What exactly do you expect as proof beyond a dozen hits from different scans?
I've double checked the files, and you are correct that the executable for TF has red flags.
(
Assumption originally made that you downloaded fishy shit)
I do need to point out that this executable is not used to run the game, you must use bin.exe to start.
Henry repacked the game to include NTLEAS, (applocale). This is most likely the reason for the false positives.
I'll go ahead and just report my own comment to get the attention of some mods. If any cyber security gurus want to chime in, your opinion might be better than mine. The executable in question does have some oddities, but again I'm fairly positive this is all related to the locality emulator.
That's TrueFacials.exe,
bin.exe is clean.