Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Gwyddion-2.67.win64.exe

Overview

General Information

Sample name:Gwyddion-2.67.win64.exe
Analysis ID:1559725
MD5:05c65dd3bf712228edad0dee5aaccc78
SHA1:7d1ca96f10c3cf1e18cfa5a7459f9e892ad0db9c
SHA256:4cea4b3b1ff1979e01f7da89802d4b864b29d05cb75b05690b180a1a008b946c
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Contains functionality for read data from the clipboard
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64
  • Gwyddion-2.67.win64.exe (PID: 7528 cmdline: "C:\Users\user\Desktop\Gwyddion-2.67.win64.exe" MD5: 05C65DD3BF712228EDAD0DEE5AACCC78)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: Gwyddion-2.67.win64.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeWindow detected: I &AgreeCancelNullsoft Install System v3.08 Nullsoft Install System v3.08License AgreementPlease review the license terms before installing Gwyddion.Press Page Down to see the rest of the agreement.Gwyddion is Free Software published under the GNU General Public License version 2 (or later) that can be found as COPYING-GPLv2.txt in the installation directory.This package contains also other components covered by various Free Software licenses: ATK Cairo dlfcn-win32 gettext GLib GTK+ GtkGLExt iconv Pango pthreads-win32 pygtk2 and pygobject2 (COPYING-LGPLv2.txt) D-BUS FFTW and freetype (COPYING-GPLv2.txt) gtksourceview (COPYING-LGPLv2.txt and COPYING-GPLv2.txt) pycairo (COPYING-LGPLv2.txt and COPYING-MPL-1.1.txt) expat (COPYING-expat.txt) fontconfig (COPYING-fontconfig.txt) jansson (LICENSE-jansson.txt) JasPer (LICENSE-JasPer.txt) harfbuzz (COPYING-harfbuzz.txt) HDF5 (LICENSE-HDF5.txt) libaec (Copyright-libaec.txt) libffi (LICENSE-libffi.txt) libjpeg (COPYING-libjpeg.txt) libpng (COPYING-libpng.txt) libtiff (Copyright-libtiff.txt) libwebp (COPYING-libwebp.txt) libxml2 (Copyright-libxml2.txt) OpenEXR (LICENSE-OpenEXR.txt) PCRE (LICENSE-pcre.txt) libzip (LICENSE-libzip.txt) zlib (COPYING-zlib.txt) and libbz2 (LICENSE-bzip2.txt). These components were repackaged unmodified from the Fedora MinGW32/MinGW64 cross-compilation environment.If you accept the terms of the agreement click I Agree to continue. You must accept the agreement to install Gwyddion.
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-expat.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-fontconfig.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-GPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-harfbuzz.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-LGPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libjpeg.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libwebp.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-MPL-1.1.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-zlib.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libaec.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libtiff.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libxml2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\binJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-list.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdbus.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gsettings.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\iconv.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libaec.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libdl.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjansson.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libsz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\zlib1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etcJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\gtk.immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\im-multipress.confJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\libJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders.cacheJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loadersJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\enginesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmapJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\fileJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\surffile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\scnxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graphJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layerJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\processJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\toolJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volumeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyzJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\shareJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterialsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Alien-AlloyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BrassJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Bright-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ChromeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Coolish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\EmeraldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\JadeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ObsidianJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PearlJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PewterJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\RubyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\SilverJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\TurquoiseJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Warmish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradientsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BodyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\CaribbeanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Code-VJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ColdJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DFitJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DigitalisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gray-invertedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-Stripes-4Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gwyddion.netJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\HalcyonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\LinesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MapleJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MetroProJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NT-MDTJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NeonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\OliveJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PainbowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PinkJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PlumJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Pm3dJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-Stripes-5Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RustJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Saw1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ShameJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SkyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Sm2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Spectral-whiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpringJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ViridisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WarmJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-monoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-spectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WykoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ZonesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmapsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_3d_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_arithmetic-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_binning-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_bold-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cantilever-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_adaptive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_auto-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_fixed-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_full-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correct_affine-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_length-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cross_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_curvature-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_data_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_deconvolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_disconnected-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_displacement_field-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance_transform-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_angle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_dwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_enforce_distribution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_entropy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extend-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extract_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_analysis-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_1d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_find_peaks-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fit_shape-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fix_zero-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_diagonally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_correction-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_frequency_split-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_bounding_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_correlation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_exscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_otsu-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_water-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_align-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_cut-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_dos-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_ascii-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_png-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_vector-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_fd-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_function-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_halfgauss-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_palette-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_pointer-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_ruler-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_period_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_fit-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_in-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_out-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hough-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_clear-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_replace-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_immerse-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_iso_roughness-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_image_relation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_italic-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_less-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_flatten_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_median-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_triangle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_light_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_limit_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_line_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_debug-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_info-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_warning-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_local_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_outliers-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_with-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_add-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_distribute-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_editor-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_extract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_grow-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_intersect-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_morph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_noisify-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_set-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shrink-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_subtract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_thin-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_measure_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_merge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_convert_to_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_current_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_find_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_parallel-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_perpendicular-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_more-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mutual_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_apply-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_train-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_next-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_null_offsets-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_path_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_perspective_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pointer_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_poly_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_previous-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile_multiple-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pygwy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rasterize-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_radial_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rank_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_remove_under_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_arc-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_sphere-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_180-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_3d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_ccw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_cw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scientific_number_format-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_selections-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_shader-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spectrum-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spot_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_square_samples-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stat_quantities-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stitch-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_straighten_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_subscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_superscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_anneal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_ballistic_deposition-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_brownian_motion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_columnar-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_diffusion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_discs-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_domains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_dunes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_fibres-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_line_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_objects-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_particles-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_phases-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pileup-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_plateaus-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_spectral-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_turing_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_waves-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tilt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_dilation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_erosion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_estimation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_indent_analyze-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_lateral_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_map-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_model-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_pid-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_translate_periodically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_unrotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_value_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: Gwyddion-2.67.win64.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405D74
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_0040699E FindFirstFileW,FindClose,0_2_0040699E
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_0040290B FindFirstFileW,0_2_0040290B
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmp, atk10.mo6.0.drString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=atk&keywords=I18N
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18N
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&component=general
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&keywords=I18N
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmp, Gwyddion-2.67.win64.exe, 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=gtksourceview&component=general
Source: nsnA40A.tmp.0.drString found in binary or memory: http://bugzilla.gnome.org/show_bug.cgi?id=%s
Source: nsnA40A.tmp.0.drString found in binary or memory: http://bugzilla.gnome.org/show_bug.cgi?id=%sg_type_is_a
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/lib/built-in-funcs.html)
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/lib/typesseq-strings.html
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/ref/strings.html
Source: nsnA40A.tmp.0.drString found in binary or memory: http://freedesktop.org
Source: nsnA40A.tmp.0.drString found in binary or memory: http://freedesktop.orgtypenameexeccounttimestamp
Source: nsnA40A.tmp.0.drString found in binary or memory: http://gwyddion.net/
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2947824135.0000000000488000.00000004.00000020.00020000.00000000.sdmp, nsnA40A.tmp.0.drString found in binary or memory: http://gwyddion.net/.gwyGwyddion.NativeDataGwyddion
Source: nsnA40A.tmp.0.drString found in binary or memory: http://gwyddion.net/Report
Source: nsnA40A.tmp.0.drString found in binary or memory: http://icon-theme.freedesktop.org/releases
Source: nsnA40A.tmp.0.drString found in binary or memory: http://library.gnome.org/devel/gtk-faq/stable/
Source: Gwyddion-2.67.win64.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://relaxng.org/ns/compatibility/annotations/1.0
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmp, language2.rng.0.drString found in binary or memory: http://relaxng.org/ns/structure/1.0
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.brynosaurus.com/cachedir/
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.cmi.cz/
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.cmi.cz/Credits%s
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/dbus/1.0/introspect.dtd
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarks
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksgroupapplicationsgroupsprivateiconmime-typehtt
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/shared-mime-info
Source: nsnA40A.tmp.0.drString found in binary or memory: http://www.mozilla.org/MPL/
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.gnome.org/enter_bug.cgi?product=gdk-pixbuf&keywords=I18N
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18N
Source: nsnA40A.tmp.0.drString found in binary or memory: https://cairographics.org)
Source: nsnA40A.tmp.0.drString found in binary or memory: https://cairographics.org))
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/iobataya/gwyddion-ja-translation
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gitlab.gnome.org/GNOME/gdk-pixbuf/issues
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gnu.org/licenses/gpl.html
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://translationproject.org/team/pt_BR.html
Source: nsnA40A.tmp.0.drString found in binary or memory: https://www.gnu.org/licenses/
Source: nsnA40A.tmp.0.drString found in binary or memory: https://www.gnu.org/licenses/gpl-2.0.html
Source: nsnA40A.tmp.0.drString found in binary or memory: https://www.gnu.org/licenses/gpl-2.0.htmlLicenseGtkGLExt
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/peps/pep-0263.html
Source: Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/peps/pep-0263.html.
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00405809 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_00405809
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,0_2_00403640
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00406D5F0_2_00406D5F
Source: libasprintf-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: zonfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpixmap.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgthread-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: process.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libhdf5_hl-100.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: spmxfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libffi-6.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libjpeg-62.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: sensofarx.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: xyz.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: npyfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgobject-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgwyprocess2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-thai.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpixbufloader-xpm.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgwyddion2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgwydgets2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgwydraw2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libintl-8.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: apedaxfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: nanoscantech.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpixbufloader-jasper.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libstdc++-6.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpangoft2-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: nanoobserver.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libjansson.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libatk-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libpixbufloader-xbm.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: im-ti-et.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: matfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libdl.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: opengps.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: rhk-sm4.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: volume.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libcairo-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libwimp.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: jpkscan.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: createc.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgail.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgdkglext-win32-1.0-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgtkglext-win32-1.0-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libjasper-4.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpcre-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: pixmap.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libfreetype-6.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgwymodule2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-ti-er.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: graph.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libfftw3-3.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: im-inuktitut.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: surffile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-cyrillic-translit.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: cmap.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-cedilla.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libfontconfig-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: hdrimage.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpng16-16.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gspawn-win64-helper.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: hdf5file.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: plugin-proxy.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: keyence.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libhdf5-103.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libssp-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgmodule-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gdbus.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: libpixman-1-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libcairo-script-interpreter-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libexpat-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: imgexport.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-multipress.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: iconv.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: tools.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-ime.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgcc_s_seh-1.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libbz2-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gwyddion.exe.0.drStatic PE information: Number of sections : 17 > 10
Source: libpixbufloader-tga.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpango-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgtk-win32-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: psppt.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libglib-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: Number of sections : 17 > 10
Source: im-ipa.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgtksourceview-2.0-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gdk-pixbuf-query-loaders.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: layer.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgwyapp2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgomp-1.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libaec.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libharfbuzz-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgailutil-18.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: nrrdfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgio-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: anasys_xml.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: file.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgdk_pixbuf-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgdk-win32-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gsettings.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: libpixbufloader-qtif.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libcairo-gobject-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: oirfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: scnxfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-am-et.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpangowin32-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gspawn-win64-helper-console.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: spml.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-viqr.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpixbufloader-pnm.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpangocairo-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: Gwyddion-2.67.win64.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engineClassification label: clean3.winEXE@1/618@0/0
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,0_2_00403640
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00404AB5 GetDlgItem,SetWindowTextW,SHAutoComplete,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceExW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_00404AB5
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_004021AA CoCreateInstance,0_2_004021AA
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Users\user\AppData\Local\Temp\nssA38C.tmpJump to behavior
Source: Gwyddion-2.67.win64.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile read: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeAutomated click: I Agree
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeAutomated click: Next >
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeAutomated click: Install
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeWindow detected: I &AgreeCancelNullsoft Install System v3.08 Nullsoft Install System v3.08License AgreementPlease review the license terms before installing Gwyddion.Press Page Down to see the rest of the agreement.Gwyddion is Free Software published under the GNU General Public License version 2 (or later) that can be found as COPYING-GPLv2.txt in the installation directory.This package contains also other components covered by various Free Software licenses: ATK Cairo dlfcn-win32 gettext GLib GTK+ GtkGLExt iconv Pango pthreads-win32 pygtk2 and pygobject2 (COPYING-LGPLv2.txt) D-BUS FFTW and freetype (COPYING-GPLv2.txt) gtksourceview (COPYING-LGPLv2.txt and COPYING-GPLv2.txt) pycairo (COPYING-LGPLv2.txt and COPYING-MPL-1.1.txt) expat (COPYING-expat.txt) fontconfig (COPYING-fontconfig.txt) jansson (LICENSE-jansson.txt) JasPer (LICENSE-JasPer.txt) harfbuzz (COPYING-harfbuzz.txt) HDF5 (LICENSE-HDF5.txt) libaec (Copyright-libaec.txt) libffi (LICENSE-libffi.txt) libjpeg (COPYING-libjpeg.txt) libpng (COPYING-libpng.txt) libtiff (Copyright-libtiff.txt) libwebp (COPYING-libwebp.txt) libxml2 (Copyright-libxml2.txt) OpenEXR (LICENSE-OpenEXR.txt) PCRE (LICENSE-pcre.txt) libzip (LICENSE-libzip.txt) zlib (COPYING-zlib.txt) and libbz2 (LICENSE-bzip2.txt). These components were repackaged unmodified from the Fedora MinGW32/MinGW64 cross-compilation environment.If you accept the terms of the agreement click I Agree to continue. You must accept the agreement to install Gwyddion.
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeWindow detected: Number of UI elements: 14
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-expat.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-fontconfig.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-GPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-harfbuzz.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-LGPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libjpeg.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libwebp.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-MPL-1.1.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-zlib.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libaec.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libtiff.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libxml2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\binJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-list.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdbus.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gsettings.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\iconv.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libaec.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libdl.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjansson.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libsz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\zlib1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etcJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\gtk.immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\im-multipress.confJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\libJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders.cacheJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loadersJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\enginesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmapJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\fileJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\surffile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\scnxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graphJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layerJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\processJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\toolJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volumeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyzJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\shareJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterialsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Alien-AlloyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BrassJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Bright-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ChromeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Coolish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\EmeraldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\JadeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ObsidianJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PearlJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PewterJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\RubyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\SilverJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\TurquoiseJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Warmish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradientsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BodyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\CaribbeanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Code-VJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ColdJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DFitJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DigitalisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gray-invertedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-Stripes-4Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gwyddion.netJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\HalcyonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\LinesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MapleJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MetroProJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NT-MDTJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NeonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\OliveJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PainbowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PinkJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PlumJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Pm3dJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-Stripes-5Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RustJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Saw1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ShameJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SkyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Sm2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Spectral-whiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpringJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ViridisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WarmJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-monoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-spectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WykoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ZonesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmapsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_3d_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_arithmetic-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_binning-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_bold-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cantilever-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_adaptive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_auto-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_fixed-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_full-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correct_affine-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_length-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cross_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_curvature-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_data_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_deconvolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_disconnected-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_displacement_field-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance_transform-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_angle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_dwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_enforce_distribution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_entropy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extend-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extract_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_analysis-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_1d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_find_peaks-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fit_shape-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fix_zero-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_diagonally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_correction-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_frequency_split-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_bounding_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_correlation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_exscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_otsu-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_water-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_align-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_cut-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_dos-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_ascii-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_png-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_vector-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_fd-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_function-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_halfgauss-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_palette-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_pointer-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_ruler-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_period_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_fit-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_in-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_out-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hough-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_clear-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_replace-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_immerse-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_iso_roughness-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_image_relation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_italic-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_less-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_flatten_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_median-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_triangle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_light_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_limit_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_line_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_debug-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_info-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_warning-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_local_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_outliers-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_with-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_add-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_distribute-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_editor-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_extract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_grow-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_intersect-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_morph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_noisify-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_set-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shrink-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_subtract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_thin-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_measure_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_merge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_convert_to_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_current_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_find_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_parallel-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_perpendicular-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_more-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mutual_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_apply-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_train-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_next-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_null_offsets-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_path_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_perspective_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pointer_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_poly_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_previous-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile_multiple-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pygwy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rasterize-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_radial_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rank_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_remove_under_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_arc-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_sphere-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_180-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_3d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_ccw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_cw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scientific_number_format-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_selections-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_shader-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spectrum-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spot_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_square_samples-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stat_quantities-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stitch-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_straighten_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_subscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_superscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_anneal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_ballistic_deposition-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_brownian_motion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_columnar-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_diffusion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_discs-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_domains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_dunes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_fibres-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_line_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_objects-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_particles-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_phases-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pileup-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_plateaus-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_spectral-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_turing_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_waves-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tilt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_dilation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_erosion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_estimation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_indent_analyze-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_lateral_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_map-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_model-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_pid-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_translate_periodically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_unrotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_value_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GwyddionJump to behavior
Source: Gwyddion-2.67.win64.exeStatic file information: File size 25684878 > 1048576
Source: Gwyddion-2.67.win64.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: libjpeg-62.dll.0.drStatic PE information: real checksum: 0xeda30b00 should be: 0xba3ed
Source: libjasper-4.dll.0.drStatic PE information: real checksum: 0xcf720500 should be: 0x572cf
Source: uninstall.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x19962
Source: nsDialogs.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x2f9b
