General Info

File name

HiPKILocalSignServer_Client.zip

Full analysis
https://app.any.run/tasks/7120e84b-f3b2-4628-ae40-3363425d3166
Verdict
Malicious activity
Analysis date
11/8/2018, 13:43:24
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/zip
File info:
Zip archive data, at least v2.0 to extract
MD5

ac10470a9f1a5d003152ac69d064e56e

SHA1

f975598958a16c3f2a9b6a366925459bbd794f76

SHA256

3a974144e2fc7f71464cba506088a5c09027ccdb9f2a8ae011f229f2055703f2

SSDEEP

98304:w64EXsMN8XlHJ8/UB3UD0lAMkPuHBfLBhcGFp5fsQO/edpL07qCuRLy/1J:VsMNQlH+UUpMkPKBQSfVtLQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • ListInfo.exe (PID: 3732)
  • HiPKISign.exe (PID: 2608)
  • HiPKIDecrypt.exe (PID: 2388)
  • HiPKISign.exe (PID: 996)
  • HiPKIDecrypt.exe (PID: 3424)
  • ListInfo.exe (PID: 2664)
  • CheckServer.exe (PID: 3068)
  • _iu14D2N.tmp (PID: 3092)
  • unins000.exe (PID: 2312)
  • CheckServer.exe (PID: 3552)
  • CheckServer.exe (PID: 3044)
  • CheckServer.exe (PID: 2040)
  • chtnode.exe (PID: 1520)
  • chtnode.exe (PID: 2576)
  • HiPKILocalSignServer_1.3.4_102700.exe (PID: 3672)
Loads dropped or rewritten executable
  • ListInfo.exe (PID: 2664)
  • _iu14D2N.tmp (PID: 3092)
  • regsvr32.exe (PID: 3164)
Changes the autorun value in the registry
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Registers / Runs the DLL via REGSVR32.EXE
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Reads the Windows organization settings
  • _iu14D2N.tmp (PID: 3092)
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Reads Windows owner or organization settings
  • _iu14D2N.tmp (PID: 3092)
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Executable content was dropped or overwritten
  • unins000.exe (PID: 2312)
  • _iu14D2N.tmp (PID: 3092)
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
  • WinRAR.exe (PID: 4072)
  • HiPKILocalSignServer_1.3.4_102700.exe (PID: 3672)
Starts application with an unusual extension
  • unins000.exe (PID: 2312)
Creates files in the user directory
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Creates COM task schedule object
  • regsvr32.exe (PID: 3164)
Reads internet explorer settings
  • iexplore.exe (PID: 3140)
  • iexplore.exe (PID: 2956)
Application launched itself
  • iexplore.exe (PID: 3196)
Creates files in the user directory
  • iexplore.exe (PID: 3196)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2956)
Changes internet zones settings
  • iexplore.exe (PID: 3196)
Loads dropped or rewritten executable
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Creates a software uninstall entry
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)
Application was dropped or rewritten from another process
  • HiPKILocalSignServer_1.3.4_102700.tmp (PID: 2236)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.zip
|   ZIP compressed archive (100%)
EXIF
ZIP
ZipRequiredVersion:
20
ZipBitFlag:
null
ZipCompression:
Deflated
ZipModifyDate:
2016:12:30 10:07:03
ZipCRC:
0xb7d212b7
ZipCompressedSize:
6661633
ZipUncompressedSize:
7012992
ZipFileName:
HiPKILocalSignServer_1.3.4_102700.exe

Screenshots

Processes

Total processes
58
Monitored processes
21
Malicious processes
6
Suspicious processes
3

Behavior graph

+
drop and start start drop and start drop and start drop and start winrar.exe hipkilocalsignserver_1.3.4_102700.exe hipkilocalsignserver_1.3.4_102700.tmp regsvr32.exe no specs checkserver.exe no specs chtnode.exe no specs checkserver.exe no specs checkserver.exe no specs chtnode.exe no specs checkserver.exe no specs unins000.exe _iu14d2n.tmp iexplore.exe iexplore.exe listinfo.exe no specs hipkisign.exe no specs hipkidecrypt.exe no specs iexplore.exe listinfo.exe no specs hipkisign.exe no specs hipkidecrypt.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
4072
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\HiPKILocalSignServer_Client.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\users\admin\appdata\local\temp\rar$exa4072.4666\hipkilocalsignserver_1.3.4_102700.exe

PID
3672
CMD
"C:\Users\admin\AppData\Local\Temp\Rar$EXa4072.4666\HiPKILocalSignServer_1.3.4_102700.exe"
Path
C:\Users\admin\AppData\Local\Temp\Rar$EXa4072.4666\HiPKILocalSignServer_1.3.4_102700.exe
Indicators
Parent process
WinRAR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Chunghwa Telecom Co., Ltd.
Description
跨平台網頁元件 Setup
Version
Modules
Image
c:\users\admin\appdata\local\temp\rar$exa4072.4666\hipkilocalsignserver_1.3.4_102700.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-hb45u.tmp\hipkilocalsignserver_1.3.4_102700.tmp

PID
2236
CMD
"C:\Users\admin\AppData\Local\Temp\is-HB45U.tmp\HiPKILocalSignServer_1.3.4_102700.tmp" /SL5="$50210,6548094,484864,C:\Users\admin\AppData\Local\Temp\Rar$EXa4072.4666\HiPKILocalSignServer_1.3.4_102700.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-HB45U.tmp\HiPKILocalSignServer_1.3.4_102700.tmp
Indicators
Parent process
HiPKILocalSignServer_1.3.4_102700.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-hb45u.tmp\hipkilocalsignserver_1.3.4_102700.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-e2rnp.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\windows\system32\clbcatq.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\users\admin\appdata\local\programs\hipkilocalsignserver\checkserver.exe
c:\users\admin\appdata\local\programs\hipkilocalsignserver\unins000.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\netutils.dll

PID
3164
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\npHttpComponent.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
HiPKILocalSignServer_1.3.4_102700.tmp
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\programs\hipkilocalsignserver\nphttpcomponent.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\nsi.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\psapi.dll

PID
2040
CMD
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe" /start
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe
Indicators
No indicators
Parent process
HiPKILocalSignServer_1.3.4_102700.tmp
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\checkserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\hipkilocalsignserver\chtnode.exe

PID
2576
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\chtnode.exe hipkiLocalServer.js
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\chtnode.exe
Indicators
No indicators
Parent process
CheckServer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Node.js
Description
Node.js: Server-side JavaScript
Version
4.2.1
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\chtnode.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll

PID
3552
CMD
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe" /stop
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\checkserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll

PID
3044
CMD
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe" /start
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\checkserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll

PID
1520
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\chtnode.exe hipkiLocalServer.js
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\chtnode.exe
Indicators
No indicators
Parent process
CheckServer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Node.js
Description
Node.js: Server-side JavaScript
Version
4.2.1
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\chtnode.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\programs\hipkilocalsignserver\listinfo.exe
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hipkisign.exe
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hipkidecrypt.exe

