Jump to content

HEUR:Trojan.Win64.Patched.gen


Go to solution Solved by AlexeyK,

Recommended Posts

abu ibrahim
Posted (edited)

hello there 

i removed a game from my PC using revo uninstaller to remove every related file to the game, then i redownloaded the game again and while downloading i got this trojan

 

Spoiler

Event: Object deleted
User:
User type: Initiator
Application name: steam.exe
Application path: C:\Program Files (x86)\Steam
Component: File Anti-Virus
Result description: Deleted
Type: Trojan
Name: HEUR:Trojan.Win64.Patched.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: EpicWebHelper.exe
Object path: D:\SteamLibrary\steamapps\downloading\376210\Engine\Binaries\Win64

 

 

Edited by abu ibrahim
adding tag
abu ibrahim
Posted

any action i need to do?
already cleaned up temp files and did full scan but not sure if this can bypass the protection

AlexeyK
Posted

Is this file still in the antivirus quarantine? If so, can you upload it here and then attach a link in this thread?

abu ibrahim
Posted (edited)
10 minutes ago, AlexeyK said:

Is this file still in the antivirus quarantine? If so, can you upload it here and then attach a link in this thread?

no its not in the same dirctory i think it was temprary while downloading but i went to the game files and it was there with the same name "EpicWebHelper.exe" and its safe

Screenshot 2026-07-08 155254.png

Screenshot 2026-07-08 155542.png

Edited by abu ibrahim
Posted
1 hour ago, harlan4096 said:

Upload also the file to https://www.virustotal.com

 

Let's see what the other av firms say...

the file got detected was in the temporary steam download folder till the game fully downloaded it will install it in in another folder with the game title, so i checked the game file after the install and the anti virus detection there is copy of it with the same name but it shows as clean file, so i think kaspersky removed the threat or something not sure

Screenshot 2026-07-08 155542.png

Screenshot 2026-07-08 224819.png

Screenshot 2026-07-08 225025.png

Posted
7 часов назад, abu ibrahim сказал:

any action i need to do?

No file, no link, no hash. Everything's absolutely unclear. How do we know what to do... Well, just do nothing, your AV is already done everything for you.

Posted
2 minutes ago, AlexeyK said:

No file, no link, no hash. Everything's absolutely unclear. How do we know what to do... Well, just do nothing, your AV is already done everything for you.

idk what to post in public i dont want to post something i shouldn't post 

Posted
Только что, abu ibrahim сказал:

idk what to post in public i dont want to post something i shouldn't post 

Don't even want to post the link to the file scan on VT or TIP? Even the hash? What's so scary about that? Did you at least restored it from quarantine?

We cannot give any answers with such data.

Posted
1 minute ago, AlexeyK said:

Don't even want to post the link to the file scan on VT or TIP? Even the hash? What's so scary about that? Did you at least restored it from quarantine?

We cannot give any answers with such data.

that file is clean but ,
if i disable the AV and restore the detected infected file to send it here or scan it in VR it will run on my pc? if not where i can find it to delete it after scanning bc im not sure if that file will auto run when i start the related game!

7 minutes ago, AlexeyK said:

Don't even want to post the link to the file scan on VT or TIP? Even the hash? What's so scary about that? Did you at least restored it from quarantine?

We cannot give any answers with such data.

that file is clean but ,
if i disable the AV and restore the detected infected file to send it here or scan it in VR it will run on my pc? if not where i can find it to delete it after scanning bc im not sure if that file will auto run when i start the related game!

here the hash
 

Spoiler

Event: Malicious object detected
User:
User type: Initiator
Application name: steam.exe
Application path: C:\Program Files (x86)\Steam
Component: File Anti-Virus
Result description: Detected
Type: Trojan
Name: HEUR:Trojan.Win64.Patched.gen
Precision: Heuristic analysis
Threat level: High
Object type: File
Object name: EpicWebHelper.exe
Object path: D:\SteamLibrary\steamapps\downloading\376210\Engine\Binaries\Win64
MD5 of an object: 9E720BC99EFE8DCE41618F8C13B184A5
Reason: Expert analysis
Databases release date: Today, 7/8/2026 10:21:00 AM

 

Posted (edited)
6 минут назад, abu ibrahim сказал:

it will run on my pc?

Haven't I already answered this question in PM?

6 минут назад, abu ibrahim сказал:

where i can find it to delete it after scanning

In the same folder from which it was deleted. The path is shown in your quarantine screenshot. If the folder doesn't exist, select another one during restoration.

9 минут назад, abu ibrahim сказал:

here the hash

You did not upload this file for analysis on TIP. Without it, we can't say anything about the file or send it to the virlab. I need the file itself, everything is in the PM.

Edited by AlexeyK
Posted
10 minutes ago, AlexeyK said:

Haven't I already answered this question in PM?

In the same folder from which it was deleted. The path is shown in your quarantine screenshot. If the folder doesn't exist, select another one during restoration.

You did not upload this file for analysis on TIP. Without it, we can't say anything about the file or send it to the virlab. I need the file itself, everything is in the PM.

check your pm

  • Solution
Posted

The detection is correct:

Спойлер

Screenshot_12.thumb.png.0b395450c023c90692747bc53165f608.png

  • Like 3

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...