Source: libpixbufloader-jasper.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-jasper.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-pnm.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-pnm.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-qtif.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-qtif.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-tga.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-tga.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-xbm.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-xbm.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-xpm.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-xpm.dll.0.drStatic PE information: section name: /4
Source: libpixmap.dll.0.drStatic PE information: section name: .xdata
Source: libpixmap.dll.0.drStatic PE information: section name: /4
Source: libwimp.dll.0.drStatic PE information: section name: .xdata
Source: libwimp.dll.0.drStatic PE information: section name: /4
Source: im-am-et.dll.0.drStatic PE information: section name: .xdata
Source: im-am-et.dll.0.drStatic PE information: section name: /4
Source: im-cedilla.dll.0.drStatic PE information: section name: .xdata
Source: im-cedilla.dll.0.drStatic PE information: section name: /4
Source: im-cyrillic-translit.dll.0.drStatic PE information: section name: .xdata
Source: im-cyrillic-translit.dll.0.drStatic PE information: section name: /4
Source: im-ime.dll.0.drStatic PE information: section name: .xdata
Source: im-ime.dll.0.drStatic PE information: section name: /4
Source: im-inuktitut.dll.0.drStatic PE information: section name: .xdata
Source: im-inuktitut.dll.0.drStatic PE information: section name: /4
Source: im-ipa.dll.0.drStatic PE information: section name: .xdata
Source: im-ipa.dll.0.drStatic PE information: section name: /4
Source: im-multipress.dll.0.drStatic PE information: section name: .xdata
Source: im-multipress.dll.0.drStatic PE information: section name: /4
Source: im-thai.dll.0.drStatic PE information: section name: .xdata
Source: im-thai.dll.0.drStatic PE information: section name: /4
Source: im-ti-er.dll.0.drStatic PE information: section name: .xdata
Source: im-ti-er.dll.0.drStatic PE information: section name: /4
Source: im-ti-et.dll.0.drStatic PE information: section name: .xdata
Source: im-ti-et.dll.0.drStatic PE information: section name: /4
Source: im-viqr.dll.0.drStatic PE information: section name: .xdata
Source: im-viqr.dll.0.drStatic PE information: section name: /4
Source: libgail.dll.0.drStatic PE information: section name: .xdata
Source: libgail.dll.0.drStatic PE information: section name: /4
Source: plugin-proxy.dll.0.drStatic PE information: section name: .xdata
Source: plugin-proxy.dll.0.drStatic PE information: section name: /4
Source: plugin-proxy.dll.0.drStatic PE information: section name: /19
Source: plugin-proxy.dll.0.drStatic PE information: section name: /31
Source: plugin-proxy.dll.0.drStatic PE information: section name: /45
Source: plugin-proxy.dll.0.drStatic PE information: section name: /57
Source: plugin-proxy.dll.0.drStatic PE information: section name: /70
Source: plugin-proxy.dll.0.drStatic PE information: section name: /81
Source: plugin-proxy.dll.0.drStatic PE information: section name: /92
Source: cmap.dll.0.drStatic PE information: section name: .xdata
Source: cmap.dll.0.drStatic PE information: section name: /4
Source: cmap.dll.0.drStatic PE information: section name: /19
Source: cmap.dll.0.drStatic PE information: section name: /31
Source: cmap.dll.0.drStatic PE information: section name: /45
Source: cmap.dll.0.drStatic PE information: section name: /57
Source: cmap.dll.0.drStatic PE information: section name: /70
Source: cmap.dll.0.drStatic PE information: section name: /81
Source: cmap.dll.0.drStatic PE information: section name: /92
Source: hdf5file.dll.0.drStatic PE information: section name: .xdata
Source: hdf5file.dll.0.drStatic PE information: section name: /4
Source: hdf5file.dll.0.drStatic PE information: section name: /19
Source: hdf5file.dll.0.drStatic PE information: section name: /31
Source: hdf5file.dll.0.drStatic PE information: section name: /45
Source: hdf5file.dll.0.drStatic PE information: section name: /57
Source: hdf5file.dll.0.drStatic PE information: section name: /70
Source: hdf5file.dll.0.drStatic PE information: section name: /81
Source: hdf5file.dll.0.drStatic PE information: section name: /92
Source: file.dll.0.drStatic PE information: section name: .xdata
Source: file.dll.0.drStatic PE information: section name: /4
Source: file.dll.0.drStatic PE information: section name: /19
Source: file.dll.0.drStatic PE information: section name: /31
Source: file.dll.0.drStatic PE information: section name: /45
Source: file.dll.0.drStatic PE information: section name: /57
Source: file.dll.0.drStatic PE information: section name: /70
Source: file.dll.0.drStatic PE information: section name: /81
Source: file.dll.0.drStatic PE information: section name: /92
Source: createc.dll.0.drStatic PE information: section name: .xdata
Source: createc.dll.0.drStatic PE information: section name: /4
Source: createc.dll.0.drStatic PE information: section name: /19
Source: createc.dll.0.drStatic PE information: section name: /31
Source: createc.dll.0.drStatic PE information: section name: /45
Source: createc.dll.0.drStatic PE information: section name: /57
Source: createc.dll.0.drStatic PE information: section name: /70
Source: createc.dll.0.drStatic PE information: section name: /81
Source: createc.dll.0.drStatic PE information: section name: /92
Source: imgexport.dll.0.drStatic PE information: section name: .xdata
Source: imgexport.dll.0.drStatic PE information: section name: /4
Source: imgexport.dll.0.drStatic PE information: section name: /19
Source: imgexport.dll.0.drStatic PE information: section name: /31
Source: imgexport.dll.0.drStatic PE information: section name: /45
Source: imgexport.dll.0.drStatic PE information: section name: /57
Source: imgexport.dll.0.drStatic PE information: section name: /70
Source: imgexport.dll.0.drStatic PE information: section name: /81
Source: imgexport.dll.0.drStatic PE information: section name: /92
Source: jpkscan.dll.0.drStatic PE information: section name: .xdata
Source: jpkscan.dll.0.drStatic PE information: section name: /4
Source: jpkscan.dll.0.drStatic PE information: section name: /19
Source: jpkscan.dll.0.drStatic PE information: section name: /31
Source: jpkscan.dll.0.drStatic PE information: section name: /45
Source: jpkscan.dll.0.drStatic PE information: section name: /57
Source: jpkscan.dll.0.drStatic PE information: section name: /70
Source: jpkscan.dll.0.drStatic PE information: section name: /81
Source: jpkscan.dll.0.drStatic PE information: section name: /92
Source: keyence.dll.0.drStatic PE information: section name: .xdata
Source: keyence.dll.0.drStatic PE information: section name: /4
Source: keyence.dll.0.drStatic PE information: section name: /19
Source: keyence.dll.0.drStatic PE information: section name: /31
Source: keyence.dll.0.drStatic PE information: section name: /45
Source: keyence.dll.0.drStatic PE information: section name: /57
Source: keyence.dll.0.drStatic PE information: section name: /70
Source: keyence.dll.0.drStatic PE information: section name: /81
Source: keyence.dll.0.drStatic PE information: section name: /92
Source: npyfile.dll.0.drStatic PE information: section name: .xdata
Source: npyfile.dll.0.drStatic PE information: section name: /4
Source: npyfile.dll.0.drStatic PE information: section name: /19
Source: npyfile.dll.0.drStatic PE information: section name: /31
Source: npyfile.dll.0.drStatic PE information: section name: /45
Source: npyfile.dll.0.drStatic PE information: section name: /57
Source: npyfile.dll.0.drStatic PE information: section name: /70
Source: npyfile.dll.0.drStatic PE information: section name: /81
Source: npyfile.dll.0.drStatic PE information: section name: /92
Source: nrrdfile.dll.0.drStatic PE information: section name: .xdata
Source: nrrdfile.dll.0.drStatic PE information: section name: /4
Source: nrrdfile.dll.0.drStatic PE information: section name: /19
Source: nrrdfile.dll.0.drStatic PE information: section name: /31
Source: nrrdfile.dll.0.drStatic PE information: section name: /45
Source: nrrdfile.dll.0.drStatic PE information: section name: /57
Source: nrrdfile.dll.0.drStatic PE information: section name: /70
Source: nrrdfile.dll.0.drStatic PE information: section name: /81
Source: nrrdfile.dll.0.drStatic PE information: section name: /92
Source: fc-cache.exe.0.drStatic PE information: section name: .xdata
Source: fc-cache.exe.0.drStatic PE information: section name: /4
Source: fc-list.exe.0.drStatic PE information: section name: .xdata
Source: fc-list.exe.0.drStatic PE information: section name: /4
Source: gdbus.exe.0.drStatic PE information: section name: .xdata
Source: gdbus.exe.0.drStatic PE information: section name: /4
Source: gdk-pixbuf-query-loaders.exe.0.drStatic PE information: section name: .xdata
Source: gdk-pixbuf-query-loaders.exe.0.drStatic PE information: section name: /4
Source: gsettings.exe.0.drStatic PE information: section name: .xdata
Source: gsettings.exe.0.drStatic PE information: section name: /4
Source: gspawn-win64-helper-console.exe.0.drStatic PE information: section name: .xdata
Source: gspawn-win64-helper-console.exe.0.drStatic PE information: section name: /4
Source: gspawn-win64-helper.exe.0.drStatic PE information: section name: .xdata
Source: gspawn-win64-helper.exe.0.drStatic PE information: section name: /4
Source: gtk-query-immodules-2.0.exe.0.drStatic PE information: section name: .xdata
Source: gtk-query-immodules-2.0.exe.0.drStatic PE information: section name: /4
Source: gwyddion.exe.0.drStatic PE information: section name: .xdata
Source: gwyddion.exe.0.drStatic PE information: section name: /4
Source: gwyddion.exe.0.drStatic PE information: section name: /19
Source: gwyddion.exe.0.drStatic PE information: section name: /31
Source: gwyddion.exe.0.drStatic PE information: section name: /45
Source: gwyddion.exe.0.drStatic PE information: section name: /57
Source: gwyddion.exe.0.drStatic PE information: section name: /70
Source: gwyddion.exe.0.drStatic PE information: section name: /81
Source: gwyddion.exe.0.drStatic PE information: section name: /92
Source: oirfile.dll.0.drStatic PE information: section name: .xdata
Source: oirfile.dll.0.drStatic PE information: section name: /4
Source: oirfile.dll.0.drStatic PE information: section name: /19
Source: oirfile.dll.0.drStatic PE information: section name: /31
Source: oirfile.dll.0.drStatic PE information: section name: /45
Source: oirfile.dll.0.drStatic PE information: section name: /57
Source: oirfile.dll.0.drStatic PE information: section name: /70
Source: oirfile.dll.0.drStatic PE information: section name: /81
Source: oirfile.dll.0.drStatic PE information: section name: /92
Source: pixmap.dll.0.drStatic PE information: section name: .xdata
Source: pixmap.dll.0.drStatic PE information: section name: /4
Source: pixmap.dll.0.drStatic PE information: section name: /19
Source: pixmap.dll.0.drStatic PE information: section name: /31
Source: pixmap.dll.0.drStatic PE information: section name: /45
Source: pixmap.dll.0.drStatic PE information: section name: /57
Source: pixmap.dll.0.drStatic PE information: section name: /70
Source: pixmap.dll.0.drStatic PE information: section name: /81
Source: pixmap.dll.0.drStatic PE information: section name: /92
Source: rhk-sm4.dll.0.drStatic PE information: section name: .xdata
Source: rhk-sm4.dll.0.drStatic PE information: section name: /4
Source: rhk-sm4.dll.0.drStatic PE information: section name: /19
Source: rhk-sm4.dll.0.drStatic PE information: section name: /31
Source: rhk-sm4.dll.0.drStatic PE information: section name: /45
Source: rhk-sm4.dll.0.drStatic PE information: section name: /57
Source: rhk-sm4.dll.0.drStatic PE information: section name: /70
Source: rhk-sm4.dll.0.drStatic PE information: section name: /81
Source: rhk-sm4.dll.0.drStatic PE information: section name: /92
Source: surffile.dll.0.drStatic PE information: section name: .xdata
Source: surffile.dll.0.drStatic PE information: section name: /4
Source: surffile.dll.0.drStatic PE information: section name: /19
Source: surffile.dll.0.drStatic PE information: section name: /31
Source: surffile.dll.0.drStatic PE information: section name: /45
Source: surffile.dll.0.drStatic PE information: section name: /57
Source: surffile.dll.0.drStatic PE information: section name: /70
Source: surffile.dll.0.drStatic PE information: section name: /81
Source: surffile.dll.0.drStatic PE information: section name: /92
Source: anasys_xml.dll.0.drStatic PE information: section name: .xdata
Source: anasys_xml.dll.0.drStatic PE information: section name: /4
Source: anasys_xml.dll.0.drStatic PE information: section name: /19
Source: anasys_xml.dll.0.drStatic PE information: section name: /31
Source: anasys_xml.dll.0.drStatic PE information: section name: /45
Source: anasys_xml.dll.0.drStatic PE information: section name: /57
Source: anasys_xml.dll.0.drStatic PE information: section name: /70
Source: anasys_xml.dll.0.drStatic PE information: section name: /81
Source: anasys_xml.dll.0.drStatic PE information: section name: /92
Source: apedaxfile.dll.0.drStatic PE information: section name: .xdata
Source: apedaxfile.dll.0.drStatic PE information: section name: /4
Source: apedaxfile.dll.0.drStatic PE information: section name: /19
Source: apedaxfile.dll.0.drStatic PE information: section name: /31
Source: apedaxfile.dll.0.drStatic PE information: section name: /45
Source: apedaxfile.dll.0.drStatic PE information: section name: /57
Source: apedaxfile.dll.0.drStatic PE information: section name: /70
Source: apedaxfile.dll.0.drStatic PE information: section name: /81
Source: apedaxfile.dll.0.drStatic PE information: section name: /92
Source: hdrimage.dll.0.drStatic PE information: section name: .xdata
Source: hdrimage.dll.0.drStatic PE information: section name: /4
Source: hdrimage.dll.0.drStatic PE information: section name: /19
Source: hdrimage.dll.0.drStatic PE information: section name: /31
Source: hdrimage.dll.0.drStatic PE information: section name: /45
Source: hdrimage.dll.0.drStatic PE information: section name: /57
Source: hdrimage.dll.0.drStatic PE information: section name: /70
Source: hdrimage.dll.0.drStatic PE information: section name: /81
Source: hdrimage.dll.0.drStatic PE information: section name: /92
Source: matfile.dll.0.drStatic PE information: section name: .xdata
Source: matfile.dll.0.drStatic PE information: section name: /4
Source: matfile.dll.0.drStatic PE information: section name: /19
Source: matfile.dll.0.drStatic PE information: section name: /31
Source: matfile.dll.0.drStatic PE information: section name: /45
Source: matfile.dll.0.drStatic PE information: section name: /57
Source: matfile.dll.0.drStatic PE information: section name: /70
Source: matfile.dll.0.drStatic PE information: section name: /81
Source: matfile.dll.0.drStatic PE information: section name: /92
Source: nanoobserver.dll.0.drStatic PE information: section name: .xdata
Source: nanoobserver.dll.0.drStatic PE information: section name: /4
Source: nanoobserver.dll.0.drStatic PE information: section name: /19
Source: nanoobserver.dll.0.drStatic PE information: section name: /31
Source: nanoobserver.dll.0.drStatic PE information: section name: /45
Source: nanoobserver.dll.0.drStatic PE information: section name: /57
Source: nanoobserver.dll.0.drStatic PE information: section name: /70
Source: nanoobserver.dll.0.drStatic PE information: section name: /81
Source: nanoobserver.dll.0.drStatic PE information: section name: /92
Source: nanoscantech.dll.0.drStatic PE information: section name: .xdata
Source: nanoscantech.dll.0.drStatic PE information: section name: /4
Source: nanoscantech.dll.0.drStatic PE information: section name: /19
Source: nanoscantech.dll.0.drStatic PE information: section name: /31
Source: nanoscantech.dll.0.drStatic PE information: section name: /45
Source: nanoscantech.dll.0.drStatic PE information: section name: /57
Source: nanoscantech.dll.0.drStatic PE information: section name: /70
Source: nanoscantech.dll.0.drStatic PE information: section name: /81
Source: nanoscantech.dll.0.drStatic PE information: section name: /92
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: .xdata
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /4
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /19
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /31
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /45
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /57
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /70
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /81
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /92
Source: iconv.dll.0.drStatic PE information: section name: .xdata
Source: iconv.dll.0.drStatic PE information: section name: /4
Source: libaec.dll.0.drStatic PE information: section name: .xdata
Source: libaec.dll.0.drStatic PE information: section name: /4
Source: libasprintf-0.dll.0.drStatic PE information: section name: .xdata
Source: libasprintf-0.dll.0.drStatic PE information: section name: /4
Source: libatk-1.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libatk-1.0-0.dll.0.drStatic PE information: section name: /4
Source: libbz2-1.dll.0.drStatic PE information: section name: .xdata
Source: libbz2-1.dll.0.drStatic PE information: section name: /4
Source: libdl.dll.0.drStatic PE information: section name: .xdata
Source: libdl.dll.0.drStatic PE information: section name: /4
Source: libcairo-2.dll.0.drStatic PE information: section name: .xdata
Source: libcairo-2.dll.0.drStatic PE information: section name: /4
Source: libcairo-gobject-2.dll.0.drStatic PE information: section name: .xdata
Source: libcairo-gobject-2.dll.0.drStatic PE information: section name: /4
Source: libcairo-script-interpreter-2.dll.0.drStatic PE information: section name: .xdata
Source: libcairo-script-interpreter-2.dll.0.drStatic PE information: section name: /4
Source: opengps.dll.0.drStatic PE information: section name: .xdata
Source: opengps.dll.0.drStatic PE information: section name: /4
Source: opengps.dll.0.drStatic PE information: section name: /19
Source: opengps.dll.0.drStatic PE information: section name: /31
Source: opengps.dll.0.drStatic PE information: section name: /45
Source: opengps.dll.0.drStatic PE information: section name: /57
Source: opengps.dll.0.drStatic PE information: section name: /70
Source: opengps.dll.0.drStatic PE information: section name: /81
Source: opengps.dll.0.drStatic PE information: section name: /92
Source: psppt.dll.0.drStatic PE information: section name: .xdata
Source: psppt.dll.0.drStatic PE information: section name: /4
Source: psppt.dll.0.drStatic PE information: section name: /19
Source: psppt.dll.0.drStatic PE information: section name: /31
Source: psppt.dll.0.drStatic PE information: section name: /45
Source: psppt.dll.0.drStatic PE information: section name: /57
Source: psppt.dll.0.drStatic PE information: section name: /70
Source: psppt.dll.0.drStatic PE information: section name: /81
Source: psppt.dll.0.drStatic PE information: section name: /92
Source: sensofarx.dll.0.drStatic PE information: section name: .xdata
Source: sensofarx.dll.0.drStatic PE information: section name: /4
Source: sensofarx.dll.0.drStatic PE information: section name: /19
Source: sensofarx.dll.0.drStatic PE information: section name: /31
Source: sensofarx.dll.0.drStatic PE information: section name: /45
Source: sensofarx.dll.0.drStatic PE information: section name: /57
Source: sensofarx.dll.0.drStatic PE information: section name: /70
Source: sensofarx.dll.0.drStatic PE information: section name: /81
Source: sensofarx.dll.0.drStatic PE information: section name: /92
Source: scnxfile.dll.0.drStatic PE information: section name: .xdata
Source: scnxfile.dll.0.drStatic PE information: section name: /4
Source: scnxfile.dll.0.drStatic PE information: section name: /19
Source: scnxfile.dll.0.drStatic PE information: section name: /31
Source: scnxfile.dll.0.drStatic PE information: section name: /45
Source: scnxfile.dll.0.drStatic PE information: section name: /57
Source: scnxfile.dll.0.drStatic PE information: section name: /70
Source: scnxfile.dll.0.drStatic PE information: section name: /81
Source: scnxfile.dll.0.drStatic PE information: section name: /92
Source: spml.dll.0.drStatic PE information: section name: .xdata
Source: spml.dll.0.drStatic PE information: section name: /4
Source: spml.dll.0.drStatic PE information: section name: /19
Source: spml.dll.0.drStatic PE information: section name: /31
Source: spml.dll.0.drStatic PE information: section name: /45
Source: spml.dll.0.drStatic PE information: section name: /57
Source: spml.dll.0.drStatic PE information: section name: /70
Source: spml.dll.0.drStatic PE information: section name: /81
Source: spml.dll.0.drStatic PE information: section name: /92
Source: spmxfile.dll.0.drStatic PE information: section name: .xdata
Source: spmxfile.dll.0.drStatic PE information: section name: /4
Source: spmxfile.dll.0.drStatic PE information: section name: /19
Source: spmxfile.dll.0.drStatic PE information: section name: /31
Source: spmxfile.dll.0.drStatic PE information: section name: /45
Source: spmxfile.dll.0.drStatic PE information: section name: /57
Source: spmxfile.dll.0.drStatic PE information: section name: /70
Source: spmxfile.dll.0.drStatic PE information: section name: /81
Source: spmxfile.dll.0.drStatic PE information: section name: /92
Source: zonfile.dll.0.drStatic PE information: section name: .xdata
Source: zonfile.dll.0.drStatic PE information: section name: /4
Source: zonfile.dll.0.drStatic PE information: section name: /19
Source: zonfile.dll.0.drStatic PE information: section name: /31
Source: zonfile.dll.0.drStatic PE information: section name: /45
Source: zonfile.dll.0.drStatic PE information: section name: /57
Source: zonfile.dll.0.drStatic PE information: section name: /70
Source: zonfile.dll.0.drStatic PE information: section name: /81
Source: zonfile.dll.0.drStatic PE information: section name: /92
Source: graph.dll.0.drStatic PE information: section name: .xdata
Source: graph.dll.0.drStatic PE information: section name: /4
Source: graph.dll.0.drStatic PE information: section name: /19
Source: graph.dll.0.drStatic PE information: section name: /31
Source: graph.dll.0.drStatic PE information: section name: /45
Source: graph.dll.0.drStatic PE information: section name: /57
Source: graph.dll.0.drStatic PE information: section name: /70
Source: graph.dll.0.drStatic PE information: section name: /81
Source: graph.dll.0.drStatic PE information: section name: /92
Source: layer.dll.0.drStatic PE information: section name: .xdata
Source: layer.dll.0.drStatic PE information: section name: /4
Source: layer.dll.0.drStatic PE information: section name: /19
Source: layer.dll.0.drStatic PE information: section name: /31
Source: layer.dll.0.drStatic PE information: section name: /45
Source: layer.dll.0.drStatic PE information: section name: /57
Source: layer.dll.0.drStatic PE information: section name: /70
Source: layer.dll.0.drStatic PE information: section name: /81
Source: layer.dll.0.drStatic PE information: section name: /92
Source: libexpat-1.dll.0.drStatic PE information: section name: .xdata
Source: libexpat-1.dll.0.drStatic PE information: section name: /4
Source: libffi-6.dll.0.drStatic PE information: section name: .xdata
Source: libffi-6.dll.0.drStatic PE information: section name: /4
Source: libfftw3-3.dll.0.drStatic PE information: section name: .xdata
Source: libfftw3-3.dll.0.drStatic PE information: section name: /4
Source: libfontconfig-1.dll.0.drStatic PE information: section name: .xdata
Source: libfontconfig-1.dll.0.drStatic PE information: section name: /4
Source: libfreetype-6.dll.0.drStatic PE information: section name: .xdata
Source: libfreetype-6.dll.0.drStatic PE information: section name: /4
Source: libgailutil-18.dll.0.drStatic PE information: section name: .xdata
Source: libgailutil-18.dll.0.drStatic PE information: section name: /4
Source: libgdkglext-win32-1.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgdkglext-win32-1.0-0.dll.0.drStatic PE information: section name: /4
Source: libgdk_pixbuf-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgdk_pixbuf-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgdk-win32-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgdk-win32-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: .xdata
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /4
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /19
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /31
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /45
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /57
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /70
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /81
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /92
Source: process.dll.0.drStatic PE information: section name: .xdata
Source: process.dll.0.drStatic PE information: section name: /4
Source: process.dll.0.drStatic PE information: section name: /19
Source: process.dll.0.drStatic PE information: section name: /31
Source: process.dll.0.drStatic PE information: section name: /45
Source: process.dll.0.drStatic PE information: section name: /57
Source: process.dll.0.drStatic PE information: section name: /70
Source: process.dll.0.drStatic PE information: section name: /81
Source: process.dll.0.drStatic PE information: section name: /92
Source: tools.dll.0.drStatic PE information: section name: .xdata
Source: tools.dll.0.drStatic PE information: section name: /4
Source: tools.dll.0.drStatic PE information: section name: /19
Source: tools.dll.0.drStatic PE information: section name: /31
Source: tools.dll.0.drStatic PE information: section name: /45
Source: tools.dll.0.drStatic PE information: section name: /57
Source: tools.dll.0.drStatic PE information: section name: /70
Source: tools.dll.0.drStatic PE information: section name: /81
Source: tools.dll.0.drStatic PE information: section name: /92
Source: volume.dll.0.drStatic PE information: section name: .xdata
Source: volume.dll.0.drStatic PE information: section name: /4
Source: volume.dll.0.drStatic PE information: section name: /19
Source: volume.dll.0.drStatic PE information: section name: /31
Source: volume.dll.0.drStatic PE information: section name: /45
Source: volume.dll.0.drStatic PE information: section name: /57
Source: volume.dll.0.drStatic PE information: section name: /70
Source: volume.dll.0.drStatic PE information: section name: /81
Source: volume.dll.0.drStatic PE information: section name: /92
Source: xyz.dll.0.drStatic PE information: section name: .xdata
Source: xyz.dll.0.drStatic PE information: section name: /4
Source: xyz.dll.0.drStatic PE information: section name: /19
Source: xyz.dll.0.drStatic PE information: section name: /31
Source: xyz.dll.0.drStatic PE information: section name: /45
Source: xyz.dll.0.drStatic PE information: section name: /57
Source: xyz.dll.0.drStatic PE information: section name: /70
Source: xyz.dll.0.drStatic PE information: section name: /81
Source: xyz.dll.0.drStatic PE information: section name: /92
Source: libssp-0.dll.0.drStatic PE information: section name: .xdata
Source: libssp-0.dll.0.drStatic PE information: section name: /4
Source: libssp-0.dll.0.drStatic PE information: section name: /19
Source: libssp-0.dll.0.drStatic PE information: section name: /31
Source: libssp-0.dll.0.drStatic PE information: section name: /45
Source: libssp-0.dll.0.drStatic PE information: section name: /57
Source: libssp-0.dll.0.drStatic PE information: section name: /70
Source: libssp-0.dll.0.drStatic PE information: section name: /81
Source: libssp-0.dll.0.drStatic PE information: section name: /92
Source: libgio-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgio-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libglib-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libglib-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgmodule-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgmodule-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgobject-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgobject-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgomp-1.dll.0.drStatic PE information: section name: .xdata
Source: libgomp-1.dll.0.drStatic PE information: section name: /4
Source: libgomp-1.dll.0.drStatic PE information: section name: /19
Source: libgomp-1.dll.0.drStatic PE information: section name: /31
Source: libgomp-1.dll.0.drStatic PE information: section name: /45
Source: libgomp-1.dll.0.drStatic PE information: section name: /57
Source: libgomp-1.dll.0.drStatic PE information: section name: /70
Source: libgomp-1.dll.0.drStatic PE information: section name: /81
Source: libgomp-1.dll.0.drStatic PE information: section name: /92
Source: libgthread-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgthread-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgtkglext-win32-1.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgtkglext-win32-1.0-0.dll.0.drStatic PE information: section name: /4
Source: libgtk-win32-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgtk-win32-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgtksourceview-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgtksourceview-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libharfbuzz-0.dll.0.drStatic PE information: section name: .xdata
Source: libharfbuzz-0.dll.0.drStatic PE information: section name: /4
Source: libhdf5-103.dll.0.drStatic PE information: section name: .xdata
Source: libhdf5-103.dll.0.drStatic PE information: section name: /4
Source: libhdf5_hl-100.dll.0.drStatic PE information: section name: .xdata
Source: libhdf5_hl-100.dll.0.drStatic PE information: section name: /4
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /4
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /19
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /31
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /45
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /57
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /70
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /81
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /92
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /4
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /19
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /31
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /45
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /57
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /70
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /81
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /92
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /4
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /19
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /31
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /45
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /57
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /70
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /81
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /92
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /4
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /19
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /31
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /45
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /57
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /70
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /81
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /92
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /4
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /19
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /31
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /45
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /57
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /70
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /81
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gsettings.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libjansson.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\surffile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libsz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\fc-list.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\zlib1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\uninstall.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\iconv.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gdbus.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Users\user\AppData\Local\Temp\nspC29F.tmp\nsDialogs.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libaec.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libdl.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\scnxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gwyddion (64bit).lnkJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gsettings.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libjansson.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\surffile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libsz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\fc-list.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\zlib1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\uninstall.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\iconv.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gdbus.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nspC29F.tmp\nsDialogs.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libaec.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libdl.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\scnxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile Volume queried: C:\Program Files FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeFile Volume queried: C:\Program Files FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405D74
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_0040699E FindFirstFileW,FindClose,0_2_0040699E
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_0040290B FindFirstFileW,0_2_0040290B
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeAPI call chain: ExitProcess graph end nodegraph_0-3723
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeAPI call chain: ExitProcess graph end nodegraph_0-3942
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_6FBB17BE Create,GetDlgItem,GetWindowRect,MapWindowPoints,CreateDialogParamW,SetWindowPos,SetWindowLongW,GetProcessHeap,HeapAlloc,0_2_6FBB17BE
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.67.win64.exeCode function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,0_2_00403640
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Windows Service
1
Access Token Manipulation
2
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network Medium1
System Shutdown/Reboot
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Windows Service
1
Access Token Manipulation
LSASS Memory2
File and Directory Discovery
Remote Desktop Protocol1
Clipboard Data
Junk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
1
DLL Side-Loading
Security Account Manager14
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Registry Run Keys / Startup Folder
Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
SourceDetectionScannerLabelLink
C:\Program Files\Gwyddion\bin\fc-cache.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\fc-list.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gdbus.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gsettings.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\iconv.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libHalf-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIex-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIexMath-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libImath-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libaec.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libasprintf-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libatk-1.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libbz2-1.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libcairo-2.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libdl.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libexpat-1.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libffi-6.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libfftw3-3.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libfontconfig-1.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libfreetype-6.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgailutil-18.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgio-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libglib-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgomp-1.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgwyapp2-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgwyddion2-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgwydgets2-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgwydraw2-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libgwymodule2-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libharfbuzz-0.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libhdf5-103.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libintl-8.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libjansson.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libjasper-4.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libjpeg-62.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libpango-1.0-0.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://cairographics.org))0%Avira URL Cloudsafe
https://cairographics.org)0%Avira URL Cloudsafe
https://bugzilla.gnome.org/enter_bug.cgi?product=gdk-pixbuf&keywords=I18N0%Avira URL Cloudsafe
http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&component=general0%Avira URL Cloudsafe
http://freedesktop.orgtypenameexeccounttimestamp0%Avira URL Cloudsafe
http://bugzilla.gnome.org/show_bug.cgi?id=%sg_type_is_a0%Avira URL Cloudsafe
http://gwyddion.net/0%Avira URL Cloudsafe
https://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18N0%Avira URL Cloudsafe
http://www.cmi.cz/0%Avira URL Cloudsafe
http://icon-theme.freedesktop.org/releases0%Avira URL Cloudsafe
http://gwyddion.net/.gwyGwyddion.NativeDataGwyddion0%Avira URL Cloudsafe
http://gwyddion.net/Report0%Avira URL Cloudsafe
http://bugzilla.gnome.org/enter_bug.cgi?product=atk&keywords=I18N0%Avira URL Cloudsafe
http://www.freedesktop.org/standards/dbus/1.0/introspect.dtd0%Avira URL Cloudsafe
http://www.cmi.cz/Credits%s0%Avira URL Cloudsafe
http://bugzilla.gnome.org/enter_bug.cgi?product=gtksourceview&component=general0%Avira URL Cloudsafe
https://translationproject.org/team/pt_BR.html0%Avira URL Cloudsafe
http://www.freedesktop.org/standards/desktop-bookmarksgroupapplicationsgroupsprivateiconmime-typehtt0%Avira URL Cloudsafe
http://relaxng.org/ns/compatibility/annotations/1.00%Avira URL Cloudsafe
http://library.gnome.org/devel/gtk-faq/stable/0%Avira URL Cloudsafe
http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&keywords=I18N0%Avira URL Cloudsafe
http://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18N0%Avira URL Cloudsafe
http://bugzilla.gnome.org/show_bug.cgi?id=%s0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://bugzilla.gnome.org/enter_bug.cgi?product=gdk-pixbuf&keywords=I18NGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.gnu.org/licenses/gpl-2.0.htmlLicenseGtkGLExtnsnA40A.tmp.0.drfalse
    high
    https://cairographics.org))nsnA40A.tmp.0.drfalse
    • Avira URL Cloud: safe
    unknown
    http://docs.python.org/lib/typesseq-strings.htmlGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
      high
      https://www.gnu.org/licenses/nsnA40A.tmp.0.drfalse
        high
        http://www.freedesktop.org/standards/desktop-bookmarksnsnA40A.tmp.0.drfalse
          high
          http://freedesktop.orgtypenameexeccounttimestampnsnA40A.tmp.0.drfalse
          • Avira URL Cloud: safe
          unknown
          http://gwyddion.net/nsnA40A.tmp.0.drfalse
          • Avira URL Cloud: safe
          unknown
          http://nsis.sf.net/NSIS_ErrorErrorGwyddion-2.67.win64.exefalse
            high
            http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&component=generalGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            http://bugzilla.gnome.org/show_bug.cgi?id=%sg_type_is_ansnA40A.tmp.0.drfalse
            • Avira URL Cloud: safe
            unknown
            http://www.cmi.cz/nsnA40A.tmp.0.drfalse
            • Avira URL Cloud: safe
            unknown
            http://docs.python.org/lib/built-in-funcs.html)Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
              high
              http://icon-theme.freedesktop.org/releasesnsnA40A.tmp.0.drfalse
              • Avira URL Cloud: safe
              unknown
              https://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18NGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://cairographics.org)nsnA40A.tmp.0.drfalse
              • Avira URL Cloud: safe
              unknown
              http://www.freedesktop.org/standards/dbus/1.0/introspect.dtdnsnA40A.tmp.0.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.gnu.org/licenses/gpl-2.0.htmlnsnA40A.tmp.0.drfalse
                high
                http://bugzilla.gnome.org/enter_bug.cgi?product=gtksourceview&component=generalGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmp, Gwyddion-2.67.win64.exe, 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://gwyddion.net/.gwyGwyddion.NativeDataGwyddionGwyddion-2.67.win64.exe, 00000000.00000002.2947824135.0000000000488000.00000004.00000020.00020000.00000000.sdmp, nsnA40A.tmp.0.drfalse
                • Avira URL Cloud: safe
                unknown
                http://docs.python.org/ref/strings.htmlGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  http://gwyddion.net/ReportnsnA40A.tmp.0.drfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://gitlab.gnome.org/GNOME/gdk-pixbuf/issuesGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    http://bugzilla.gnome.org/enter_bug.cgi?product=atk&keywords=I18NGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmp, atk10.mo6.0.drfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.freedesktop.org/standards/shared-mime-infonsnA40A.tmp.0.drfalse
                      high
                      http://www.brynosaurus.com/cachedir/nsnA40A.tmp.0.drfalse
                        high
                        http://www.cmi.cz/Credits%snsnA40A.tmp.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://www.freedesktop.org/standards/desktop-bookmarksgroupapplicationsgroupsprivateiconmime-typehttnsnA40A.tmp.0.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://gnu.org/licenses/gpl.htmlGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          http://relaxng.org/ns/compatibility/annotations/1.0Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://translationproject.org/team/pt_BR.htmlGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://library.gnome.org/devel/gtk-faq/stable/nsnA40A.tmp.0.drfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://www.python.org/peps/pep-0263.htmlGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://relaxng.org/ns/structure/1.0Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmp, language2.rng.0.drfalse
                              high
                              http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&keywords=I18NGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://freedesktop.orgnsnA40A.tmp.0.drfalse
                                high
                                http://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18NGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://bugzilla.gnome.org/show_bug.cgi?id=%snsnA40A.tmp.0.drfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://www.python.org/peps/pep-0263.html.Gwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://github.com/iobataya/gwyddion-ja-translationGwyddion-2.67.win64.exe, 00000000.00000002.2948575126.00000000028B1000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    No contacted IP infos
                                    Joe Sandbox version:41.0.0 Charoite
                                    Analysis ID:1559725
                                    Start date and time:2024-11-20 21:20:16 +01:00
                                    Joe Sandbox product:CloudBasic
                                    Overall analysis duration:0h 6m 56s
                                    Hypervisor based Inspection enabled:false
                                    Report type:full
                                    Cookbook file name:default.jbs
                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                    Number of analysed new started processes analysed:6
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Sample name:Gwyddion-2.67.win64.exe
                                    Detection:CLEAN
                                    Classification:clean3.winEXE@1/618@0/0
                                    EGA Information:
                                    • Successful, ratio: 100%
                                    HCA Information:
                                    • Successful, ratio: 100%
                                    • Number of executed functions: 57
                                    • Number of non-executed functions: 23
                                    Cookbook Comments:
                                    • Found application associated with file extension: .exe
                                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                    • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size getting too big, too many NtOpenKeyEx calls found.
                                    • Report size getting too big, too many NtQueryAttributesFile calls found.
                                    • Report size getting too big, too many NtQueryValueKey calls found.
                                    • Report size getting too big, too many NtSetInformationFile calls found.
                                    • VT rate limit hit for: Gwyddion-2.67.win64.exe
                                    No simulations
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):18107
                                    Entropy (8bit):4.671170220500741
                                    Encrypted:false
                                    SSDEEP:384:oEUwi5rPL67cyV12rPd34FomzM2/R+dWb7+Ud:o7F4ExGFzeda7+Ud
                                    MD5:D0FC6D9576B29914AF3C2F8586D0B40E
                                    SHA1:DD3C2E9061F0A16CE21517D3989C7C80CBA7D02B
                                    SHA-256:62F859793A07E5AFAE04229F79FF279EECC1FD1FC9B253B024545A00FB273E7E