PID
3068
CMD
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe" /debug
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\checkserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll

PID
2312
CMD
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.exe"
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\unins000.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\_iu14d2n.tmp

PID
3092
CMD
"C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.exe" /FIRSTPHASEWND=$801BA
Path
C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
Indicators
Parent process
unins000.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\_iu14d2n.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-ueqjo.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll

PID
3196
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll

PID
2956
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3196 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\jscript.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\msxml3.dll

PID
2664
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer/ListInfo.exe {}
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ListInfo.exe
Indicators
No indicators
Parent process
chtnode.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\listinfo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hicospkcs11.dll
c:\windows\system32\winscard.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wtsapi32.dll

PID
996
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer/HiPKISign.exe "{\"pin\":1234,\"tbs\":\"MTIz\"}"
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKISign.exe
Indicators
No indicators
Parent process
chtnode.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hipkisign.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winscard.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3424
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer/HiPKIDecrypt.exe "{\"pin\":1234,\"cipher\":\"123\"}"
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKIDecrypt.exe
Indicators
No indicators
Parent process
chtnode.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hipkidecrypt.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3140
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3196 CREDAT:14337
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\msxml3.dll

PID
3732
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer/ListInfo.exe {}
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ListInfo.exe
Indicators
No indicators
Parent process
chtnode.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\listinfo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hicospkcs11.dll
c:\windows\system32\winscard.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wtsapi32.dll

PID
2608
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer/HiPKISign.exe "{\"pin\":1234,\"tbs\":\"MTIz\"}"
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKISign.exe
Indicators
No indicators
Parent process
chtnode.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hipkisign.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winscard.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2388
CMD
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer/HiPKIDecrypt.exe "{\"pin\":1234,\"cipher\":\"123\"}"
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKIDecrypt.exe
Indicators
No indicators
Parent process
chtnode.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\programs\hipkilocalsignserver\hipkidecrypt.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
1514
Read events
1278
Write events
232
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
4072
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\HiPKILocalSignServer_Client.zip
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
4072
WinRAR.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2236
HiPKILocalSignServer_1.3.4_102700.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
BC080000A88021BC6077D401
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
784B2E0964B32FF4A0F623A38F9045676CCB4FE3879B59351B9F7F2756A14D06
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\xOUC.exe
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
F27213FEA890B0B33913EC75D8BDAF08744C94B05C20B672C855E7D624BC612F
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
跨平台網頁元件
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe" /start
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
Inno Setup: Setup Version
5.5.7 (u)
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
Inno Setup: App Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
InstallLocation
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
Inno Setup: Icon Group
跨平台網頁元件
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
Inno Setup: User
admin
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
Inno Setup: Language
english
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
DisplayName
跨平台網頁元件 version 1.3.4.102700
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
UninstallString
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.exe"
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
QuietUninstallString
"C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.exe" /SILENT
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
DisplayVersion
1.3.4.102700
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
Publisher
Chunghwa Telecom Co., Ltd.
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
URLInfoAbout
http://repository.publicca.hinet.net/
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
HelpLink
http://repository.publicca.hinet.net/
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
URLUpdateInfo
http://repository.publicca.hinet.net/
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
NoModify
1
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
NoRepair
1
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
InstallDate
20181108
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
MajorVersion
1
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
MinorVersion
3
2236
HiPKILocalSignServer_1.3.4_102700.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC093D9C-5611-413C-BC42-8CD59357D13A}_is1
EstimatedSize
24622
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\AppID\{B415CD14-B45D-4BCA-B552-B06175C38606}
FireBreathWin
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\AppID\npHttpComponent.dll
AppID
{B415CD14-B45D-4BCA-B552-B06175C38606}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CHTTL.HttpComponent.1
Http Component
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CHTTL.HttpComponent.1\CLSID
{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CHTTL.HttpComponent
Http Component
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CHTTL.HttpComponent\CLSID
{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CHTTL.HttpComponent\CurVer
CHTTL.HttpComponent.1
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}
Http Component
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\ProgID
CHTTL.HttpComponent.1
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\VersionIndependentProgID
CHTTL.HttpComponent
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\InprocServer32
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\npHttpComponent.dll
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\InprocServer32
ThreadingModel
Apartment
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}
AppID
{B415CD14-B45D-4BCA-B552-B06175C38606}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\MiscStatus
0
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\MiscStatus\1
131473
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\TypeLib
{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\CLSID\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\Version
1
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-httpcomponent
Http Component
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-httpcomponent
Extension
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-httpcomponent
CLSID
{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}
3164
regsvr32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc351f85-cdfa-5183-8985-da7dbdcd8c8f}\iexplore
Count
1038960
3164
regsvr32.exe
write
HKEY_CURRENT_USER\Software\MozillaPlugins\www.chttl.com.tw/HttpComponent
Path
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\npHttpComponent.dll
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\TypeLib\{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}\1.0
HttpComponent 1.0 Type Library
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\TypeLib\{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}\1.0\FLAGS
0
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\TypeLib\{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}\1.0\0\win32
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\npHttpComponent.dll
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\TypeLib\{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}\1.0\HELPDIR
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{380DE194-90B0-5E94-BC32-4E371760C4C0}
IFBControl
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{380DE194-90B0-5E94-BC32-4E371760C4C0}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{380DE194-90B0-5E94-BC32-4E371760C4C0}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{380DE194-90B0-5E94-BC32-4E371760C4C0}\TypeLib
{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{380DE194-90B0-5E94-BC32-4E371760C4C0}\TypeLib
Version
1.0
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{2DFD48D9-85E1-5439-9655-FC98951621E8}
IFBComJavascriptObject
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{2DFD48D9-85E1-5439-9655-FC98951621E8}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{2DFD48D9-85E1-5439-9655-FC98951621E8}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{2DFD48D9-85E1-5439-9655-FC98951621E8}\TypeLib
{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{2DFD48D9-85E1-5439-9655-FC98951621E8}\TypeLib
Version
1.0
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{B1363E25-8C71-5D4E-ADCA-2A795B6E5FAD}
IFBComEventSource
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{B1363E25-8C71-5D4E-ADCA-2A795B6E5FAD}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{B1363E25-8C71-5D4E-ADCA-2A795B6E5FAD}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{B1363E25-8C71-5D4E-ADCA-2A795B6E5FAD}\TypeLib
{024E6F0E-0417-525F-9ABF-ACA06A2F7D4A}
3164
regsvr32.exe
write
HKEY_CLASSES_ROOT\Interface\{B1363E25-8C71-5D4E-ADCA-2A795B6E5FAD}\TypeLib
Version
1.0
3196
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
3196
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{3BF026F7-E354-11E8-9C83-5254004AAD11}
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E2070B00040008000C002D003800D403
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E2070B00040008000C002D003800D403
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070B00040008000C002D0039004A00
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
13
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070B00040008000C002D0039006900
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
28
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070B00040008000C002D003900A800
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
25
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018110820181109
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018110820181109
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018110820181109
CachePrefix
:2018110820181109:
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018110820181109
CacheLimit
8192
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018110820181109
CacheOptions
11
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018110820181109
CacheRepair
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
7CD9A6FF6077D401
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
DisplayName
Local intranet
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
Description
This zone contains all websites that are on your organization's intranet.
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
Icon
shell32.dll#0018
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1001
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1004
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1200
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1201
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1206
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1207
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1208
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1209
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
120A
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
120B
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1400
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1402
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1405
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1406
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1407
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1408
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1409
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1601
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1604
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1605
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1606
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1607
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1608
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1609
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
160A
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1800
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1802
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1803
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1804
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1809
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1A00
131072
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1A02
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1A03
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1A04
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1A05
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1A06
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1C00
131072
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2000
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2005
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2100
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2101
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2102
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2103
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2104
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2105
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2106
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2200
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2201
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2300
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2301
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2400
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2401
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2402
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2600
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2700
3
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2004
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2007
65536
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2001
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
2107
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
CurrentLevel
66816
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
Flags
219
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
3196
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
WarnOnIntranet
0
2956
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
2956
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018110820181109
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018110820181109
2956
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018110820181109
CachePrefix
:2018110820181109:
2956
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018110820181109
CacheLimit
8192
2956
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018110820181109
CacheOptions
11
2956
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018110820181109
CacheRepair
0
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
ProxyBypass
1
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
IntranetName
1
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
1
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
0
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
4
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E2070B00040008000C002E000A008001
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
13
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
4
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E2070B00040008000C002E000A009F01
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
29
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
4
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E2070B00040008000C002E000A00AF01
3140
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
21

