xsherlock.xem
XIGNCODE3
Wellbia.com
It runs as a separate (within the context of its own process) windows Service named “xsherlock”.
Publisher:
Wellbia.com Co., Ltd. (signed by Wellbia.com)
Description:
XIGNCODE3 Game Start Service
MD5:
8b692900ad145469c69351e7c9181cc4
SHA-1:
d3107948f8f647c328c483d96a1a63d78eadd20c
SHA-256:
53e7529ab5ac65560ed2ec2231388db5cf0a00c061231886c8c1d7c6479cc7ab
Scanner detections:
1 / 68
Status:
Clean (1 probable false positive detection)
Explanation:
This is mosty likely a false positive detection, the file is probably clean.
Analysis date:
4/26/2024 12:55:48 PM UTC (today)
Scan engine
Detection
Engine version
Quick Heal
(Suspicious) - DNAScan
1.14.12.00
File size:
661 KB (676,880 bytes)
Product version:
3, 1, 0, 0
Copyright:
Copyright (C) 2006-2011 Wellbia.com Co., Ltd.
Original file name:
xsherlock.exe
Common path:
C:\Windows\System32\xsherlock.xem
Valid from:
2/18/2011 8:00:00 AM
Valid to:
2/19/2012 7:59:59 AM
Subject:
CN=Wellbia.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wellbia.com, L=Guro-gu, S=Seoul, C=KR
Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial number:
2EA94BD10C9ABD0B0BE3321BD7C26851