                                    SHA-512:485AD1D4FE0E4F77491C3543D1C2458F2FDCC51BD2FD9D62D1D13854AD7FF019EE0B76F4610D0766C4B5C8F88E3AD136226C52BA5F6547D1AE84A689FB46B920
                                    Malicious:false
                                    Reputation:low
                                    Preview:. GNU GENERAL PUBLIC LICENSE. Version 2, June 1991.. Copyright (C) 1989, 1991 Free Software Foundation, Inc.. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.. Everyone is permitted to copy and distribute verbatim copies. of this license document, but changing it is not allowed... Preamble.. The licenses for most software are designed to take away your.freedom to share and change it. By contrast, the GNU General Public.License is intended to guarantee your freedom to share and change free.software--to make sure the software is free for all its users. This.General Public License applies to most of the Free Software.Foundation's software and to any other program whose authors commit to.using it. (Some other Free Software Foundation software is covered by.the GNU Library General Public License instead.) You can apply it to.your programs, too... When we speak of free software, we are referring to freedom
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):25293
                                    Entropy (8bit):4.6202271784571005
                                    Encrypted:false
                                    SSDEEP:384:xv5UwOVAIZ4zZyydV+X6wFDVxnFw7xqsv/t+zP8EfHinIhFkspNM9b/7upt0M6QC:xvuFmIHiV+DnFM/gReSNm/7GtX6QC
                                    MD5:F3FEA5E763F8885B6BB5D02D9EB29D46
                                    SHA1:456B3F002866889CB197564C71292E8D1C332614
                                    SHA-256:677D431F8B6D8BC3685D74B82F64A5594A5F9A9D722D9CFED42DB5A99F50A678
                                    SHA-512:1AFB31E3F905B97CF276AD59E59200A5059C9C3B4A36CC5DB9C775911862AA4DB61474D4A0DFB67F0AFF743B84E5D4A057E48FDDCD2DEE11F23AC099CFEAEAE6
                                    Malicious:false
                                    Reputation:low
                                    Preview:.. GNU LIBRARY GENERAL PUBLIC LICENSE... Version 2, June 1991.. Copyright (C) 1991 Free Software Foundation, Inc.. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.. Everyone is permitted to copy and distribute verbatim copies. of this license document, but changing it is not allowed...[This is the first released version of the library GPL. It is. numbered 2 because it goes with version 2 of the ordinary GPL.]..... Preamble.. The licenses for most software are designed to take away your.freedom to share and change it. By contrast, the GNU General Public.Licenses are intended to guarantee your freedom to share and change.free software--to make sure the software is free for all its users... This license, the Library General Public License, applies to some.specially designated Free Software Foundation software, and to any.other libraries whose authors decide to use it. You can use it for.your libraries, too... When we speak of free software, we are referring to
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):25755
                                    Entropy (8bit):4.627449807901279
                                    Encrypted:false
                                    SSDEEP:384:ZuCPLhqsT7Wlj7gwZFUoBjyKddfnpdp9dlKBAbN1EkhbVs5IsUfTNTukkv2n:bPLhCAijy+F9T9hGdasUfTkkkv2n
                                    MD5:BFE1F75D606912A4111C90743D6C7325
                                    SHA1:ABA8D76D0AF67D57DA3C3C321CAA59F3D242386B
                                    SHA-256:53692A2ED6C6A2C6EC9B32DD0B820DFAE91E0A1FCDF625CA9ED0BDF8705FCC4F
                                    SHA-512:FBDDECCEA689BA830DF464C144C1258EC696AE6D797B5E98AD86AA9419A8BFFBF6CC2E4614CC1A8497B495D3BB18BFD0CB7B1CF2B0BB4459E9C31DBEE1CF70F6
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview: MOZILLA PUBLIC LICENSE. Version 1.1.. ---------------..1. Definitions... 1.0.1. "Commercial Use" means distribution or otherwise making the. Covered Code available to a third party... 1.1. "Contributor" means each entity that creates or contributes to. the creation of Modifications... 1.2. "Contributor Version" means the combination of the Original. Code, prior Modifications used by a Contributor, and the Modifications. made by that particular Contributor... 1.3. "Covered Code" means the Original Code or Modifications or the. combination of the Original Code and Modifications, in each case. including portions thereof... 1.4. "Electronic Distribution Mechanism" means a mechanism generally. accepted in the software development community for the electronic. transfer of data... 1.5. "Executable" means Covered Code in any form other than Source. C
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1208
                                    Entropy (8bit):5.126710469799819
                                    Encrypted:false
                                    SSDEEP:24:CnEoiJHxRHuyPP3GtIHw1h39QH+sUW8Ok4odZo3U/qldFD:AtiJzfPvGt7NQH+sfINi3OMFD
                                    MD5:1B71F681713D1256E1C23B0890920874
                                    SHA1:FD02365360C1936FDD069B08D29C16C6B16E4EA4
                                    SHA-256:F6EEB2310D0B00E5CECAC39C73A0696A5BDBFB754B26325ED5A502FC1A6C338C
                                    SHA-512:89275719E2E791B26BC82D788CF75823496367D7E06C144C07B3B8C78B5CF8FF4A4F49ADDE81767812B869D8E7566FF9199366A7EDB59F54EDC1FB9797B0270C
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:Copyright (c) 1998, 1999, 2000 Thai Open Source Software Center Ltd. and Clark Cooper.Copyright (c) 2001, 2002, 2003, 2004, 2005, 2006 Expat maintainers...Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be included.in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:Unicode text, UTF-8 text
                                    Category:dropped
                                    Size (bytes):1124
                                    Entropy (8bit):5.125484636623076
                                    Encrypted:false
                                    SSDEEP:24:zEIBH50q6k8mq6jItjX4DViyYA/TjAUiaw/ea:zEIJmt+t0taViyYykUin/ea
                                    MD5:F3AD4145DEA6CA7EFA2F1BEE8165A7A1
                                    SHA1:97CBFA7E8BD49934F04133699D444E53A8647B09
                                    SHA-256:853046EC5C75C400CD64887C49DD7B0BD3C4CF6B8102AFEDAE52BF79DB23F800
                                    SHA-512:B47FF690A64C1CEAE1688491C522EAB810E74636FAA2D9BB32C00A8AD38CE28D4F1BE2E1C72B7BD0D162155CFD64FD2F83F8C6FE751A6F83378658AD4F4BDEDD
                                    Malicious:false
                                    Preview:fontconfig/COPYING..Copyright . 2001,2003 Keith Packard..Permission to use, copy, modify, distribute, and sell this software and its.documentation for any purpose is hereby granted without fee, provided that.the above copyright notice appear in all copies and that both that.copyright notice and this permission notice appear in supporting.documentation, and that the name of Keith Packard not be used in.advertising or publicity pertaining to distribution of the software without.specific, written prior permission. Keith Packard makes no.representations about the suitability of this software for any purpose. It.is provided "as is" without express or implied warranty...THE AUTHOR(S) DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE,.INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS, IN NO.EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY SPECIAL, INDIRECT OR.CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE,.DATA OR PROFITS, WHETHER IN AN ACTION OF CO
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:Unicode text, UTF-8 text
                                    Category:dropped
                                    Size (bytes):1690
                                    Entropy (8bit):5.316577102282905
                                    Encrypted:false
                                    SSDEEP:24:0F1JTGywLbvX8EU0CqA/99D+Z0IR/8jtk9fTsOBtfPxsmWOkN8IAgKe:0F1J5wLbvAfD+ZiOt9jPxsrN8IAgKe
                                    MD5:E021DD6DDA6FF1E6B1044002FC662B9B
                                    SHA1:E911ADF5641A09F13FDD5D59962AD37DA043DF79
                                    SHA-256:2A886915DE4F296CDAE5ED67064F86DBA01D0C55286D86E8487F2A5CAAF40216
                                    SHA-512:6C6425A23C4EFD4D6D35CD300D0B1F6D486D91A4B97A579AFD3EFE5A2F5C94657F2A3B3501C89F0CE50A8814D98C90947A7DAB1AF35092DBA51DA7C50C9741DF
                                    Malicious:false
                                    Preview:HarfBuzz is licensed under the so-called "Old MIT" license. Details follow..For parts of HarfBuzz that are licensed under different licenses see individual.files names COPYING in subdirectories where applicable...Copyright . 2010,2011,2012 Google, Inc..Copyright . 2012 Mozilla Foundation.Copyright . 2011 Codethink Limited.Copyright . 2008,2010 Nokia Corporation and/or its subsidiary(-ies).Copyright . 2009 Keith Stribley.Copyright . 2009 Martin Hosken and SIL International.Copyright . 2007 Chris Wilson.Copyright . 2006 Behdad Esfahbod.Copyright . 2005 David Turner.Copyright . 2004,2007,2008,2009,2010 Red Hat, Inc..Copyright . 1998-2004 David Turner and Werner Lemberg..For full copyright notices consult the individual files in the package....Permission is hereby granted, without written agreement and without.license or royalty fees, to use, copy, modify, and distribute this.software and its documentation for any purpose, provided that the.above copyright notice and
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):2259
                                    Entropy (8bit):4.7030113384031464
                                    Encrypted:false
                                    SSDEEP:48:cKDQHSxpTM6Lck1Z7nPg+ubwc3FT+2tRteDSLNjyNAg36Gb1B:ZDA6Zi8w6McC1yKaz
                                    MD5:2578FEA3829F3FE60EE71023F264FE40
                                    SHA1:BD2DB031B873E6949E6297FA3DC550F95C33C78D
                                    SHA-256:F9769D0238C1806CA5C998343F3C7BA3499E0F8928B91753A1A92D582E76396E
                                    SHA-512:80F373922E6CDF2975AF91F0639F7102E1091F9AA3D3D606B2BD249580EBCAAD88B1E177E5742DF56C23E1D5E6C884419490E1C73C23C01F9B87D4EA36433437
                                    Malicious:false
                                    Preview:..LEGAL ISSUES..============....In plain English:....1. We don't promise that this software works. (But if you find any bugs,.. please let us know!)..2. You can use this software for whatever you want. You don't have to pay us...3. You may not pretend that you wrote this software. If you use it in a.. program, you must acknowledge somewhere in your documentation that.. you've used the IJG code.....In legalese:....The authors make NO WARRANTY or representation, either express or implied,..with respect to this software, its quality, accuracy, merchantability, or..fitness for a particular purpose. This software is provided "AS IS", and you,..its user, assume the entire risk as to its quality and accuracy.....This software is copyright (C) 1991-1998, Thomas G. Lane...All Rights Reserved except as specified below.....Permission is hereby granted to use, copy, modify, and distribute this..software (or portions thereof) for any purpose, without fee, subject to these..conditions:..(1
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1496
                                    Entropy (8bit):5.089007947804457
                                    Encrypted:false
                                    SSDEEP:24:DiK7jUnoc+bOI/rYFTY+Jy/rYFTcqLef09RdozFDBTP4894Os43sEskuK8WROLTe:DiYdOYrYJarYJFS8dozFVP4+4943Je58
                                    MD5:6E8DEE932C26F2DAB503ABF70C96D8BB
                                    SHA1:59CD938FCBD6735B1EF91781280D6EB6C4B7C5D9
                                    SHA-256:5AEC868F669E384A22372A4E8A1A6CD7D44C64CD451F960CA69CC170D1E13ACF
                                    SHA-512:04702240D3D891CACEA23641652FA8E001733538E5671360B411CA5AF94813968F992268142E054B34478C3B1BCCB22E76C32F09B88130C2F5BAD32C50F7E065
                                    Malicious:false
                                    Preview:Copyright (c) 2010, Google Inc. All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are.met:.. * Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... * Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in. the documentation and/or other materials provided with the. distribution... * Neither the name of Google nor the names of its contributors may. be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS."AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL TH
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):1472
                                    Entropy (8bit):4.5247018409170945
                                    Encrypted:false
                                    SSDEEP:24:1jxsMvvcxAbr2tQNNMTpxGvNbyo8POABZ86o1NXgmr+JxV8BJhny:1e4vcebyt6NMTpxe1ypWqZ86YNXx+pAy
                                    MD5:E2106A42E424045D9AB6F5D18ADC7135
                                    SHA1:F934726236DE2FF4DC610F5D6F43A2B77CC16C6D
                                    SHA-256:D7F6C672A25722455192BBDE2F2A1F6619F3B3DE35C8D8AD3BB8000D66546824
                                    SHA-512:7B8F420D41E5C9AC52984D21477ABC8706A39D8C5C300C994229299E00CD79D9DC9ED60641D76AAC10C1826DAC65B19142F4AAD5206959F25270A254F19A93C5
                                    Malicious:false
                                    Preview:..Copyright notice:.... (C) 1995-1998 Jean-loup Gailly and Mark Adler.... This software is provided 'as-is', without any express or implied.. warranty. In no event will the authors be held liable for any damages.. arising from the use of this software..... Permission is granted to anyone to use this software for any purpose,.. including commercial applications, and to alter it and redistribute it.. freely, subject to the following restrictions:.... 1. The origin of this software must not be misrepresented; you must not.. claim that you wrote the original software. If you use this software.. in a product, an acknowledgment in the product documentation would be.. appreciated but is not required... 2. Altered source versions must be plainly marked as such, and must not be.. misrepresented as being the original software... 3. This notice may not be removed or altered from any source distribution..... Jean-loup Gailly Mark Adler.. jloup@gzip.org m
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1500
                                    Entropy (8bit):5.262012915401088
                                    Encrypted:false
                                    SSDEEP:24:KFrFLPA+5DUnogbOIhrYFThJyhrYFTX79LFmr43sEskuK8WROLTt3hyxLTfyL3tY:I5EhOorYJKrYJBxmr43Je53hELmL3tqL
                                    MD5:3D460E16A7D7C854DF7C0E91991C7A3B
                                    SHA1:C4BEAFCB1437CA0F701803FB22323419C65527B1
                                    SHA-256:EFCEF27F44A3FAAB503B3B29B05C8A6B9AD9746E7C7A72A17B056E5842AAF119
                                    SHA-512:CD5DE660C66F46EB39A180076208995D01E24D3C58B8A5AB06667D3D6F2084F7D80E351FAF90F87863A3985D46A41ED9C3A5529075E53CA8439871E0EA901321
                                    Malicious:false
                                    Preview:Copyright 2012 - 2017..Mathis Rosenhauer, Moritz Hanke, Joerg Behrens.Deutsches Klimarechenzentrum GmbH.Bundesstr. 45a.20146 Hamburg.Germany..Luis Kornblueh.Max-Planck-Institut fuer Meteorologie.Bundesstr. 53.20146 Hamburg.Germany..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer..2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS.``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHA
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1146
                                    Entropy (8bit):5.165452112098906
                                    Encrypted:false
                                    SSDEEP:24:5/fpCHTHImq6fTYAP1ynM98HTS0OkhpybVAJTJ8oVwF3Ow:53portjP1yO8HTd/yRABJ8oSF3Ow
                                    MD5:34DA3DB46FAB7501992F9615D7E158CF
                                    SHA1:A2F64F2A85F5FD34BDA8EB713C3AAD008ADBB589
                                    SHA-256:FBD6FED7938541D2C809C0826225FC85E551FDBFA8732B10F0C87E0847ACAFD7
                                    SHA-512:A550BF004806C7B3DA2E6DFC187B0D5FCFC8FB1C965440471925DE496C44CC3712FCCA9E901162516BF3FB48078A7348F5C1E6F69BD46B9F338D5A5A9252FDC9
                                    Malicious:false
                                    Preview:Copyright (c) 1988-1997 Sam Leffler.Copyright (c) 1991-1997 Silicon Graphics, Inc...Permission to use, copy, modify, distribute, and sell this software and .its documentation for any purpose is hereby granted without fee, provided.that (i) the above copyright notices and this permission notice appear in.all copies of the software and related documentation, and (ii) the names of.Sam Leffler and Silicon Graphics may not be used in any advertising or.publicity relating to the software without the specific, prior written.permission of Sam Leffler and Silicon Graphics...THE SOFTWARE IS PROVIDED "AS-IS" AND WITHOUT WARRANTY OF ANY KIND, .EXPRESS, IMPLIED OR OTHERWISE, INCLUDING WITHOUT LIMITATION, ANY .WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. ..IN NO EVENT SHALL SAM LEFFLER OR SILICON GRAPHICS BE LIABLE FOR.ANY SPECIAL, INCIDENTAL, INDIRECT OR CONSEQUENTIAL DAMAGES OF ANY KIND,.OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER OR NOT ADVI
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1498
                                    Entropy (8bit):5.040468071401183
                                    Encrypted:false
                                    SSDEEP:24:EYNhVoLrmJHHH0yN3gtbHw1hj9QHOsUv4DOk4qyoaqXmFGTrPnaFwyJ:EYNXwaJHlxEs5QHOs5NjaVFIryFwk
                                    MD5:BB90C48926316D9AF6E2D70CA7013ADE
                                    SHA1:23A1E6369B12379F07C61BBBAA73E13704EBC30E
                                    SHA-256:013556FF1AA847AC0E365337321C200EEE1C69051DB8870DB37002C852A4E98D
                                    SHA-512:E025659C8C069B7CE5CF74FC38D085628B2C74A225197E3359F3A4EF37FC7A26C7C22C1732645C5507AF387A15FD0F06435F2BC0C61D13EAD8618CF51F0BB7EF
                                    Malicious:false
                                    Preview:Except where otherwise noted in the source code (e.g. the files hash.c,.list.c and the trio files, which are covered by a similar licence but.with different Copyright notices) all the files are:.. Copyright (C) 1998-2003 Daniel Veillard. All Rights Reserved...Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is fur-.nished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FIT-.NESS FOR A PARTICULAR
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):4677
                                    Entropy (8bit):4.704074341157644
                                    Encrypted:false
                                    SSDEEP:96:7sOyHQyHzu6uvmdoFe32qmchF3ccrdCwjeCEQdaQ:IOGQGHrdowmdcnMidVjeJnQ
                                    MD5:57E5351B17591E659EEDAE107265C606
                                    SHA1:489C0C5DE66E7BD4D419E7E556F951DA223B4AFF
                                    SHA-256:3D8E39397A04652AE54F04A6DA8B51B2472CDE8C721A1F00E4329C512D6A016F
                                    SHA-512:1EDC3F2CE62EA4F3CDD4E25C158596ADB1D87786E4F79CABA4D56202645BF6185DD19F81761F4F9F182ACA3F99FDC8C92995B47BAEDCBC8E66FE832CFBB8512E
                                    Malicious:false
                                    Preview:.Copyright Notice and License Terms for .HDF5 (Hierarchical Data Format 5) Software Library and Utilities.-----------------------------------------------------------------------------..HDF5 (Hierarchical Data Format 5) Software Library and Utilities.Copyright 2006-2016 by The HDF Group...NCSA HDF5 (Hierarchical Data Format 5) Software Library and Utilities.Copyright 1998-2006 by the Board of Trustees of the University of Illinois...All rights reserved...Redistribution and use in source and binary forms, with or without .modification, are permitted for any purpose (including commercial purposes) .provided that the following conditions are met:..1. Redistributions of source code must retain the above copyright notice, . this list of conditions, and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright notice, . this list of conditions, and the following disclaimer in the documentation . and/or materials provided with the distribution...3. I
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):2744
                                    Entropy (8bit):5.0942183084478545
                                    Encrypted:false
                                    SSDEEP:48:bhPJ1lPvcw4iP+HSs5SaWmurkmxF3es4cozFL/XWzUzgYaobqc:brPpx+HjW5TeGozFL/EPY5
                                    MD5:BAA697D7510288A9CDCCE9BD7EDAF9BC
                                    SHA1:14B5D0210560128E1A5D5204698CF705011EF792
                                    SHA-256:EDF9F4257CC33A1F396F9B062CA4A01DCA7C79747C7D85B8947E603E5166760E
                                    SHA-512:55E7BD1B4B17CB311F7F40632759D88940751AFC9A13CE50A05049B763784F36F8B4A469C2647843C56FD0595544F8C44614769847EBB0FD483E6EA7A856FF77
                                    Malicious:false
                                    Preview:JasPer License Version 2.0..Copyright (c) 2001-2006 Michael David Adams.Copyright (c) 1999-2000 Image Power, Inc..Copyright (c) 1999-2000 The University of British Columbia..All rights reserved...Permission is hereby granted, free of charge, to any person (the."User") obtaining a copy of this software and associated documentation.files (the "Software"), to deal in the Software without restriction,.including without limitation the rights to use, copy, modify, merge,.publish, distribute, and/or sell copies of the Software, and to permit.persons to whom the Software is furnished to do so, subject to the.following conditions:..1. The above copyright notices and this permission notice (which.includes the disclaimer below) shall be included in all copies or.substantial portions of the Software...2. The name of a copyright holder shall not be used to endorse or.promote products derived from the Software without specific prior.written permission...THIS DISCLAIMER OF WARRANTY CONSTITUTES AN E
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:Algol 68 source, ASCII text
                                    Category:dropped
                                    Size (bytes):1697
                                    Entropy (8bit):5.055574007641632
                                    Encrypted:false
                                    SSDEEP:48:U+RAtO4rYJMrYJ5uVAIV+Pli432sf32sBEtI33tEH3:GA4rYJMrYJ5uObJ3T3d9uX
                                    MD5:459493CEC2D4A115E731C482FFFC4B8A
                                    SHA1:72F59FBAC43FA1A7F0607D7FDBA747832E626656
                                    SHA-256:14EBA5F05238F57C77E94F0EBD29A0B3736BA0456FF990CDA16E21B6903AC453
                                    SHA-512:3819C12557FB5DEEC9250C51399D7B598A927FFF26E46C52FECAF653EFC284DF58D8C44F36D86D953742C4BC265BC107DD9E4C2B7F0CDCCC0FA501C6BAC41788
                                    Malicious:false
                                    Preview:Copyright (c) 2006, Industrial Light & Magic, a division of Lucasfilm.Entertainment Company Ltd. Portions contributed and copyright held by.others as indicated. All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are.met:.. * Redistributions of source code must retain the above. copyright notice, this list of conditions and the following. disclaimer... * Redistributions in binary form must reproduce the above. copyright notice, this list of conditions and the following. disclaimer in the documentation and/or other materials provided with. the distribution... * Neither the name of Industrial Light & Magic nor the names of. any other contributors to this software may be used to endorse or. promote products derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONT
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1901
                                    Entropy (8bit):5.1923513949066304
                                    Encrypted:false
                                    SSDEEP:48:doO3DJOorYJD6LraxZC6EPtiVn432sv532s3qtY1BtEHJ:dlIorYJ+sZC6kH393zrup
                                    MD5:7023994919680C533B77301B306EA1C9
                                    SHA1:D964DBE91CBF7511E4F1857DB9E99FDAF6658055
                                    SHA-256:E8A6B63336018EEC09AC3A7CDFE5A80BDA635641BC0397A77B8BAA25BED03800
                                    SHA-512:9F6294D3AC4B5D8FD56059F764B1F2E0A73B5B598FA468B1A9E0ACE76971F672EAD7327DC256B14C7117220DA4DCF98F720BF751ED830ED4A75095630D74E6F4
                                    Malicious:false
                                    Preview:.--------------------------------------------------------------------------..This program, "bzip2", the associated library "libbzip2", and all.documentation, are copyright (C) 1996-2007 Julian R Seward. All.rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. The origin of this software must not be misrepresented; you must . not claim that you wrote the original software. If you use this . software in a product, an acknowledgment in the product . documentation would be appreciated but is not required...3. Altered source versions must be plainly marked as such, and must. not be misrepresented as being the original software...4. The name of the author may not be used to endorse or promote . products derived from this software without sp
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1132
                                    Entropy (8bit):5.126128868977439
                                    Encrypted:false
                                    SSDEEP:24:KDXiJHTHuyPP3GtIHw1Gg9WPH+sUW8Ok4odZo3U/qldFD:KTiJTfPvGt7ICWPH+sfINi3OMFD
                                    MD5:0CAA055E49A3FB6C57780595E995E2AB
                                    SHA1:874F526BC4A51D56E52F2FEEB52EE45D98D483EC
                                    SHA-256:14FC11F72068E29AAF50306A33BFF2503D932DA1A2068FCC0641E6A5B7166D57
                                    SHA-512:CA73AAFB080970564AC16604DE59DC934831150457DCC8EF92FCE6072E39ED761F6568025967757B387773F0551DD78A931981E10578A23A68F23C22827686D2
                                    Malicious:false
                                    Preview:libffi - Copyright (c) 1996-2011 Anthony Green, Red Hat, Inc and others..See source files for details...Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the.``Software''), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED ``AS IS'', WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):4195
                                    Entropy (8bit):4.806906509727483
                                    Encrypted:false
                                    SSDEEP:96:aUaBPvSsJ1g1z7WCgms1mLKK9SMon1E4Ubg2O8vBddz7:aUaZSeeR7W9msw4Mon1E4o5pP7
                                    MD5:A294A2BB08B7F25558119EDBFD6B2E92
                                    SHA1:DBFB42F6E975CA9FD5DD96176B31975A9B068220
                                    SHA-256:2A995675EF33E51B186EDBCE58A6520C3601332EE8595FA7603466D6B97DDD88
                                    SHA-512:7CD4E1DC72CAB6F6D7BCD6F3D16699052FE8B2667E92CFF9F6F946B4BE76387BE775E2849013147F6E9C172BF9018BDAFB0A398A31CCD18947E47B6A76301D1F
                                    Malicious:false
                                    Preview:.This copy of the libpng notices is provided for your convenience. In case of.any discrepancy between this copy and the notices in the file png.h that is.included in the libpng distribution, the latter shall prevail...COPYRIGHT NOTICE, DISCLAIMER, and LICENSE:..If you modify libpng you may insert additional notices immediately following.this sentence...This code is released under the libpng license...libpng versions 1.2.6, August 15, 2004, through 1.2.44, June 26, 2010, are.Copyright (c) 2004, 2006-2009 Glenn Randers-Pehrson, and are.distributed according to the same disclaimer and license as libpng-1.2.5.with the following individual added to the list of Contributing Authors.. Cosmin Truta..libpng versions 1.0.7, July 1, 2000, through 1.2.5 - October 3, 2002, are.Copyright (c) 2000-2002 Glenn Randers-Pehrson, and are.distributed according to the same disclaimer and license as libpng-1.0.6.with the following individuals added to the list of Contributing Authors.. Simon-Pierre Cadi
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1452
                                    Entropy (8bit):5.165301888670777
                                    Encrypted:false
                                    SSDEEP:24:XD5x4yBMcUnogbOInrYFT5JynrYFTcCLqtRIBTPP99Vn432s4EOk8NwROF32s3q5:TgyBmOYrYJGrYJl8EPl9Vn432svIP323
                                    MD5:067E9870BBA57E1CE20695C4D5672F30
                                    SHA1:45318F6FA59E6E142CC7E81FDB34ABF273B75E88
                                    SHA-256:DEAE392DE70503672793EE784D603BFA8069DCD5974A325DFBF91160F3A147D6
                                    SHA-512:9B908923B183C7462E88E9D18AE2FC03CE11875988FA0591B6B2CD2091DB0BA6A33039332F3C4BFF007F847E98103C33FB604C7DA6BFE7AD0436C07CCAFF8019
                                    Malicious:false
                                    Preview:Copyright (C) 1999-2020 Dieter Baron and Thomas Klausner..The authors can be contacted at <libzip@nih.at>..Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in. the documentation and/or other materials provided with the. distribution...3. The names of the authors may not be used to endorse or promote. products derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS.OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS BE LIABL
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):3182
                                    Entropy (8bit):5.165985964776611
                                    Encrypted:false
                                    SSDEEP:96:wWclPcU13MKIiB9JyrYJWPkLY5F3X31EBQ:gPDeMTyrs1E5F3X3OQ
                                    MD5:B8221CBF43C5587F90CCF228F1185CC2
                                    SHA1:F3F2DED535A8B33041E9A818B2BEECEB690E39C1
                                    SHA-256:3441595E1A5F7970ADB99286B68962CC20252AA0FB8B5D7D775F97760083D563
                                    SHA-512:01E28BA8D5259BFDDE3423ED6717F5FF8BBAF047706E8E26F3A842EFCBF9441589CF4FDF730A608A1A2D61ACA12D6888269049920EFCB218262D5D940C03DAAC
                                    Malicious:false
                                    Preview:PCRE LICENCE.------------..PCRE is a library of functions to support regular expressions whose syntax.and semantics are as close as possible to those of the Perl 5 language...Release 8 of PCRE is distributed under the terms of the "BSD" licence, as.specified below. The documentation for PCRE, supplied in the "doc".directory, is distributed under the same terms as the software itself. The data.in the testdata directory is not copyrighted and is in the public domain...The basic library functions are written in C and are freestanding. Also.included in the distribution is a set of C++ wrapper functions, and a.just-in-time compiler that can be used to optimize pattern matching. These.are both optional features that can be omitted when the library is built....THE BASIC LIBRARY FUNCTIONS.---------------------------..Written by: Philip Hazel.Email local part: ph10.Email domain: cam.ac.uk..University of Cambridge Computing Service,.Cambridge, England...Copyright (c) 1997-2016 Universi
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):57227
                                    Entropy (8bit):5.854878740915308
                                    Encrypted:false
                                    SSDEEP:768:AaeZuM6JdE6PAhVQGUQPY8Z+tD2MpPmVXrA/uG+EuJlCMpgt6tA6eIu1x7Um:APGJO64nQZ8ICMdkXSRuDpgt6ti
                                    MD5:D57AEB2D3FC4A7790C2B097D9405634F
                                    SHA1:F9A52182CAB41EA606C25B34095CB6E24EA84A53
                                    SHA-256:B0F31F361D4F3CBD33F74A345C3DDD3279A5F3802D08564EBE7B92E95F47FAC3
                                    SHA-512:248755E61EA9F4A36B415FDA1C80E0960E1A73A3AFCD9F0CC83158A7FAC534F729D3FBAC342F09FCBEC5978C3948459238EFB8F75DC4C852885A21C42716CB0D
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................'...."......................@..............................@............... .................................................(...............................................................(...................(................................text...H...........................`.P`.data...0...........................@.P..rdata..p...........................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..idata..(...........................@.0..CRT....h...........................@.@..tls......... ......................@.@./4...........0......................@.0B................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):53533
                                    Entropy (8bit):5.829360944152274
                                    Encrypted:false
                                    SSDEEP:768:2kP0SvXAfJdTmJwNA2UoPK8a0R2w12LmVZcS/DG+B+qwi+ZRHgGt8ldbu1xbt:PcSvAJRM0Af8zwwckZd/+JZRA4
                                    MD5:01F989B5E5764A422BA1EAC95C04DF6F
                                    SHA1:C1078402F924A2178D546A089F1A1AE9E759BF1A
                                    SHA-256:2E4DA27E6BE41FE66E7C548F314AE5638B327E40DE5CDDA43EEC2C2A5651A236
                                    SHA-512:F425F90BDD9FD3509A7AFC0CAA2E9DA6CF22E1A22009C60F9F1E40D1A50FB14506F4A878AC62B03AD220B5A317EB308CB95BF9684336995A4E545D29BC58774A
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................'....".~....................@..............................0......U......... .................................................,...........................................................@...(.......................@............................text...x|.......~..................`.P`.data...0...........................@.P..rdata..............................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..idata..,...........................@.0..CRT....h...........................@.@..tls................................@.@./4........... ......................@.0B................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):59006
                                    Entropy (8bit):5.571070102327143
                                    Encrypted:false
                                    SSDEEP:768:y2wL6ElDW3/Wi1JecI5HakiF0FHYkWq3vy42wi+mdd9Vjt8Z0n9vmemaBSffRNWA:Vwx+/lJnI5H37FUn+mdF8+NBSfpNW8F
                                    MD5:9EB50DA35CA9D48152D5367FE86A5834
                                    SHA1:697B24CDE4061CD2D641AD71CAC5284007013323
                                    SHA-256:C545DFB726C9811A3F2172186C86EB3B48DE71A6D1020CD8E69A1AF2532FAE26
                                    SHA-512:1EAAEB1BC6F27F6B4F2A1322E085C84065AABDF04C11123FECCAC2F2D0F7732E0AD15C54761A218CB180190F162DCD009B565863F599D444C194D8B83133614D
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........p.....&....$.^.....................@.............................@.......Y....`... .................................................T...............0............ ..............................@...(....................................................text....].......^..................`.P`.data........p.......b..............@.P..rdata... ......."...d..............@.`@.pdata..0...........................@.0@.xdata..............................@.0@.bss....@.............................`..idata..T...........................@.0..CRT....h...........................@.@..tls................................@.@..reloc....... ......................@.0B/4...........0......................@.0B........................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):29392
                                    Entropy (8bit):5.115809326826697
                                    Encrypted:false
                                    SSDEEP:384:cJU6v7WdnrowwRlMMsmrJJmz0r6xMgzNJJD4jam67g38vv3SViOM6OwXbifrsF:MDWdWUkJJ76Ogp4XuEIqVioOwbyrsF
                                    MD5:9DA2DEE453F85FAC37691BE49069EB3C
                                    SHA1:27144C941B934E310DF86E9357CA59FF3E92239B
                                    SHA-256:EB3D7ABD1A1112370F0CD333D4E1F80E93C6A7A5869A3AA7AAF9D428C565899C
                                    SHA-512:82A3B9E0116619B84774D2292D9E63C5043729E20DAE1BDD8E3AD9B4F97586425528B8F7A2CF0234E8081E6F6957F01AAD8B8624C1A960C3D5840BECAA02FA15
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........V........&....$.$...P.................@..........................................`... .................................................x............`..4...........................................@S..(...................$................................text....".......$..................`.P`.data........@.......(..............@.P..rdata.......P.......*..............@.`@.pdata..4....`.......:..............@.0@.xdata.......p.......>..............@.0@.bss..................................`..idata..x............@..............@.0..CRT....h............N..............@.@..tls.................P..............@.@..reloc...............R..............@.0B/4......(............T..............@.0B........................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):40700
                                    Entropy (8bit):5.300536509625396
                                    Encrypted:false
                                    SSDEEP:384:k9WcZ4bpackG9V0pUmxJxtxdjgJPumOPZbGarVvxhmNkt4wvwOMJNFogf:exEa89V0W4njgJGmGbXjVt4tPNFogf
                                    MD5:9B56E1E1B617C71A8A594F740C057D05
                                    SHA1:58C62160B3892A463BEC64A0099704E9E15ED225
                                    SHA-256:E9998EFF343271BD63BE5014348342F06DFA8129CD765D090591272C5A4D3F34
                                    SHA-512:CAC5B33C7D20051615E1F54395F09D3E7972A679CD062AE1AB0D67624892956B4C0B527D2156909CA2AC68C6062B4530142EB234F5CE06B9AAD14954E57509D0
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........t..(.....&....$.2...n.................@..........................................`... .................................................D............................................................k..(.......................x............................text....0.......2..................`.P`.data........P.......6..............@.P..rdata.......`.......8..............@.`@.pdata...............P..............@.0@.xdata...............T..............@.0@.bss..................................`..idata..D............X..............@.0..CRT....h............l..............@.@..tls.................n..............@.@..reloc...............p..............@.0B/4...................r..............@.0B........................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):24867
                                    Entropy (8bit):4.936942371647577
                                    Encrypted:false
                                    SSDEEP:384:RCL1EY9k82NZ0qpzBlJGplBi8eLjVsVBKJhQxxiOMvyqgl/0:RCLpClZ0IBlJ27i86Kj+kipyqgl/0
                                    MD5:3716D87B022C519B4BC3982822822921
                                    SHA1:9145160DD2A625CC9AD39511156FBA0E0703E94E
                                    SHA-256:49394562AF9AEEECEB84AD0EAFACA5CE43F64971FEFFB9AC1313F1207C796C6B
                                    SHA-512:83A0269591E0652BB76371518C58472629160BEC332775C19F6BF5AD13F6921DA1B5B50DBFDDD4E99281008D4328B8C43B7A91D82722C680D4D08044A7BFD81E
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........L........&....$. ...F.................@.....................................!....`... ..............................................................P..@...........................................`@..(...................\................................text...H........ ..................`.P`.data........0.......$..............@.P..rdata.......@.......&..............@.`@.pdata..@....P.......4..............@.0@.xdata.......`.......8..............@.0@.bss.........p........................`..idata...............:..............@.0..CRT....h............D..............@.@..tls.................F..............@.@..reloc...............H..............@.0B/4......,............J..............@.0B........................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):24903
                                    Entropy (8bit):4.962246739250747
                                    Encrypted:false
                                    SSDEEP:384:iE7EPkzT5bWeZiZ8BWtXDJhVggwB6M389jVsVBKJhQUpH/OMvyqgl/0:iEDNDkztXDJ+lmKj+hhpyqgl/0
                                    MD5:A9C07424EF0E9C3843221C22FB2A4E96
                                    SHA1:908FFCFEE50AC6C410F501DC4628B895954827D6
                                    SHA-256:085230EDE2EEA210F332315B474B1C68164AFFF2F4926885A797FCDF8A4B7546
                                    SHA-512:9C7B42ACE2674FAE0424F161085DC05B0134D9FC66A4DBAAC2D2181717B983262DF750E8D850B6C1FB43C8E382418641823A2AF7D3B1229F4E3EB1452742BF0E
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........L........&....$. ...F.................@..........................................`... ..............................................................P..L...........................................`@..(...................\................................text............ ..................`.P`.data........0.......$..............@.P..rdata.. ....@.......&..............@.`@.pdata..L....P.......4..............@.0@.xdata.......`.......8..............@.0@.bss.........p........................`..idata...............:..............@.0..CRT....h............D..............@.@..tls.................F..............@.@..reloc...............H..............@.0B/4......$............J..............@.0B........................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):23107
                                    Entropy (8bit):5.125716149412629
                                    Encrypted:false
                                    SSDEEP:384:hE0kYSCFkYTXH8ZdlQVJZ6AhrmMLA3X3g5Oxhtdw9MOMSq:9koFlUlQVJZ6AAHwsrgMwq
                                    MD5:1183F1C7477504F694A0D6A43BA5829F
                                    SHA1:3D34696067500C7D6495CD3416177376D8FB7849
                                    SHA-256:58D950AAC438F5680FBCFCAFACEFC7486D8634E51D08A73D12DE3503A2A87AB5
                                    SHA-512:3A7E2E26FF441831CEC382A5FD81904182F5C772FE0BF4B2A150036F5C3D7DCC33B6DF2C3F5329733B58FA8941ECE94CD68DDDC316EBF8BEC91E9B251849AEE3
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........L..y.....'....". ...F................@......................................C........ ..............................................................P..@...........................................`A..(......................H............................text............ ..................`.P`.data........0.......$..............@.P..rdata.......@.......&..............@.`@.pdata..@....P.......4..............@.0@.xdata.......`.......8..............@.0@.bss.........p........................`..idata...............:..............@.0..CRT....h............F..............@.@..tls.................H..............@.@./4......(............J..............@.0B................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):125725
                                    Entropy (8bit):5.184830778119501
                                    Encrypted:false
                                    SSDEEP:1536:rH1RLJ38NEW6hoXWVKLGpiOHOkMgu9S01yDNHhKp2iUD7yXkr:rH1XMNf6hoWVKA3/5WeLNhp
                                    MD5:8ED15BCD6CC5C6FD160BC9827F5B3C54
                                    SHA1:F5DE1B3CBF0150E20AA97BE4CD3535558D1DB95E
                                    SHA-256:DE06E3D4EBA698462A1D1942BEAF210836322C91FF4CABC1F28857C3B099ABD5
                                    SHA-512:3FC2AAD45971D1C586BE233F60E716890EF4D829FB922C1C5EEF1A2339627EBF89ACE9892B8D83776DE85B98DD20407EA6F690E0EDB7DEC60634213CF6629BEE
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.N........'....".0...l................@............................................... ..............................................................p..............................................@[..(....................................................text............0..................`.P`.data........@.......6..............@.P..rdata.......P.......8..............@.`@.pdata.......p.......R..............@.0@.xdata...............V..............@.0@.bss..................................`..idata...............Z..............@.0..CRT....h............n..............@.@..tls.................p..............@.@./4...................r..............@.PB/19......x.......z...t..............@..B/31.....L....p......................@..B/45.....{...........................@..B/57..... ...........................@.@B/70.....q...........................@..B/81.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):678139
                                    Entropy (8bit):5.649126770329012
                                    Encrypted:false
                                    SSDEEP:12288:vorAol+S2dO0zcZ+qCW42DYUZrY+v6o476obJcdopmxCKAkNQ66ys89vVmB9jyK0:vorX+S2dO0zcZ+qCmfZc+Fc+NQ6RFvVH
                                    MD5:01A70D0904F85D841887FEFAE90FB5FF
                                    SHA1:3FC1A1ABFA64F37CE756FC70FB72C26A26B35A74
                                    SHA-256:098D207A126782F655B649CCBD4D924E4A989FC0BD4C09D7618A0535097897B7
                                    SHA-512:321C51D8D038AC295735A07915B4717EF351A14D4705D5E0A691A035C28ADA83CE0AA65BE437F2BCD93CDD998C10605A1A81E6D13542ADC5A2763D75B0420F46
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.P........'...."..... ................@.....................................?......... ..................................................c..............4...............................................(.......................X............................text...............................`.P`.data....+.......,..................@.`..rdata.......0......................@.`@.pdata..4...........................@.0@.xdata..............................@.0@.bss..................................`..idata...c.......d..................@.0..CRT....h....p......."..............@.@..tls.................$..............@.@./4...................&..............@.PB/19..................*..............@..B/31......-...0......................@..B/45.....A....`......................@..B/57.....P%.......&..................@.@B/70......M...@...N..................@..B/81.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):36575