Files activity

Executable files
19
Suspicious files
1
Text files
178
Unknown types
7

Dropped files

PID
Process
Filename
Type
4072
WinRAR.exe
C:\Users\admin\AppData\Local\Temp\Rar$EXa4072.4666\HiPKILocalSignServer_1.3.4_102700.exe
executable
MD5: a21a85bae8d01014d2864ae8031ce9f8
SHA256: ad800d2e729c5e6bfabe45ee2d208ba9c05436d14885fa6fc627944f17b848ff
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ListInfo.exe
executable
MD5: b76ea8b1967e4fdea7acc9eae260cf06
SHA256: 903bde974aae44330f5d55eec76a1c9c8b22b2e0507a6ae1670658160e608854
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKIDecrypt.exe
executable
MD5: 2f02a16243b02902bb55611923bc7ef8
SHA256: 1b06283ad5941223b596a67cfc231e1c0fa2d222cbe0937676aba665c476943e
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKISign.exe
executable
MD5: c0fb336d69a50ee09b6c84064a31570d
SHA256: ce90703dceb112dfb10954b6d0e840b2743b84f15c1d6f3a3352e75b2c3c7649
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\chtnode.exe
executable
MD5: b6643ad90417cecf190c58398518c9c3
SHA256: c22fcbf2f1db7ff3cd71b4c771f277fe8d75caff8689a3be50aeee1a7682820e
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\xOUC.exe
executable
MD5: 791d6ce7be8e6968555ee7e4f4a6a380
SHA256: 3ea2d26d4ee725d9ef883abf2d13cfb28d1ac1706156ee1ac6c35f67bc656e1c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CheckServer.exe
executable
MD5: 3680040582439df86c7f86594bdd8096
SHA256: ba005b7e4dfe46da4af027f5c294eab4c6a3be4c3f0952110b01eb5d42e34843
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.exe
executable
MD5: 41cf72fc9b9afd06025c9b7b268e1a02
SHA256: bc7b0f03635cbd282186320eba16ec5d3bd6c935ef7eeb77f753768babd6739d
2312
unins000.exe
C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
executable
MD5: 41cf72fc9b9afd06025c9b7b268e1a02
SHA256: bc7b0f03635cbd282186320eba16ec5d3bd6c935ef7eeb77f753768babd6739d
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Temp\is-E2RNP.tmp\_isetup\_shfoldr.dll
executable
MD5: 92dc6ef532fbb4a5c3201469a5b5eb63
SHA256: 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKIUpdate.exe
executable
MD5: a337b5e1d852c06864d114a7df16df2c
SHA256: 57af7158a4d6ee09709520e3559ea0917bb95c67583d4b5282dbd3876a754151
3092
_iu14D2N.tmp
C:\Users\admin\AppData\Local\Temp\is-UEQJO.tmp\_isetup\_shfoldr.dll
executable
MD5: 92dc6ef532fbb4a5c3201469a5b5eb63
SHA256: 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKIWriteCert.exe
executable
MD5: b1f2ff870b3122449ee18c4c9db9ecff
SHA256: aaab8cdb7ddfd1cd934e9f738a24506e00d1237d6b4e005332b0c0daab5ba1e0
3672
HiPKILocalSignServer_1.3.4_102700.exe
C:\Users\admin\AppData\Local\Temp\is-HB45U.tmp\HiPKILocalSignServer_1.3.4_102700.tmp
executable
MD5: 5d24df58050074281dccba181709bc1b
SHA256: bacb38d6f5c16a9f8c1b94ddbeec14b2bf955f9b5fb7a768d896f8240731be01
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiCOSPKCS11.dll
executable
MD5: 5aabf70415c9ba792bcc774ea532d998
SHA256: 303114aabacd5f6983ac4c4d98e27e98a4c8081f4f7c95b213d64fa743675062
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\npHttpComponent.dll
executable
MD5: 3afadc2f0a7c9c689ffebea61b985e89
SHA256: be21d2b2bbfeb965a242b1b9041bf70204b49514ccc490f88d26bbcf00c3dbd1
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ICCDFCDLL.dll
executable
MD5: b250791f99a3c28c9169a6ae81a75939
SHA256: cd7486312f073013417bb45b6c91d5170a0afa1b8ff5677bc234c64ea24d7fd6
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ICCDFC_Crsbr.exe
executable
MD5: 7ef48fea1534718b7dfe0e3d23dee4ff
SHA256: c80c93fa62136ada730aaa383e80348e32bd80c9b39e3c951d971340e89e92f2
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\HiPKICSR.exe
executable
MD5: 85f72a88d332476812ea829e1571b4ca
SHA256: a682dde2425b3cce6a0475ea7bf6f1d7930ebb925c3365fa419b2ab44354be85
3068
CheckServer.exe
C:\Users\admin\Desktop\systemstatus.log
text
MD5: 3976d00caf873898d9f308e7881cb231
SHA256: 5052e1475dd0c07f026804b58e43314caa3ffa1fe961f67f32e586ba354b3321
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\unins000.dat
dat
MD5: f1c20c82b8e76263a28d999a8963d105
SHA256: 15a78178a25c67900125c3f392fdec9083c7c33b7ae1e4f86e054a2fbb05fc63
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\進行元件偵錯.lnk
lnk
MD5: b501b42504c35298c8243da4c57e2484
SHA256: 7869b62dc7094f42063481710509aaa7430b1e2dec60e94c3ae2c81ed6ff3ebb
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\解除安裝元件.lnk
lnk
MD5: 095a57abd79385a988bf38e3f11b5270
SHA256: 25a5a30587bde96b54e203d9659b56f442985361c9d79851c847013c156ead81
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\停止元件服務.lnk
lnk
MD5: 6b9d5f5052272128ba498c1009f41ec5
SHA256: 3488858fe6b83e42aa6874c5356c4482bbdaae52828ae3e00f4a58021c432378
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\啟動元件服務.lnk
lnk
MD5: c98479ea8306355fdfb54200250baf4d
SHA256: e319039586077aa8e89db5905e344a9a63dd2eddb920d98a1c44e4f4b70998a8
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\IC卡元件自我檢測.url
text
MD5: 995239ea3f0943c07b8984084118109b
SHA256: 02a80cfb8974934268f154e43ec73b020aaaadcb94bd7d2751ec1475669d25dc
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ReleaseNote.txt
ini
MD5: e1e1add2eb13d0a9843ffd2fbeae4c55
SHA256: 4d12e4420d76957c38099a123b910ebeb7963211b5fc8572243065c603d4b0bb
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-QBT6R.tmp
––
MD5:  ––
SHA256:  ––
1520
chtnode.exe
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\debug.log.2018-11-08
text
MD5: 04ff5e50bcf600a5b418bbb75ff4ca67
SHA256: f981cdab2d4b3abbd944068a93ca8c8b67c49acdac19c6c9d8169b3cd66d3885
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-JKN8R.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\IC卡元件自我檢測.url:favicon
image
MD5: b0a5e5b810efa1fed361541002490b71
SHA256: c6339c725ab7c572eed7383d8a4281ef0ed4f181cfa7bc0ccae1df1cc8b0bc1c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-DBLO3.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\IC卡元件自我檢測.url
text
MD5: 283ef67bf39ac1d3183f5a2a1f60350a
SHA256: e59001bd44edf804de3aae5059657fb3d4e7155d8940c44dc319441c77976e85
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-QE6VC.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].htm
image
MD5: b0a5e5b810efa1fed361541002490b71
SHA256: c6339c725ab7c572eed7383d8a4281ef0ed4f181cfa7bc0ccae1df1cc8b0bc1c
3196
iexplore.exe
C:\Users\admin\AppData\Local\Temp\www3029.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-AVNR9.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CHT.ico
image
MD5: 5fabf3c3f29b570a27e47c0c1511fa40
SHA256: ca60df95e46343aebb15afcce36b21a35a1408111eaadc9d9021d99b87af8bd4
