Chengdu Xi Hui Tech. Co., Ltd.

Publisher Information

Chengdu Xi Hui Tech. Co., Ltd. is a software publisher located in Chengdu, China*. There is one additional code signing certificate issued to this publisher.
Authority:
VeriSign, Inc.

Valid from:
9/28/2012 8:00:00 AM

Valid to:
9/29/2013 7:59:59 AM

Subject:
CN="Chengdu Xi Hui Tech. Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Chengdu Xi Hui Tech. Co., Ltd.", L=Chengdu, S=Chengdu, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
56e79b990345999c83478f2de9dca44f

Status:
Inconclusive detections from multiple engines

Scan engine
Details
Detections

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
25.00%

Bkav FE
HW32.Nonim
25.00%

Trend Micro House Call
Suspicious_GEN.F47V0208
25.00%

Dr.Web
Adware.Plugin.274
25.00%

McAfee Web Gateway
BehavesLike.Win64.Suspicious.qh
25.00%

Jiangmin
AdWare/Vitruvian.j
25.00%

ESET NOD32
Win64/NetFilter.A potentially unsafe (variant)
25.00%

ESET NOD32
Win64/NetFilter.A potentially unsafe application
25.00%

1 / 68      (inconclusive)
tfpf.sys (NetFilter SDK by NetFilterSDK.com)  (684615e4eba611d2fbd6a3be9cc12367)

0 / 68
tfpf.exe  (01c699581fd9fcfbbf9e962d286a16db)

0 / 68
tfpf.sys  (dc726346a653fa95bab7a512e70b80f7)

5 / 68      (inconclusive)
tfpf.sys (NetFilter SDK by NetFilterSDK.com)  (2132fa5938605738f4fd900719b1c0fb)

1 / 68
xfvsnet.sys  (93bbb375d04c21d15db5913882274954)

1 / 68
tfpf.exe  (3573fe09ca09001f05acc40f075e244e)

0 / 68
xfvsnet.sys  (068fe75d721c672c4e2b20e33363d701)

0 / 68
xfvsnetsv.exe  (6f80be15f349251c07cede23c3cca75c)

The following certificate is also signed by Chengdu Xi Hui Tech. Co., Ltd..

64C187953A8C2AB6C880FD32F6CA114B  (Sep 17, 2013 to Oct 18, 2014)

* Note, the details and description above are based on the code signing digital signature issued to Chengdu Xi Hui Tech. Co., Ltd. by VeriSign, Inc. on September 28, 2012 with the serial number '56e79b990345999c83478f2de9dca44f'.