                                    Entropy (8bit):5.2613733608161715
                                    Encrypted:false
                                    SSDEEP:384:ir99D06+Tmdt9Dnws9Bu+hlEnJOg1KATGIEoS+A1UacrL2LSjtV+R+sOOFOMss9O:q9qYVjBuQ6nJHDTGIET+A1UaCRwb15A
                                    MD5:136A1A91F56672F47DD16C9980FC7BB8
                                    SHA1:3B22E2EA9AC7EF6EADA2584DA2339120EC96C5EB
                                    SHA-256:688DA51277925EE0A06C6741E79591FD465BE8128CB61AB94C164D84A395ADD0
                                    SHA-512:195816FD536C0DA3A40CB65AA40E79709AC7AACFABF9EE8CFE38044271A1FE7C04C71ED24ABD39C158EDD027305F5F040FD929D4B03D3AFD8A1279B183FFBA68
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........`.....& ...".4...~......P..........c............................. ................ .................................................<...............................D...........................`...(.......................h............................text....2.......4..................`.P`.data...@....P.......8..............@.`..rdata..P+...`...,...<..............@.`@.pdata...............h..............@.0@.xdata..X............l..............@.0@.bss....0.............................`..edata...............p..............@.0@.idata..<............r..............@.0..CRT....X............z..............@.@..tls.................|..............@.@..reloc..D............~..............@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):282154
                                    Entropy (8bit):5.636827130073007
                                    Encrypted:false
                                    SSDEEP:6144:FlHWP0bUtZIWqt8DWHs3jhb4wcwl/9ZRvQQEkrl:FNvb+HE8SHs3dv/T58krl
                                    MD5:7B1FD1057A538352595CCEEFDF681DB3
                                    SHA1:0E71AC6B2A2BF88B70118C5FA379549F5898CE2E
                                    SHA-256:459322E7AB737DCCA893C7AD74C6BEE76DECCD86CBDACA0A9527168104DA8F41
                                    SHA-512:823A07A4352CB119D728C8E65614AC564BFFE28FC0A1B0BDD13D3251032D1C34BECB350AB1C731CD16477A09E637529DCDD57EE8AE33A315803A5FDB055F2B52
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........D..R.....& ...".....>......P..........m.....................................i........ ..............................................................P..L...............`...........................@D..(...................@................................text...............................`.P`.data...p....0....... ..............@.P..rdata..p....@......."..............@.`@.pdata..L....P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata...............4..............@.0@.idata...............6..............@.0..CRT....X............<..............@.@..tls.................>..............@.@..reloc..`............@..............@.0B/4...................B..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):480436
                                    Entropy (8bit):5.863390700343565
                                    Encrypted:false
                                    SSDEEP:3072:54jAh6snCOQPutssC+VE3b7MyXk/Uxl/+cinPSE0xxJuHhkrL:Jh2bh3bLXjxl/b0SNxmh4L
                                    MD5:4569280F74CC127A0A8570B39A583C55
                                    SHA1:79CEDE0B9C2BDAD697D59A32F7AA617682221644
                                    SHA-256:E6DEF34FD302F70B00BF93024A9F85B5DA5947FD055A990E49337F8107A750E9
                                    SHA-512:EC4EC951CCE30FDEC20CF30EC50632AB1EF69A151CD210A82BAF8371E17DDFA2164F50F2558BFADC9E299B21AFB3780906EBB3876285A9FA7940FD1C37FA0EF8
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".>..........P..........k............................. ......:&........ ......................................p...U......|...............@J..............l...........................@c..(....................................................text....<.......>..................`.P`.data...p....P.......B..............@.P..rdata...b...`...d...D..............@.`@.pdata..@J.......L..................@.0@.xdata..83... ...4..................@.0@.bss.........`........................`..edata...U...p...V...(..............@.0@.idata..|............~..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..l...........................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):19623
                                    Entropy (8bit):4.673944030439923
                                    Encrypted:false
                                    SSDEEP:384:mv9Ds18iwJOzu6b7b7b8eX7u+ogrZMl6vWTnMs:a9gCiwJ4Fb7b7b8/l6+J
                                    MD5:2EE8B80794D316236B93555E22F7DB69
                                    SHA1:DBDE31E51C268FBF680134DFC214EACD7F62E7B3
                                    SHA-256:9F0ED8B986EA820CA7CE46D0219C3309A149D9E030FA6D29C170DD4FDA6BC7E1
                                    SHA-512:74B9994A196C5A1C3D4110AC16E0EFDF3A415E2FA1E95E98D286C500547560C33B83534723B19533EBBEF45595F4FB166CE73270E1F81FF1248B580930AB756E
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........B..S.....& ...".....<......P.........`c.............................................. .........................................R.......d............P..@...........................................@@..(......................`............................text...8...........................`.P`.data...p....0......................@.P..rdata.......@......................@.`@.pdata..@....P.......*..............@.0@.xdata..t....`......................@.0@.bss.........p........................`..edata..R............0..............@.0@.idata..d............2..............@.0..CRT....X............:..............@.@..tls.................<..............@.@..reloc...............>..............@.0B/4...... ............@..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):3258844
                                    Entropy (8bit):6.42454283558418
                                    Encrypted:false
                                    SSDEEP:24576:mAmPl4tsPSkMJR5qdKgRI9R1j9fHdkkkkkkkkkkJfuBH/v3RN:CMIE2KgGRXuB/P7
                                    MD5:97503EEC52E517268B6DB695AFA8D8D8
                                    SHA1:120E26EF681E9DEBF5F1D2704D40788A81374FD2
                                    SHA-256:46994BBAD2EEFF320BB562EE966E16771ABB22C290DA74A96DFB09C31C619154
                                    SHA-512:C248A36A0C3D13F98B27A2E5CF6105B8DB239419550A934A07ECD654BF9EF24358332DA807A8B28C4CC1D958324FFF50A96E753F378785D3FAB12C0DE23BD8CD
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........n,.......& ...".....h,.....P..........b..............................-.....R.2....... ...................................... +.Rn....,.L*............)..l............,.p...........................`]).(....................,..............................text...............................`.P`.data...............................@.P..rdata..............................@.`@.pdata...l....)..n....).............@.0@.xdata..H....0*.......).............@.0@.bss....@.....+.......................`..edata..Rn... +..p....*.............@.0@.idata..L*....,..,...4,.............@.0..CRT....X.....,......`,.............@.@..tls..........,......b,.............@.@..reloc..p.....,......d,.............@.0B/4............,......l,.............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):189301
                                    Entropy (8bit):6.223989300733396
                                    Encrypted:false
                                    SSDEEP:3072:1J9ouvsbVQ8LlubhgpYnnAlZQAB9tWAQmM3f8jWgwls/EASfmM1M:TeuvsrluChXWAbMmWgwlsyfmM1M
                                    MD5:3EAE841634062119D9F09890580AAA40
                                    SHA1:A69EE63792A36E786C9F4540925FAE78E77700C3
                                    SHA-256:F028BBE17E13A724C1B27352C0A913E011C5AEC795ACF2ED7716165E23440BFA
                                    SHA-512:E162424FF00EA9C8481207E599D58BEA87A445E8263511703E2A84280B9520BFDE55797D45DCF6971D64BD248EFECC0BD7EB653D3A3AF0E0E53CAEDED5E00434
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".R..........P.........<f....................................`V........ ..........................................6...@...&..............................................................(....................E...............................text....Q.......R..................`.P`.data...p....p.......V..............@.P..rdata...!......."...X..............@.`@.pdata...............z..............@.0@.xdata..............................@.0@.bss..................................`..edata...6.......8..................@.0@.idata...&...@...(..................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B/4...... ...........................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):37287
                                    Entropy (8bit):5.541612106723831
                                    Encrypted:false
                                    SSDEEP:768:69T5p6gZwB4FJgoeVsSRiRlDkg4jJu3YJ:6p5twIJeVsSRiRlD3YJ
                                    MD5:74E656742519434DCBAD979D8A28EE65
                                    SHA1:E280BF8CD118F2CB932FFCA660250F83C94DF282
                                    SHA-256:93595FFC5EA945EB39E6D571A8225DA2C53935A58B1A408D29AB3BF6774DB26E
                                    SHA-512:5A14FB1349CB351F972A3EDC69BE2AB81B6639E078FB7B6078746BE9E5B5C63A0F78CAA6B394677721E9159D57602A0B0C2D369D30896AE99CB8205CDA52B6C7
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........p........& ...".....j......P.........,d...................................."&........ ..............................................................p...............................................R..(....................................................text....-..........................`.P`.data...p....@.......2..............@.P..rdata.......P.......4..............@.`@.pdata.......p.......F..............@.0@.xdata...............L..............@.0@.bss....0.............................`..edata...............R..............@.0@.idata...............\..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..reloc...............l..............@.0B/4...... ............n..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):105157
                                    Entropy (8bit):6.173482003245648
                                    Encrypted:false
                                    SSDEEP:1536:xz5xbJG9dz8m9opYJEPs4qA4dbV0z3kNLpHMB4Q6lzS:nXG9dzrqyhA4dbVoUNLvQ6lm
                                    MD5:660808EBEEB271E6C52DAEF5048CAC1A
                                    SHA1:A3C7B956267E1238A7DB96B5E3E537DA2E683C74
                                    SHA-256:68D482F13EA30586C0F487563324E894588C379A2999D0004EDD7028B1ACF270
                                    SHA-512:4367662A1678CF219D0CB0C77D9009610DCB8BBCACC93A94674995525DD3C4D049250893F27F2F96B63CDC873993524E05EC429066C08EA34AE0407713D8131D
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........^........& ...".....X......P..........e.....................................J........ ......................................p...)......\............@..............................................`"..(.......................X............................text...............................`.P`.data...p...........................@.P..rdata....... ......................@.`@.pdata.......@......................@.0@.xdata.......P......................@.0@.bss.........`........................`..edata...)...p...*...$..............@.0@.idata..\............N..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc...............Z..............@.0B/4...................\..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):38124
                                    Entropy (8bit):5.754263910108255
                                    Encrypted:false
                                    SSDEEP:384:bb9fNGZtlEhKZkWnyvVLPC5fvcdJ9nPEfaNcZJOWS7BhrOypAIra55M/Fu:P9fNGZ8sytzUfkdJ9nsyeZJFeAI1Fu
                                    MD5:3387FBF9D240CA0D69439AA7A56F7E37
                                    SHA1:9EB30567B61E8C86C69B078BDC3FA725622914E4
                                    SHA-256:4A1F150220CC745828F15A6F77FC16DCA0D4B9C4B3E44690CDA2129D6C0A190C
                                    SHA-512:694B896D906D821DD9F3B682869FA3194D49768A1275C51657E9300219D0D1F9144DE74021870BF5C35CED0AD37A7C1DE437F66EEA446BD1F86EC523C30C8027
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.X...|......P........................................ ......F.....`... .................................................................D...............|...............................(....................................................text....V.......X..................`.P`.data...p....p.......\..............@.P..rdata...............^..............@.`@.pdata..D............h..............@.0@.xdata...............n..............@.0@.bss....p.............................`..edata...............r..............@.0@.idata...............v..............@.0..CRT....X............z..............@.@..tls.................|..............@.@..reloc..|............~..............@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):33498
                                    Entropy (8bit):5.564451442653682
                                    Encrypted:false
                                    SSDEEP:768:d9e9z3adJ9Pr5gSs1xAdyburYRsyztJPZYuH2A:duz3q9PWSsDssJBPHv
                                    MD5:45F1A65ED814C0C86BC4A4616E1BA6D9
                                    SHA1:B9C0B4F327BF2F0D0E9E468CC967B17918B045B3
                                    SHA-256:1FD3AD4C979DE56174B07504C34D573E3824839198BAAA06473E88646B792ABB
                                    SHA-512:7B0EBF062CDC9828C70DEBB8227981D530064801445FE10FE2D9AD9F51F1292A73102A6755B8364EFB046246B41B89475EC9EDA62F19CE3BD31A8770418F6980
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........v..l.....& ...".F...p......P.........dl............................. ......z7........ .................................................................................`............................s..(.......................@............................text...@D.......F..................`.P`.data...p....`.......J..............@.P..rdata.......p.......L..............@.`@.pdata...............X..............@.0@.xdata...............\..............@.0@.bss..................................`..edata...............^..............@.0@.idata...............b..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..rsrc................l..............@.0..reloc..`............r..............@.0B/4...................t..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):176338
                                    Entropy (8bit):5.875368464272613
                                    Encrypted:false
                                    SSDEEP:3072:F2VVCzpF/ktxFBnU2ZZCI5/3J+g9ur5FXsF8T:skmH1llJorvsOT
                                    MD5:08B8E206C57E35B95B2F4576BFDA978A
                                    SHA1:1EFF2F6FCD53454A2AD3D8AF4679E0C355872DDF
                                    SHA-256:B85BA4EC193B955E6FF36EC9A14B3F60E52F7BFFE867C9FA1932040D3621F2C9
                                    SHA-512:4EF74B038706CFD507DD79B5A59F849C2AA4EE479C1EA8A83257956FE8A01F6A434F86F75DA951167FF746C52E6870B27D571EAF8305345DE0A877FCF800A675
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........>........& ...$.2...8......P.........d.....................................q.....`... ......................................@...(...p..........0...................................................@...(....................t...............................text....0.......2..................`.P`.data........P.......6..............@.P..rdata..P....`.......8..............@.`@.pdata..............................@.0@.xdata..`...........................@.0@.bss....0....0........................`..edata...(...@...*..................@.0@.idata.......p......................@.0..CRT....X...........................@.@..tls.................0..............@.@..rsrc...0............2..............@.0..reloc...............6..............@.0B/4...................<..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):103974
                                    Entropy (8bit):6.153679599111177
                                    Encrypted:false
                                    SSDEEP:1536:L07r8Vg7wsNwmUMdKx7l13XsGYrHlJLP/+8EjYmkWQZz8LfQ2M:ar8/sNRdKZ3cGyD1MYcQ6LhM
                                    MD5:08E0C9D5520049AAD2F459E606D9B8EC
                                    SHA1:09F48177670ECE6250FB28257FC10D4A23D85FB4
                                    SHA-256:2964BAE4C347877437E4DBEF9D21C2096AC11D1C19D8538DAD368B1325B06B10
                                    SHA-512:50BACCA09961BAB4B378EF1C8E9E63F4742B8FA9DB01532EC7DF1E0F0C32B3C36B105126A31A9720DD510887C011BF3B8F595EC262BB217D8703F2332B05C661
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".....z......P..........i............................................. ..............................................................p..H...........................................@[..(...................................................text....-..........................`.P`.data........@.......2..............@.`..rdata..p....P.......@..............@.`@.pdata..H....p.......\..............@.0@.xdata...............d..............@.0@.bss..................................`..edata...............l..............@.0@.idata...............p..............@.0..CRT....X............x..............@.@..tls.................z..............@.@..reloc...............|..............@.0B/4...................~..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1159948
                                    Entropy (8bit):6.380882269309101
                                    Encrypted:false
                                    SSDEEP:24576:mqeK7qOibql/URQe+M/SyM2m/AHuwjf9i1:mqepOiul/Uufl2m/WuwZi1
                                    MD5:F4CF11F766C87EB2EFB91B7BE2DBFFF7
                                    SHA1:A8669D5EC09AEC531C6EFB4A8BF96BB81FBEAFD3
                                    SHA-256:7B4ABAC4119866130CFD3254367E0C35FAB1987A11E7B311091FF0E3664D246F
                                    SHA-512:62BE9CFF51A52C8089A7EB62A46C3C6D3E3C050C6745CCCAC8AB32E775518B055C08E1C4FFFB86DB617806929A1493966BAFB9092E2835D4D3DECBBFFCB9B7F6
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........0.....& ...".........$..P..........h.............................`.......D........ .........................................R9.......-..............|t...........@..T............................@..(....................................................text...............................`.P`.data... ...........................@.`..rdata..`...........................@.`@.pdata..|t.......v...f..............@.0@.xdata...}.......~..................@.0@.bss....."............................`..edata..R9.......:...Z..............@.0@.idata...-..........................@.0..CRT....X.... ......................@.@..tls.........0......................@.@..reloc..T....@......................@.0B/4...........P......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):38449
                                    Entropy (8bit):5.168362177112994
                                    Encrypted:false
                                    SSDEEP:384:3vi9UsYYoqFP8/DWHJOgxxeBDLi5RPdfEq0+z+HeeyoEhytykWrcDaWIQdtkMK:fi9PKsU/DWHJRxeM1F0ZeelEnWzdtW
                                    MD5:416CABF3237F1C63701659B0B8B93DDE
                                    SHA1:130BF60FBEF1DD6A4BFE9C544C7EC835FAFE083B
                                    SHA-256:D2AFBDDF69FEC5AB9234406538745952BF74FC3DDE6A7FACA72A71E1BFB51540
                                    SHA-512:9C972681E9D35DD33135C3F71DC0FE9205DC60116FC2D6488E85C464665FE0E313DE70B7B919B35070C650A81C04BF80463E112925A84190233A490B73263A76
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........|.....& ...".&...~......P..........l............................. .......8........ .................................................h...............`...............<...........................@|..(...................,................................text...x$.......&..................`.P`.data...p....@.......*..............@.P..rdata...4...P...6...,..............@.`@.pdata..`............b..............@.0@.xdata..8............f..............@.0@.bss..................................`..edata...............j..............@.0@.idata..h............p..............@.0..CRT....X............z..............@.@..tls.................|..............@.@..reloc..<............~..............@.0B/4......$...........................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):177321
                                    Entropy (8bit):6.103041427092698
                                    Encrypted:false
                                    SSDEEP:1536:lO7waXMpkl4zNyZB/nA5jft1RxdJuUswu7ZIdk+Cwjcf15smC3dxK9ZPGqR3530:paYLNy/n6zPQZVIPCwju15sJqn3Z0
                                    MD5:B7D2A0436FCD11C93A670C537A7CA3F9
                                    SHA1:7E3F485D16D4186C965F6CF3687117E8A4FA2B81
                                    SHA-256:CAFF90F100117E14B80B569A97E271B5B20BF9F9CEF40DC3DE95A3C788DCBA53
                                    SHA-512:9C770CCD6733CA1FA9832618F7539CACD840AA4E9585FC31AC16E48353A9CC30B04B17BB92C08E26A54F6AA5179630BFBF2898149AB7B4726989EF863A933DFB
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........d..p.....& ...".....^......P.........0m....................................`......... ......................................`.......p...'.............................. ........................... ...(....................w..P............................text...8...........................`.P`.data... ...........................@.`..rdata...=.......>..................@.`@.pdata..............................@.0@.xdata..T....0......................@.0@.bss....@....P........................`..edata.......`.......$..............@.0@.idata...'...p...(...0..............@.0..CRT....X............X..............@.@..tls.................Z..............@.@..reloc.. ............\..............@.0B/4......,............b..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):45016
                                    Entropy (8bit):5.826549834253712
                                    Encrypted:false
                                    SSDEEP:768:Y9fxr0RJSwxvvDUwPOcnstT2jSVfmVq7YYAtG+oD2OFSATVyHjprL1P:YDeJBxvGcQSjukq0YKB
                                    MD5:5D694EF2B4A8485DBE7B999E9D157BEB
                                    SHA1:A76B953E82A52191D4E2E314DA08A6AA7AADD1BB
                                    SHA-256:9BC68903CD383D9433E20EBFDAEDD7E840B0CF09D1BB4B51C3C9EED2CDF1EBF4
                                    SHA-512:97BCC2654655D82212891A2B3D679D849397BB55052A5A9CE95745AD8D2A92ABD37A3BCBCFF7A60E9495CEF229C5D22CB24FDC8655E0F4726BD46C7F1F5DDD41
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".n..........P..........q.............................0.......)........ .........................................w.......................P...............`...........................`...(....................................................text....m.......n..................`.P`.data................r..............@.P..rdata...............t..............@.`@.pdata..P...........................@.0@.xdata..............................@.0@.bss....p.............................`..edata..w...........................@.0@.idata..............................@.0..CRT....X...........................@.@..tls................................@.@..reloc..`...........................@.0B/4........... ......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):217543
                                    Entropy (8bit):6.262587386570798
                                    Encrypted:false
                                    SSDEEP:6144:5WUtMhIF6VVJ1a4XD2zfAEJdZmNBuS7UHPCS:EUtELValJrSMX
                                    MD5:07DEB7B6C536FA43AE2C1A6ECCF14161
                                    SHA1:B89FA56216FC1E89D8E302A2ED9FD197FA86B07E
                                    SHA-256:1A846C6EA8FA60198C4E0FBB6F0521EC717B33E956D19E369DA853FDC3E0F237
                                    SHA-512:4F791B9727D4130389012F71F4AAEAA90F97CC11B645D2EBDD4528F80C9CDC0A591D2AB4E795E866A4F8242A6FCA4FC76F70CC4F62BD9912518C922EFB15B5F1
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".B..........P..........h.....................................)........ ......................................P.......`..............................................................@...(....................a..x............................text....A.......B..................`.P`.data........`.......F..............@.P..rdata..p....p.......H..............@.`@.pdata..............................@.0@.xdata..x....0......................@.0@.bss.... ....@........................`..edata.......P......................@.0@.idata.......`......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):30127
                                    Entropy (8bit):5.545406166525639
                                    Encrypted:false
                                    SSDEEP:768:Ik9iadsHIeD3LSYjUVqS76xuDVhT0Jn+j5:lxso/9/JmJn+j5
                                    MD5:DB43E0C412AF2682E720248B06258BD1
                                    SHA1:198A9E8CEE03FE28846D81C50B16EC3C7F8119C7
                                    SHA-256:3F525E791A423AE43707D19B4A635DC6526A005D83E90EB471A3FED83934D985
                                    SHA-512:C8356E95E096BCE12B8C574ECAB67B834F3D5F928909BDE473819E5A0C39D0718D044F3E2B8E77D8AEAABBF2419CB7C5F9CAAB49112DB4D03F9DB348540C2D76
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..S.....& ...".D...f......P.........tk....................................j......... .................................................................d...............l........................... r..(....................................................text....C.......D..................`.P`.data...p....`.......H..............@.P..rdata.......p.......J..............@.`@.pdata..d............V..............@.0@.xdata...............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............`..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..l............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1153736
                                    Entropy (8bit):6.016402131360048
                                    Encrypted:false
                                    SSDEEP:24576:pZUQ+U8i1uEvhr/cuHsSeMc5mQMeJh2ZVIKfck9:pB/R1u/uMnoeJM93
                                    MD5:EFF9D6946942E8F7775828A1756B0B6A
                                    SHA1:C4D07A5F7DBBEC4817EB151B2D5A857032AC17DD
                                    SHA-256:F21653D274C3DDF86E2AD1DA7F137DB83B30A3967BAAD61F801899BF06AE7796
                                    SHA-512:25F02F739C6A2F7FF6C8E0B05B89B9BF478FDFA7584FE2FC100EDC1AAB694F1ECE33BC51915084809807C34B882EB69C347B0D06F40D92AA5E019AEE62966813
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P.........hp.............................P.......W........ ..............................................................0..h=...........0..................................(....................................................text..............................`.P`.data...@...........................@.`..rdata...Z.......\..................@.`@.pdata..h=...0...>..................@.0@.xdata...^...p...`...L..............@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.......0......................@.0B/4...........@......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):345584
                                    Entropy (8bit):6.062856786074557
                                    Encrypted:false
                                    SSDEEP:6144:auBYK0UHvIIM07TlBmO8NqSlsHp9NZqMG2:aFevrj8OhZ9G2
                                    MD5:3109524E67A7F8FA6A2FB1DBCA23FC6A
                                    SHA1:57DBB8755F253184B2546F2D86ABE4400E9515AE
                                    SHA-256:317CFC114580BCDAB4EE24B39EBA2B87FD3F0B0C7978CC4E44231F77AA610B5C
                                    SHA-512:8047A7967089B25FA3B3270A8F68B486929967CDAD8F12F08840218F6FF24BDDED452EE6400C2489CC9B6766093B493C3D53432787D5136BD84CA16CDEF07080
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........f.....& ..."."..........P..........d....................................T......... ..............................................0..................| ...........p...............................b..(...................$5...............................text....!......."..................`.P`.data...0....@.......&..............@.P..rdata...0...P...2...(..............@.`@.pdata..| ......."...Z..............@.0@.xdata..` ......."...|..............@.0@.bss..................................`..edata..............................@.0@.idata.......0......................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4...... ...........................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):774548
                                    Entropy (8bit):6.418408919486473
                                    Encrypted:false
                                    SSDEEP:12288:vhFhyNWbJk9/WRTB47uHAFuzlavIeD/SWTD7fEWmPmDWNGbmls:vhFhy79sEF8l187TDQZ5W
                                    MD5:51797D661B4CDF3DD08BFD497EAAD017
                                    SHA1:9953A69C8B8136DBA08F392908B895980293E701
                                    SHA-256:0FBE942A4FFD237B7B2482F8A046CA633D3B18A8B79E5A2CCB4255F7D8DFF9A5
                                    SHA-512:E04DE093BF6C0E8BC49C0CBBFD50DDBC6167161CDCA60733ECE2731C710D9EA50B614F2A71A99B497236AF99EC7B5D08D4EC29BD5A04FF8459276B62AA359CBE
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........4.....& ...".2..........P..........l.............................................. .............................................. ..T....P.......P...C...........`..0............................4..(...................l#...............................text...(0.......2..................`.P`.data........P.......6..............@.`..rdata..p....`.......8..............@.`@.pdata...C...P...D...&..............@.0@.xdata...E.......F...j..............@.0@.bss..................................`..edata..............................@.0@.idata..T.... ......................@.0..CRT....X....0......................@.@..tls.........@......................@.@..rsrc........P......................@.0..reloc..0....`......................@.0B/4...........p......................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):43441
                                    Entropy (8bit):5.406163163366608
                                    Encrypted:false
                                    SSDEEP:768:j9UMlqf8MtMy4UrLSBusVUQSpJ9n1wDEpf+Q+cfM:jKMlqYz3oJqUf+H
                                    MD5:3E73162C0CFED3D76E4D194FC5F5F183
                                    SHA1:20DEEB5278913764CCA7EB4DE1AB8D9DBE65E372
                                    SHA-256:F90A3BB9280873A248F38D54431F46E152A7B634F4C6773A0C41952853CCD60A
                                    SHA-512:27B6BB3D65A953D4E19BD7ADC3B5D33EBDE644E590A61553736D5C004102A098FFB6E697F23803BA3ED8D48EFA6771C54C3E16601CBDE091F1E41B66CDDF9FB1
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".T..........P..........j.............................0................ .........................................`.......................................`........................... ...(....................................................text....S.......T..................`.P`.data...p....p.......X..............@.P..rdata..P............Z..............@.`@.pdata...............d..............@.0@.xdata..0............h..............@.0@.bss..................................`..edata..`............l..............@.0@.idata...............p..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..`...........................@.0B/4...... .... ......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):565393
                                    Entropy (8bit):5.1066638213809545
                                    Encrypted:false
                                    SSDEEP:6144:kwYmYW8e1aCKZ260YZ2OH5ufzyW7VoVxu7fjYd8wsrTbz3slPoxYHwdORaNEO:ezXe1hKZIOHkHalPoxYHYEO
                                    MD5:EC5082EFD58FEA602DD97CD824D3D9B7
                                    SHA1:E4CA5AE2C7513303D8046C98B9C973E79E3C0124
                                    SHA-256:F79BF5E08C71F1DB0735A22AB7DFB6751A82545BFAF1C70FBC18CF99B45B187B
                                    SHA-512:95B244FA646821DE6D5D980AF2BE92B3E5DB404C7175CE713C3FE7703A2124F8918E1BFEA8A0EADAFFEABA994BDC0E44B748C4E291568DB9769B20E11C36FDFD
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...3..a.f........& ...".....>......P.........Da.............................0......(......... ......................................p.......................@..................`...............................(.......................@............................text...............................`.P`.data...p...........................@.P..rdata..0*.......,..................@.`@.pdata.......@......................@.0@.xdata..H....P.......$..............@.0@.bss....0....`........................`..edata.......p.......,..............@.0@.idata...............8..............@.0..CRT....X............>..............@.@..tls.................@..............@.@..reloc..`............B..............@.0B/4...................D..............@.PB/19......!......."...Z..............@..B/31.....Ba.......b...|..............@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):842229
                                    Entropy (8bit):6.347233803892302
                                    Encrypted:false
                                    SSDEEP:24576:hs2Yj10eBIFszwJEwbPDY4TARDj8M2SRTpBPCJ:HFszibnTAR/8MppBPG
                                    MD5:4475108D84CCBB397F11956BC69C5D7B
                                    SHA1:C8B52585429F3A3343262E690D9013F928D594D0
                                    SHA-256:62D4939BE3E82B8EBE6E731BE3D8C45FABDB6E64B739D2FA64C3045FEAC64D8C
                                    SHA-512:BFF43FDF3E1DBF531F82C4F4C208E7C90CD44A0FE813224B5BA8FA839B160D509E080DFB8D01354FCC0B3D7F46AFB62BC4A0B79A11116BC320DB4409D140BB20
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P.........4l.............................@................ ..........................................b...0...[.......h......<H........... ..L...........................@d..(...................tC.. ............................text...............................`.P`.data...............................@.`..rdata.. .... ......................@.`@.pdata..<H.......J..................@.0@.xdata..|F...P...H... ..............@.0@.bss....`.............................`..edata...b.......d...h..............@.0@.idata...[...0...\..................@.0..CRT....X............(..............@.@..tls.................*..............@.@..rsrc....h.......j...,..............@.0..reloc..L.... ......................@.0B/4......$....0......................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):247824
                                    Entropy (8bit):6.1658005510125395
                                    Encrypted:false
                                    SSDEEP:6144:zTYOIokau6RgMRDAy6A/52h+y8moldlGVrSh:zpI/xKgMtAJ+kVrSh
                                    MD5:E75939B59B63E8CC8BC33AEE9CE71315
                                    SHA1:A080DDBB1BC3FC58366A04E2488B751B58C16EE7
                                    SHA-256:2FE733D3772E6426014D9A89FF4725D5AA787CE545EBC4C38D3794645A7F9ED2
                                    SHA-512:DB52BDB33154840195B8FF4C03B90E5D2C6EDF52A95EF7A9A968960289CF4E15120A30AE7AEBB52D965CEB383ACEF5C91204967543519913AF6FF9360C17C3B5
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........ ..F.....& ...$.&..........P.........D..................................... _....`... ...................................... .......@...2..............................@...........................@...(....................J...............................text....$.......&..................`.P`.data........@.......*..............@.`..rdata..0q...P...r...,..............@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata....... ......................@.0@.idata...2...@...4..................@.0..CRT....X...........................@.@..tls................................@.@..rsrc...............................@.0..reloc..@...........................@.0B/4......$...........................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):466711
                                    Entropy (8bit):6.054309228794742
                                    Encrypted:false
                                    SSDEEP:6144:lpf3LOMBhLY/RCyrWz+nhwdyxq4+SeGH9KDnfP2daNHgOLdPkMOPbBUrR:lR7FM/l+AKLXJ3RumF
                                    MD5:5A49616AA5CEE62E9446BAE37B746F6D
                                    SHA1:65BC9993ABAB3B7F6E0B4E8321BC0BC62D846B46
                                    SHA-256:AA366E9BBCEE47A5F52C6425539B427CE0F94E12AF3DF62F54B180D09F06A5DA
                                    SHA-512:EE0AE0E07C25FA34850375DF5B5D845FB1BFB7165287F286EE29F02AFE5D3DB8F9703A7CA0ED7731D8A49710683ED2234FB4A7C67072BD9F2BFFB37470DF8A15
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.l..........P........................................`...........`... .........................................x....................p...F...........@..,...........................@]..(...................\...X............................text....k.......l..................`.P`.data...@,...........p..............@.`..rdata..`...........................@.`@.pdata...F...p...H...Z..............@.0@.xdata..L0.......2..................@.0@.bss..................................`..edata..x...........................@.0@.idata..............................@.0..CRT....X.... ......................@.@..tls.........0......................@.@..reloc..,....@......................@.0B/4......(....P......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1735073
                                    Entropy (8bit):6.312685645644657
                                    Encrypted:false
                                    SSDEEP:49152:T24GYHS/8FT60qvkT97p2ER2iptNzvEMTEpajBj27W:XpFqvw7pXZtpvEkBj27W
                                    MD5:855C789C5C95B1DB4DC71079A7DDCCA6
                                    SHA1:138B6607053188DBCBC2CC66F60FBFA77FB08CE9
                                    SHA-256:1C3C2DBDF6AE20D090D64FA4970DF505F054196EEDC605D5AF862BE9E6E5F247
                                    SHA-512:7396936D59CEBC92AAFCC0041B5AD1DA23F2EF965AFD607820E5C783D597A975A5AFDAF4372A88BB0AB937C3995DC144CA42F03A94B5E4C284B2DBCED679E505
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.z.......8..P.........*...........................................`... .........................................\.......P.......`....................................................o..(...................d...8............................text....y.......z..................`.P`.data...p............~..............@.`..rdata..@...........................@.`@.pdata..............................@.0@.xdata...............x..............@.0@.bss....p6...p........................`..edata..\........ ...D..............@.0@.idata..P............d..............@.0..CRT....X....p......................@.@..tls................................@.@..rsrc...`...........................@.0..reloc..............................@.0B/4..................................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1264018
                                    Entropy (8bit):6.284739836376171
                                    Encrypted:false
                                    SSDEEP:24576:0JhIYfp45umxRIoYEb+0EIrLVeUtvMiQ3KYuue32c+bGA2n20:0JbuRIoYEb3Eo/tvDQhe3PA2n20
                                    MD5:2A952363638A702792FD3E3F01FBB294
                                    SHA1:7D8C696E187231B95DE431CAFF5CF160584B0D9B
                                    SHA-256:8E77DEE5D08D38AF2A3996872AAA3802F5BBEA746F3BC069BA336162D4E6B271
                                    SHA-512:7F192C5238F0F04583BF18504E1E33060FE558751754CF49165A20A231EC7CE05D87057BA911BBE105289D9228233FC9748C8C9BBD95A52C81CA87DEF2793B4D
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.:..........P........./..............................P......U.....`... .................................................."... ..........@k...........0..................................(....................................................text...@9.......:..................`.P`.data........P.......>..............@.`..rdata.......`.......L..............@.`@.pdata..@k.......l..................@.0@.xdata...e...p...f...V..............@.0@.bss..................................`..edata..............................@.0@.idata...".......$..................@.0..CRT....X...........................@.@..tls................................@.@..rsrc........ ......................@.0..reloc.......0......................@.0B/4...........@......................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):27553
                                    Entropy (8bit):4.972781576756485
                                    Encrypted:false
                                    SSDEEP:384:fp9GJSnNu9Kl4QATk8SJ5JOCmWQ1kk4phBoMdWuNggUMvoRm/+:h9GJSNTqFjSJ5JTrzdNxoRm/+
                                    MD5:07CA708B4DEF1C6F3DFDEA61695D8839
                                    SHA1:45E62109538EC88DF7C7C73E3C0AD6CAB76A6705
                                    SHA-256:69D7F3408899AD807C2C8C32D216E7656717DF3B17AAA23665F2D753C2ACEA21
                                    SHA-512:84F1AC0CE0B8F86BB841300512F8EAC671798466250C0D23D7BD7FA6B962D3426406ADFB49C6A4F5CE42556750CC78F91EB77868C207E9101E9EFF4C28815158
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........T........& ...$.&...N......P...............................................t.....`... .........................................O...............p....`..@...............`........................... R..(...................l................................text...($.......&..................`.P`.data........@.......*..............@.`..rdata.......P.......,..............@.`@.pdata..@....`.......6..............@.0@.xdata.......p.......:..............@.0@.bss....0.............................`..edata..O............<..............@.0@.idata...............>..............@.0..CRT....X............H..............@.@..tls.................J..............@.@..rsrc...p............L..............@.0..reloc..`............P..............@.0B/4...... ............R..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):331396
                                    Entropy (8bit):6.18993407003996
                                    Encrypted:false
                                    SSDEEP:6144:dIFL8cCAcE773yLLezHU6ChvVd0kN9KufbOMp7fPQlcKHyL+cRVj9wUdaguqhAGQ:dI98cCjE77gok1Bdf79KCHIqhAGQ
                                    MD5:2FF0DD6DA2BE0FFDAD5BE741D4670EEE
                                    SHA1:7FF3EB6F67E63662789137CEE296966409EB83D2
                                    SHA-256:6097E384FC2660ACC07448D76254ABEDD2ACC5EEA94F7CDD5164F78CDEF15FF5
                                    SHA-512:39009AB8D5D37AB193ADF0CB583AE5F1E7B4E9954B2AF76B230A9FBA7333B647D0CC830EFF94E87B38708E5EDCCDC5595A09F4DD81692062B7C57E7CF5D897EF
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........H........& ...$.....B......P.........u...........................................`... ...................................... ..;9...`..................\(..............X...............................(....................f..@............................text...x...........................`.P`.data... ...........................@.P..rdata..,...........................@.`@.pdata..\(.......*..................@.0@.xdata...!......."..................@.0@.bss..................................`..edata..;9... ...:..................@.0@.idata.......`... ..................@.0..CRT....X............:..............@.@..tls.................<..............@.@..rsrc................>..............@.0..reloc..X............B..............@.0B/4...... ............F..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1620492
                                    Entropy (8bit):5.399586686416974
                                    Encrypted:false
                                    SSDEEP:24576:H3lS39D/rMnrwg1KcArDfPJ3NEqOyu0w6:A9wIPJayu0w6
                                    MD5:3E9127BCFF638781329AC5EB55F93F22
                                    SHA1:A89D99F3EB77899502D52E4F56A090C6C548EE1C
                                    SHA-256:2F29E7E72B3D21B47FF3F7691602FB07799B667101D9081004C7FCC6211EFA84
                                    SHA-512:57A9456B3EE9B862E47404F7E683ADBD78D1F3CE5457DB7F98446E17CD18E93BEAC97FCE14899A673628E62A7D5F3614C8DCE0AA0B8C5217AD84A67DEEB2966F
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...O..a.J........& ...".....~......P.........`c.............................................. ..........................................4................... ...!..............................................(....................................................text...H...........................`.P`.data...............................@.`..rdata...C.......D..................@.`@.pdata...!... ..."..................@.0@.xdata... ...P..."..................@.0@.bss..................................`..edata...4.......6...<..............@.0@.idata...............r..............@.0..CRT....X............~..............@.@..tls................................@.@..reloc..............................@.0B/4..................................@.PB/19.......... ......................@..B/31..........0......................@..B/45.....PO.......P...N..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):18693
                                    Entropy (8bit):4.528202239487991
                                    Encrypted:false
                                    SSDEEP:192:3zd+9NcoRdTD+NkSEQVJYZ4D5JOgZQYS5/5WrcrDuTxadvlnv1fDSMy4gxc:3zI9FloEQk65JOdZ/5WrcfuTxIvYMb
                                    MD5:FDC4D49ED1B3032B025CFF09A95B8F83
                                    SHA1:BEAB58D6EF9A46640AFDB107100DBFDECBC15517
                                    SHA-256:65514E4D72D0D8061E902DFCDFE3808DA50B4F32E656AAD6DFA9995F3806ECD9
                                    SHA-512:E869246563A585B2C4C5AA69C832850E635D91AA31549DB6F7FB8D0DB5776D047D8888A67EAF950B1AD74AD8499530CA5F13EA1DC4294F514A328681200A8DF5