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-GHI2A.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-9BIJC.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\跨平台網頁元件\IC卡元件自我檢測.url\:favicon:$DATA
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-V6G5E.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Local\Temp\www3029.tmp\:favicon:$DATA
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-KE9NG.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\Module_CardManagement.txt
text
MD5: 021aa1f7589d15a77d8d4ddbd7e01dfd
SHA256: 97b36340df15c2bb60cd93c8b5acbe0dc213b6e0e81bc53142ee5c3915400119
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\whiteList.txt
text
MD5: 3cc684b7baeead56ec68bc00dd7fc251
SHA256: f29b8c73c6ade2b76887a607c08b2de63d17897cc631e5876fcc3bd9ab65e91f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-JQEJO.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-QJMT2.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\update.bat
text
MD5: a71caa174ec3b263f14b5bf4842b6720
SHA256: ce62f1a8539033b26d25a85ae5137693abad4ba13897453456cee9ecfa3d3995
3196
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\favicon[1].ico
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\Module_HiPKILocalSignServer.txt
text
MD5: 89fc6d765eb42f2aae767d8bf9ce6461
SHA256: 8eedf8518f6851e8107baabf781b0d08ec36a94a108e1c6791bc26c34088531f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-6S7ED.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-C9THI.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-5GVHN.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\popupForm.htm
html
MD5: 9831129038dd75f571430d4f276a769a
SHA256: 7662fedb449cf8e13002e37190ba74af1f232e206fd8265a51f5f7bf78dad8a4
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\ChtPopupForm.htm
html
MD5: 10d06461025bebbd106c0ee1f0506152
SHA256: af977c32eff31bc15af2c889b2ec1c6edba8f263ed475491b7f4bcde087b825a
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\selfTest.htm
html
MD5: d1a1e63e96544827f53ce132e352cad5
SHA256: dd6b6c55614361c7c6bdd136e0fdd3e6c9b5292a58c98f24217d0e07c894439d
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-8EJ5D.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-SUN71.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-R2647.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018110820181109\index.dat
dat
MD5: 3cb12c110a0b0e4d9f30d0bcce38fdc0
SHA256: e992930007479b963cea90ba42108d221dfcdad38fb937cd9bfda35e2b217e04
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\hipkiFuncs.js
html
MD5: 68e47a4074f381d72215e13fe570ef61
SHA256: 6dce62c28da6c3a4217e6c5ec09a37dbb5cf811c2b97df775f4279ab417e16dd
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\addDomain.htm
html
MD5: 470be65bff635662e9f6c52aa7ce8e59
SHA256: 88e345455a4dfddb3a8717c042e2ac48b22dd6fb47738b6b4ff28fe8e5ef14a4
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\invisible.vbs
text
MD5: c578d9653b22800c3eb6b6a51219bbb8
SHA256: 20a98a7e6e137bb1b9bd5ef6911a479cb8eac925b80d6db4e70b19f62a40cce2
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\hipkilog.js
text
MD5: a295319cd49cdc01d3256cc0d1675caa
SHA256: 2cd66cae2457787066afadd281f73dc32702408252b960c48cee8a11cdcaf54b
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\version.vbs
text
MD5: fd5a6985e3b2cd87ef4292a4b161790c
SHA256: dc3f35b8d87f6337f26eec31f7284a6b0931c5c668b5d0e9d05ca70c945eecac
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-CPGNG.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-2CVT3.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-N3T0K.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-HRSD7.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-N428A.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-HTH6V.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\hipkiLocalServer.js
text
MD5: 2ddbff6325475b22a5570514765a01c6
SHA256: 14370cce5c40182288376f424f7b80ced4ec3cf86c4be35d619a572270398321
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-QCEUV.tmp
––
MD5:  ––
SHA256:  ––
2956
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018110820181109\index.dat
dat
MD5: 97ffdc9d69e6efc8c3c9c317f8de93b4
SHA256: 82c6310027fc8576361ba1f70938d6b85902a22755c433ebd87d898a04953edc
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-175F0.tmp
––
MD5:  ––
SHA256:  ––
2956
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\selfTest[1].htm
html
MD5: d1a1e63e96544827f53ce132e352cad5
SHA256: dd6b6c55614361c7c6bdd136e0fdd3e6c9b5292a58c98f24217d0e07c894439d
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-FJ1E2.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[2].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-J5LKN.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\errorcode.js
text
MD5: 11b6fa1cc53ed3a35692dd46c37a7f3a
SHA256: 586edda0a499afb14790704025ed59d92907d3b1c122c8131f48115b5a963bd8
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\is-UNABT.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\6.png
image
MD5: 2e2fff630683c785d97997a6db8b19af
SHA256: 6e25853fa0d711ebd53d0e35942a8500413edfa6e66c75cf8bd6beade78bb64e
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\9.png
image
MD5: 4f5e65a7f4d7ba1a92f2a9f03574527a
SHA256: 02ca23b2b5079f4728e2f87ede3ed7d63e9f6f324bbd91296f7346f3cb196b33
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\5.png
image
MD5: 63105cf128c197f436e99731c795ec49
SHA256: bdba14a88bf76487f241a242f5b33bb833328f7b67ae8cc97ed70059e96b10dd
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\7.png
image
MD5: 455642265d78cb64ee71faad2abc9ce0
SHA256: ebb9c568a8c98b120ba27666c7e534e7f90f5768990dbdf11b9c2d69c4884254
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\8.png
image
MD5: 7349f7c347844bc8760c36b289502765
SHA256: 7a1d6b9914ba76a0ae8c494f7ce0a273f4b9e4a2dfae3308de297f08e5844b16
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-QCQFP.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-96BA1.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-QDRA4.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-HMSPR.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-4I0N6.tmp
––
MD5:  ––
SHA256:  ––
3196
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\1.png
image
MD5: 65656c3a7bb02b18dff093af46a02037
SHA256: 644910224daa23025d5b6d3b75ba1778a520dbd7aea426377e37b341f366cd79
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\3.png
image
MD5: a256c099b78ec1f3469b7daeced20599
SHA256: 5e055918592fa965599e6072d6cbae7ffa9f608be81510d7f62f71478f2f1abb
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\4.png
