Since I was suspicious of the source, I had checked the torrent files both using my own scanner and using virustotal.com, but the result was negative. Therefore I am pretty sure the original upload of the restoration patch was free of known malware.
Btw. I think it's bad praxis to add directory exclusions too lightly... if ever a male-ware actually compromises a file within such a directory, the warning will be suppressed... I wonder why no anti-virus program I know of allows to whitelist by exact name and some hash, because all you should want is to white-list this exact file.