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........<..g.....& ...$.....6......P...............................................m.....`... .................................................<............P..................`........................... A..(...................L................................text...............................`.P`.data...p....0......................@.P..rdata.......@......................@.`@.pdata.......P.......$..............@.0@.xdata..0....`.......&..............@.0@.bss.........p........................`..edata...............(..............@.0@.idata..<............*..............@.0..CRT....X............0..............@.@..tls.................2..............@.@..rsrc................4..............@.0..reloc..`............8..............@.0B/4...... ............:..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):4508683
                                    Entropy (8bit):6.433770562702181
                                    Encrypted:false
                                    SSDEEP:98304:SttjZcj4G2MPzQNPhD6FfXmnsG2LtZZBHtlfZe:qusPPhD6FfXmnsG2LtZZBHtlfZe
                                    MD5:B5095CCB9599617A9B73FD30FA18D3DC
                                    SHA1:FFDCC0D95ABBD832A8C17CEF0BE3F3D9E090C51F
                                    SHA-256:029BBDA30C6831A99623232D4AEB571FEB40BA25D23EB415F267A95A88E8CD23
                                    SHA-512:83115869979F94BC3D16AAD01F137F5D9E33D048BB89E29A43F14BB7EA30E8832A6F937C2C034F71CED4486057BB59044E354951E314E9045B715CE3E02C8D57
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........=..-....& ..."..'...=..6..P.........xa..............................=.......D....... .......................................:..>...@<.p,....=...... 6...............=.............................@.5.(...................tv<..4...........................text...8.'.......'.................`.P`.data...0....0'.......'.............@.`..rdata.......@'.......'.............@.`@.pdata....... 6.......5.............@.0@.xdata........7.......7.............@.0@.bss.....4....9.......................`..edata...>....:..@...~9.............@.0@.idata..p,...@<.......;.............@.0..CRT....X....p=.......<.............@.@..tls..........=.......<.............@.@..rsrc.........=.......<.............@.0..reloc........=.......<.............@.0B/4......$.....=.......=.............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):27409
                                    Entropy (8bit):4.964297349134333
                                    Encrypted:false
                                    SSDEEP:384:p7Ic9A27Fd1w/wTfz1rJO8CVDccHxr6R+vHM5q:pMc9z/1wY7hrJyHG+4q
                                    MD5:67D79C4B05FB25A1949BB393A2B16CAC
                                    SHA1:DE7076655702E9846FD9F159BF8F74D4CBE76CA7
                                    SHA-256:26056FA23BB2935D82704C1327B8CC77DE198E8280A6D6C96E9C20ECDC547C68
                                    SHA-512:8343A5C14BE3491ADE0E1A8BD6BC08C9BEB62F53FF38D92CEA7D47E364F781BC286A1EF847EB8698D168DD84E47CC7664F7F7251D86545CEB19A38793BC5356F
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........P........& ...$. ...J......P.........$...........................................`... .........................................,....................P..|...............`............................B..(....................................................text...h........ ..................`.P`.data...p....0.......$..............@.P..rdata..@....@.......&..............@.`@.pdata..|....P.......2..............@.0@.xdata.......`.......6..............@.0@.bss....0....p........................`..edata..,............8..............@.0@.idata...............<..............@.0..CRT....X............H..............@.@..tls.................J..............@.@..reloc..`............L..............@.0B/4......(............N..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):499812
                                    Entropy (8bit):6.128024272252829
                                    Encrypted:false
                                    SSDEEP:12288:yvl6cydAiGIbA5C4L6dPR6tHKxxoxHNSX:4lzydqIbcC4LTHrNSX
                                    MD5:CC9D06CD608B52CEF68081D0116531AE
                                    SHA1:2921D881276A9E4E4B0F464F7577A87A1775B7E2
                                    SHA-256:05EFF375B699F1859345A57D12DD69A7BBA400227AD390EC5457450AF8164938
                                    SHA-512:682019587CC19CE6B8714820C9ABA9432F3F02CDE8CB46CBAB9BF5C5C98AC52BF80556E05700CF79184D4DB18814B22A40F6EF9E7A7643D84B93552E9CF2A690
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........C.....& ...$............P.....................................................`... .........................................B7.......................(...........p..h...............................(....................................................text...............................`.P`.data... ...........................@.`..rdata.. .... ......................@.`@.pdata...(.......*..................@.0@.xdata...*...@...,..................@.0@.bss.........p........................`..edata..B7.......8...:..............@.0@.idata...............r..............@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc..h....p......................@.0B/4......(...........................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):4212963
                                    Entropy (8bit):5.649808268951972
                                    Encrypted:false
                                    SSDEEP:98304:PnOmYdVXar7OF27UqJcaJN3o0phlTneFBnTQjEpC6uEeXV8uKQM0FBnTig3sGlDf:/nmVXar7OF27UqJcaJN3BhlTneFBnTFy
                                    MD5:4139419CECC783D9B4D3C9EE424B0BF5
                                    SHA1:01C51DD35658742E81D3D7F1DCE261AA0B5E2D23
                                    SHA-256:4DB8C65CE76705E98D631ABFBB68DBCBE5F65D458F443ADE023E7DF8C4D4E9F5
                                    SHA-512:5C14261F2688AAA2F03B9A48C38A38174DFC282089F589176655A1042459801E7B57B82CCF407955E7705D509C75C8C08C1B3F3928E29AFB76D5424EC5585732
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..;.T2....& ...".4...V......P..........j..............................;.....I.A....... ......................................p...Z.......................@..............l...............................(...................T....%...........................text....3.......4..................`.P`.data........P.......:..............@.`..rdata..@O...`...P...<..............@.`@.pdata...@.......B..................@.0@.xdata...I.......J..................@.0@.bss.........P........................`..edata...Z...p...\..................@.0@.idata...............t..............@.0..CRT....X............R..............@.@..tls.................T..............@.@..reloc..l............V..............@.0B/4...................\..............@.PB/19.....2".......$...d..............@..B/31.....2.... ".......!.............@..B/45.....D....."......>".............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1828620
                                    Entropy (8bit):5.253466292810523
                                    Encrypted:false
                                    SSDEEP:24576:mrEKjEdtkuSzStAgubyiI5C77Qyxvrf9F+snwbsz9fmwro:VSuShr79uwz9f1o
                                    MD5:0B1B553E27A096C0992FD4097A436CCD
                                    SHA1:6E2448532FB44F8EC46D4B5B561557B98A29856F
                                    SHA-256:D84F380277C4C9BA7880389119991F14C8813018357271272C1CFF796F7F35B7
                                    SHA-512:F2DD0B101E591513010BC69B8EF654131E8ED27227EDB65506FA8D05D5AF11C6DA3E1D5B0B3556C28D93E2B25F179EAD94B925A2466A9481E8C20A114D525355
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...D.2g..........& ..."............P..........p....................................h......... ......................................`...1.......2...............%..............|..............................(...................................................text...............................`.P`.data...0...........................@.`..rdata..............................@.`@.pdata...%.......&..................@.0@.xdata...)... ...*..................@.0@.bss.... ....P........................`..edata...1...`...2..................@.0@.idata...2.......4...P..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..|...........................@.0B/4......p...........................@.PB/19.....z.... ......................@..B/31.....Bp.......r...J..............@..B/45.....lw...`...x..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):3890963
                                    Entropy (8bit):5.754039230335163
                                    Encrypted:false
                                    SSDEEP:98304:lL9vISFTOwWb8FSayN/1ffiNcvZCKZMdwU9UNqlsgm4RmfT27ulQrW/gYoJwaJ6d:B9vISFTOwWb8FSayN/1ffiNcvZCKZ8wf
                                    MD5:FF0FDF6B69AB4CFC1E77B79C81FEF9E2
                                    SHA1:00D76BE4CBB76D8982C87EAD52DFC8B7D2A7A9A7
                                    SHA-256:3ABADDBD32309A2D0738F21973DD099009EFA5AA7C405900B6B83A0BF375E106
                                    SHA-512:5C25873C7810062E3CA2DC08DCCF8B4D5F6BDDC353B0AB1EDD3856C927B9A6D6132AFC70C60E39C18A4B0878AEBB1DF4E7D99D0D410D516D1C7A754F3F367A6B
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...h.2g.(7..)....& ...".....d......P..........e..............................7......j;....... .........................................lH... ...............0...:..............0...............................(...................0<...............................text...............................`.P`.data... ...........................@.`..rdata..0.... ......................@.`@.pdata...:...0...<..................@.0@.xdata...A...p...B...>..............@.0@.bss..................................`..edata..lH.......J..................@.0@.idata....... ......................@.0..CRT....X............b..............@.@..tls.................d..............@.@..reloc..0............f..............@.0B/4......`............j..............@.PB/19.....I............v..............@..B/31.....C!....#.."...6#.............@..B/45......z....$..|...X$.............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):345133
                                    Entropy (8bit):5.182285955432787
                                    Encrypted:false
                                    SSDEEP:3072:AD7RE26mNji6g83GPUylclorJ65kXV14Zfh+0Wb4A0+62yA9/Eah+QoGCR:AZE26mocGPUyDvXV1mh+N4ABoAYGCR
                                    MD5:B949CDDB858B0795A8632A6200C37D9D
                                    SHA1:C3C454CFE2D377ED9AA966CF3A02051C8F814D5D
                                    SHA-256:32295870F875EDFE5A75983CA69B6A84DFFBD2E7C46076F890E8634FA28B6626
                                    SHA-512:D15CEB7B91E36001A0EC5EE9AAA43B00885DE12FEEB1A9A37FA950E21C248241AA8B0118461DE9C12F9E9E8759EAFAF6550DA76894F7F9BD41B61F6E3E904447
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...X.2g..........& ..."............P..........b.............................@................ ...................................... ..e....0..|............................p..t...............................(...................<5..`............................text..............................`.P`.data...p...........................@.P..rdata..P........ ..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata..e.... ......................@.0@.idata..|....0......................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc..t....p......................@.0B/4..................................@.PB/19......U.......V..................@..B/31.............. ...^..............@..B/45.....0f.......h...~..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):351400
                                    Entropy (8bit):5.260188816489625
                                    Encrypted:false
                                    SSDEEP:3072:yaxJQcvhEuUFS0KXV/mzqaCrKzXOu0it2jYRSsw50hjDXrmijHp+:blhEdFDKXV/JCwitMYRSGDyijHp+
                                    MD5:DDE415C873EC1328626BA479A0097B43
                                    SHA1:1B135880BF0845E0A15B48261FB7C0E4670E36CE
                                    SHA-256:0898A5A5E7F6CEAD06AE27246CBAF55EA1E2DBB92065F0A9D4F8FB4EA5B03CDD
                                    SHA-512:CA175E597781A96C11AEAD9C4C9F78DFE0D16E0502339ABB732334F9D033152FD4024E50BD3A9CF50FEFE91EBB0ADDAD82CB10802E24EF9365CD04D4FEB9719C
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...o.2g....2.....& ...".x..........P.........pj.............................@................ .........................................P.......P............................P..................................(.......................0............................text....v.......x..................`.P`.data...p............~..............@.P..rdata..`).......*..................@.`@.pdata..............................@.0@.xdata..(...........................@.0@.bss..................................`..edata..P...........................@.0@.idata..P...........................@.0..CRT....X....0......................@.@..tls.........@......................@.@..reloc.......P......................@.0B/4...........`......................@.PB/19..........p......................@..B/31......'... ...(..................@..B/45......a...P...b..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):5680623
                                    Entropy (8bit):5.1807078105793325
                                    Encrypted:false
                                    SSDEEP:49152:tp2dXGRIJthx9rjNB/Y6q61Se9zZyes4XRZ1gJPKVXcQbQ+HfB8icFvROLU2K:teGCJth/rdVXcQb/fpLU2K
                                    MD5:6F0275ECC52F1D380F781E2EA5C6897F
                                    SHA1:0F3B4D023AF1126E1005CF3806276ABDD5778FB3
                                    SHA-256:5400EF6FB1234B7176677D9B2DD5A3785D9B8EE7B8AB1FFFC5F0723BC4DFF58A
                                    SHA-512:4BBBA1A4F64375C5C67AA54401DE79EB685360B8B7EFBEB159E0EC37A3458F4E37ACDD202D942BD3D1E1B54A6F5311B44DCAA29C69540A5C814C0212B7F24595
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...U.2g..S.......& ..."."...b......P..........f..............................T.....4.V....... ..................................................)..............XP..............t...............................(....................................................text.... ......."..................`.P`.data........@.......(..............@.P..rdata..P....P.......*..............@.`@.pdata..XP.......R..................@.0@.xdata...}...`...~... ..............@.0@.bss..................................`..edata..............................@.0@.idata...).......*..................@.0..CRT....X............X..............@.@..tls.................Z..............@.@..reloc..t............\..............@.0B/4...................h..............@.PB/19......U.......V...r..............@..B/31.....K....P$.......#.............@..B/45..........P%.......$.............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1068487
                                    Entropy (8bit):6.537919242293345
                                    Encrypted:false
                                    SSDEEP:12288:N5lfzOM6VJiPFmSY5Ynys5wNV8jBRuA47VudmKAtRokD8FUnTV5eTC:N5lf+FSBbFg0XZFUnTV5eW
                                    MD5:0D06E0B8CD4FC1739F1CA3B31382B5AB
                                    SHA1:7A8497FD27256DCA853A599A18A7FD766657828F
                                    SHA-256:D5FBFBFC47E4B5EC63B54C7985D38C60E2DEDD37623966F3639B3FD381CDCFF5
                                    SHA-512:58D35D42D3F7EA425933A0F97C921337D3EFCAEA52BCAF1365A23C5F4CA3694E08EC2F1D43DBA9FC0EFD5A5B2FA175771A49EDD380490C82692E5BDF02467160
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........K.....& ...".l..........P.........`a.............................................. ......................................p...8......\................>..........................................`...(...................0................................text....j.......l..................`.P`.data...`............p..............@.`..rdata...1.......2...z..............@.`@.pdata...>.......@..................@.0@.xdata...K.......L..................@.0@.bss....@....`........................`..edata...8...p...:...8..............@.0@.idata..\............r..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):3847574
                                    Entropy (8bit):6.25682704458707
                                    Encrypted:false
                                    SSDEEP:49152:13kWv94TxtcOhCncm/5/rgNqOZsbYDBfqDD+D8Cz4fC7lGJZ6XdTYKFQhAsaUsz9:13Z4Tr+b++GfdEdFszW6IWeOvb
                                    MD5:060E1037A1469B24939DB320A1BB653C
                                    SHA1:021EE6E7D1F48AF88731CA8A751D63F512B48E5D
                                    SHA-256:30A427E3BB3C053F2A27B04BF3C33D8F0A02D2DF63890D9766D9FDBEAD98A280
                                    SHA-512:B8B942A4FBC91A8C462150944F96F686D75FC9ECCD26CE97489CD32A66B52BB0D9D8634741D861CDF01AE89F5C050B8FD4BB33B15B232A3D4DE715A98D0A7B2F
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........7.......& ...$..,...7..:..P.........................................8.....G{;...`... .......................................6.5d...08...............4..............p8.............................."4.(...................058..............................text.....,.......,.................`.P`.data....H....-..J....,.............@.`..rdata..`d...P-..f...:-.............@.`@.pdata........4.......4.............@.0@.xdata..<.....5......t5.............@.0@.bss....@8....6.......................`..edata..5d....6..f...R6.............@.0@.idata.......08.......7.............@.0..CRT....X....P8.......7.............@.@..tls.........`8.......7.............@.@..reloc.......p8.......7.............@.0B/4............8.......7.............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):166156
                                    Entropy (8bit):6.032341889696207
                                    Encrypted:false
                                    SSDEEP:3072:fG5ACLS00SlJn08lbVZUw2Zkx6LIlilm2t1g1ap7L0+ONdgVLGx:fLktlG8Rl2ueIlilmY1g1aJopNdgVLGx
                                    MD5:BAF7406F38D5DF5FCBFA54988B6232C3
                                    SHA1:5CFD77A85DFEB4F12B98D7F16D23CAFF0BDB269E
                                    SHA-256:4462983084F84C66AF7C77DD5B25E3CF04FB22F8587E368DACE62E00B68F3552
                                    SHA-512:9F79DECC0949B26DA7CA0462C6743F8057ADD1DA1588C575BC411A6EFCC0C316F05AF51BBE16B9779122554489A81143AB58CE77A4F4212FF6E10C1401582F04
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........(........& ...$....."......P..........M....................................g.....`... ......................................@..c....`..4...............................................................(...................\f...............................text..............................`.P`.data...............................@.`..rdata...3.......4..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss......... ........................`..edata..c....@......................@.0@.idata..4....`......................@.0..CRT....X............ ..............@.@..tls................."..............@.@..reloc...............$..............@.0B/4...... ............&..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):98070
                                    Entropy (8bit):6.053721811697992
                                    Encrypted:false
                                    SSDEEP:1536:CvZswjoSLZBCQ3r78PIGO4hNm9uNY6UCi7EdZzR93aSDxW/ea2LeP5p8JmeXLi66:CB1joyIPjgAY6Xi7QR93aZ/aVxF2F3zF
                                    MD5:981594300418B252310860271E9AE83E
                                    SHA1:9B1CD2DD01EA56726C61741E9122EA0F2C918984
                                    SHA-256:CD6836A6DC5971B7BFFE718E48DDE7710851AC79F8A8C10D09AAD27F3A22B297
                                    SHA-512:A06B244274C4F579A88DA44EB4E3180303CEE4E2548872D488D0710D9655395D1ED33A8C3DF1552AA7ECFA5E664B8824B898816BE19F852FA69D34322764EA8C
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........d........& ...".....^......P..........a.....................................A........ .........................................C....................P..................\............................>..(...................h................................text...............................`.P`.data...............................@.`..rdata...O.......P..................@.`@.pdata.......P.......*..............@.0@.xdata.......`.......2..............@.0@.bss....p....p........................`..edata..C............8..............@.0@.idata...............D..............@.0..CRT....X............R..............@.@..tls.................T..............@.@..rsrc................V..............@.0..reloc..\............\..............@.0B/4...................b..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):82194
                                    Entropy (8bit):6.0362555944692975
                                    Encrypted:false
                                    SSDEEP:1536:pxUuRKm1lJLOynX3MkEbtDJDBZGHkJBk1aQUaBhCS6NK/aO:8/IpT4ZV2HU+aQb8jK/aO
                                    MD5:B1D17913D79C9B73F34D06D68F480122
                                    SHA1:27E7DA1F76B2CEC54CB6722150D879E34EC94ED1
                                    SHA-256:AEE0DAF699BB2295BBFFB854C569789D61F3FC5AC6AD0870EBAA7AAE71D5A5D4
                                    SHA-512:B39AAAA457023B4012CDD15CE37A2A49ECE89233F83B3F9F37B7A2D088E841489FD092767B0FFB4ECBF2EAC359034D725E0CF8A99C9B6FEBB8E5B2DD6115BA20
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........ ........& ..."............P..........p.............................................. ......................................P.......`............... ..................................................(...................$b...............................text...x...........................`.P`.data...............................@.P..rdata..............................@.`@.pdata....... ......................@.0@.xdata.......0......................@.0@.bss.........@........................`..edata.......P......................@.0@.idata.......`......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):354390
                                    Entropy (8bit):6.414795060934278
                                    Encrypted:false
                                    SSDEEP:6144:nRb7l/kP5EdWY/1Ww/8YcqhC6vhpjtwgmY6VQYHy060LSix/:RN/MMRtWw/BF/eaKy060Gih
                                    MD5:E0F118D905C704F3DAE86E5EB6C9FD3E
                                    SHA1:868DDFF9614EF5A9503C9FBD2992730EF4052F0B
                                    SHA-256:6CB70343248E41B5D491B587E8AF4CF71AC260B55D4DA5933ED5A1DDDD78DCA7
                                    SHA-512:A97AC43F042248BFAA5970E4E3E3DF31A65D5D1B128924AB766E484D4807CB36FF7F410980DD04D56001CA37485BC5E8B3A657F40AED366452E894DC5E000D96
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................L..!hT!.p sirgorc maonnaeb tnur ni SODedom.......$....PE..d...........*.....& ...".........2..P..........g......................................r....... ......................................@.......`..................................t........................... ...(...................|c...............................text...............................`.P`.data...............................@.P..rdata..p...........................@.`@.pdata..............................@.0@.xdata........... ..................@.0@.bss.....1............................`..edata.......@......................@.0@.idata.......`......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..t...........................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):762100
                                    Entropy (8bit):6.070183682990754
                                    Encrypted:false
                                    SSDEEP:12288:ntCvBJhZhpBzdeZkBLGphpDWJCDXYo4IYY7Kxd:tCjeGBLEhNWJCLKxd
                                    MD5:F277B55DBAB50F60F4110234920FCCBD
                                    SHA1:010FA2116343A2EEAC91C5458DAF942C939FF27A
                                    SHA-256:9550AC314F125D1FEA7351DD800CB0A06137F890C10D53AD40F021A962C97FBC
                                    SHA-512:CD39AB93E71D8AE03F058BEC3B9C2567702EC1811581D9382D725D39431E528D055D8094EABE0D8917CF8D6A605956352923DDCE4FBAB5ADC0E57DAB8E6A3C44
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................L..!hT!.p sirgorc maonnaeb tnur ni SODedom.......$....PE..d........P........& ...".....J......P..........p................>............................. ......................................p....................... ..................................................(...................................................text...x...........................`.``.data...............................@.P..rdata...o.......p..................@.`@.pdata....... ......................@.0@.xdata.......@... ..................@.0@.bss.........`........................`..edata.......p.......0..............@.0@.idata...............>..............@.0..CRT....X............F..............@.@..tls.................H..............@.@..reloc...............J..............@.0B/4...................N..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):329147
                                    Entropy (8bit):5.957449197471745
                                    Encrypted:false
                                    SSDEEP:6144:MAOgQxT8ZxPzE9cvnm98Ol+Mw5tJWfGCnRqGEFOwdje5hTT:MFgQxT8nzE9Em98OlPVfGCnRqGEFOwp2
                                    MD5:C6F5DF9383A8902D8E13A578C72FC2F9
                                    SHA1:D0ACE63E7A4AB4F62EDECD8AEA2F686957E62CE0
                                    SHA-256:E7BFDA6077198DEB0136EF1594FD311EBEE951606D7F9140EA302D55256DFECA
                                    SHA-512:1DC8DB4636D53B8C2E1261D6B2F66951D9B3AD861084A1C3A21CF4130835A3674C687A23EFC2BEC7C54065FFAD64381695EBCC628CB36694B12239D5BD45A59D
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........f........& ...$.:...`......P.........+T....................................*\....`... ......................................@..+;......d.......0....................... ...............................(....................................................text...88.......:..................`.P`.data........P.......>..............@.P..rdata..0....`.......@..............@.`@.pdata..............................@.0@.xdata..p...........................@.0@.bss.........0........................`..edata..+;...@...<..................@.0@.idata..d............:..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..rsrc...0............Z..............@.0..reloc.. ............^..............@.0B/4...... ............d..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):87457
                                    Entropy (8bit):5.601098622413987
                                    Encrypted:false
                                    SSDEEP:1536:5r9RdrCScVGhKlsB/0zm1JZMIuoRSKfpCMTaRa1iHSqHxE:l9RIS5/0zgIoRSSEMKa1iHSqHxE
                                    MD5:24AECFA6FDE66276275A8477904C45E9
                                    SHA1:35920C901F5126105C824141ECB138E447A13D36
                                    SHA-256:052077A4D2142930CEA0C2276EC8267C9B4C96174AB31F88AD095FFC679F5BF0
                                    SHA-512:0F9F0A1CFF7579437DF57D21936105AC9E431CF79B0146C67EAA4C162A2A17306CF2D2CA5732FD1E03330B5A61F51671AD6F57C0D7BE918B9DC2BC2024FB8232
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........p.....& ...$............P................................................n....`... ..................................................(...`..`.......t............p..|...............................(....................................................text..............................`.P`.data...............................@.`..rdata..............................@.`@.pdata..t...........................@.0@.xdata..............................@.0@.bss..................................`..edata..............................@.0@.idata...(.......*..................@.0..CRT....X....@......................@.@..tls.........P......................@.@..rsrc...`....`......................@.0..reloc..|....p......................@.0B/4......$...........................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):115051
                                    Entropy (8bit):5.634472441690908
                                    Encrypted:false
                                    SSDEEP:3072:HtSDzYA0UhIqHqHq7AiRsrLBG7fottfai3Qm7a7P7cN7uO1DAf:SYAzIGRRs0QttBGrI1u
                                    MD5:7E99586845BCC76AFCE740362632F8BA
                                    SHA1:F90E38C79BF60CD8B4FE81AED20FEDA1311C48C5
                                    SHA-256:56AA67AE75DB60D19160C9BC13F91CFD838DA02427E49954CD7288CEEB53A366
                                    SHA-512:04CA488E23764841BF26227087F94F35141450D2C3D641D064DA68688B88F9ABDD896C1DDFE1AFF92FC83341946CC37719F4394FD55BD7DE0A0771DBC21D458C
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........8..C.....& ...$.....2......P.........A.....................................=s....`... ......................................0.......@..p2..............p...............t...............................(....................I...............................text..............................`.P`.data...p...........................@.P..rdata...'.......(..................@.`@.pdata..p...........................@.0@.xdata..@...........................@.0@.bss....p.... ........................`..edata.......0......................@.0@.idata..p2...@...4..................@.0..CRT....X............,..............@.@..tls................................@.@..rsrc................0..............@.0..reloc..t............4..............@.0B/4...... ............6..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):113606
                                    Entropy (8bit):5.951391680564109
                                    Encrypted:false
                                    SSDEEP:3072:mgIGKirO8ao6L5IPQWbLzd3f0bPRe3q0M91jMgC:m3oEIYezd0bP50M91jMgC
                                    MD5:80575EC4DE0615EA9D2A3EFBB9EE1A5C
                                    SHA1:A76CC1FD5CBCAE8388E5887FC3B39C287866B385
                                    SHA-256:E63AB6A72FBECEE4471AF837E961BEC8448B22716CA1BB1F18505D468A1E5646
                                    SHA-512:4A79EF0A2168678195E7AF071CF3067E52710E1C098C305045AE7427566C4DE2C780B72A94B4F6098736BE5E8C2411CC355427A715BFFA75CF118347A668D676
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........`..[.....& ...$.....Z......P................................................G....`... ......................................p..-........#...........@..p............................................%..(....................................................text...X...........................`.P`.data...............................@.P..rdata...$.......&..................@.`@.pdata..p....@......................@.0@.xdata.......P....... ..............@.0@.bss....p....`........................`..edata..-....p.......*..............@.0@.idata...#.......$...0..............@.0..CRT....X............T..............@.@..tls.................V..............@.@..rsrc................X..............@.0..reloc...............\..............@.0B/4......$............^..............@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):284951
                                    Entropy (8bit):6.16927796191791
                                    Encrypted:false
                                    SSDEEP:3072:gmi4YPf5tgppPB/3KxIVq4yzR9rUUeMbaCmg/VWGIDc8q4RlQ6+PiaAtF/lEj:rCP3SvXkrvvm8IDcYRi6+ad7l2
                                    MD5:2CAB80FBA80EA4FB503A071D27ABF1A3
                                    SHA1:2804E415DDBAE00C16B873155529C26FDBC82E21
                                    SHA-256:B07B5953A13CFC33ED96AB1E028C703599D2676B84EA6DB26E42B0B690C37171
                                    SHA-512:62C733EF2CA2D5CF33C362F847084CD139031A6600E64E81E47180E52F4F11BF1D98FFE3BFBB7D409E3131B8E6FEB3316919251D42DC4B9D013761810572B740
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........H........& ...".....B......P..........i.....................................'........ .........................................5....................P..h........................................... ?..(.......................h............................text...h...........................`.P`.data...............................@.P..rdata...|.......~..................@.`@.pdata..h....P.......&..............@.0@.xdata..|....`.......,..............@.0@.bss.........p........................`..edata..5............2..............@.0@.idata...............:..............@.0..CRT....X............@..............@.@..tls.................B..............@.@..reloc...............D..............@.0B/4...................F..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):735923
                                    Entropy (8bit):6.433769847811494
                                    Encrypted:false
                                    SSDEEP:12288:8uWYdY3xY/Ji6gpWLIDu2plA5aRnxzzQ4AY:zVY3xY/JvgpW8D1fA5aVRzQ4T
                                    MD5:EC9B5BBBF6480C1D3CB4305FBFA964E9
                                    SHA1:5522D22D9F25CED0C2D3DDD4C4A3E7212D2D5034
                                    SHA-256:E2ADAB099A3280BB39B23E398AAEEB131EF422114AB843EEEEEA84E2D393EBF9
                                    SHA-512:B285C09D0BD8EDE5BB94408364E785E2718DE9D1BF0FE0DF695FD301CB5064547C3660770F9221B3B6A8F67EB664996E828E33118236ABE699FDEB58E82FD129
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........t........& ...".....n......P.........Pc....................................."........ .................................................,...............x3..............................................(.......................`............................text...............................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata..x3.......4..................@.0@.xdata..lO...0...P..................@.0@.bss....@.............................`..edata...............F..............@.0@.idata..,............\..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc...............h..............@.0B/4...................r..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):256789
                                    Entropy (8bit):6.36729961832555
                                    Encrypted:false
                                    SSDEEP:6144:qFV2YByNs8WxeWttNZRhx+Rp6CFhoXK4O9KCnqWtEfmF:yVx8WxfRhx+zFhSKtKCREfmF
                                    MD5:546AEF9D3B986B8211FACAF312BC6F9F
                                    SHA1:B19F84C8191E81BEDA3DB6B587647C0D5BBEE9CE
                                    SHA-256:CC2C2E273709439897F7A32159EB4D74E4E19B15FC1F92F92CCDA2DBCF3D2C72
                                    SHA-512:B6FCDBEA3444C69E6FD8016B02F723E9FBB1F2981D9BB9415A73E8B1BC81ACC5EB402942625693C5B5E9BF5D8BE856DC996537915C6D0FD610ECCC8499BA2F84
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P..........h....................................-x........ ..............................................................P..X...............p........................... 7..(...................t................................text...............................`.P`.data...............................@.P..rdata..`\.......^..................@.`@.pdata..X....P......................@.0@.xdata.......p.......J..............@.0@.bss.... .............................`..edata...............b..............@.0@.idata..............................@.0..CRT....X...........................@.@..tls................................@.@..reloc..p...........................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):88316
                                    Entropy (8bit):4.838596222049979
                                    Encrypted:false
                                    SSDEEP:768:w92MJy8UJhpPvFvPJiv7I7Bs5C+iOr6T/rxrc2YEpdAFdj:w0M0JXGv+3e6T/rxIFdj
                                    MD5:2A2B179C03BE99147C4B724E3C3F0EC6
                                    SHA1:5CC45BD900946A5CCB39606BE69DC7A02C54EB2A
                                    SHA-256:73C7B73EBFA3BBD18B8E10084197DA15F516E3B45B28CC1B576D1A0DA0E2A69B
                                    SHA-512:22EAE64D7718E5AAE77618C47542A7FFEA23317A23EAB9458D224D02A867B8321BEC2706626FC5321CA0A47F7A717F2C9E71947DD91BB78825554309605FAA93
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...@..a..........& ...".....<......P..........h....................................M......... .........................................i.......X............P..|...............`............................@..(.......................8............................text...`...........................`.P`.data...p....0....... ..............@.P..rdata..P....@......."..............@.`@.pdata..|....P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata..i............4..............@.0@.idata..X............6..............@.0..CRT....X............<..............@.@..tls.................>..............@.@..reloc..`............@..............@.0B/4......0............B..............@.PB/19......P.......R...F..............@..B/31..........@......................@..B/45..........P......................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):26189312
                                    Entropy (8bit):5.577547696726397
                                    Encrypted:false
                                    SSDEEP:196608:hwLfcteXpnzVyC/iM4yI63M+2iOp1/jQwAQkWAYmKtT8/zEucOuj/ZD0qXlYqKEd:hbLkjwTkhujV0qXlvjd
                                    MD5:226E92F75F84CFADE55E67BDBAC23087
                                    SHA1:E78F709A5E4A0EB5286B519AF5AB910BAD662BA5
                                    SHA-256:CDB43800431304675E4B454A7379AC558F33E511CA2A4AC0EA3DFF91C52EEDA3
                                    SHA-512:AC6E9C156DE235ED51CEF88A1C8E2DA40C1E73745F848398545B9BAFE25896DBA5BA9C8DCC40E7A01EB454857FA8C488A357711A4325C569B0D92390D6EC39B0
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....a.|f.|.....& ..."............P..........o............................. g............... ......................................p...9.................................................................. ...(...................t................................text...............................`.P`.data...`9...0...:..."..............@.p..rdata.. x...p...z...\..............@.`@.pdata..............................@.0@.xdata...j.......l..................@.0@.bss.........`........................`..edata...9...p...:...4..............@.0@.idata...............n..............@.0..CRT....X...........................@.@..tls................................@.@..reloc........... ..................@.0B/4...... P.......R..................@.PB/19......U...p...V..................@..B/31......i.......j...R..............@..B/45.....K....@......................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):40389
                                    Entropy (8bit):5.798464039126552
                                    Encrypted:false
                                    SSDEEP:768:Q9GQMXfVOZ8JytzUfkdJVnmWSRNJKomv7O7JD2F3l:Q0/fAuJyKsTEdJKomDA52F3l
                                    MD5:28D766F182AC56E1550EBB1BA05178F9
                                    SHA1:FCE30575E622FF53C1545D57785B8DF7BF613EAE
                                    SHA-256:3A801C25F33E677404F85664F372EEFD9D0BE5ACC0C3F81B659B05CFCF55A8E3
                                    SHA-512:C23236D3DAB638D806DE016FFF907BAC5EF53700C3529C1B4A0097E4B99D2B11CCD9CE17B7A62371317D2EC512CC105D181B995AC3D9B5CDE7AF0B090D995784
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.`..........P..........)............................. ......-.....`... .................................................................t...............|...............................(....................................................text....^.......`..................`.P`.data...p....p.......d..............@.P..rdata...............f..............@.`@.pdata..t............p..............@.0@.xdata...............v..............@.0@.bss....p.............................`..edata...............z..............@.0@.idata...............~..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..|...........................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):509760
                                    Entropy (8bit):5.835147726002544
                                    Encrypted:false
                                    SSDEEP:6144:Iy4lckklNynyIYaWrnLDSrwAB1eT2PhnoixlahbAsOkhsHu1nQbaL+cpDdO:IncN4ZWLDswi1Rhnh7aPhsQVVo
                                    MD5:A3762A140A807AD2389B26D69224B3DE
                                    SHA1:79771C20573693BE2C53CB9A8C753497FACE7429
                                    SHA-256:19D8747778C3E35177758C6E3400B1E806D6118C420912784A9DBD5067DCEF4E
                                    SHA-512:6FC8399E4E8775D3F7F2ABA7B2AC9B297E98E779CB597EC5412FE9636C020706E52B2BF631CFADCB4A6B978F712C07ACB6C1767D85C3BB74728C2A9B838C6125
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........`........& ...".X...Z......P..........h....................................p......... .........................................}........................ ..............0........................... ...(......................@............................text....V.......X..................`.P`.data........p.......\..............@.`..rdata..p............`..............@.`@.pdata... ......."..................@.0@.xdata...!...@..."..................@.0@.bss.... ....p........................`..edata..}............*..............@.0@.idata...............F..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc..0............Z..............@.0B/4...................^..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):485170
                                    Entropy (8bit):6.471136624247681
                                    Encrypted:false
                                    SSDEEP:6144:KAVs3QsAR3aEd92iLcM8Sdpe2NZCa/0RHygzuj7Hmx2rdxuBchY3:dsiplNZCK6tzuj7GwjBO
                                    MD5:BD9393441C4B449E0A021CBF629CC4AA
                                    SHA1:FF2F1FFE9BEC909E64E25BC994E8F04CAC923D52
                                    SHA-256:125F05AAB77AC2CC19D5AD707EDE401EDFE1A1B5005CCB468D56BE7DC3700836
                                    SHA-512:CF3FA3EF103C0FF13B8416BC26666D19F5D05C285207148C1486D0C4805AF3E5705D46170C6A6F6DD6DC90551FD89F024D2BF34C2A757CFBEAA271983E94BC13
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........8.....& ..."......... ..P..........a.............................p................ ..........................................;... ...............P..h+...........P..............................@...(....................!..X............................text...............................`.P`.data...............................@.`..rdata.. ...........................@.`@.pdata..h+...P...,...2..............@.0@.xdata..h1.......2...^..............@.0@.bss..... ............................`..edata...;.......<..................@.0@.idata....... ......................@.0..CRT....X....0......................@.@..tls.........@......................@.@..reloc.......P......................@.0B/4...........`......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):66133
                                    Entropy (8bit):5.73685267962144
                                    Encrypted:false
                                    SSDEEP:1536:fPujTmyf1exgBF9gJtim3YN5gqRbymzDX:vyYwmtim3YNvbfzDX
                                    MD5:9BDFBAD6C1CB82B3F93190D134EE3B21
                                    SHA1:EDE0F18E0E784012150963DD6D51916ED2A7E34A
                                    SHA-256:2ACE26664A0C7CD723874652805DEA3748AD21F6CF4BB22A197A785327D5CE7E
                                    SHA-512:FF47C5BFC2F9CDD1AF3B2A8B22F9838D44D7E22230423BA0C2B55B72DD3C1BE7A701A50C13E5694E48F97B704B4BFAA5CAA7FF083A3125E6A2AEF945F908083E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P..........d.............................p......0U........ ......................................................@..P.......8............P..`........................... ...(....................................................text...x...........................`.P`.data...............................@.P..rdata..@...........................@.`@.pdata..8...........................@.0@.xdata..h...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....`.... ......................@.@..tls.........0......................@.@..rsrc...P....@......................@.0..reloc..`....P......................@.0B/4...... ....`......................@.0B........................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1452692
                                    Entropy (8bit):6.405789258500374
                                    Encrypted:false
                                    SSDEEP:24576:+7cxVEcfOOzjoebRBg7sbqu5EvYW3V71HTOqZyU4:+7cxGsO3q3g2quM9VZKq4
                                    MD5:25AA4BCF34DE86D8D46E6AEF8D77A89B
                                    SHA1:BF4431F6D24EBF2EFB02A1BF3F5AB046DA221EFF
                                    SHA-256:5A97D215807F9DA14F99D2CFBF944145CC43E79D99E72AAFA4E8660A7788E5B5
                                    SHA-512:1B11882E1579F031F94AC0F9DD9968B84B0F5C7B13FEAA2A9CD4E527A1BC484A6076FA8D33441F429F0F4624955FF29FA3EB96C93BBCCFD61BE692D1D5CF14A1
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........|..P.....& ...".....v..."..P..........p.............................................. ..................................................................~.......................................... s..(.......................x............................text...x...........................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata...~..........................@.0@.xdata...{... ...|..................@.0@.bss.... !............................`..edata..............................@.0@.idata...............F..............@.0..CRT....X............Z..............@.@..tls.................\..............@.@..reloc...............^..............@.0B/4...................z..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):160185
                                    Entropy (8bit):6.105313141781387
                                    Encrypted:false
                                    SSDEEP:1536:MG+3ibUAGPWNxY4xOfrMEm+75SJVmmzloC2FsEJ9WLW86UAmkV8N6To1a0gwlcfa:G19o9AjMk8O/cdlA38ADml3
                                    MD5:194E5927747D12886E7FFD073977CFC3