image
MD5: 445b3b5adba7bb4151c3fa3aee8c0db7
SHA256: b68c8862571d062932edcd93c76655d7c1a5b0e41ed64e9c3a39c0aaf4ed7554
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\0.png
image
MD5: c8ac9a49dcbc4f9658b7fcc38a9402af
SHA256: 1fe3394036e9056b6bb806053fb68774493599d64fa51129fbf672a4d377fb81
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\2.png
image
MD5: 5926debedc470d640cb9fd4be4cd30d7
SHA256: 8d11a9208c5b0734bc526983bc8122aad27f04515d4bbb818da65ef47a5ee087
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\is-8II0Q.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-J6UHE.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-9O381.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-9F0BD.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-TJ7RD.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\digits\is-GK5DH.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\CMCPopForm.htm
html
MD5: 6815762c973c06ef699ca7078092be01
SHA256: 39a3dfa9f0c9f46702d820416f4e59a7d5be73fdd5bbed3f3d97a9397f4b6a23
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\popupFormCM.htm
html
MD5: 13e08249a8538d0f431b8b03a5f4b534
SHA256: 6c55de79ac5d714c364fd7dd7b6a0a7bbfa4aedbd3ae7777cc7b8d57a78a69cf
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\transport.js
text
MD5: aa8567ece0079a4b1de77ff1830607fc
SHA256: c8dde2e8905152ce411b95b3e238cb4cc9f601bbb4d59f4b4bb2e3223971ada8
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\whiteListCM.txt
text
MD5: 3cc684b7baeead56ec68bc00dd7fc251
SHA256: f29b8c73c6ade2b76887a607c08b2de63d17897cc631e5876fcc3bd9ab65e91f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\CardManagement.js
text
MD5: 0385e26fddcdaf6e0606d7187f0c130d
SHA256: f2d5d2fb2d17bb1014c2067f7e70220cb9fd1f60753ee5b3d6e4a831b19b61ff
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-4NQRG.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\is-UDVRK.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\is-0736O.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\is-MTVPN.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\CardManagement\is-QKEMK.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-test.js
text
MD5: 3ad918aa5f627cc5dbe5697892aeec39
SHA256: dd8a3065198b9205f30ac69f4cb23da7155fcd86658adf5d37d91bf92d3bd0da
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\http-test.js
text
MD5: 737d2f567ece00264a37e301f0b1c340
SHA256: 2ab555148d6f54963ccc54ffdf978f02bccc4829aa31807e89a06335e71fed98
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-stress-test.js
text
MD5: b46997f31be597e0dd642623e9ab833b
SHA256: eb82a27fe2e9f44c98af4968129445b5e020711e7748310b064d6e209090dba2
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\memory-test.js
text
MD5: b8a6990f545c306596625467efbececb
SHA256: 6bd2d15471a6ec206319e6a7e99274c08f95a8a4d58f231b436772f942e98f0c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-tailrolling-test.js
text
MD5: d42b71d826bb5438397b7584789fab10
SHA256: 1b8b0e130b986bf982a7dfb1df65a39cd26f2236d7b090e7d110679f19db6671
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-SBHNN.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-RCDCS.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-HE7T3.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-O3KI4.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-QL9GJ.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-archive-test.js
text
MD5: 177a369193ccc1d8c371d85a2595c649
SHA256: 352891a7adad2a2b41455e9d4e414466145303a84bd81c8b5b3a043aecd4b1af
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-maxfiles-test.js
text
MD5: 047ec3634fc16d0b7f25e6b4cd764a7f
SHA256: c13d909e689208e1ea97d195c70bc835bc6191f00eaf785c70fa261bc6793412
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-maxsize-test.js
text
MD5: 1ccca66894b94045654e573787468c36
SHA256: da994406fb02312a1192f2a30243cf915c6c04abe6931195505b503b310758be
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\file-open-test.js
text
MD5: deaf118c992ecf30b10bba3a5591d502
SHA256: 4b0ed1571d5eda128a973ff5a1dba37289a8ef16152989b69a248bd656c5f9c7
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\daily-rotate-file-test.js
text
MD5: 9d091fafc2b053bf772930159ebfae79
SHA256: 3e15a20bbe2443608a07a4baa241155ff3ea1ef1e728ac854f5109070462dcae
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-62BG8.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-BJN6J.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-QR48E.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-GPILS.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\unhandle-exceptions.js
text
MD5: b3a8dd3b13ce8938216c7828b0f0f132
SHA256: 4cd510d2836b057ad822a7093033e23fe1c2e9d4154bc6ebb38382aa52c4a8b5
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\console-test.js
text
MD5: f12e7099e99cbbc29c973cf0e6a6a5a5
SHA256: adbffecff0dcec0d20f9c3791920864ec886df09ae9a4a68f11821dcc1afc67e
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\stress\http-server.js
text
MD5: ad4f691d26682f9cb26255d1644629b4
SHA256: 280fdf14269ccee68a22b11330c92a92186b0de172a15b2e2356eb7804480a7c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\log-string-exception.js
text
MD5: 7d862e1aaef7aedba89f78935d9575b2
SHA256: 3122e7b5c165e40aa84a8dd4a45255be65ac3772512718785116c6d1e7ed413c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\is-6O3EO.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\is-6GGCD.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\stress\is-FT55O.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-QLQ21.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\transports\is-751GT.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\log-exceptions.js
text
MD5: 45279f95d5b8c2f0ea2b888e0585eabe
SHA256: 5a7951a39d56ac5eabd6afb562bf66b450837ece28c0af7ec119f264a44a5746
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\exit-on-error.js
text
MD5: d147ab3a77b22f03543dbaf16cccf840
SHA256: 9472296d14bd912aa73b8d2be76c644c6122e88651a0a671e4de06276985d8c7
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\default-exceptions.js
text
MD5: 46778942856bea8fedfe99ccf6359706
SHA256: d5301886a59a2af59309abf60bfade952e0aed5ff727bc6a68e8ed1846adec40
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\logs\.gitkeep
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\logs\is-5OS70.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\is-HAMIP.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\is-6PM8M.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\scripts\is-VGPGA.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\logger-test.js
