How to remove CrashReportClient.exe

CrashReportClient.exe

The module CrashReportClient.exe has been detected as Trojan.Heur!

CrashReportClient.exe

CrashReportClient.exe is a Windows file recorded in the ThreatInfo database. It is associated with CrashReportClient. The reported company name is Epic Games, Inc.. The current detection status is Trojan.Heur!, based on the latest analysis from 2023-12-13 23:18:29 (2 years ago).

If CrashReportClient.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: CrashReportClient
Company Name: Epic Games, Inc.
MD5: bb22f0cf5327a9633f6502527b6d488c
Size: 22 MB
First Published: 2023-12-13 23:18:29 (2 years ago)
Latest Published: 2023-12-13 23:18:29 (2 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2023-12-13 23:18:29 (2 years ago)
Signed By: Embark Studios AB
Status: Valid

The signature on CrashReportClient.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%\steam\steamapps\common\the finals\engine\binaries

ThreatInfo has observed CrashReportClient.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Germany with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for CrashReportClient.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

CrashReportClient.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x00e5b158

PE Sections:

Name Size of data MD5
.text 15259136 0616dbf2d7db3b09659477b62c3e8f24
.uedbg 292352 24fe9146f59b1222a103b360b3e67a95
.rdata 6291456 9cdcf05676c4abf429e22e865d687980
.data 708096 b5577fe072a1e76d36ee56b482450a46
.pdata 741888 771eb7949ea5284a8a79b6e1314295fe
.mbrkcf2 512 bf619eac0cdf3f68d496ea9344137e8b
_RDATA 150528 02df7da9353eccbe140d6a73d0838671
.rsrc 27136 5913f04aa9207eef0b139ae5a102ef44
.reloc 125440 060eea10b6d0ed445a5452a64807a264

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for CrashReportClient.exe