                                    SHA1:4D84D14044DAFFC6E5186D97BADE88DE6D9C4ABE
                                    SHA-256:BCCE9990533144B2873E26758290CFA2E52032CEC0BC0B8F91292B86F4493FA8
                                    SHA-512:2533AC20880C1EA389D85C11C2131527E305E79110CB1FDA35A29329620234CC6825B086A82DC5077F29487CD9E227605871CD19EC01F59D016296AB3EFC3FEB
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........"........& ..."............P..........d.............................................. ......................................@.......P..................................d...............................(...................hT...............................text...H...........................`.P`.data...............................@.`..rdata...9.......:..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss.........0........................`..edata.......@......................@.0@.idata.......P......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..d...........................@.0B/4................... ..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):123873
                                    Entropy (8bit):6.327673262113837
                                    Encrypted:false
                                    SSDEEP:3072:SgRq5sPDRAED8/IGd+kZKjA0fxTBfoyQaPzWwDS:SgRtPDeED8/IU3ZK3TB9QaPzWr
                                    MD5:D8851061A755A675A6CDEBE9984C882E
                                    SHA1:80429536CDEE9B48AC41D749BAB5436FD7E5384E
                                    SHA-256:AC43FDBE8D4B5B3DBFE436730B77CDADEE7C583F9D6B0CC5E2AB642446E2F60E
                                    SHA-512:B95E6A3581A58EED9EF9E417ADB7788F3F8782C25660DBAC727131EFBC30281CA4184E5D20366822BD21ABB146CB1FE69CCC6C280DAF6C7BFCCBBA114B965A4E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".6..........P..........e.............................P......2......... ..............................................................................0.................................(.......................h............................text....4.......6..................`.P`.data........P.......:..............@.P..rdata..@X...`...Z...<..............@.`@.pdata..............................@.0@.xdata..\...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.......0......................@.0B/4...........@......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with very long lines (301), with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):1735
                                    Entropy (8bit):5.112605138685413
                                    Encrypted:false
                                    SSDEEP:24:tvY5MS2l5MS22cpMS2epMS2bcpMS29C8CjzivCB6MB+C40NLkCddeyC7vC0jYzV2:BGDjzbgMBZNdUupzMLtFRkG+8waj
                                    MD5:26D2EF3EC4188D38C874BD2F445AD353
                                    SHA1:69B0CACC173FFDED97CAFBC8DE351DAF2699A27A
                                    SHA-256:5363E2B9349A32B28EADBB58AE7EADB283D2C7E3A544FEA4790228A5C4715131
                                    SHA-512:48CFDD170099CD4EA8D271188F134D686982A4031BC2864D5FA6B497D552D10FC06A1F3D2B2D821A89B069BD933EF6AB26B01DF3B856BB87ECDC61744257BC2B
                                    Malicious:false
                                    Preview:# GTK+ Input Method Modules file..# Automatically generated file, do not edit..# Created by Z:\usr\i686-pc-mingw32\sys-root\mingw\bin\gtk-query-immodules-2.0.exe from gtk+-2.17.11..#..# ModulesPath = Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\2.10.0\i686-pc-mingw32\immodules;Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\2.10.0\immodules;Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\i686-pc-mingw32\immodules;Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\immodules..#.."../lib/gtk-2.0/2.10.0/immodules/im-am-et.dll" .."am_et" "Amharic (EZ+)" "gtk20" "../share/locale" "am" ...."../lib/gtk-2.0/2.10.0/immodules/im-cyrillic-translit.dll" .."cyrillic_translit" "Cyrillic (Transliterated)" "gtk20" "../share/locale" "" ...."../lib/gtk-2.0/2.10.0/immodules/im-inuktitut.dll" .."inuktitut" "Inuktitut (Transliterated)" "gtk20" "../share/locale" "iu" ...."../lib/gtk-2.0/2.10.0/immodules/im-cedilla.dll" .."cedilla" "Cedilla" "gtk20" "../share/locale" "az:ca:co:fr:gv:oc:pt:sq:tr:wa" ..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:Unicode text, UTF-8 text
                                    Category:dropped
                                    Size (bytes):890
                                    Entropy (8bit):5.202678107381836
                                    Encrypted:false
                                    SSDEEP:24:4MxI1KhRFJSk4VXpUb9GyJyk1jwiv3+3+Wk+ppJajhvxm7:XI8hrJT4Z49GyJRhv+OMShk
                                    MD5:C358838E1789C1D4E6DA7F525FC922CF
                                    SHA1:576FFC2F578A8B78B2295584C059338D976C485A
                                    SHA-256:D52DFEA88F5964B7581C93CDEA1A3E47DD7B1D8334E8F5EB53018711428221ED
                                    SHA-512:524FCCB13EAE05A54297320119626B668BD3F615772931F068344395A73CED6363A580B64431B9F739F15920CE541BBC5375FE4D399A749C52E75B73560CC778
                                    Malicious:false
                                    Preview:# Example configuration file for the GTK+ Multipress Input Method.# Authored by Openismus GmbH, 2009..#.# This file follows the GKeyFile format. On the left of the equal sign goes.# the key that you press repeatedly to iterate through the text items listed.# on the right-hand side. The list items are separated by semicolons ";" and.# consist of one or more characters each. The backslash "\" is used to escape.# characters; for instance "\;" for a literal semicolon..#.# The example configuration below imitates the behavior of a standard mobile.# phone by a major manufacturer, with German language setting..[keys].KP_1 = .;,;?;!;';";1;-;(;);@;/;:;_.KP_2 = a;b;c;2;.;.;.;.;.;.;.;..KP_3 = d;e;f;3;.;.;.;.;..KP_4 = g;h;i;4;.;.;.;..KP_5 = j;k;l;5;..KP_6 = m;n;o;6;.;.;.;.;.;.;..KP_7 = p;q;r;s;7;.;$.KP_8 = t;u;v;8;.;.;.;..KP_9 = w;x;y;z;9;.;..KP_0 = \s;0.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:SVG XML document
                                    Category:dropped
                                    Size (bytes):2285
                                    Entropy (8bit):5.039478352344204
                                    Encrypted:false
                                    SSDEEP:48:4JWROXUoAtH6d5koN40ezkozdme+oVLrvenoDRkQxofWGno3DGholm8:4bEo5TkouxzkoZ3+oVveno9Dxornoahq
                                    MD5:A7E34846279F076184736ED26698BA27
                                    SHA1:99B7EDF0357CCB7BE4E44D13457EF87741C8504B
                                    SHA-256:299E2323EBED8FC0A7E5DDB793F0057BFFEAA380DC6E81C40AEBD0D518D3BFC5
                                    SHA-512:56CB068CE560FF9BE8A68FD41A06170EC10CAC55EA7E48CCBBE33E8CF8839D44090597D45C4BB333D0374F3C022BA03612A9EC955935CBA1FC3F5F02FEDAE339
                                    Malicious:false
                                    Preview:# GdkPixbuf Image Loader Modules file..# Automatically generated file, do not edit..# Created by gdk-pixbuf-query-loaders.exe from gdk-pixbuf-2.36.7..#..# LoaderDir = Z:\usr\i686-w64-mingw32\sys-root\mingw/lib/gdk-pixbuf-2.0/2.10.0/loaders..#.."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-ani.dll".."ani" 4 "gdk-pixbuf" "Windows animated cursor" "LGPL".."application/x-navi-animation" "".."ani" "".."RIFF ACON" " xxxx " 100...."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-icns.dll".."icns" 4 "gdk-pixbuf" "MacOS X icon" "GPL".."image/x-icns" "".."icns" "".."icns" "" 100...."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-jasper.dll".."jpeg2000" 4 "gdk-pixbuf" "JPEG 2000" "LGPL".."image/jp2" "image/jpeg2000" "image/jpx" "".."jp2" "jpc" "jpx" "j2k" "jpf" "".." jP" "!!!! " 100.."\377O\377Q" "" 100...."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-pnm.dll".."pnm" 4 "gdk-pixbuf" "PNM/PBM/PGM/PPM" "LGPL".."image/x-portable-anymap" "image/x-portable-bitmap
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):30126
                                    Entropy (8bit):5.1562988744270495
                                    Encrypted:false
                                    SSDEEP:384:5o9wlaBZB9XoxgkjuYbBnT9mJOkkYcHFPI6QsrKlwAzAzCBan+SbsyJFMOYM8nLO:29UiZB9Xolj/9ToJMYgczi8LO
                                    MD5:2A2C6A330D616B4C28CBEACCEF01F602
                                    SHA1:44B066A2144D46B6668CA25D501CB983E2832BE0
                                    SHA-256:44FADD8CBF6DC4D96D97DD709D8BA9293C2A1958589AD586725B49539CD791A5
                                    SHA-512:5DF8AF980E20504E328A02C148E528DC9ABEF588C6449D3E17619B070680F175E0CF0501E70141DDBF1EF216FCA3F75CE94966CDE22AB0DAF0CD08E244B7E75A
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........X........& ...$.*...R......P.........).....................................m.....`... .........................................j....................`..................h............................R..(....................................................text....(.......*..................`.P`.data........@......................@.P..rdata.......P.......0..............@.`@.pdata.......`.......:..............@.0@.xdata..(....p.......>..............@.0@.bss....0.............................`..edata..j............B..............@.0@.idata...............D..............@.0..CRT....X............P..............@.@..tls.................R..............@.@..reloc..h............T..............@.0B/4......$............V..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):24091
                                    Entropy (8bit):4.832512351006504
                                    Encrypted:false
                                    SSDEEP:192:8Qa/9cKXc+FZ65O+q/odIodzyrgsmrM6liSIJOL/MP6OUSUMrFK4ST/Xca+DzfGa:JG9k2xKI8zsmI6UVJOr3QrFy8DzM9to
                                    MD5:7BDB63482497F7E2DF8179E9366B2367
                                    SHA1:938809EA5EF6A7446A490ECB35B07D8CA173B50A
                                    SHA-256:29B03D6CC8829FA074F7E6DAA4A6D12EAB76BC2B73E8A1312869BCC1175A439F
                                    SHA-512:7A1190B78C77FDC7FCC33C0D29CACAFEAC1437B3B79BF5C2F379526F8C372043F471188E5F6F63B293005A66060A08B76B9062183D9F9F955F424BDCB6D00101
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........H........& ...$.....B......P...............................................=.....`... .........................................k....................P..................h...........................`A..(...................T................................text...............................`.P`.data........0......."..............@.P..rdata..`....@.......$..............@.`@.pdata.......P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata..k............4..............@.0@.idata...............6..............@.0..CRT....X............@..............@.@..tls.................B..............@.@..reloc..h............D..............@.0B/4......$............F..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):21617
                                    Entropy (8bit):4.933393529217816
                                    Encrypted:false
                                    SSDEEP:384:W+9s/PiIc1YdWyRZJOIC1b+Om32wrcJasMpUM0g:L9sn9cI/RZJW1b7Jxa3p4g
                                    MD5:5BCA09AC3BA1B34936BAE00317A37BA1
                                    SHA1:8D23B02E6F7642F1E21651DAC2176CEB5759C62E
                                    SHA-256:BCD2AC658D965765CB6184371CF4CAD30B317AB73038F5545FDFE3CDEC4D0436
                                    SHA-512:D59D5375809DCE16DBB05B712FBDF9496113A9D382E7D2D50EC604D1AC4322B75142DFA214616038FEC214D78E077D098D2054939A766E9BABD69FA4FC58F336
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........B........& ...$.....<......P.........7e.....................................9....`... .........................................m....................P..................t............................B..(...................$................................text...H...........................`.P`.data........0....... ..............@.`..rdata..p....@......."..............@.`@.pdata.......P.......,..............@.0@.xdata..\....`......................@.0@.bss.........p........................`..edata..m............0..............@.0@.idata...............2..............@.0..CRT....X............:..............@.@..tls.................<..............@.@..reloc..t............>..............@.0B/4......(............@..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):26886
                                    Entropy (8bit):5.108100184101569
                                    Encrypted:false
                                    SSDEEP:384:jR9lVYrU3ST1sz/eV9HYLkKHBV9PJOB9WSrLOY1Jv1TMNw+n4G:19RCT1szU4oO79PJOJz+9
                                    MD5:72872FEC2D06F5F60B6A7D3677B507B8
                                    SHA1:06D6CF1C80A29151C01C0ABD9F9BF32C3D83C8F9
                                    SHA-256:3D3BD153613C84F709D13D1F3AE519BDFA0B5238C7A1491C7DD71D310ED5202C
                                    SHA-512:6B3EB4DE80A5ADAD5324E09913EBC3DEC4C1B8F122E053662A7938379BEF4FFB1BFF4A8CCD7ECF66FF4437889FE106BDDDD720129A114F6F7F3664CF61D39EBF
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........V........& ...$.*...P......P...............................................yC....`... .........................................j....................`..(...............|............................V..(.......................p............................text....(.......*..................`.P`.data........@......................@.`..rdata.......P.......0..............@.`@.pdata..(....`.......>..............@.0@.xdata.......p.......B..............@.0@.bss..................................`..edata..j............D..............@.0@.idata...............F..............@.0..CRT....X............N..............@.@..tls.................P..............@.@..reloc..|............R..............@.0B/4......$............T..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):24286
                                    Entropy (8bit):4.927914456719635
                                    Encrypted:false
                                    SSDEEP:192:0jc9d+lXb2FZqo9B+1M3+TEZSk3sCJOQCDSd/7cdVJlQrzgM+3DmAPLfk8SMy4KF:6c9ySvP+tTExJJOqd/+JlQrz511MrG
                                    MD5:F09B8C98DE983C84B31D5F82658C2D50
                                    SHA1:C6C87C4FF7F6DB071B2DBB04F3BF61FAE862DB49
                                    SHA-256:2AF25E0CFD858AF6D37F494B70A2DA0E7AE081305B2B4761D2123F77146D3B4E
                                    SHA-512:88EA21CC4C29228A5C0B7D722311D037FB573EF1389B5F962BAF1532FFAEC1B5D7E4FA2F8C36AD446534ABCA39D319F2E8CF1AB46501992DBFE7B3677FF4AD24
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........J........& ...$. ...D......P.....................................................`... .........................................k....................P..(...............p........................... C..(...................$................................text............ ..................`.P`.data........0.......$..............@.P..rdata.......@.......&..............@.`@.pdata..(....P.......2..............@.0@.xdata.......`.......6..............@.0@.bss.........p........................`..edata..k............8..............@.0@.idata...............:..............@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..p............F..............@.0B/4......$............H..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):30548
                                    Entropy (8bit):5.263790902307366
                                    Encrypted:false
                                    SSDEEP:384:9G9TTB/I/z/fwQ5FZ+w5TMmACnfdLr9JOfcouFmkxrKlPVCCAxMlhnGwdd:I9v8/oQooTxACf1r9J+CLXuhpdd
                                    MD5:56830F89D9B89F0C88424D90533BF4D6
                                    SHA1:FCF79D5DEE3FD05B2BEB66D83CDF82E61D1C04BB
                                    SHA-256:687693FB3300923B267D03686AF35C80E8C3DAA42D49FC3E0D8600E10812084E
                                    SHA-512:DB0936B39851CBC8BD1F8F0135C1FD64098E484DF7A004A3D9EF6D01EBADE9A9D589C492B90E44660E59661B8582EAB0FEC75A82550F78670D9BA48DF7501833
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........^........& ...$.....X......P.....................................................`... .........................................j....................`..................|...........................@V..(...................\................................text...8-..........................`.P`.data........@.......2..............@.P..rdata.......P.......4..............@.`@.pdata.......`.......B..............@.0@.xdata..@....p.......F..............@.0@.bss..................................`..edata..j............J..............@.0@.idata...............L..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc..|............Z..............@.0B/4......$............\..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):66472
                                    Entropy (8bit):5.830247127893983
                                    Encrypted:false
                                    SSDEEP:1536:cTrnuJJmCbd/iY1wdy3nFMhKvCcHsxBklaRsfxr1HWBJJFh:Nlbd/vudy3nO09HkOaal1H0JJFh
                                    MD5:AE9468F874D41ADC6BBE50517AA4DE49
                                    SHA1:67B4C3205A16BD5850AA634C6FCA4AB2D724A479
                                    SHA-256:EC4D4DB3B2ADE9A1EA7514636FB31393D846D4485DDCE34EBFE5B6F6C6538046
                                    SHA-512:158F0159A04253BBD84C05784C4455B8AFC1E0720BAFA4AD84925530B51CC8E4C8769F91CCA89F1477EE4763352E20307DDA4444FB9AE2E7AED9440C147C6371
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$............P....................................................`... ...................................... ..j....0..x...............\............`..p...............................(....................2..@............................text...(...........................`.P`.data...............................@.P..rdata..............................@.`@.pdata..\...........................@.0@.xdata..0...........................@.0@.bss....0.............................`..edata..j.... ......................@.0@.idata..x....0......................@.0..CRT....X....@......................@.@..tls.........P......................@.@..reloc..p....`......................@.0B/4......$....p......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):80788
                                    Entropy (8bit):6.041649105323227
                                    Encrypted:false
                                    SSDEEP:1536:BBFJ+tarN78biYYwd83vFshk9/hfrJaBk1aaM/WZrM3yH8Kdsqx6GOk8L:flrN78bvVd83vu+zrk+a96M3yH89e6GG
                                    MD5:3B1E243B7701AC33E9435F14BC0E38CC
                                    SHA1:EB6D29A69A15D0EF1724B2C3A6848CD3F9F08D54
                                    SHA-256:1CD03652C78629DBD9B5CC1861E16FE4C89D2A1F43D864C145E47AF8B8107D73
                                    SHA-512:188486869BFE1BD2D02550249D2C86601456AABD9BA625838A2EDD17E71235E9207BDF18A0AE92658233E9FBC998498578C309FEE4221AEE039EC731662E192E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........../.....& ...$............P.........<...........................................`... ......................................@..j....P..D...............................................................(...................xS...............................text...8...........................`.P`.data...............................@.P..rdata...;.......<..................@.`@.pdata..............................@.0@.xdata..d.... ......................@.0@.bss.........0........................`..edata..j....@......................@.0@.idata..D....P......................@.0..CRT....X....`......................@.@..tls.........p......................@.@..reloc..............................@.0B/4......$...........................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):51185
                                    Entropy (8bit):5.553102081938478
                                    Encrypted:false
                                    SSDEEP:768:Iv9oc1kmGPy3mE6BX8Sys+tK9+1mdJL+kbyF/UZ:Ivh1fGmeBsSyXtK9NJL+kui
                                    MD5:FEEB4C3AA3658142B1C75502A6714024
                                    SHA1:49F2D452D88BA8091BA779DC188DFD7DD0D1C1E5
                                    SHA-256:E5F80CE21CDC457A325A5AA48C4230439BA431A0C440D40FA8C62D66A3267A72
                                    SHA-512:E50C6FC38B15871E6645EDB7383FA29A41A6183D3F109D193F97874EA06FFA98EFD679752C3483D4E6500A2D0D557BC57D83D9187F750CE54992DD10717AA432
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".l..........P..........h.............................P......:......... .................................................D............................0.. ...............................(....................... ............................text....j.......l..................`.P`.data...p............p..............@.P..rdata...............r..............@.`@.pdata..............................@.0@.xdata..`...........................@.0@.bss....P.............................`..edata..............................@.0@.idata..D...........................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.. ....0......................@.0B/4...........@......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):70413
                                    Entropy (8bit):5.696661490761055
                                    Encrypted:false
                                    SSDEEP:1536:CaztYCbgt/lKMxmIPNx8HJark6EG1w9+TUv+zZ6YybEdViAT:JYC0GvIPNSarkxG1wiT
                                    MD5:89A11A2D77CD475965659048456A39BF
                                    SHA1:ED77A7AF416AA0DF40741915AE771D990CB6A5DC
                                    SHA-256:7C0158486DCFE16B21359359032A072CC8D123912361F471C405255F47525B24
                                    SHA-512:D74E1E570291991B4702E1B42E4636542B62FE953AA4B31EF3E090018D130EF78478D2C976CB45902034B8000FD674983F687C1CC4C6494469357D3249145B15
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P..........b....................................8......... ...................................... .......0...............................p..................................(....................6...............................text..............................`.P`.data...`...........................@.`..rdata..P".......$..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata....... ......................@.0@.idata.......0... ..................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4..................................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):29911
                                    Entropy (8bit):4.0106519634753
                                    Encrypted:false
                                    SSDEEP:768:G9+QsZJ9SMLCRYkwxdOPBgBaWlKTv8BcWToe2jXuksE1UpryVh9mvxlm0RDmeQoN:GQhJ5pbRDR
                                    MD5:328B6D04E15E76F4AEBF9C90FF106BA7
                                    SHA1:0B770032120006AA11E5DBF8290036F200566738
                                    SHA-256:EDD3CD871248461BC3AABFD5359EF4EEC485CBDC439651B16C0D653B35EE9BAC
                                    SHA-512:096EF52724BDAED272054EF543602115560BCD2BF0BC86E2299C887D3AB6D8EDE146DD7FFF190F0BA965E302C18FD7D1E1121300940E608534B83764EB0831C3
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..J.....& ...".....f......P..........f.....................................A........ .................................................................................t............................p..(...................x................................text...............................`.P`.data....4...0...6..................@.`..rdata.......p.......P..............@.`@.pdata...............X..............@.0@.xdata..D............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............^..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..t............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):16603
                                    Entropy (8bit):4.6548754089028925
                                    Encrypted:false
                                    SSDEEP:192:eV89dQQC1/dODPXE/LZa+oKJOfVCV5ZBV8qHtrcr0A/H0uf5OSMy43Z:q890dGXE/LA+NJOwFHrrc9vLMN
                                    MD5:746E2D25885AA53230A2685FB4C627E2
                                    SHA1:CD17D63D0D94FA8A9087B60E3586CA0DAF266901
                                    SHA-256:3573F5614444591BB05A43D8692DEE49CB3F8F8E0B88BA9CCE0D14A35549EC8B
                                    SHA-512:CDFFB8932C2B33A434D02C3FC2B6D8A510AAD4F001DEA498FD30BFA35523FAC10FAB469944ADF51CB20379D18B9454F15B4BDF10D2A4392B8D677B57A612CAB6
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........8..J.....& ...".....2......P..........o.............................................. ..............................................................P..................h............................A..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@......................@.`@.pdata.......P.......$..............@.0@.xdata..D....`.......&..............@.0@.bss.........p........................`..edata...............(..............@.0@.idata...............*..............@.0..CRT....X............0..............@.@..tls.................2..............@.@..reloc..h............4..............@.0B/4...................6..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):18159
                                    Entropy (8bit):4.556575201115682
                                    Encrypted:false
                                    SSDEEP:384:V1n89NdGXE/LA+NJOJbDt/oLdCHoBrcmM7MN:Q9UALAkJsbMN
                                    MD5:47CDAD5FE3E9321A162FF58F297C9786
                                    SHA1:1864C3F97AEB98F9BCAD8A17220ADC1CAF7579E2
                                    SHA-256:DBC63B0E25B953545CF81409C75117F30AF289B1EA943E1449FFFB875623A842
                                    SHA-512:6980544DB70BDA517A3C2630145D823471160CAD36F107D6DA251CE86D3B6ADA40B9D471EF09FC51A6E35C83F3A5B3FE9B0F98366DBCCFC57C8EC979A20C78D4
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........>..J.....& ...".....8......P..........e.............................................. ..............................................................P..................h............................A..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@......."..............@.`@.pdata.......P.......*..............@.0@.xdata..D....`.......,..............@.0@.bss.........p........................`..edata..............................@.0@.idata...............0..............@.0..CRT....X............6..............@.@..tls.................8..............@.@..reloc..h............:..............@.0B/4......$............<..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):31963
                                    Entropy (8bit):5.18964700946902
                                    Encrypted:false
                                    SSDEEP:384:hP90OQLtOME2KqRHQg0MQRiYhg1JO7wLqeJxereTbuLrc7EKMRrlG:h9+tOyv0XoCg1JzqjKHujBG
                                    MD5:44A0140362019588F4E5C1BAEFF58E4E
                                    SHA1:D195006DDA9B390270103011A9F7EC405FA1F0D2
                                    SHA-256:FD44373CFCD446247A1F2EFE7748821EDAC57ACB70564A3FD39924D1AB975D6C
                                    SHA-512:4624B7BF1FBA904808C155C972211F219A4D4C50DD100B36D9EA3767CAF50B4FF450FACAF80563786D81722EEA7CC7FE83D0E06D931B95B48F29B69B20289A08
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........h........& ...".2...b......P.........,i.............................................. ..............................................................p..................l............................e..(...................................................text...(0.......2..................`.P`.data........P.......6..............@.P..rdata..@....`.......8..............@.`@.pdata.......p.......F..............@.0@.xdata..h............J..............@.0@.bss..................................`..edata...............N..............@.0@.idata...............P..............@.0..CRT....X............`..............@.@..tls.................b..............@.@..reloc..l............d..............@.0B/4...................f..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):18655
                                    Entropy (8bit):4.537004954002481
                                    Encrypted:false
                                    SSDEEP:192:sVX99MQo1/BjPXEfLZ6kqJOfVhvQMpg13I0EwZBVWqHtrcr0LDUOdfuSMy43Z:sX9aVXEfLgZJOTDOVEsHRrcMlMN
                                    MD5:64331F4F52478F07F3C89ED8619533F3
                                    SHA1:92EC9C9C65AEB6550D459238C2DF2E661EBD6551
                                    SHA-256:3A601DB718DF72D9AD4A5E7BF110FB766691D69CFA008BB82250393940471288
                                    SHA-512:182EB6967CFA95BD118F4E718C28774FC8DAD4D29819F31A0FD553CD7DD9231639C3E0A18F1CD2812D7C1B87E90DBB7663C2CF54546281F49D496F7AD0D6729E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........@..J.....& ...".....:......P..........k....................................n\........ ..............................................................P..................h............................@..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@.......$..............@.`@.pdata.......P.......,..............@.0@.xdata..D....`......................@.0@.bss.........p........................`..edata...............0..............@.0@.idata...............2..............@.0..CRT....X............8..............@.@..tls.................:..............@.@..reloc..h............<..............@.0B/4...................>..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):17098
                                    Entropy (8bit):4.602296422922742
                                    Encrypted:false
                                    SSDEEP:192:nxZX9dOQ04/hePXE/LZa+dKJOfVLCpXaZBVuIqHtrcr0aFhu9NfpSMy43Z:3X934XE/LAZJOqaHyrcXhLMN
                                    MD5:1FC750C7E69477837F6EB51DDDC943D4
                                    SHA1:F8DF9A0E713A62E0B6ACC099FD084843A461A5AF
                                    SHA-256:BA638CE05DF4E4DF4B8C26ECA830256ACC747E09186549856CFB5138C65F43E6
                                    SHA-512:14066427A05CE9117C8135582A95718AC7D4205D3D97F2856A14BFB8714FCC317F431EC58D6285C9B4A9A6B24D2E5F77F81B7A67ACBA4AD344703D11A5FA4D26
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........:..J.....& ...".....4......P.........Dk.....................................8........ ..............................................................P..................h............................@..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@......................@.`@.pdata.......P.......&..............@.0@.xdata..D....`.......(..............@.0@.bss.........p........................`..edata...............*..............@.0@.idata...............,..............@.0..CRT....X............2..............@.@..tls.................4..............@.@..reloc..h............6..............@.0B/4...................8..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):22674
                                    Entropy (8bit):4.891526718310465
                                    Encrypted:false
                                    SSDEEP:384:TD69UZzCT59T9g4nJODrKRc1rcYuZhWMj:f69UKO4nJkrotht
                                    MD5:ACED12D5BAA49E6D4A472C4B22199518
                                    SHA1:C303D34172FFB4E95A53EF921B64E58B8A5B3010
                                    SHA-256:2C462DB083D0C8CEECA72556A0A65BD7CC62ACD91F3552BC6091450520EAFC36
                                    SHA-512:2C8F4441EED4B685404BACC9C0B14C9A378D8E1FBFBE23ACBE1D87303AE498C171D8E7EBEDA54DDD177E6C8E17003187937EDB44E1FA7669F97E65AFAB5D4E98
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........J..q.....& ...".....D......P.........<a.............................................. .................................................p............P..p...............l............................B..(....................................................text...(...........................`.P`.data........0......."..............@.P..rdata.......@.......$..............@.`@.pdata..p....P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata...............4..............@.0@.idata..p............6..............@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..l............F..............@.0B/4...................H..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):21915
                                    Entropy (8bit):4.757418617440637
                                    Encrypted:false
                                    SSDEEP:384:y79G36RT65F18KX6jPNJOj9NtKrcRCnME7:O9G36RO5FTqjPNJyXCn
                                    MD5:B701790AF77DF279C0C5D309BAC53661
                                    SHA1:78AD28AE8215C82EC16E0FF53A9F424CF86C8ACC
                                    SHA-256:71075A55864F3A64DE5656422D9EB4E459B0029661D00C4B7ED0DA485E1894FB
                                    SHA-512:D6C9E4C37AAB6A54460BA20811C3997EA84A7E878D12EC98EB3297E1E06A3DFF6D0887FBE2109AE0F80CC8D5A3F90BBE23C64ECE8020D4F70330CE0E3A5E02C4
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........J..\.....& ...".....D......P.........@l............................................. ..............................................................P..X...............l............................F..(.......................X............................text...............................`.P`.data........0....... ..............@.P..rdata.......@......."..............@.`@.pdata..X....P.......2..............@.0@.xdata.......`.......6..............@.0@.bss....0....p........................`..edata...............8..............@.0@.idata...............:..............@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..l............F..............@.0B/4...................H..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):29911
                                    Entropy (8bit):4.00968808206656
                                    Encrypted:false
                                    SSDEEP:768:LO99QsZJtSMLCRYkwxdOPBgBaWlKTv8BcLToe2jXuksE1UpryVh9mvxlm0RDmeQN:yDhJ2pbRDM
                                    MD5:1DDE855360F923B1FE26E3F9957A9D9E
                                    SHA1:A8E907B0E99B6D5C3EA7072CEABF33B8EB1CAB36
                                    SHA-256:D91668159C495259C197584477CE8ACE78A8C72641F2A9F652A5949CABCF955A
                                    SHA-512:CA0D2E0B347B027A78D242E07745F71E091E5277CD29118D8D12B99714EF79FE63198C6B86954825243CD69561A4323D455ADB482B84D085F95B7B16529AD6DD
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..J.....& ...".....f......P..........i.....................................V........ .................................................................................t............................p..(...................x................................text...............................`.P`.data....4...0...6..................@.`..rdata.......p.......P..............@.`@.pdata...............X..............@.0@.xdata..D............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............^..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..t............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):29911
                                    Entropy (8bit):4.009652718050617
                                    Encrypted:false
                                    SSDEEP:768:U9kQsZJlSMLCRYkwxdOPBgBaWlKTv8BcLToe2jXuksE1UpryVh9mvxlm0RDmeQoJ:UWhJOpbRDN
                                    MD5:B15FE82A5ED54CB3DF2D893F1BC686DE
                                    SHA1:0E81E14E53BF9933F53EED2BA631B948DEDD2E8A
                                    SHA-256:1A4271E7C6DC2D9E6132380690F24D4FB1FDEABCBA92BD6B7611AE4D28269D28
                                    SHA-512:0B2861DAA8D139C8187D9E13C0FDFB9C782FFE0A2B48E8DE65D00550D4E71219F9ACB77C16FBB41606A3E6AC5F9EE4453DF13D4BDA52B7881C1A3BF07D2C079B
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..J.....& ...".....f......P.........lg....................................^O........ .................................................................................t............................p..(...................x................................text...............................`.P`.data....4...0...6..................@.`..rdata.......p.......P..............@.`@.pdata...............X..............@.0@.xdata..D............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............^..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..t............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):18645
                                    Entropy (8bit):4.5095948752797215
                                    Encrypted:false
                                    SSDEEP:192:mxX991Q31/BjPXEfLZ6kqJOfVCkxMHYp+wn7voZBVxqHtrcr0ShVcyfQSMy43Z:eX9yVXEfLgZJOxM4pbn7v0HorcFhpMN
                                    MD5:77257C225BFC65B49C8C34C9CB1C0C3F
                                    SHA1:1A659952983FBF57AC6D8CE5260F190FFBD4BDBD
                                    SHA-256:5B82CA52A8C1916E655A36385B91F046FF8F0D744AF8C7943D7F5CE30DFD4E85
                                    SHA-512:F7C3E1A3AD5F8D0D375D9A295E79AEE97759D0B1414F1E67D6BD31313A104D46DB6295F9F51CE2D24EE05E98500E26A330BC5DB60BED5D8C8B90C7097F44F8D4
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........@..J.....& ...".....:......P.........dg....................................2......... ..............................................................P..................h............................@..(...................x................................text...............................`.P`.data...@....0......................@.`..rdata.......@.......$..............@.`@.pdata.......P.......,..............@.0@.xdata..D....`......................@.0@.bss.........p........................`..edata...............0..............@.0@.idata...............2..............@.0..CRT....X............8..............@.@..tls.................:..............@.@..reloc..h............<..............@.0B/4...................>..............@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):389587
                                    Entropy (8bit):6.065853382051008
                                    Encrypted:false
                                    SSDEEP:6144:3Ae5AZRQrKIa0pAl7SddEMfRt+WLWkzb1+K6IJFqtnFNZAYBZAyU4UkDIg8EaSyb:weHKFXl8FT+WLWkzb1+K6IJFqtbZA1yK
                                    MD5:8059FF4FEE3A2A9AF43D03A555B184DE
                                    SHA1:6B222720DD5650B9BCAB534AF3369BE06C333736
                                    SHA-256:A91553E15DE1A663608578A486962239DFE3AF7CE5BD6B00A22F7A1D53687E33
                                    SHA-512:C447612F311D5470CC524016CB41367FDDB87AA3D9CC05B1DE7F7126E5C4A003CB6662F38233C761583A2002E3F614DD4407926E48D76123823426CF412C19B9
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".(..........P.........Ll.............................@......<......... ......................................p..........xo...............<........... .................................(....................................................text...H&.......(..................`.P`.data........@.......,..............@.`..rdata..Pv...P...x...0..............@.`@.pdata...<.......>..................@.0@.xdata...2.......4..................@.0@.bss....p....P........................`..edata.......p......................@.0@.idata..xo.......p..................@.0..CRT....X...........................@.@..tls................................@.@..reloc....... ......................@.0B/4...........0......................@.0B................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1216297
                                    Entropy (8bit):5.711191625979728
                                    Encrypted:false
                                    SSDEEP:24576:Xe5gDMoIHD2UMky2c+WmPOcEPwNm7AzuJSgV7fCJI18SDg4IQHrx2/oG:+gHMqz8Ofc/S0gdj1rgALx2wG
                                    MD5:7F234B1054FB6A62147FF7E96D6E4504
                                    SHA1:55D38E7FA37EBC1B98BAAFAEA9FB667C3B291AA4
                                    SHA-256:AEF543280ECBCD62B7D171BC22FD137C766240B8A7770D1616C9CFDA2B86B9F1
                                    SHA-512:A1295C7A5C45948876BDAA43839A0129F109572ACA7F224E826032020F2CE32DADD1B241474B9DAB7058D9611D50B8E230F8AEFB05B2A5C332EFB2CF6CA60EE6
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....a.....& ..."............P..........h.....................................(........ .........................................M.......|J...........`...............................................F..(....................................................text...h...........................`.P`.data...............................@.`..rdata...A.......B..................@.`@.pdata.......`.......:..............@.0@.xdata..P....p.......D..............@.0@.bss..................................`..edata..M............R..............@.0@.idata..|J.......L...T..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B/4........... ......................@.PB/19......:...0...<..................@..B/31......Q...p...R..................@..B/45.....s`.......b...8..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):123197
                                    Entropy (8bit):5.099743336546625
                                    Encrypted:false
                                    SSDEEP:1536:RN1ULfI07JzgV8fv8c3gW9FvO2sXLmf0TE3JZUzN6n+cm/BZXxLhbReOiKCiJ:0X9fUc3R9O2sXyZgXr
                                    MD5:E1956280820E979DFD305896D0842874
                                    SHA1:7AD179BB6CE99AA6A9EE44746CBA662EA16083DE
                                    SHA-256:798193E4132696B031A757482BFF37F433A5FD3657356D6E281BD577038EAF74
                                    SHA-512:432CFF3DAE0EDBC88A43A111B55055A752747ACF3337EB9F805FF03B51B85FD18E9E4ADF8DCB580F738078C1B8A35CD47425276102B2D6AEAC6D68B3E857E49E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.f..9.....& ...".4...d......P..........p.............................@......~......... .........................................S....................p..................l...........................`d..(...................................................text...x2.......4..................`.P`.data........P.......:..............@.`..rdata..0....`.......<..............@.`@.pdata.......p.......J..............@.0@.xdata...............N..............@.0@.bss.... .............................`..edata..S............P..............@.0@.idata...............R..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..l............h..............@.0B/4...................j..............@.PB/19......v.......x...l..............@..B/31.................................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):132716
                                    Entropy (8bit):5.092551169226596
                                    Encrypted:false
                                    SSDEEP:1536:k6BmQxJj7FXlozvPtzE5dU2iNwFGOfYajCUXSem6JGcyMhD0VRiK:Vmm0zH90dU1NFhGIT
                                    MD5:7437FBEEB202C39479DB19AB551FFB40
                                    SHA1:4B5BE07135C76AE937740B87689FCAC370004FA3
                                    SHA-256:F254730A90884DAAAAA864B1A1C6473A328B87218F3B2CBCAE0776743568EE44
                                    SHA-512:BBFE22DE8CF9545840C79774338C925904E367639F50AB2FDBFE58980EE33F83351A1BD0FDAA19A55B76580798AE6813AD5AB695FAB819358D33C2F02F756031
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.... .....& ...".0...`......P..........k.............................P.......0........ .........................................S....................`..4........................................... W..(...................................................text..../.......0..................`.P`.data........@.......6..............@.`..rdata.......P.......8..............@.`@.pdata..4....`.......H..............@.0@.xdata.......p.......L..............@.0@.bss.... .............................`..edata..S............N..............@.0@.idata...............P..............@.0..CRT....X............`..............@.@..tls.................b..............@.@..reloc...............d..............@.0B/4...................f..............@.PB/19.................h..............@..B/31.....X...........................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):111500
                                    Entropy (8bit):5.075506283819968
                                    Encrypted:false
                                    SSDEEP:1536:LZfzLKJw+gvCogE0Xkoqe8mf0H9NpKnrp:JzOwPKy038Gp
                                    MD5:D666670ED1E4BDA82DFEEC5F3BF3B049
                                    SHA1:14678E015628A670E2D95746E9C59C6AE93F92DE
                                    SHA-256:82BAE38CC874F08349BDA5EACCDDBA422E0CF015A8B87C1D4847CED50B979FF8
                                    SHA-512:91C6A15F8682250F1CAA7FB6D342C1B426DBB4249AEE0B224372A4770C960B4B0FD1E0E63E659AFE26F509CE46399D20BB96A4B68E52F1908AFB8AF8B6C1DEE5
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.L..h.....& ...".*...b......P..........n............................. ......r......... .........................................P.......p............p..................p........................... c..(...................P...`............................text....(.......*..................`.P`.data........@.......0..............@.`..rdata.......P.......2..............@.`@.pdata.......p.......N..............@.0@.xdata..|............P..............@.0@.bss..................................`..edata..P............R..............@.0@.idata..p............T..............@.0..CRT....X............b..............@.@..tls.................d..............@.@..reloc..p............f..............@.0B/4...................h..............@.PB/19.....{h.......j...j..............@..B/31..........p......................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):7299380
                                    Entropy (8bit):5.439311617819013
                                    Encrypted:false
                                    SSDEEP:98304:bWa9MhhrqCKb83qKfMCXnowU9ZmOo0sdiQ5kKPIDN:VMDmC9q8XnowYmOo0sfEZ
                                    MD5:217FD3FD7AAFA0EE8F8A973F5840928E
                                    SHA1:7F41BC935C0BF8C3453882BF8C39410B0382702B
                                    SHA-256:B62C5494AA5A939C2A58F5DA251B93E750DF6CDB1319162CBA974C3FD74A66C3
