searching via that IP we get one alert for this URL hosts a threat identified as: CYSC.BLACKLISTED.GEN.
This URL is or was distributing a malware variant of EXP/GifDropper.D
This URL domain/host was seen to host badware at some point in time
Malware site.
Malicious site.

AntiVir–EXP/GifDropper.D
ClamAV–PHP.Hide
DrWeb–PHP.Shell.41
Fortinet–PHP/Rst.CO!tr.bdr
Norman–Giframe.A
Sophos–Troj/PHPShl-AK

I have been discussing this threat earlier in July this year here: https://forum.avast.com/index.php?topic=151587.0
seems to be a malicious script of some sort, and yes it is harmless as a compressed file.

polonus

@polonus

So its safe for me to have this file in my computer?

Hi franco.cappu,

I assume it is but I asked essexboy, our qualified removal expert to look into it and give us his opinion.
Wait for him to react, but my results seems all clean: https://app.webinspector.com/public/reports/27249226
Only thing that worries me are some spam alerts:
up came for IframeCheck: Suspicious

htxp://ox-d.zam.com/w/1.0/afr?auid=537196355&cb=511758226’
Javascript Check: Suspicious

t> <iframe id=“cb437965f3” name=“cb437965f3” src=“htxp://ox-d.zam.com/w/1.0/afr?auid=537196355&cb=511758226” frameborder=“0” → Outdated Web Server Nginx Found Vulnerabilities on nginx nginx/1.0.15

Spam check: option value=“648” >payday 2 pirates of the caribbean</op…

Side-wide check: Suspicious

rl?q=htxp://www.nexusmods.com/payday2/&sa=u&ei=hpz7vktcd42wsas9iykaaq&ved=0ccqqfjad&usg=af
See for web rep status: https://www.mywot.com/en/scorecard/ox-d.zam.com?utm_source=addon&utm_content=popup
While other say it is OK: Good MMO site to find info about online games.

So let us wait for that second opinion,

polonus

Well let us consider it is OK,

polonus

@polonus

Ok, well thank you for your help.

Hi,
As the file can only be downloaded by users with paid membership, I am unable to analyze the file that you reported. Can you upload it on virustotal.com and post the link to the analysis here?
Thanks!