text
MD5: 41f07de7a200767b70052264870acd28
SHA256: 934c922768358d3fa53255e79afd07664be4e598f94b9570bd163e10dc933229
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\logger-levels-test.js
text
MD5: 8ca6a075fd8574c663fabe089e13188b
SHA256: c0f35dc67836f2d3caf8fdff8723d3b6962329c93853570ef4bb738b1a6e80a8
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\winston-test.js
text
MD5: e7de1d20c21d8ea88a63b23d94fc43e9
SHA256: 92b932f0d60bd324b6f0b8fadf97eedb4c352be8b59f7652ebdece0d46fccade
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\.gitkeep
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\fixtures\is-PELEA.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-82LDR.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-15437.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-43H71.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\helpers.js
text
MD5: 9915707fdd3b2f9d55c3bda1a611f369
SHA256: 29842f5739b9c97cf7ec280db3ca920d2cac1bd68502cb3785a0267165a013a4
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\log-rewriter-test.js
text
MD5: 3764d8e677f5edd85ccee6ab28b03195
SHA256: d8837a1532954b9b2741cd2602eaa2833063d683536142b26f5e4d9c8bff4502
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\humanReadableUnhandledException-test.js
text
MD5: 494be950be34633bffbf9217a636a244
SHA256: a76705bf1bab40f6304aa167426903f8ac83ed70755ce734a6f75f63c86023c2
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\log-exception-test.js
text
MD5: cbd27dc51ba50d16fac7a9e05e89263a
SHA256: be58729759cbff4b48bbf143380689dd82b62f1911f2ef48261e50692dfae385
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\log-filter-test.js
text
MD5: 50fb5efbe6d1e1d17d5dd8293de941e0
SHA256: 9e24e2c2855223793620c0650965335c95fe55788ae797e6372b83f734c5bab9
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-9VD7N.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-EJJ5N.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-1JLCI.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-MPULP.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\custom-pretty-print-test.js
text
MD5: a7be05c2ef3753680d8413421fd590be
SHA256: dcb9897b93221dbdb3586287cc4cffc3db8f7716e295c1f8e8cb615e90f1e982
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\custom-timestamp-test.js
text
MD5: 2066b8bb19ceb25682a6d846f9459550
SHA256: deb1d32b83c4e1bf3af5b730bec6b4a58ef68d56975b4c88266c45e66a44a5f0
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\exception-test.js
text
MD5: e326e4c63f09e038583578edd770dee1
SHA256: d2da04763b1da1d50e40710959dae3c5b7608e8f49e976608e34c6b21e062ac9
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\custom-formatter-test.js
text
MD5: 6a1c825dc9ac24122e646895092ae708
SHA256: 4090a323bbc4be75e7f584a5b2c7d90205fbc7aac8fc9b5b7d95ab7befa11685
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\container-test.js
text
MD5: ee32908d799a2363ef447f0906fb1ab3
SHA256: 3edc82adc80886a6511310cdd6b658a5928bb9bcba99d64c70461663b96a288f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-KCPGF.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-OS1P7.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-88C79.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-A56N1.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-MSGQD.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-0H1J1.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\Readme.md
text
MD5: f601e6713e1631f91c7fe5a451f1513a
SHA256: 2bb5ef30e98619a107985f32afda56a2d25de619a3e5b215ecd730348f041cce
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\package.json
text
MD5: bab068940439e16b1a8e88bee2e9f52d
SHA256: 0e083e5a438cbcf9cf2882c0b473cae889e2450284d7e1e859856d507131ac7c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\cli-test.js
text
MD5: 549425be1ca51154a302fd3e1b20ca2d
SHA256: da7e259440acf8e49d8e8619c363eebe0e2769c172c2d62cf1ec2671f8e7a941
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\lib\stack-trace.js
text
MD5: bb1b485663d2df790950d772a3eae736
SHA256: b18bfc219286dbaf79747aa51d5f8f93aeebeea8dd0cd35bb23685f9bb9e3d1f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\test\is-3483G.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\lib\is-1J68C.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\is-F32V4.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\is-870DP.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\lib\pkginfo.js
text
MD5: ecc58633b5294f48781b36690fc187e5
SHA256: 317736f00cf66689ebed2490fcb7e094a25e1e082d3f0ee6ae39996e93a866c0
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\License
text
MD5: 9fbf93f7a763e64c0a30207b5693bf75
SHA256: c5ece09265dbd6335030832335dec72919b9ecfd4db126cb9bb9b8d023970304
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\test\pkginfo-test.js
text
MD5: 6f503bb52b40dd518b6a30d947caa55a
SHA256: b65b5663c9f63aff07e5ee5eaef429b7926e06f11095d17c50cc62a5a8eaeba3
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\.npmignore
text
MD5: 13e138d54eb8818da29c3992edef070a
SHA256: a963eca407ca32675dbaeeff3ab8391db935047656eb64c45308e2d0c2e0df0d
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\Makefile
text
MD5: 041194427eb086c4a43c1185463ccb8f
SHA256: 1198d929eb419c98480f89727e0266e2c643e5bbec336e70046c1333732dc9b9
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\is-E732N.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\lib\is-RN8FG.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\test\is-68KOD.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\is-IVOC8.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\stack-trace\is-FRVP8.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\package.json
text
MD5: 98219f1bc417afcddfbd16cf5eca9b50
SHA256: b1a010dc12223a981f1f482ce1542cf2c718b6e0dbae2632b6e845ffd8c0fbbe
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\subdir\package.json
text
MD5: 116fe592816e07b4d5dacffee71512ce
SHA256: ce8a9f8639b4fb58259514311a493fd5597bc227c34418ab4972b577c92cef1a
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\target-dir.js
text
MD5: 25c69a11dcfeb570088581cfed2dc056
SHA256: d631d6d95b831c4eb9243bb1de7bc6bcfb32783cea7179098264c871118cbc17
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\object-argument.js
text
MD5: 3f9193e23b2cabc79a12aa742f662964
SHA256: 36ee6296e930af2823312d23df629e858148a4764df58db28e5d466a04d779fb
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\single-property.js
text
MD5: cf016b39e426be5210f591582110bb85