                                    SHA-512:3C5F28C08E279D40436FF289A44D7A7FADA03D4FBCCA044EBBE1C6555EA622D04CC203DC47A5CC3F1478F9BDA228BB547867ECAD415589C4C107BDD3E83D3A58
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.hk..,....& ...".....F......P..........p.............................@l.......o....... .........................................M........w...........`..$6...........................................'..(...................l&..@............................text...x...........................`.P`.data....#...0...$..................@.`..rdata.......`.......B..............@.`@.pdata..$6...`...8...<..............@.0@.xdata..dD.......F...t..............@.0@.bss..................................`..edata..M...........................@.0@.idata...w.......x..................@.0..CRT....X............4..............@.@..tls.................6..............@.@..reloc...............8..............@.0B/4...................L..............@.PB/19......j'......l'..f..............@..B/31.....GS...`9..T....8.............@..B/45...........;......&;.............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):603876
                                    Entropy (8bit):5.4134125078937565
                                    Encrypted:false
                                    SSDEEP:6144:URNGerkm/fmUEWbm17zqyDFEmgSwS5qPfWCGnbSGIOCw4Pv7fS0:YGwBfaWq17zBDqmgSwS5qPfWWHbS0
                                    MD5:D0F1230BA39F415A0742CF1AE7899EAB
                                    SHA1:ACDC01E3D097DD21A5FE288D12219B9250CC70E5
                                    SHA-256:FBBBBFAAE54EC95BF1785B84CCADABC6B8CE5EFDDA27821F153B404E019C56F6
                                    SHA-512:77E1DE6653EB49462ED952075115C2AF52155D62B581DCC60F63FF8E64B318815A254C8EF126191E0E10921C538732B8589BD2D8E703702F220523E2046D8DC4
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....1.....& ...".x..........P..........e.............................................. .........................................Q........0...........................p..............................`...(...................P...8............................text...Xw.......x..................`.P`.data...0............~..............@.`..rdata...-..........................@.`@.pdata..............................@.0@.xdata..$...........................@.0@.bss....@.............................`..edata..Q...........................@.0@.idata...0.......2..................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4..................................@.PB/19.....1...........................@..B/31......0...@...2..................@..B/45................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):716411
                                    Entropy (8bit):5.679211650658157
                                    Encrypted:false
                                    SSDEEP:6144:KJ8k70kAKK42lcUU4LWY34dVIrgFwyELTpidnkF3WLIlSAakDEMdwI1/f28k0pLb:wffKrLWYodVP6NLYk7SATw3yD
                                    MD5:84F7798B39BFF4E658039A222EEBEF8F
                                    SHA1:ACA186755973F3EBDC3F27973222F4044C479667
                                    SHA-256:1DAD46D6B30366785866F4647F65960BEC78E14712CFB1AD4C953A80F03795A6
                                    SHA-512:0400E05801887302BF5129E3F05357BF99AF58EDE18B74445B90074A4E4DCAB0712E2CDCDF9C9A6B88B1631D025A9564D8F641E6546F6FA78B97C550650FC718
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....e.....& ..."............P..........j.............................................. ......................................@..Q....P...2..............................................................(....................Y...............................text...............................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata..............................@.0@.xdata..t.... ......................@.0@.bss....@....0........................`..edata..Q....@......................@.0@.idata...2...P...4..................@.0..CRT....X...........................@.@..tls.................0..............@.@..reloc...............2..............@.0B/4...................4..............@.PB/19.....=$.......&...6..............@..B/31.............. ...\..............@..B/45......... .......|..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):748789
                                    Entropy (8bit):5.432681926653613
                                    Encrypted:false
                                    SSDEEP:12288:/OK2Heftkkd99LY4cgO3IOn1eApewiELQwLNc1v:12Hotkaf8Xn1eApeuLQwLNc1v
                                    MD5:13F9997D581F6EAC4AE745098FD6DA92
                                    SHA1:FEA4170590184DA9D541F2D44C6921402FFFBC58
                                    SHA-256:E319DA9AA530939B2BE37CB89F6D49D924A85F3DD9341FE55C7328D7D41B5834
                                    SHA-512:0EB925E0DE5929F7301254C973125AF777B20CB085621B1CD541760CBA01A2ED16DDA5AF1E1F8B008895ED3E21BE0CFD7A4CB0F29088DF30037B0D8316D4EB88
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ..."............P..........i.............................p.......(........ .........................................R........Q...........P..................l............................0..(......................`............................text...............................`.P`.data...P...........................@.`..rdata...4.......6..................@.`@.pdata.......P......................@.0@.xdata..$....`.......:..............@.0@.bss....@....p........................`..edata..R............H..............@.0@.idata...Q.......R...J..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..l...........................@.0B/4........... ......................@.PB/19.....F....0......................@..B/31.....E....0......................@..B/45..........P......................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):402712
                                    Entropy (8bit):5.125051076638829
                                    Encrypted:false
                                    SSDEEP:6144:OUwmpc60IYOqn2S8oQw7Ld8FKeEhE9GaZkVyRQDhNS:7hVlpyrW3YYmhNS
                                    MD5:334BC0E46345B65CCD09307DF5DE71D9
                                    SHA1:3D9908CB8EB8EE4611EED546BFA31D5E81D2A1AA
                                    SHA-256:FAA4356D98FA854FC08E174EEF5D6FB0C05BDDD1D434B186C7A100D46DEC691E
                                    SHA-512:6D71616DAF1128B2947EB3F909E370E7D6E93451AE5FEB6F9227F82E36E6D5EC919229246FE1EAD03C761BCE0D500FACC6FC25CA45895538E45FB6E1E8F33E83
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.`........& ..."............P..........n.............................0................ ......................................@..P....P..<...............|...............t...............................(....................V...............................text...............................`.P`.data...............................@.`..rdata... ......."..................@.`@.pdata..|...........................@.0@.xdata....... ......................@.0@.bss.........0........................`..edata..P....@......................@.0@.idata..<....P... ..................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..t...........................@.0B/4..................................@.PB/19.................................@..B/31..........`......................@..B/45......q.......r..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):200178
                                    Entropy (8bit):5.072995542700929
                                    Encrypted:false
                                    SSDEEP:1536:PMaYmroe1NMAJJUhv8Pa55Gk4GS1h2yZsgUzs7vJgosdNi5f7kojBMv0sQRedlJq:tPNFJucaHGk4GMFZsRwvsdNi97kQ+e
                                    MD5:3E44E814628C136E496393FCF621247A
                                    SHA1:B5FBD4D007F79EC0858914AE5D968D9B24448E39
                                    SHA-256:36FD0E41CE7C93A688DEF50099B819ABA49437939EB5009948F17DCFA1D9A26A
                                    SHA-512:2511900C26EBDA58EE25D017BA0AD66A359FCA0496C4748248573F262F4BCF67D556B5D51325F178C10E3E4AA6A99D50D0D350ADD92733F82656BF7FA02F5192
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".P..........P..........h.............................P................ .........................................P...................................................................`{..(....................................................text....O.......P..................`.P`.data........`.......V..............@.`..rdata..P....p.......X..............@.`@.pdata...............l..............@.0@.xdata...............p..............@.0@.bss..................................`..edata..P............t..............@.0@.idata...............v..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B/4........... ......................@.PB/19..........0......................@..B/31.....i............n..............@..B/45.....i4... ...6...z..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):89604
                                    Entropy (8bit):5.11502861659061
                                    Encrypted:false
                                    SSDEEP:768:n9RZCmtbbAdUZJHSQiaPJivRzu1OApqrdv99D2V/v2XGhkxs564hJv61wRroxiPq:nUm1auJHwvL4qrdvrD29urX4nvjr9ecG
                                    MD5:FBB9CA9E50D0DA153D3EF2CD53BB2908
                                    SHA1:9C98A690191F490C198BD047981AAD9FD3A5C08C
                                    SHA-256:54D366DF866A6E3447B351F58E9D0755F60A16631B4223C07946EE4123C7FB27
                                    SHA-512:2CEC67D35D02BA6C1AB7080B116169568CF9ECF1622A898365C8E0208FE2B6D1559DF36727EE9A95A866D59854844C0206B2E63ABC5F8655294DDA1D29C33327
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....,.....& ..."."...J......P..........q.............................................. .........................................P....................`..................l............................T..(....................... ............................text....!......."..................`.P`.data........@.......(..............@.`..rdata.......P.......*..............@.`@.pdata.......`.......6..............@.0@.xdata.......p.......:..............@.0@.bss..................................`..edata..P............<..............@.0@.idata...............>..............@.0..CRT....X............J..............@.@..tls.................L..............@.@..reloc..l............N..............@.0B/4...................P..............@.PB/19......Y.......Z...R..............@..B/31..........P......................@..B/45...../....`......................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):236818
                                    Entropy (8bit):5.385722337498393
                                    Encrypted:false
                                    SSDEEP:3072:Qc5/rt7vbtufIOyk3kuabxftHNksoFWXKhKrYmOvRSwkHoPHcND+:XckuAHSsCpKsmOvREoPHcND+
                                    MD5:7A9FFE4EF525B9F9DB65DA818DC8D017
                                    SHA1:D5875B8B4A7401F8E7ADCA315CE5E5D01E0A90A6
                                    SHA-256:B6479D54A861A4AD7854912564DA49E41B2BF92AC323E1F7CFDD57169C66D6A4
                                    SHA-512:7600EC3A7B90A8B25FEEDD9DF2B47FE226238213058241F6F9CD5153589B80CA08AB9ACAA7DEA66D45F6D1555F76236FE4170E234FDDEBECC2383776AE342F85
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ..."............P......... q.............................................. ......................................P..U....`............... ..................................................(....................e...............................text...............................`.P`.data...............................@.`..rdata..............................@.`@.pdata....... ......................@.0@.xdata..T....0......................@.0@.bss.........@........................`..edata..U....P......................@.0@.idata.......`......................@.0..CRT....X...........................@.@..tls................................@.@..reloc............... ..............@.0B/4..................."..............@.PB/19.....b............$..............@..B/31.....J...........................@..B/45.....'/.......0..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):176472
                                    Entropy (8bit):4.914687530139777
                                    Encrypted:false
                                    SSDEEP:3072:Qb6uMBy/81SMnoHWO/n4+PKQ6m6xrJsk1Z:Qb58C2+4wKQ6lxWmZ
                                    MD5:FEC66B18F1F0BD24B9B81C9DE5B60A13
                                    SHA1:8207141974A25FEFC50B8AC901E3139AFD6F7B07
                                    SHA-256:6C5446809B6F803825EA8D79F0720654C6E7E8FB03874136C3740BC22F847A45
                                    SHA-512:A7EAE5147DCCDD982F551EE8F3992420F344291026B4FFF7EB0D29EEB5B6D9757CBE66654908557E471BCCFC9D748777808F5E2839CF5DFE3001FD950ED8B9BD
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.(........& ...".D...v......P..........i..................................../......... .........................................U.......x...............................l............................s..(....................................................text...xC.......D..................`.P`.data........`.......J..............@.`..rdata.. ....p.......L..............@.`@.pdata...............X..............@.0@.xdata...............\..............@.0@.bss.... .............................`..edata..U............^..............@.0@.idata..x............`..............@.0..CRT....X............v..............@.@..tls.................x..............@.@..reloc..l............z..............@.0B/4...................|..............@.PB/19.....>.... .......~..............@..B/31.................................@..B/45.....K(.......*...(..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):114864
                                    Entropy (8bit):5.100811513736305
                                    Encrypted:false
                                    SSDEEP:1536:HUSmIm0JmvfTlKZp3yFEKlh+RL1soxKEhKUrDGbkc9s+l9:HbZmDlKW96L1aEht/e
                                    MD5:CEBF8C0C310994C94AD24C31215908DB
                                    SHA1:840CA7B33BD466B6F8168263CD46867CD3275725
                                    SHA-256:8E3E9CD48E709E2B134A4C14EA29667553D1B6F863DB511C34EDF177E3AE6AFB
                                    SHA-512:7213B65E449D88316EDE5902BC00F771A77B8D99DACF1A33C62CE67A7D71493CDF81EE5542643A73505E652273DB122FA0F39BCB658D24F7D4EC50F8F81C7B7E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.L........& ...".,...Z......P..........d.....................................[........ .........................................P.......4............`..(............................................U..(...................................................text....+.......,..................`.P`.data........@.......2..............@.`..rdata.......P.......4..............@.`@.pdata..(....`.......B..............@.0@.xdata.......p.......F..............@.0@.bss..................................`..edata..P............H..............@.0@.idata..4............J..............@.0..CRT....X............Z..............@.@..tls.................\..............@.@..reloc...............^..............@.0B/4...................`..............@.PB/19.....)w.......x...b..............@..B/31.....#....p......................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):242944
                                    Entropy (8bit):5.371150727912922
                                    Encrypted:false
                                    SSDEEP:3072:rHH17JjvICQ2oSqswjOaciSaa2bi2WoL5hVVM+/GIe5TPyZIhDnPHnHfu83y:rwDjO3aPbL++/S5TPyZIlnPHnHfu83y
                                    MD5:DC7E33A6B08F394339EDE034279CC6E1
                                    SHA1:C707B996E0A36B1B1E8717BAF3F3925A33BDA68A
                                    SHA-256:5493CFF7CAC6E574488988A0400ABC9243C964FD65C64ECAAD8AFCBCB4FEE9B0
                                    SHA-512:75DA6B87F40547FB62147C8C07FFA8468E137DFF70F7633D150AA4F29A10322EB271616AF57015C5F4CA4D9139DAD98A80F873C6DB314B772A33249F5019BDC4
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....2.....& ..."............P..........h.............................................. ......................................P..Q....`............... ..................................................(....................f...............................text...............................`.P`.data...............................@.`..rdata.. ........ ..................@.`@.pdata....... ......................@.0@.xdata.......0......................@.0@.bss.... ....@........................`..edata..Q....P......................@.0@.idata.......`......................@.0..CRT....X...........................@.@..tls.................0..............@.@..reloc...............2..............@.0B/4...................4..............@.PB/19..................6..............@..B/31.................................@..B/45......1.......2..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):161867
                                    Entropy (8bit):5.0442243470533565
                                    Encrypted:false
                                    SSDEEP:1536:/IBJ3R9J3tjbJJ3JBAvxwUYupLIVEMngt3Jeg5KXHH9CBc0XDCjB2QORwg41tD8i:gBv3etYupOtmZeg5KXt2CjBXzg4C/n7k
                                    MD5:B185B33BDA59A63794ECB8A5FDDBE1A3
                                    SHA1:4DC084180D7E6CA53009FF779644727C926B4A74
                                    SHA-256:8A0653290ECC71A893358915BB8B3F886FD37AA5692D699F3750926A548C1FEB
                                    SHA-512:D2391B8B06B3515A676D897D4B366FB0E5FF5FADCEC438707481C3E1D2F786C85C232834E648BC0253C3B275866CFE28C3E4E89A46CCBC644812DAA2F947C380
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".>...v......P..........e....................................8......... .........................................P.......................................|............................i..(...................t................................text....=.......>..................`.P`.data........P.......D..............@.`..rdata.......`.......F..............@.`@.pdata...............X..............@.0@.xdata..@............\..............@.0@.bss..................................`..edata..P............`..............@.0@.idata...............b..............@.0..CRT....X............v..............@.@..tls.................x..............@.@..reloc..|............z..............@.0B/4...................|..............@.PB/19.......... .......~..............@..B/31.................. ..............@..B/45......).......*...,..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):135726
                                    Entropy (8bit):5.1231513238220066
                                    Encrypted:false
                                    SSDEEP:1536:y+soc0JfitLPgv6mbaNZ82YZUzq6JYyiddvOPMLar8p+Zh9epNxX3:ZsoJqt8+N6yzq6JYOUe+xv
                                    MD5:99555F3A96A24CB88FCC7F32B9B840FC
                                    SHA1:9514A97B1F21055E38279423934D9A0613DEF22C
                                    SHA-256:DB6BB4002DBB8C180868E8C22FFD73940A23C930343170A3D26D94B4BEDAA388
                                    SHA-512:6DD55659A1363DEF87F92B8A50004F887E5F6903A9D65759D642BB81AD169E4655102FBEDBED9E63F745B02E56AE273AE359AA023A4E789D8D85D430CB4D7101
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".4...j......P.........Ph.............................`......=......... .........................................P.......t...............4...............x............................j..(....................................................text....2.......4..................`.P`.data........P.......:..............@.`..rdata.. ....`.......<..............@.`@.pdata..4............N..............@.0@.xdata...............R..............@.0@.bss..................................`..edata..P............T..............@.0@.idata..t............V..............@.0..CRT....X............j..............@.@..tls.................l..............@.@..reloc..x............n..............@.0B/4...................p..............@.PB/19.......... .......r..............@..B/31.................................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):282910
                                    Entropy (8bit):5.156966178698751
                                    Encrypted:false
                                    SSDEEP:3072:iZjBTs40IpjtLhTEIYvOe7yq8xSJuG1s9SsyQfJs/3brUiYGnaLVc0n126bK8bE3:iZls40kZ4uG1+SZZo2s8z6G
                                    MD5:1B77D42C13F73BE81AF4328C83D7E86C
                                    SHA1:5DCBD63C188E33C0CDA188607923E83779911808
                                    SHA-256:AD7982B2217BE45C263A287CDC10B6A913A5CBD9FCDB35B50364DF3EF0A02404
                                    SHA-512:5BE3C155727C5354BDAB79F3FCB8AF175E4C0698940115D04CE91360F2AFD968EE8FE6B9697993C8C71F40B384F446F72ED63C7816DB886641061826397DB8D1
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".t..........P..........k.............................P................ .........................................O.......................|............@..............................@...(....................................................text...xs.......t..................`.P`.data................z..............@.`..rdata.. ............|..............@.`@.pdata..|...........................@.0@.xdata..T...........................@.0@.bss.... .............................`..edata..O...........................@.0@.idata........... ..................@.0..CRT....X.... ......................@.@..tls.........0......................@.@..reloc.......@......................@.0B/4...........P......................@.PB/19..........`... ..................@..B/31.................................@..B/45......M.......N..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):122111
                                    Entropy (8bit):5.059741041845896
                                    Encrypted:false
                                    SSDEEP:1536:EMKq/susJMymeZvKqGquG3kL6T0b9k7SYPaS:2UeZCCAGN
                                    MD5:4EE4BF9355A79E2D7E74DFB4751C3D92
                                    SHA1:5ADBC713ED0C33BAA3E59F607CA7BC444E304D25
                                    SHA-256:C727E011BDA504FC4131419442C5C5ACC46F62C3A19E8DB11041365268FD950F
                                    SHA-512:FC04823BE3813B52DD51D8C9224E16D97C1881FB69627785B9E6F406FB10E15F7EDAA5CCFF5CFAD3929E130416F4720CAD35C7302232E36389CB90FCF5FDDA82
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.d..%.....& ...".2...b......P..........b.............................@................ .........................................N....................p..@...............x............................d..(...................................................text...(1.......2..................`.P`.data........P.......8..............@.`..rdata.......`.......:..............@.`@.pdata..@....p.......H..............@.0@.xdata...............L..............@.0@.bss.... .............................`..edata..N............N..............@.0@.idata...............P..............@.0..CRT....X............b..............@.@..tls.................d..............@.@..reloc..x............f..............@.0B/4...................h..............@.PB/19.....@s.......t...j..............@..B/31.................................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):195671
                                    Entropy (8bit):5.019744649702786
                                    Encrypted:false
                                    SSDEEP:3072:DQF+HvC6vDISqqFKe4UgacSxrMlLHfGUf+LB:c6geP5WbG
                                    MD5:EC2B1CF7E0B2559A05E440AD17D8684D
                                    SHA1:72E9E0E02314C0B86C855DE93A7024E56C6E0C9B
                                    SHA-256:EE71747830E275D579346851B4A9AAE7D0552E1BB73CBE6CBFB08E4B764194F9
                                    SHA-512:A59DEB99DCE21F2AC5853A4263AD65F18272F12A30E8497ABD77FB2EC34690C24A7DD30E0382A20C75EADB583DC7B9EDD4C70C2DAFE7491C52C8372387A790F4
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....I.....& ...".H...~......P..........k.............................`......9......... .........................................P....................................................................}..(...................P...`............................text....G.......H..................`.P`.data........`.......N..............@.`..rdata.......p.......P..............@.`@.pdata...............f..............@.0@.xdata...............h..............@.0@.bss..................................`..edata..P............j..............@.0@.idata...............l..............@.0..CRT....X............~..............@.@..tls................................@.@..reloc..............................@.0B/4........... ......................@.PB/19..........0......................@..B/31.....I.... .......h..............@..B/45..........0...0...t..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):112589
                                    Entropy (8bit):5.052058280019082
                                    Encrypted:false
                                    SSDEEP:768:F9myyk4sXLJX2KOLCsw7PJivrAj3vg9OyJ9gvu/QG6Y6B8DNV4FQ/9Zmb6woms9I:FZyk4sJqvUo9OC9g7G6YFrYgMsBP7M
                                    MD5:14B9F36D27FB63E80731D8BC8A32FF94
                                    SHA1:4D737845B01FEA8322C369DDA54A1BA7FDEF9515
                                    SHA-256:40555D1EA5E371408AD437649D8EE7DF4E8DD4ACA1DA7FF50E2362C89BE1229B
                                    SHA-512:1208F650EE51EADFF101E1D13DFA51E058974FA41BB382B2DAE5985176DC99EFFC8976CE42A394B63D3B112295CB1B3D82C0525842DA9C52C891013F38FDF251
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.B........& ...".*...V......P..........p....................................2......... .........................................Q.......p............`..(...............p............................T..(...................................................text....(.......*..................`.P`.data........@.......0..............@.`..rdata.......P.......2..............@.`@.pdata..(....`.......>..............@.0@.xdata.......p.......B..............@.0@.bss..................................`..edata..Q............D..............@.0@.idata..p............F..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc..p............Z..............@.0B/4...................\..............@.PB/19.....Vm.......n...^..............@..B/31..........`......................@..B/45..........p......................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):123479
                                    Entropy (8bit):5.007821577965834
                                    Encrypted:false
                                    SSDEEP:1536:3M3hyXUhakJYnYvNPQ40LnXAnbP9aqLy8HLVUXgNk+OQxJ7:830XoDYnYFPQPnuLFHH9OG
                                    MD5:379B0CA363B84F642A4C5A32EC7E2EFF
                                    SHA1:6C76E5C9F6EA113A45F2E8E8F7565DB7DDAE7485
                                    SHA-256:FDF77D74DA9890804119C1B5C84B453991EE69A737B78F93A69186519ABAFBE9
                                    SHA-512:759E589209C037C6A93CEB1727F44CB2A0BC8B7393E33EDD9340FD666A73955A96046665E5EF1F265CAA42BBA233AF56BC0B7DB1A786A7A55AF14EF1BE3F1FC7
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.d..\.....& ...".....^......P.........,e.............................0............... .........................................R.......|............`..4...........................................`U..(...................D...h............................text....,..........................`.P`.data........@.......4..............@.`..rdata.......P.......6..............@.`@.pdata..4....`.......D..............@.0@.xdata.......p.......H..............@.0@.bss..................................`..edata..R............J..............@.0@.idata..|............L..............@.0..CRT....X............^..............@.@..tls.................`..............@.@..reloc...............b..............@.0B/4...................d..............@.PB/19......t.......v...f..............@..B/31.....o...........................@..B/45.....&...........................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):131439
                                    Entropy (8bit):5.119042756499886
                                    Encrypted:false
                                    SSDEEP:1536:jgxiyJMiMF3bvckDKUyxNtchYNW4XoRjcASi3RYGkWBJnub:EMhAWXMoRAAu
                                    MD5:0CD85F335D621A159C19F6632F15C5FB
                                    SHA1:E7D6FC754DFBCFAC9C8F60831EC3FD3542B53949
                                    SHA-256:20FCC83BE95B92E7F913A414F258AF9A2CDEB265C2DA6E7E29CE3997A7C1F6A0
                                    SHA-512:3F77D728D42FD2800C362F5F02C02E6006DC1DBBB4563E772FDAA2203E50E157D4F778FC056530B0E4A35FC6D916F680FCB65DA42554E9CFF8F697F4E8A42A05
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".8...h......P.........<n.............................P................ .........................................M....................p..@............................................g..(...................................................text....6.......8..................`.P`.data........P.......>..............@.`..rdata..`....`.......@..............@.`@.pdata..@....p.......P..............@.0@.xdata...............T..............@.0@.bss.... .............................`..edata..M............V..............@.0@.idata...............X..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..reloc...............l..............@.0B/4...................n..............@.PB/19..................p..............@..B/31.................................@..B/45.............. ..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):127252
                                    Entropy (8bit):5.131437979245908
                                    Encrypted:false
                                    SSDEEP:1536:YAuOc1Jz4xvhvtWJ8YAo2qnr4m5MZLHs1bS3ODrCaEYWJrr:RuOSIZvtIfcmmzs1bSQWr
                                    MD5:A88070824DCDF520029FF7CF69E0345C
                                    SHA1:672D2CE91E685DE38A90FA54EDA60CEC9D63C1D6
                                    SHA-256:82498DACB14DBDC5A62C74334B9717AA285C1DBA9774E0A300D47A6E63DE4F9C
                                    SHA-512:063E53E2CA190A4CE707F7DFC84F73D5907E2AEA630AE4635C55AE048BA5E4DC0FD0EA4366E8F6D36FD9931D3CC0329CE0BCF68E674C045FB4A370016AD5A7A9
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.r..k.....& ...".2...d......P..........a.............................@................ .........................................Q....................p..X...............p...........................`d..(...................$...H............................text....1.......2..................`.P`.data........P.......8..............@.`..rdata..0....`.......:..............@.`@.pdata..X....p.......H..............@.0@.xdata...............L..............@.0@.bss.... .............................`..edata..Q............P..............@.0@.idata...............R..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..p............h..............@.0B/4...................j..............@.PB/19......p.......r...l..............@..B/31.................................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):145575
                                    Entropy (8bit):5.114118690327512
                                    Encrypted:false
                                    SSDEEP:1536:yguYtAAsJjK1MvQW64oYerAmvRNbpX5OF86fNqOdT4dJqL2/sjekcmDBTM:ntw9H67Dlxp08oxc/p
                                    MD5:DA4FAB34256DEDF41B6CCFE4F650424C
                                    SHA1:84CB478019D487B72F327425B9B7D4EDC1AC72CB
                                    SHA-256:1980724FE10A23EC8F48ADEA0565DC23FC64C590C8F117DFFDB5CA536E7B0A25
                                    SHA-512:7B22A9D7FF27E5ADB3C865DBDA65A46FA3BDBC151D31C42633FDB02887924D1C41A58BB7F0CAD4DF36F51794C65341B92B96B29AA5D47BB5056F0FF6D7757669
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....!.....& ...".B...t......P.........Df....................................g......... .........................................Q.......................(............................................v..(....................................................text....@.......B..................`.P`.data........`.......H..............@.`..rdata..`....p.......J..............@.`@.pdata..(............Z..............@.0@.xdata...............^..............@.0@.bss.... .............................`..edata..Q............`..............@.0@.idata...............b..............@.0..CRT....X............t..............@.@..tls.................v..............@.@..reloc...............x..............@.0B/4...................z..............@.PB/19......... .......|..............@..B/31.................................@..B/45......".......$...&..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):120089
                                    Entropy (8bit):4.991302153722504
                                    Encrypted:false
                                    SSDEEP:1536:MJXaZtdJz3Euv+WpEvqPYZdb++p6wLMx4876/St3mgE0kr:MNCVJJpEvkgY4876F
                                    MD5:FAB464BC002F9615272E1BBD8C4B4D70
                                    SHA1:E23DF187385167EEBF9FFD96DBCF27A365D2838E
                                    SHA-256:8EEB65F1DA82E4389BD8727AECAF69A3C91617C5BAF82E3D5AF385CE6A149AD8
                                    SHA-512:149C2FA8C550798631A7E3DED95B39E72E54DEA8EB6C85B492B347EA67578984A6BC93CB5C9385DDEDBD08D54BAF6B68E7FCEC828C17E68A13C142FFD1B4AB7E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.X..Q.....& ...".*...X......P.........|a.............................0.......V........ .........................................P.......\............`..................p............................T..(...................<...`............................text....(.......*..................`.P`.data........@.......0..............@.`..rdata.......P.......2..............@.`@.pdata.......`.......>..............@.0@.xdata.......p.......B..............@.0@.bss..................................`..edata..P............D..............@.0@.idata..\............F..............@.0..CRT....X............X..............@.@..tls.................Z..............@.@..reloc..p............\..............@.0B/4...................^..............@.PB/19......r.......t...`..............@..B/31.................................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1462803
                                    Entropy (8bit):5.842269588129382
                                    Encrypted:false
                                    SSDEEP:24576:p2pVv6G25TG31qCub6PvjY7hNk0BBQLa4lZyZHmUvewuusQFeN:p2pt2QlqDukEf/YHmNwuusQQN
                                    MD5:39D3C4A201F62BA543B5D67EE69267F2
                                    SHA1:40619C02D33A58C4691457DC58DA633483A09008
                                    SHA-256:CCFD5A19DEBF97D20B2B3A07CC4C40E1F994BA4B5DFA9BE1F6278C659D175495
                                    SHA-512:2636587A16A157FD150D00FF87D6CA7B081BA0BB2CCB5C0B01F50FF19378D7B4FB695CBBA7BC5114B8BB1DD7BD74E44E1B9833EAEC9A18F5A4404EAB889D5A76
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.d........& ..."."..........P..........p.....................................E........ .........................................N........Z...........................p..................................(.......................X............................text.... ......."..................`.P`.data...@....@.......(..............@.`..rdata...W...P...X...2..............@.`@.pdata..............................@.0@.xdata..,...........................@.0@.bss..................................`..edata..N...........................@.0@.idata...Z.......\..................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4......0...........................@.PB/19.....W...........................@..B/31.....+h...p...j..................@..B/45..................Z..............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):758057
                                    Entropy (8bit):5.606328025160473
                                    Encrypted:false
                                    SSDEEP:12288:AVatSo2tn3Ql2Iib68MJ1C6npvvPTMkvi:AVatS1n3s2Iim8MjCuc
                                    MD5:15F24BA803FD6440D972593EADCD34DD
                                    SHA1:3560C4F51D7C770FC0249F91198A21F541F9E9B8
                                    SHA-256:14CA7356BF5935ED52E7A93ECD4AF7C62F3A6CFDAC93D64EEEE535500348450E
                                    SHA-512:B52FE705A4A1E9A2F25A0CFE9880F11F1FBB66C270BF96B797A56F530BCC176825B56D91EF5D44C0387AAC91ECAE1A183DBB420F88B98F7A5AF14720E2839F6E
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".N..........P..........j.............................@................ .........................................N....................................0..............................@...(.......................p............................text...hM.......N..................`.P`.data........`.......T..............@.`..rdata...3...p...4...X..............@.`@.pdata..............................@.0@.xdata..@...........................@.0@.bss..................................`..edata..N...........................@.0@.idata........... ..................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.......0......................@.0B/4......`....@......................@.PB/19.....+....P......................@..B/31.....O=.......>..................@..B/45.....[....P......................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):140687
                                    Entropy (8bit):5.169742775088518
                                    Encrypted:false
                                    SSDEEP:1536:jX45JC2KP2SvjyzNtdCnOtpHW7bZBoRxmDKLnQ0fHlXvuKdXh84QzRQ0hUkr:bCDKxCX4a2/ZBQ86vZvNu
                                    MD5:8EA9E8F779EB9D19CCFA2895167313C9
                                    SHA1:6AFF505C0D4DD8B476A0E4917C3A6273A8CDB54D
                                    SHA-256:1C4A73C11820A84A8A8CD9FC0D20E194EC91AD6B7C554F125ABE1A401596B5A7
                                    SHA-512:2C813CD89387942326C83B493254DB73054020A78D92CF84FFC0A765CB34C562BBBF702DD8F72390EBC688012CB8303766C5EF47AE7E1240377FFDF3A032A6ED
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".>...v......P.........lg.............................`......P......... .........................................U....................p..d...............|...........................@h..(...................................................text...x=.......>..................`.P`.data........P.......D..............@.`..rdata..0....`.......F..............@.`@.pdata..d....p.......V..............@.0@.xdata..T............Z..............@.0@.bss..................................`..edata..U............^..............@.0@.idata...............`..............@.0..CRT....X............v..............@.@..tls.................x..............@.@..reloc..|............z..............@.0B/4...................|..............@.PB/19.................~..............@..B/31.....h...........................@..B/45...... ......."..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):9405666
                                    Entropy (8bit):5.861087725930266
                                    Encrypted:false
                                    SSDEEP:98304:UputMs4YlHgkfY8te+DgEDEIphEr7H/rt4HLc2z9HZjXs9L7nUrt0HBQaty0hxnD:68tnrvOhVY2LO/ZCMiY7f6G0Paj9s
                                    MD5:BEBA6167304EAE1E15B78BAD4BB5EB07
                                    SHA1:743BFAE0746CB93398724652EAF033720DA079B6
                                    SHA-256:8F7A886AB0A3A8B7976AB34201C2832DB52B9E44ADEF936B67366A7B3A07C0C0
                                    SHA-512:62F5BE163F1E93415FD1743AAC47709E96F71D7A2D0FEB4C1B82C2461CE5C6909C8038D658A93E646E0FF571D505E6E9071A58D2CD1BC7ABD59DE79C511044FF
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g....F....& ...".....V......P..........m....................................)........ .........................................P........................P..............P............................O..(....................... *...........................text...............................`.P`.data....*.......,..................@.`..rdata..............................@.`@.pdata...P.......R...l..............@.0@.xdata..............................@.0@.bss..................................`..edata..P............@..............@.0@.idata...............B..............@.0..CRT....X............D..............@.@..tls.................F..............@.@..reloc..P............H..............@.0B/4...................\..............@.PB/19.....u&@.. ...(@..z..............@..B/31.....n....PV.......U.............@..B/45......L...0Y..N...vX.............@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):1895845
                                    Entropy (8bit):5.777575687765836
                                    Encrypted:false
                                    SSDEEP:49152:GQDaPwbzDJ+BRoG/FUWay4NAicxvVuHUyW:nzDcBb/FUWay4NwxvVuHUyW
                                    MD5:A48E4FEEA559BC65FC75D5CB1E2FE532
                                    SHA1:8184F4D3049D29AB82FFFA6868586C9F8505B4D6
                                    SHA-256:0C137E9D773DAC4F99015BF64E1A4ABF4B7349EB4D3A76D11881996469CEAFF4
                                    SHA-512:CE9C2A4863866CAE95E02F37C8718A0D75195551A9B1A8FDF72B6052CF165B96611AE1BE0D0CE56DBC39909ECCF3761C2C7F737CD0D9F7BCFF5855EF02A45719
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g.2..B.....& ...".....j......P..........a.............................................. ...................................... ..N....0..................................................................(....................F...............................text...............................`.P`.data...@....0....... ..............@.`..rdata.......@.......(..............@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata..N.... ......................@.0@.idata.......0......................@.0..CRT....X............h..............@.@..tls.................j..............@.@..reloc...............l..............@.0B/4...................p..............@.PB/19..................v..............@..B/31......{.......|..................@..B/45......#... ...$..................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):2369237
                                    Entropy (8bit):5.767779899769283
                                    Encrypted:false
                                    SSDEEP:49152:9VtIukvPgIvbCkC45QD7xqMuFag2n6qFMCoIlBG1akZOg:NkvPGL4S77u4j6qF19lBG1akZOg
                                    MD5:421B8F583A8BC21A87E7ABB5CAC4E0E4
                                    SHA1:17DC0A3D0C4C6B9C68E3DD7B1C3B8D74D1E615F2
                                    SHA-256:A536B35AD437B72981204D0E433D4D2BF3DB609AB1614A49162B51B7B04DCB6C
                                    SHA-512:BC1A6D5C25A3ED6C48523737282DB40CDE7E3741E94518B4CAF6E68C6E1F65C73F8A3554756ADAFE61606C2A9287E8C685FDA93F16D8958ABB10FB089360B95B
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g."!.......& ...".....F......P..........c..............................!......Q$....... .........................................O.......................................8............................u..(....................................................text...............................`.P`.data... ...........................@.`..rdata..`...........................@.`@.pdata...............z..............@.0@.xdata..............................@.0@.bss..................................`..edata..O...........................@.0@.idata..............................@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..8............F..............@.0B/4...................L..............@.PB/19.....@............T..............@..B/31..................8..............@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                    Category:dropped
                                    Size (bytes):573243
                                    Entropy (8bit):5.663814732368988
                                    Encrypted:false
                                    SSDEEP:12288:9l1R4AqmPOt7PpCL+rP7spunqunhg8JqTu7:9WhmPy7PpCL+rD8bTu7
                                    MD5:8E6E79C048CE57042967FCAD21013E88
                                    SHA1:7063161AD5C1B24C1BDE86D0AD7C141FE08B5DC9
                                    SHA-256:7CD647AA80B3F0C0CD8875A394D30594EF9486430061CEDA8DD5E32BB649165A
                                    SHA-512:B24A04E7E8B5A02CACD275E7A599A2EAF2E6D33E1AE7C1DBDE08A4BC99EA2E04382067E286F2DFFE7528147105309E42B77783737D5F856DDD019B270D883022
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....2g..........& ...".....X......P..........e.............................P......LA........ ......................................`..L....p...4...........0..................D........................... ...(....................z...............................text...H...........................`.P`.data...`...........................@.`..rdata..@&.......(..................@.`@.pdata.......0......................@.0@.xdata.......@......................@.0@.bss.........P........................`..edata..L....`....... ..............@.0@.idata...4...p...6..."..............@.0..CRT....X............X..............@.@..tls.................Z..............@.@..reloc..D............\..............@.0B/4...................^..............@.PB/19.....7............b..............@..B/31.....F1.......2..................@..B/45.................................@..B/57.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):10320
                                    Entropy (8bit):4.576136228832107
                                    Encrypted:false
                                    SSDEEP:192:lySIB2jtyhc10+AlXV6y279BovSRWnxQopafSqUoJko7fKWXfiNzM9:lySIB2jty00Ll0y2ZfopafSqUoGo7yW5
                                    MD5:8E997374B060E1B5450814F731306016
                                    SHA1:AB7530FB426F2D41BBC149C33B9DADFB4A065F52
                                    SHA-256:08CF0580D5FB9AFCBC5DDCF45E4C0C653F9ACFDBEBEB394AC670B94FDB0553C6
                                    SHA-512:33B01561723DC4BFBDB861568B278DD79FAED06B261C18E1CDBD1E8E9CE1CDA8C68E2159FF3BCD58DD2F72CFAEDA030B66F30FF060BC47B2F9B52868D2576114
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Authors: Marco Barisione, Emanuele Aina. Copyright (C) 2005-2007 Marco Barisione <barisione@gmail.com>. Copyright (C) 2005-2007 Emanuele Aina.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<language id="def" _name="Defaults" hidden="true" version="2.0">. <styles>.. <!