SHA256: 7a29b81fae6d1d3b6ad94e18c0bff50d7cb61f070ba13a31ed900108891c1281
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\multiple-properties.js
text
MD5: 6f6509d3dca6464ceef917ea62541588
SHA256: fdb6c93c7718b1b1ccb4a3865d076194b4360e1ca47f50034cb26302a64c3255
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-L21NP.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-654PS.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-P8UJS.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-E5NHH.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\subdir\is-4EHOO.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-1QDFH.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\LICENSE
text
MD5: c018b0f606e174a199be171b05c4b77d
SHA256: 14b7412df81b2589940fca446dee5c9432312dd6a170231e52ad8ff9c24d97dc
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\README.md
text
MD5: 5fb9ea70fd64591998b620e7626b4ddd
SHA256: 3813f7e0117c08021ad6c8c1cdf572e4ba783cb5184131a5111f5af882ba9168
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\docs\pkginfo.html
html
MD5: 064e849483375a1ad26e76e464043c26
SHA256: a6b28e031e80f5a85bd118c6f8dc20408efbb17353b04a0eb0f66aa487da019c
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\all-properties.js
text
MD5: 791302d41c27c4d0d4c06c165a2702f7
SHA256: 314f603b05fbf195af5555309e8b35296754dee9b68ec62e160525164532c5c3
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\array-argument.js
text
MD5: 18dc3c575976c84a3dba665e352933af
SHA256: b7b8861c01a3e59540074b4730cffa6c7c7dc9e875a99eae3f2d19d2035baa21
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\package.json
text
MD5: f9eb755d2afeec05271d487c23317bc9
SHA256: 0f1a0a0abb9b369454d83b5dab8b50e119dc819ba8613279492720780b05be35
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\docs\docco.css
text
MD5: 599cb4ffe281fc1377994c9078e88520
SHA256: a260d1119dfcfe604b1cce69626d9fd50882ad3dc9fdbb618f2777b9a7a52e97
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\docs\is-F85BG.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-3AB9O.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\is-E7B2S.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\is-QLOK8.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\examples\is-09III.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\docs\is-IVQ0V.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\package.json
text
MD5: 450b241a7f3b1a93181298e9604be1e1
SHA256: fe7fe5311a9043461496ecd02fb4dc7965ee037a24223fc4385fa27334138117
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\test.js
text
MD5: 1d3e1284e9e7f826a3bfb2fdc41d7379
SHA256: 8072e7039f80ce3618bd585a38f7c2c626e90ae84501c939dcd84e5fe2d85db3
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\README.md
text
MD5: 03eefa287ef213060cd015086b0c0239
SHA256: 861602c05359d5d5c6fdae15c8f6b9790c52480188722e0a6a84d50981e6067e
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\.npmignore
text
MD5: 5ae411da17e00ce7720908cc528ecdf7
SHA256: c8341c04c8894fbdf28dc14bfdca64122e5c3968e17b94a6dd0b7904fbfdda68
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\is-OS39K.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\pkginfo\is-HQ0D1.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-2B4EM.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-5JAOC.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\isstream.js
text
MD5: e04c90cca8842fbace2f2e5d9d0f9b10
SHA256: c0c3871cd08bc9ea569d1e7ed485201b348f21ee29007eef81f6666b95f22987
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\.npmignore
text
MD5: be81722199ad931863c172cd71d320d4
SHA256: ae9a2868b5090b9e81953b7cd8316b3002e7cd6897320c2aa69ee71fc27be3ae
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\LICENSE.md
text
MD5: 1798150b9d70250c42b55b3530e6af2b
SHA256: a7a5808b700606f042c8c4b00d6291f46472b51614d9f03a309bdd9f3a9585c5
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\test\eyes-test.js
text
MD5: 7e52569d8c8608862e0265bb82859e4e
SHA256: af7bd4d095053d4c6ef75e4c8f48c9ef1f8e94469464b5edc8959e15f89d961f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\.jshintrc
text
MD5: d076f635f903502ebe7d197f593bfa21
SHA256: 013f74283e3cd84de64ebd694f8554a26338ede29e2e26d38d01e196e0e29ab7
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\.travis.yml
text
MD5: 1828ef789b67e8ac58764b0dc9af553e
SHA256: 853129eb75f6ba39a1375ac0662e976e5fa20a71ff8f88700be4a6a37ac1f5da
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-QUHR0.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\test\is-NUJEA.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-IC9HA.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-94O89.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-JBK4P.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-FSFIA.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\isstream\is-CC56N.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\README.md
text
MD5: 580c04c7e9aa231919d613cd6beb3658
SHA256: 45ec5b4d5e79155354e25725a458f66e9fa1a90a00535c31f2aa31a15a277a02
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\LICENSE
text
MD5: f3d830b792e909506145eb84ff52da91
SHA256: e424cbb68485fe465f6e58959da4bf157e5a0e716c02cd8d9a2041a12520fb93
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\lib\eyes.js
text
MD5: 7bf2dc06d52d7bb73216bd0ca7a7c984
SHA256: b80d87954efabbec3ed22a04b3da7eb96fc65bab19bd43cef5519d60ff2bb5c0
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\package.json
text
MD5: 1c1b0af9775caca33aa178fd6afada6b
SHA256: c374cfe0f19e3cfa04c11456a995e50a01a1a65e599fe4313c2ca0860fbe9a4a
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\Makefile
text
MD5: 947cc5ce9232f7322ca3776b930ab452
SHA256: e3c2f8efd58284315ed7d86bbc6793cfc8a66aaed1e85779ed02354d96b9f7b2
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\is-3060R.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\is-VUU1O.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\lib\is-A0U5S.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\is-DS0NF.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\eyes\is-38NIL.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\themes\generic-logging.js
text
MD5: 8ae0394cb9f1165729513b6c35767b27
SHA256: 66246d67bc87ebe9a26e5e912c33c3440cf039c96c3612311785fc8963bc9a34
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\cycle\README.md
text
MD5: 7c6a7b6de0882ece95a524015c0227ca
SHA256: b7422c41571ab85d502dea4527d2b6639d637f802e5502d815b5b5e01c9f7462
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\cycle\cycle.js
text
MD5: 7c29bb5ee6ad3fef5a190bc2d2749949
SHA256: 5407e3072d747732b2a3f3253a5f37a47e44719b7735f7049a42a5449f4a5b02
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\cycle\package.json
text
MD5: 493e73a9c38bf4771cbcb775b6e1c31b
SHA256: 80f4bb9eb597c6d6356b675ec01d77e67d4f7d7905f388d1deacbb06ecb02fdc
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\cycle\is-JBJJ2.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\cycle\is-AD8BQ.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\cycle\is-4QFLI.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\screenshots\colors.png
image
MD5: d1917e77ce9339af60cba6b3ef7e9778
SHA256: 9c9941d663763ea62037eeac2e3cc4e852f9db8459a0bfb9350347c5fb44eff7
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\tests\safe-test.js
text
MD5: 2f1fd52e9f73d856617c3f3088864b35
SHA256: 79453bd270d1c72fe0dd24b2ed198e005e9b0ed1e8d209ff22525ec564407d83
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\tests\basic-test.js
text
MD5: 83049b1d8a43872af1b37baaa5cf581d
SHA256: de5d164d611068dfebe498a138be1415c78a52ec5b2fdb6c2637c6cda9f93ace
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\tests\is-3HTCG.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\themes\is-I71Q4.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\tests\is-AGCFQ.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\screenshots\is-4QQ2A.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\random.js
text
MD5: 215190c55bec091e76d4ab23d2e800f0
SHA256: aebf6ae23ae92fc1e2575001ff4cea7c768af3fb504eb3d0053f970957586584
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\system\supports-colors.js
text
MD5: 3b2eb2b3f23d060b03e22594975e8b65
SHA256: 4c551865776fdeb5b4e9dee8f0f249a8d5b4100582c40abc6add738656eb9e02
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\rainbow.js
text
MD5: ed9f81fd564e13f7f700934d402e1295
SHA256: 476bfaac2c2e1f3c7e297ecf0384a922168aac5f2fe933cd2a5afa4ab661ccef
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\zebra.js
text
MD5: 4c17884a7b48ac35a55cae719706e16e
SHA256: 1dea8484417dce22eb31048431e059a43d0dc3cc23e04e154fcc3fb10c3a784d
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\is-0L9G4.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\is-CIJO5.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\system\is-1I7H9.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\is-HU49U.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\custom\zalgo.js
text
MD5: d2b172db85298279d9f5a0609fbe85f0
SHA256: 6d72b04e797f7e9f6a66edc203f8c592c0d9da460faf51aee4a327262e886aab
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\index.js
text
MD5: b72c7c98080ece5e30752b98f4f9ce20
SHA256: 26ecb1fc1e10d55cbc8130d13dc37fba8f469065ac18a8973c9922adeb058446
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\america.js
text
MD5: c5db7181a898205c5a11d574d2547505
SHA256: 315c3e669ed455f3f925c4893bd2655f79200d7319d5774be8c2e7814f813cd2
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\custom\trap.js
text
MD5: f2ee7bb09ae20fa870de29e5f4005ccc
SHA256: b52098df1395ab322e761958cb0160df2187c800f94bf8770c904224311932a4
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\styles.js
text
MD5: cea3b4a8ea9ddc87024a0b1144f22e89
SHA256: bd3cf0187438efca4bf091703f6a9b5f77b47bcd282c6889be002316ca81be13
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\custom\is-PIONU.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\maps\is-6IJDE.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\is-RCIAA.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\is-5D1OS.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\custom\is-35F1M.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\examples\safe-string.js
text
MD5: 75741ef1a3ae3b2b7a943cee9603864b
SHA256: a331a4bd9552c9e0fec122a7d2f179e32c00fd788918d479b7a1479c53d5fbba
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\extendStringPrototype.js
text
MD5: 00727f39d2ea096fb48dd86cda2f62e1
SHA256: a1474b2e6a24a95479110f6b2406abff84919c2b4a3d12e6e6014e5afd2ee477
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\safe.js
text
MD5: 063c215cd884513a25751997f5114a14
SHA256: 91094fccc6ea2d002306a7981f891a86b9cb2c6424479bd3b0cfa7999e71b4e9
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\examples\normal-usage.js
text
MD5: c0b05aa5df8703a3e6bfbc3850025ef2
SHA256: 3d63520217591c03ec5440936733acb27278e7368a1965d94e96e1b401cdf8e7
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\colors.js
text
MD5: 6d906e159e5462634474ef5f76195159
SHA256: 772aea40881a96bd06be0ce09cc6b1eb12e9d22af2a9db3e387b8d21d6f343ac
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\ReadMe.md
text
MD5: 9b9568bbfa51e074be1034c6ac63509e
SHA256: 2b843e51e5acd4de5641c8a82f18636f2b54d8b8004fcb5c987774c9dcbb4747
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\examples\is-5PU01.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\examples\is-3JP1Q.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\is-QI8P8.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\is-JDIT7.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\lib\is-8BTRC.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\is-5D0V5.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\async\README.md
html
MD5: 6fa441e52d5db9e59ce7ec3294f8ae30
SHA256: 1ed4a189f5edf42902a16b87ee66206ddca1419fa2b72aae91ef056b1d9b1862
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\async\support\sync-package-managers.js
text
MD5: 398f506c2d33d4edd06f576452379ed2
SHA256: a17629e70bccee31624f21a777c3eae71c38ee5602854c4f19dc364f410193c8
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\MIT-LICENSE.txt
text
MD5: 5bc6c72caa0dcc082d24a52a6ae12112
SHA256: 44bb8ad1e40e4f995686b99eb610f118b1a1e936b19678ecfe167fa1d78903b0
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\package.json
text
MD5: 07562fb7bacad36f43b649da45fe0ed6
SHA256: 8baebe46cc2dbd847489d93b6edbff39579e1041275aff9393a09c8df5b8f516
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\.travis.yml
text
MD5: b53f5e50059d5378e6d40284d8db38ee
SHA256: 805aad07a7bc07f1e4ab5da448957344c7959580323cce2a94a5a73d947f52ee
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\async\lib\async.js
text
MD5: 7f2d54b98f1304a5d101eba6306f4d78
SHA256: 8ba1062943c9006b1936d8098a2d0071ea0dda06e6a66329da926510c2e17d1f
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\is-HIM15.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_102700.tmp
C:\Users\admin\AppData\Local\Programs\HiPKILocalSignServer\node_modules\winston\node_modules\colors\is-5CBKJ.tmp
––
MD5:  ––
SHA256:  ––
2236
HiPKILocalSignServer_1.3.4_10