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):11071
                                    Entropy (8bit):4.638238373756212
                                    Encrypted:false
                                    SSDEEP:192:iySgpyg6ZXlGsMyHntZbnqbnan2narXBnafXGPSenX7YfYbpofafamigennYk:iySHgDMHntXdSe7hbpiIa7D
                                    MD5:AAEAF316490E5A11A4727066FC40E87A
                                    SHA1:BEFE460F91BBDCDC9DA3090C046DF74FCED865A6
                                    SHA-256:8BA47A33D3076C9574D1ECABFD0E1F81CF5C3AC2799BD46F598ED02EEA5F47FF
                                    SHA-512:CEE30CD21C74B370CC9EEA716957DB6D4F1C3176AA29F839A9CE3120C1710EEA80B2D8A72D1648DD0170A8F18C0295833FF23BAEB5A2FDE37945D711FB2154B7
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2005-2007 Marco Barisione <barisione@gmail.com>. Copyright (C) 2005-2007 Emanuele Aina.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->. . This file describes the XML format used for syntax highlight. descriptions for the GtkSourceView 1.x library.. . .lang f
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):13615
                                    Entropy (8bit):4.011935129443769
                                    Encrypted:false
                                    SSDEEP:384:iySeI/b1N9mrYAzolzIXq0JxfNBo1rYLaAh9LNkd0IaalAhv9LNkL9vCkzVaNk5u:PSeIazolzI/xroa
                                    MD5:5DE2E8ED11BBCCBDED825D7CF57D9711
                                    SHA1:0FF99208DAD1FF41A17E065D8F3ABF3ED4D0CE2F
                                    SHA-256:52B433E5854C37C22D341C4EC106675500CEB83FEB5DD16BE0EEB4EB9705FFD4
                                    SHA-512:0F8180923802A995251C66B30745EA192EC98C79391D4798A2ED450505D5AA479688687F6EF08ED2F4C1AE9D4B677D37A7908088DDF815015600B2035899B952
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2005-2007 Marco Barisione <barisione@gmail.com>. Copyright (C) 2005-2007 Emanuele Aina.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<grammar xmlns="http://relaxng.org/ns/structure/1.0". datatypeLibrary="http://www.w3.org/2001/XMLSchema-datatypes">.<start
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, Unicode text, UTF-8 text
                                    Category:dropped
                                    Size (bytes):15026
                                    Entropy (8bit):4.705271831904072
                                    Encrypted:false
                                    SSDEEP:192:XSICmdXBwFK9IAW0Ye477DRK9mOYgR7B7611wYj:XSICm8A9IAW0Ye477DRK9mODEnj
                                    MD5:6DA7821D0372C966A2B3BF8CE0780212
                                    SHA1:27BA4722800897DEE588FF03B847066E8A9B75D6
                                    SHA-256:DB2C396EC8F4A1D27742E458E6BDD23E9F37546E899D7E6DF197AC82AAF477E8
                                    SHA-512:E6E9531B4B59B891B925C3BD73BA7D62417B35480F764B87A800C233B3757155889892AB02F6BBECA61AC9F65EBC48767E4AA46080B49B041CC2CC9FF59998CF
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Author: Gustavo Gir.ldez <gustavo.giraldez@gmx.net>. Copyright (C) 2003 Gustavo Gir.ldez <gustavo.giraldez@gmx.net>. Copyright (C) 2004 Beno.t Dejean <TaZForEver@free.fr>. Copyright (C) 2006 Steve Fr.cinaux <nud@apinc.org>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<lan
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):4269
                                    Entropy (8bit):4.77474899491439
                                    Encrypted:false
                                    SSDEEP:48:c2bFNJyvHqiawfCSNr6RSaeTeqitFQu6RvIWbVz4UAYz+jX:/NA/awcH0g2+b
                                    MD5:27D2D1C51143C4DEE887C7B052655AA3
                                    SHA1:D192E93BA04F08C3176B7031D4A5CED028C049AC
                                    SHA-256:6CFCE53C79B7BE66F23E6C33F12268E3A9F4D0381B8DBA0D7F8873BE00A154AC
                                    SHA-512:80E896189759B6A6FCA3317C40832877FD7CC2029FDF27DAABA104F0E2B7505956E1D1F4D9E6DE7B323DD58D0318F1D490C45A8BECFA3F67CDAD5FE71E2E8D63
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 GtkSourceView team. Author: Yevgen Muntyan <muntyan@tamu.edu>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<style-scheme id="classic" _name="Classic" version="1.0">. <author>GtkSourceView team</author>. <_description>Classic color scheme</_descriptio
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):6522
                                    Entropy (8bit):4.617281808911092
                                    Encrypted:false
                                    SSDEEP:48:cEFNJyvHqwPamnIHgzunKDS1g4srVglrnfE/5stGwvSux/9/knGAiojmkezZG557:jNAPPa0IHganKBr+IstG2Urj0VujpCEx
                                    MD5:F84DCCCACE552F31C298D8E76D91F5F5
                                    SHA1:FCB2C9E418570BAC3F462033120E85792FC1FACE
                                    SHA-256:1634956FDE389345971C2C57E1EC844F33A40B846D7945D5BD8984CFD1017E2E
                                    SHA-512:63B694C1B5C0F581E5239DFED0E31D87B604678E0E89BF5EDB0922394019F53CF1C337E3F2391ADA60F91497CC26F82DF35AA0C4E512AA2F0FC67059B02AC32E
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 Will Farrington <wcfarrington@gmail.com>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA.... Theme based on the style of the same name from pastie.caboo.se.-->..<style-scheme id="cobalt" _name="Cobalt" version="1.0">. <author>Will Farrington</author>. <_descr
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):7760
                                    Entropy (8bit):4.598866607165661
                                    Encrypted:false
                                    SSDEEP:48:c2bFNJyvHqiaW/c1M/qvoIOI/btSFDuIv3MshutdBtUcfM/ycX7CM+k7sHwftvmk:/NAjaW/c1MluRfMKcX73+k7sHMtvT7Aw
                                    MD5:B628E36E5B283CFA9A144D9BC20AF6C7
                                    SHA1:CD246A25F940DCDFD3DB65A185389D7E1A679D85
                                    SHA-256:343025A57585E2E361A44DBD1DA98D1822DAEC094266D692E9171E34F51864AD
                                    SHA-512:74F0D363BCB5C33B613C715418EFA06500920F7033F4FC1D0F31E401DD9DA0C3D1B89AA21259790C81FB495FA7B4B413888D33FF58CA00EE7439998C0A3A2EF6
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 GtkSourceView team. Author: Yevgen Muntyan <muntyan@tamu.edu>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<style-scheme id="kate" _name="Kate" version="1.0">. <author>GtkSourceView team</author>. <_description>Color scheme used in the Kate text edit
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):5461
                                    Entropy (8bit):4.5995288425836485
                                    Encrypted:false
                                    SSDEEP:48:cjNdFNJyvHqPtG0xhvp8+H2Hk/j0wb1sbUV5SfDADtGAaM1rD0YfiAgqAFf/ffFx:WTNAeG0Bb/j0u3/UFZ7NGbUB
                                    MD5:76F4263D0B53019A0306CF00D2931404
                                    SHA1:756E3CBB392D6F02EB867BF9A30A1EB7CB614650
                                    SHA-256:8FB046A55E13C657DD9BD2A80AC09B4E400B9BDC2506C22B33411DBE94888615
                                    SHA-512:42957CD5D1BBC74BDAF32919AE8E1431E4138A3285F40D4DE8BF77A4C3EF3F8901EFCB63647F2C2717A79DF17CD8BFCE7DE23ABE2C9BD832297746996CC3B26C
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2007 GtkSourceView team. Author: Paolo Borelli <pborelli@gnome.org>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->..<style-scheme id="oblivion" _name="Oblivion" version="1.0">.. <author>Paolo Borelli</author>. <_description>Dark color scheme using the Tango colo
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):3401
                                    Entropy (8bit):4.54417605834984
                                    Encrypted:false
                                    SSDEEP:96:xNAeN9mABHYCojlCnuCJglVm49VxqnogbyFoArheLXn:xSkmABw4Ym4DxqoGyajb
                                    MD5:11E2345777971F68DF18D8EFA2A95D38
                                    SHA1:023DAC5CD32C514D521B3C0EEA4F9A341519A46B
                                    SHA-256:5E738E82B5F0DB3B3A2F04BBEE31B6088AEA72CCED1CCD34AB7ED8C6BD556361
                                    SHA-512:E1EA4F9618B948F5E7E22881A5ECEEDF062F230E297F98EBBFC537C4BCE584D6919DE46887E0C9C274C882169C630E1FF01702CE688623BA0E8CAD311C8D1AC6
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 Yevgen Muntyan <muntyan@tamu.edu>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<grammar xmlns="http://relaxng.org/ns/structure/1.0". datatypeLibrary="http://www.w3.org/2001/XMLSchema-datatypes">..<start>. <element name="style-scheme">. <att
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):5592
                                    Entropy (8bit):4.589603429741462
                                    Encrypted:false
                                    SSDEEP:48:c2PMWFNJyvHqz584xhvp8+H2Hk/j0wb1sbUV5r2zZaM1E0YFtiOsrF0Bu4cvSg3u:XNAU5xBb/j0u3xdQ44r/O
                                    MD5:E83BC7AD11ADE4B217E879E65BB88517
                                    SHA1:7922B25F41000D2849A1A76EF744F2DAC0CE26D2
                                    SHA-256:7F474589A106B40E96BCD2B73A8554FBC87EE677B62110C595E19D78AA1E95B0
                                    SHA-512:B34E4ADCC82E1EC64C99993D99DA11F7FB40A62A3791972989CE1C6BAB767E22A9C078848AFF84A25C9DFD3559BB9C2E277D0E8800BC4E560553887EED537AD1
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 GtkSourceView team. Author: Michael Monreal <michael.monreal@gmail.com>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<style-scheme id="tango" _name="Tango" version="1.0">. <author>Michael Monreal</author>. <_description>Color scheme using Tango color
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):100
                                    Entropy (8bit):3.6821516450789775
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1MYLvLvvLvLZ0DF4LZNLMLLJ:aNWr1NmY/3/mZGM/J
                                    MD5:E3562CCD62765D7D3002597F3C3C833B
                                    SHA1:EB59BCC59AB992AC5FA719AC7EBF8CCF836CF5B1
                                    SHA-256:B81BE2973EBE9D884F26D34872CD333CAAC4C28AEB60F147E09DFE9701ECDB59
                                    SHA-512:3ED0BA132B5B4B0FC6B930AC52F911F782EDDC4A0ACBEB7214343CCC8E24CDB18D392BE8B392D84AC738BDED0B2834F6733E8F01EF8E6B853BEB7F210B2BFE35
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 1.0 1.0.0.6 0.0 1.0 1.0.0.0 0.9 0.0 1.0.0.0 0.0 0.0 1.0.0.4.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):106
                                    Entropy (8bit):3.644696898026447
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1NLMLL6VGVGUhZ3GSVvVLZNLMVXQv:aNWr1NY/644U/HVvhM9Qv
                                    MD5:79867A332CB1759E1775D387761CF852
                                    SHA1:9DC65B3E2F97FE07F7A842169C5C791E32371BA1
                                    SHA-256:3F6D6AA5F18406BCCC49006DB57D543AAD122593016BD3E6B8908604E14FC81E
                                    SHA-512:201084E4555A64A058B0BCEC3BB3179E34BB0DC826FAE6B99FAF24E7D5D21CA1276C1ABD66A11F03EBFB863DE4B32A85B472DFDB71AFA9C559A9CA70FAD92F93
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.01 0.01 0.01 1.0.0.50 0.50 0.50 1.0.0.0 0.0 0.0 1.0..25.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):110
                                    Entropy (8bit):3.840172487209101
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN5zVzULvL6VGVGUhZxVfULVvhZNLMVVSFv:aNWr1N4LT644U/ILFhM/SFv
                                    MD5:0463EDF8B7157B56E586829BEE9C9E66
                                    SHA1:71369E2FF1CA20EB4BE34C35B9DA85F692D92328
                                    SHA-256:4FEACE58D14481A43BAB9DA0F96FA122F91E149C9BCE885F16F5EDAB4F977F84
                                    SHA-512:22FC901C5E09EDD89CCDAB83EB81A8B3B48586D01CA1397566FC939140FD6494E8D89DFF2FA411247CE7BB0FC47B2CDE1FB7BAC8C7E5E74E8F2DB32D3DC9598A
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.02 0.02 0.02 1.0.0.01 0.01 0.01 1.0.0.4 0.4 0.4 1.0.0.0 0.0 0.0 1.0..078125.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):152
                                    Entropy (8bit):4.260956733214682
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNYnceETaWniCU9BLFVLggNSvexZZNLMLLbvn:aNWr1NibwQCUHTV5M/Ln
                                    MD5:847C64D20DCE377A8B04CD3CB28B3833
                                    SHA1:065151919677EDC04164768EA29837B2C8FA7C3F
                                    SHA-256:0CB4918977BB40B097A347C6093DF50FB625D5A0690A85A277CA690882834576
                                    SHA-512:5E1670B088CCF07B7F91FC696BEA57B8B75A8A790FAAAE18BA88F7C49091AB2D6AFAB25BB66F0275CFF3E661268BD3025F6037199F08C07FFB31EF4B29033B02
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.329412 0.223529 0.027451 1.0.0.780392 0.568627 0.113725 1.0.0.992157 0.941176 0.807843 1.0.0.0 0.0 0.0 1.0.0.21794872.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):88
                                    Entropy (8bit):4.020330150126378
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNLjb5VpvpN5V4VLNLMVW6n:aNWr1NiUZn
                                    MD5:2E224DF6656F6D9F5951EC8C0BF4B410
                                    SHA1:27D6EF798EF53C7C9854084E2628B474E856DDCD
                                    SHA-256:0DFCFEDBBD047F9C38DCD5B3999B3613908C4ADDBB41769E5C6132599D44D748
                                    SHA-512:62E3DA865ABC812EF62426920613D8ED48EFF0A8AAB42B8BCF0319B0C42A9A1B77792A69579E2837CEE03C34CD799F6841868CA6A658157FC50B5994176D5332
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.2 0.2 0.2.0.8 0.8 0.8.0.5 0.5 0.5.0.0 0.0 0.0 1.0..35.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):132
                                    Entropy (8bit):4.2072421174441565
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNHWhVQWTjhRXdjCPDRhSTLkSVZZNLMLL/:aNWr1N2hVBTjhR8PDSTLJTM//
                                    MD5:7891F84C415B025CF6D57F9ED7059467
                                    SHA1:12270FB13AA9F0A55793863B41A0411D7F2D0C7F
                                    SHA-256:583417898ECE9B6AB8E6B4B44A4B9624856B751A7CC87CE5A2F647E029614D9C
                                    SHA-512:73A69C5B9372D440B6D9683E812A997B3695B839606C4ADECD7D407E0BD83F66F5C8D834AE51C4630CFA3744541037E61BF0BAADE4AB4168FD56B7109D88CD76
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.2125 0.1275 0.054 1.0.0.714 0.4284 0.18144 1.0.0.393548 0.271906 0.166721 1.0.0.0 0.0 0.0 1.0.0.2.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):118
                                    Entropy (8bit):4.102460959153464
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNcsvsuLVvVLxVfULVvhwcSvLwcSvLwcSu5VLZNLMLLj:aNWr1NT/ILFhpSvVSvVSwM/j
                                    MD5:D9C2782FE02B0E7625E7B69D27366998
                                    SHA1:37915BB968F1B467E399AB3E2E244B5BFA7683D0
                                    SHA-256:A840D580CCE41D0E3267FEBAC5AEB8FEC7BFA52ABEC0366E9E663626F27C2E21
                                    SHA-512:5F7CC77507F5E4EE0F42A25D9F2BFC0FBA53DFA95F86F458CC51430C40E4DD38F62430F16A8CC60AB58177963B1632C898D085216DEB06A6291652F8769DBC46
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.25 0.25 0.25 1.0.0.4 0.4 0.4 1.0.0.774597 0.774597 0.774597 1.0.0.0 0.0 0.0 1.0.0.6.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):100
                                    Entropy (8bit):3.9750108102672788
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNLja+h1oUSvL/jdEVvhZNLMVW6n:aNWr1Niwqt2FhMZn
                                    MD5:680AEF1F735715A3DDA94AA668A4B25F
                                    SHA1:3C6ECC45EF6857F97E1A5723BA8DE1F7C920029C
                                    SHA-256:8111D68D32E63218C39F1A76983D24101EF1663171D927119BD291DF9CCA524F
                                    SHA-512:7428FEC0222F1E5E57686338522267EEDF53A6CA780A87E50B45F0D0ADE483DA8D1893F30B3CCE3959A3AFE5B67BE41404D1D48B46F94C65398C195A17F7E8D2
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.2 0.2 0.3 1.0.0.8 0.9 1.0 1.0.0.2 0.2 0.4 1.0.0.0 0.0 0.0 1.0..35.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):135
                                    Entropy (8bit):4.141656617603121
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNJEVh1QFYVLhdTXgdNET1hvLPMhjVZ5hZNLMLL2:aNWr1NJvFGhh7T1ZTM/hM/2
                                    MD5:3F9ADF4D169B11A2F57FF1083F251433
                                    SHA1:E54053DD0A788D1C1D9C5ED9339C71E4571C4A4B
                                    SHA-256:3FF34A4B2F0691958BA8245B6851FD5888AA9DE877899E00672FEBADF9D2A43F
                                    SHA-512:00C0FFE607C5573B607D4DA6FED958652ED946BAC118B404BFEBA79E67C67248993A9AE983082F536FA030C4562C6957B0CB8B1A4140F1CE231E710F1A3A8EFF
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.19125 0.0735 0.0225 1.0.0.7038 0.27048 0.0828 1.0.0.256777 0.137622 0.086014 1.0.0.0 0.0 0.0 1.0.0.1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):136
                                    Entropy (8bit):4.037132329056418
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1chqvhZAcXWcFXWcsvVLYVSHCpVSHCpVSHSTZNLMVXQv:aNWr1NahUhacGAGBvhYQCpQCpQSTM9Qv
                                    MD5:08CCF2E7E247E5A70402DB3F61BB6D0D
                                    SHA1:E6903090F54E80FB57E86E8F7ABCC1C8AF9FA11B
                                    SHA-256:167251926ACEC9E15A6750E495F023D5510CD347D994A53218131248C45A4C6E
                                    SHA-512:423AD24ADE69004C1B917BB60938838A99523D82D9B6DD3C793FC36452D675348E1B62BF76D5FC5CA9A6CA80D1EE7C9582000BBD4544FDAEDF160B5764119E77
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.1 0.06 1.0.0.0 0.50980392 0.50980392 1.0.0.50196078 0.50196078 0.50196078 1.0.0.0 0.0 0.0 1.0..25.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):107
                                    Entropy (8bit):3.8949478911747493
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1AVQ+VL/ULVNL3STvLZNLMVVSFv:aNWr1NW7c/iTTM/SFv
                                    MD5:9677D65C48072A4B95BB26F9CCA949AC
                                    SHA1:7BA1449913F8CA929545F8326F1D9EDDFAB6D824
                                    SHA-256:C69188CBDB3E04CF0F5F3260299DD8D3AFA3132CB604C1C06C48B655F1781B7B
                                    SHA-512:20FBE4AA1D9CFA947972D1310D62F9A673D50753B9FEEDDBEDEFC3088A4E105DAA3074A67A0EB919A5C1330AB1E92A1310D304366DEA4D01A0A8E77321E2E7E6
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.05 0.05 1.0.0.4 0.5 0.5 1.0.0.04 0.7 0.7 1.0.0.0 0.0 0.0 1.0..078125.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):130
                                    Entropy (8bit):4.160356377300852
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNpVgS2FgQULLdRFVURXpPFUhvhdvX1uLFhZNLMLLj:aNWr1NpVXbQG7FVUR5PFYh1XeM/j
                                    MD5:C0E3790466D9905FFDA597D4BE8DBB83
                                    SHA1:A9378A6E43BD14322B6BE65E1D28FE9F1521F44D
                                    SHA-256:5E017165CE8A119C6C99A5FE6B9656003FF267546D4495794970F254C89441FA
                                    SHA-512:D69A39DDF7902B067B4C880E598BAC839639704231207479162167EB818BB8DB70CEA3A76014D6DA42CC4F84E011F0731478A7338FB478D728877E31EFC0EA4E
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0215 0.1745 0.0215 1.0.0.07568 0.61424 0.07568 1.0.0.633 0.727811 0.633 1.0.0.0 0.0 0.0 1.0.0.6.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):137
                                    Entropy (8bit):4.2091222535596415
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNgXQCihzFULVNLORflFVrT7EFhJMqXDUZtLLZNLMLLJ:aNWr1NgXbIzuLT+eFh2iIZt/M/J
                                    MD5:839FA2DF92CDF5C3167C024B4289CC92
                                    SHA1:9100B2AE8BA7421238938BF5AD0FD523BE79FDD9
                                    SHA-256:E59E79CE475AD7B86384B7C52D109A5A57945BAE6460C1D89F7BC4F58FC222CF
                                    SHA-512:7090BA0C70B1306C65D8E53DBC1A94516A1E1CFF8DD8E1969F7B8A8DE62595BAB1070010358BBF2FD90DC87EB91A8756E8933B9B6362ED958D0BC5D35A0022FE
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.24725 0.1995 0.0745 1.0.0.75164 0.60648 0.22648 1.0.0.628281 0.555802 0.366065 1.0.0.0 0.0 0.0 1.0.0.4.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):104
                                    Entropy (8bit):3.857253945645381
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1NLMLLkL/AGQQF4LZNLMVXQv:aNWr1NY/C/5QQGM9Qv
                                    MD5:E5EF8A0F7F31E79D53A3FF72AF76C46D
                                    SHA1:6F9180D98DA01A4AF8E0720EEF8D4F70AF97498B
                                    SHA-256:DF66325329297256A024E446CFFD0604E298A133D7DCE453E6DE53097535080B
                                    SHA-512:9ACBDADDFE4ED4D4F66B3C72F7B763BB56FAE33D3E15F202F507987B9EAAF04908FD1A2BB74B80F77EE917306ADAAFDFA9298B4E7D02413FE539F19682E6911B
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.1 0.35 0.1 1.0.0.45 0.55 0.45 1.0.0.0 0.0 0.0 1.0..25.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):107
                                    Entropy (8bit):3.8720725243278
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1AVFULLBVvh3STBGZNLMVVSFv:aNWr1NWvU/BFhiT8M/SFv
                                    MD5:F04ECC324C91835A58CDAE312CC3FBB3
                                    SHA1:3EFBD1DBC0B07452D3568CA7027D1C1B21B45311
                                    SHA-256:FFFA9B6475F15C8F12E1139347040E185E64C3489107F38D49AFA076FD0E4C32
                                    SHA-512:A85722EDA4159C16F3F8BD817650C5F62EEE325FB640CBC37A42D70A59827A1906BC31A6B20F1A8683C1B9CE76EE415943A9634101B735C008CD0048D6E11A70
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.05 0.0 1.0.0.4 0.5 0.4 1.0.0.04 0.7 0.04 1.0.0.0 0.0 0.0 1.0..078125.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):126
                                    Entropy (8bit):4.183861482790752
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN9LUw+VL0p0FWET1TTxTTxwZNLMLL2:aNWr1NpUww0p0d155wM/2
                                    MD5:58DDBD05A6BD4F9138D0D9CB9B1AADB0
                                    SHA1:BF3E812B22B63850523D53F90613CD0E719EE3DE
                                    SHA-256:E7A401A3E8CA0578ABDBD4D0CDE8BD65C2DAFF4AA1725DB62A03692C340CADEE
                                    SHA-512:6FE8972750DEB7A3BDF8BD5CC50F00DFAAD5D72EC3D42BBDD94A4518FDB2D43CB0FD41D3E304CEEC41BE758727E95CF52068F4E803DE727F28E55204AC037DBC
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.135 0.2225 0.1575 1.0.0.54 0.89 0.63 1.0.0.316228 0.316228 0.316228 1.0.0.0 0.0 0.0 1.0.0.1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):133
                                    Entropy (8bit):4.183784927087676
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNBSu6TVTTAFULFVL+SQTUyvFU5VLpvLvTW1lqLZNLMLLo:aNWr1Nu50FU/oTvu/CwM/o
                                    MD5:CA9BA2CBE51CFCD55F76797E9E87FFCC
                                    SHA1:DD0EA970EBEEF496A71AC731CC5419571343775D
                                    SHA-256:0E1E9A4F9A9A1DCB8F3E616151BFB625BC43E305A4AA97C538E072588DB4DBE0
                                    SHA-512:0CF2E5A6443B2925F688C244FD29D0E219E2C4EBB730B0612FB7D767BC964A97ACA21761B0753BD12CE7FB35ADE628F4E047FE44D5B9B45441F8A0299A7919F5
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.05375 0.05 0.06625 1.0.0.18275 0.17 0.22525 1.0.0.332741 0.328634 0.346435 1.0.0.0 0.0 0.0 1.0.0.3.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):130
                                    Entropy (8bit):4.1630155355592615
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNcpZvLXVZu5UXW9U1LM51LM505hZNLMLLdn:aNWr1NEZxZuKKUK5K505hM/d
                                    MD5:242CBE018066C683C84E61D90866AE4B
                                    SHA1:57F3D40BC617EDC0757A17EA81B7D9E581B74C66
                                    SHA-256:9F0FEE790F0CCC971A78B78B105C8B7E2990BBD4B0AF157EE701F39A90606A12
                                    SHA-512:C94586623CE09A3C723A5D13A23ED65D149170AEC5D75C7637FFDC281A3E995D54487F543446CCC55FD75FAF2077D25F36919AF7CDF2DECB1C24756EC9FED31A
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.25 0.20725 0.20725 1.0.1.0 0.829 0.829 1.0.0.296648 0.296648 0.296648 1.0.0.0 0.0 0.0 1.0.0.088.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):150
                                    Entropy (8bit):4.222459957751247
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNFddXvhSjVwkBLFVLIQ60hjWMjWMAQ8ZZNLMLLecGvn:aNWr1NFHAj3TIQ60hjWgWjQwM/ecGvn
                                    MD5:3A9B933F1380367EA38332E401CC8F99
                                    SHA1:60AD6B2A128B22FB87441D75C1AF4F9C1C7D642E
                                    SHA-256:56EF6C5E3732AA59ABD0140A7570B27C2A3EAA633D2875D05F1F1DE598CBAC49
                                    SHA-512:8634A399D79FF13140ADB7BAEAAF869B88EB8247F26479FA7542CE9F87E3778A91DE02AF3B10829830C38F8E293126B6D1DDB0DC7ABF5583E1ABFA00AD083612
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.105882 0.058824 0.113725 1.0.0.427451 0.470588 0.541176 1.0.0.333333 0.333333 0.521569 1.0.0.0 0.0 0.0 1.0.0.076923.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):128
                                    Entropy (8bit):4.186817826612881
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNc0L5pu5VLETHVDTwwcSvL2drjVVTEETZNLMLLj:aNWr1N/sETHRUpSvGdawM/j
                                    MD5:95313A0312E0F34B2FCA7281D64437BE
                                    SHA1:F7D2B83BBC713E8ED75F3D754823F87D8ACEC2F5
                                    SHA-256:FF4A01541FE5072246104CCDF856318D2EDC897E651D9FA9ECC4DA3CACB06211
                                    SHA-512:A74CF79261E2DC59426CAE248A65D3C2AACA765DAC60A941455E5A7622BD283D55296534D7AD6CAB6DE583E184A49C40E2D921BD2E7B4738561BE12AE103647F
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.25 0.148 0.06475 1.0.0.4 0.2368 0.1036 1.0.0.774597 0.458561 0.200621 1.0.0.0 0.0 0.0 1.0.0.6.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):134
                                    Entropy (8bit):4.133243296968186
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNIQVLtXQLSQU5VLvHVJhVmLTOIQQSVcSTZNLMLLJ:aNWr1NIQVLeLSQGvHVJhVmLTdQaSTM/J
                                    MD5:FF271BA08123E5141FCF50E77100BB7F
                                    SHA1:0BED4919C86B83A3C776C7CBE8328A12F8EFF7F0
                                    SHA-256:349832B8E36EF92163C0009FE6C9BB1ECAC1143462560704FFC876FF644E4722
                                    SHA-512:5911A14B0494F29D88E5E4BB87359357AED2572ED0E607F1E75EFA0029C76AB644929F8CC6FF5B260C27DC8C65B5D9B5E4F7A0F850838619A6E2D7876136E0FE
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.2295 0.08825 0.0275 1.0.0.5508 0.2118 0.066 1.0.0.580594 0.223257 0.0695701 1.0.0.0 0.0 0.0 1.0.0.4.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):136
                                    Entropy (8bit):4.203817269126771
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNgXQBXipQULLITRWLybTCfZxdVVAFhZNLMLLe:aNWr1NgX6i6U/ITRWObTCHuFhM/e
                                    MD5:C0224EB189AA5AFA086DCD8180ADEE11
                                    SHA1:726BECF53D0A5AA36490215B3DBF26618FCD4E1F
                                    SHA-256:7C5D24D428CB90D23973333C3F8E9EFBE728AAEBCFCE1A5E7A03427F3D1F2B69
                                    SHA-512:3028DF555517F1D1CF11506CEC5FFFB35AE9E9ADC450A68EEBED160CD8C605748A1D1A8E0BC041C231819726C07C2CDB169AED3A41E08A43D2FDC1476518B8BA
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.24725 0.2245 0.0645 1.0.0.34615 0.3143 0.0903 1.0.0.797357 0.723991 0.208006 1.0.0.0 0.0 0.0 1.0.0.65.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):100
                                    Entropy (8bit):3.777822442392851
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1NLMLL6LMLLyLbLUZNLMVXQv:aNWr1NY/B/YMM9Qv
                                    MD5:78C7315BD58038CD201FF4A9EBED0CD3
                                    SHA1:E3D5A76E1FC7AB84EE836970385B17EC9F91F5D8
                                    SHA-256:77E81571C62E1BFB80A23C7C05B267C547C576E0C58CCD16D64F009AB4809B0B
                                    SHA-512:D4920F052FCE8547F035054D2EC9561CB4A6A8E3E89BE6C1CDC8A3E49622D5EDC6D805CDEB7B49E4903A9CA5639F7E370D4905804EBD597587B6B1F058F417F5
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.5 0.0 0.0 1.0.0.7 0.6 0.6 1.0.0.0 0.0 0.0 1.0..25.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):107
                                    Entropy (8bit):3.8720725243278
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNShVFVLMLL4ULVvhyLBhVCZNLMVVSFv:aNWr1NShvq/ZLFhYMM/SFv
                                    MD5:B4563CBB3A250E36D22F426CE34E6EFA
                                    SHA1:8153E6A98750457C87DA1BF9D52322157EA2E511
                                    SHA-256:EC0A65E3E43FCC60741722CF85B4B1DCC5D3A347DE17743FA5125D87044F1BA3
                                    SHA-512:C7D0955813027DF3BEAFCE24D365959C0DF74D9C07903D2BD7259F54E7AD0E1699771E89E813AE6113AF5D6DD723E32D31575EF2BC5A13C15311548B91E8CD2A
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.05 0.0 0.0 1.0.0.5 0.4 0.4 1.0.0.7 0.04 0.04 1.0.0.0 0.0 0.0 1.0..078125.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):138
                                    Entropy (8bit):4.175660217138283
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNmFzh+MmvVL8Xp1uTbEJfAJwZNLMLLj:aNWr1NRZ8516bERAaM/j
                                    MD5:9A02EB5FE8CBF67988E71F2F6DFD0786
                                    SHA1:F8D2C7F0FFE6F0070C42F13FE6FDB8ECD0C77212
                                    SHA-256:01467C6EBFB90565296A9A8825E7C2196A3644EB153D8B33AD1A94FC47C08E97
                                    SHA-512:AB9D71B31D12D6833CCE088CD47CC7DE833A969E139554F862468317A5BDEA3B1BD54C5F0312F78438837F5E6D1065F5066F29A5A25703D3A386E81852662478
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.1745 0.01175 0.01175 1.0.0.61424 0.04136 0.04136 1.0.0.727811 0.626959 0.626959 1.0.0.0 0.0 0.0 1.0.0.6.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):139
                                    Entropy (8bit):4.127930249850105
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN9qAVLUvwvwuLTrTZNLMLLJ:aNWr1N9q+UvwvwwfM/J
                                    MD5:9CBFEF9FB4E5958DC4C4797ABCB64AB5
                                    SHA1:3A9DF3261245838CA5E8B7B44BBCD1678B139EDF
                                    SHA-256:EE3EC48510CCD77EE36E4D30FDDCB142770EA145C183B1D875464C1B73A68775
                                    SHA-512:71EF0D6D4C22696B4CD4EE9FBB7DC3EEBCFCE6ECD1914E0166B849D9A545D49F9D236E6972302DD1B574D3CF036387937EFD7FD8C400CADCD1327704D54BCA21
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.19225 0.19225 0.19225 1.0.0.50754 0.50754 0.50754 1.0.0.508273 0.508273 0.508273 1.0.0.0 0.0 0.0 1.0.0.4.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):131
                                    Entropy (8bit):4.22316429183848
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNwL7LzFmNLfmYln4LbFXcvi5TuuLVZZNLMLL2:aNWr1N+7L0ftdGbtcaNzVZM/2
                                    MD5:53593E7583271296C92B8D1ED9604996
                                    SHA1:3D071D320E8018D511752BEC4093EE6B84C01B26
                                    SHA-256:F328919831D115FE1500C783775141C5B722274043A3FFE7143E7FA4DC7A4ACB
                                    SHA-512:C6C59B80875FA168DE48205CA6BC2A03CCA48FD386C39BE168B2FF98E97982791965163774FD362D4D4F4F408A9641254B95CEDA74E1996E25A46728325AEB82
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.1 0.18725 0.1745 1.0.0.396 0.74151 0.69102 1.0.0.297254 0.30829 0.306678 1.0.0.0 0.0 0.0 1.0.0.1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):100
                                    Entropy (8bit):3.9750108102672788
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNKFVjrWFLFGXBqLZNLMVW6n:aNWr1Ne1WFxGCMZn
                                    MD5:617A64265828442D6B1A03EAD0F587B7
                                    SHA1:0F224B624B3B440886BDAB762AE01A66ABE1C0BB
                                    SHA-256:17E9EDB77AA1C090B22B8B91529E436125D5D87BF9D0B3A075D1CD995086AE30
                                    SHA-512:863B735F8E30FA5F5FB674709908F577EAFD0B73D40291B503337E9D2B4A8818E3B74E31CFA08B3785231BEF2AFF98FEF1ACBD29E5BA41FC699D466B638B4DE3
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.3 0.2 0.2 1.0.1.0 0.9 0.8 1.0.0.4 0.2 0.2 1.0.0.0 0.0 0.0 1.0..35.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):106
                                    Entropy (8bit):3.774457705300799
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1NLMLL/GffVLyyVLZNLMVXQv:aNWr1NY//yPhM9Qv
                                    MD5:2F657CB15A6383F504D2A1FD5FE6A089
                                    SHA1:7D49BF72759E19C75E521E21ABB00C672081A7AA
                                    SHA-256:03972B14B66369C37D7B57B2B85F83804919120CB3F1EE372B0635026F3E7E8C
                                    SHA-512:21576D37A460447AF725B5A8002FB7B9C5C8C777EA4F22624187C2217B506C615A463AD08495B16516D95E806F8EF93B4F280F31C08DA0F452F8D32B94D9715C
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.55 0.55 0.55 1.0.0.70 0.70 0.70 1.0.0.0 0.0 0.0 1.0..25.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):107
                                    Entropy (8bit):3.8642022701485206
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNShVQTVQ+VLtVMULVNLyLYvLZNLMVVSFv:aNWr1NShA7V/YYTM/SFv
                                    MD5:AAF151DD690211427D9676421E33D456
                                    SHA1:2CDC684730DAD3D0D457A667154D89038E7A21B4
                                    SHA-256:EDF19AC9B9F6C9DADC59E33D597EC9B6A995BB0401AE8A55E8CF2437732A6EF1
                                    SHA-512:767E74817CD6CB7E93D7F0E9C96D97BC31B2BD460F8F8D665E43473F9A226C861BD44C60AF8F61E2B914148CC65A74319B7A6362AC374ECF26D4ADDE6A9FD9EF
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.05 0.05 0.05 1.0.0.5 0.5 0.5 1.0.0.7 0.7 0.7 1.0.0.0 0.0 0.0 1.0..078125.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):103
                                    Entropy (8bit):3.7275130767701317
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgN1NLMLLtVYLLZGSVvVLZNLMVXQv:aNWr1NY/Y/FVvhM9Qv
                                    MD5:674A6E99B6895E1DC7AD10E72C53DED9
                                    SHA1:45DABE4B297E3EE605C268FDC5FCFCB05A731045
                                    SHA-256:25B10401718160234CF638E49C14088EF635AC66D90A062353671CA0BB9F7378
                                    SHA-512:3AEDBCB6D393FCFBC359872613E7D12F59FF161EEE6E7F4EE74FB33181DA24EB601ED9AC7FD7C947C1E1C3D197595223C8A5F8F9D9030AF040E91C7BD6FDF5BB
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.5 0.5 0.0 1.0.0.60 0.60 0.50 1.0.0.0 0.0 0.0 1.0..25.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):107
                                    Entropy (8bit):3.8949478911747493
                                    Encrypted:false
                                    SSDEEP:3:a3NW6GFMgNShVQTVFULLtVaVvhyLYBGZNLMVVSFv:aNWr1NShAvU/aFhYY8M/SFv
                                    MD5:1FF1BE1F158EA862DA02332B0D66903A
                                    SHA1:94A70F504240D2047FEC5E2D450CBB7D4880A88C
                                    SHA-256:7E34E346DA362803FD0665604E5937CC775863F4EFCF5831F8186480F09FE91F
                                    SHA-512:1E7BB9C98E28D01A69FC349F7B453179B5D8829BE61FA2222429A821A56E736CA5A588B86588564268C361693F5371591B77BCE417391D9AC136D894112E818B
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGLMaterial.0.05 0.05 0.0 1.0.0.5 0.5 0.4 1.0.0.7 0.7 0.04 1.0.0.0 0.0 0.0 1.0..078125.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):186
                                    Entropy (8bit):3.817341498806536
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOF8gVLUUp+algVLWWRWCY1UF+VLQQQ5vUuUgVLSSsw01UVu:aNWFF8gCUpnlgAWRWQF+GQoRUgESsT1F
                                    MD5:0B948A1F50508751F803DEEA6CD1545C
                                    SHA1:400C901402FD2DBB755EAF6A93FEDADD083D58CE
                                    SHA-256:75A0DBE25C6BEA6E734415342C537CA885CB2585B337C21D863AF1E08C593380
                                    SHA-512:A14321B293449E6683D4BAFA71B30CEDA43CAAD9E3FAAE77D587AF7DF58B56603C5E93D6C9CC8957BD707E190FBB5E5D597DD5FBAA5BED2B4DF607540D16A026
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 1 1 1 1.0.111111 0 0 0 1.0.222222 1 1 1 1.0.333333 0 0 0 1.0.444444 1 1 1 1.0.555556 0 0 0 1.0.666667 1 1 1 1.0.777778 0 0 0 1.0.888889 1 1 1 1.1 0 0 0 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):284
                                    Entropy (8bit):3.1630978519932453
                                    Encrypted:false
                                    SSDEEP:6:aNWFFbXSfCc91mV4fAc916mF9GcF9Kx0fEcfwvu91Ufn:p9S6ceVnmFUcFSvu8f
                                    MD5:A29972E344E7D76E3C7401365DE910DE
                                    SHA1:D5BEC7786935F82773C633171534E7F78FA6BF81
                                    SHA-256:2992343036EAE00444D1D89C67235A10B8E3D741EB1F45111842E75E8BF2860D
                                    SHA-512:B253362178632F1D956E3B7839B9400016ABBAB77BF7037D36C4FF71FE18AD2C00B4AE3F588F41320E6F99E1CDF9F43396CA17CD99DF2365DFE2C09A4B49B588
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.09 0 0 0 1.0.11 1 1 1 1.0.19 1 1 1 1.0.21 0 0 0 1.0.29 0 0 0 1.0.31 1 1 1 1.0.39 1 1 1 1.0.41 0 0 0 1.0.49 0 0 0 1.0.51 1 1 1 1.0.59 1 1 1 1.0.61 0 0 0 1.0.69 0 0 0 1.0.71 1 1 1 1.0.79 1 1 1 1.0.81 0 0 0 1.0.89 0 0 0 1.0.91 1 1 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):345
                                    Entropy (8bit):3.198553860573438
                                    Encrypted:false
                                    SSDEEP:6:aNWFLIm9Vvm/CkiR8UbdcTFKVnhbylV+QIf000/:pLiP3sdcTQFhbylV+pI
                                    MD5:B2B28CB23EBE8400642925E19401BEF4
                                    SHA1:CC574FAC7721477BDC732FFAFF2136BCDC2C5BB7
                                    SHA-256:4022683CB25E3AE12C1DE224C46B1753BC01FEBB3A31370129D5193A8C3DD0C3
                                    SHA-512:D8C08E0F52D46C85A563936FDAE95BE67800CF87AB617216B91105214D7CEFCE7FD018405A900F159957B8DABE4583C9F71E7237C0A001F3CDDAB6EB70C48CD8
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.200000 0.388235 0.187535 0.009135 1.000000.0.300000 0.329000 0.319111 0.268771 1.000000.0.400000 0.222991 0.405319 0.490196 1.000000.0.600000 0.232616 0.617000 0.223354 1.000000.0.800000 0.925490 0.602476 0.853287 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):570
                                    Entropy (8bit):3.4651482700891503
                                    Encrypted:false
                                    SSDEEP:12:pLeV/15Yj1GWATSMBhoZDcdT8AY8K9fg8DwwwxV:lu1g1BeSuoZghA8iDI
                                    MD5:6C76200A6ACD3366B2BEE69D36F859AD
                                    SHA1:F6A596E2CB2AC31DC1DEA8ED44030A47BC7F5DF1
                                    SHA-256:88D73228F99AA5257691F771CBD5B2DBC7DBD9CF7E28584F3AF84F68D2C71163
                                    SHA-512:9A2A6CBB63CDE4249F258F2A881F36B5120FEA1B4953E5F92C56B91BDD494C1F64E4BD715C09FE2A19E037BCC58B61A7CAD8A0FEACB01F5E74C1DB753C1F8EFB
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.053922 0.023529 0.054902 0.494118 1.000000.0.166667 0.023529 0.235294 0.360784 1.000000.0.279412 0.023529 0.352941 0.066667 1.000000.0.392157 0.025405 0.470000 0.025405 1.000000.0.504902 0.360784 0.705882 0.082353 1.000000.0.561275 0.589000 0.779000 0.057000 1.000000.0.617647 0.741176 0.729216 0.023529 1.000000.0.730392 0.741176 0.552941 0.023529 1.000000.0.843137 0.741176 0.400000 0.023529 1.000000.0.955882 0.741176 0.305882 0.023529 1.000000.1.000000 0.833333 0.833333 0.833333 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):62
                                    Entropy (8bit):3.7933252882600437
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN11+n:aNWFFd+n
                                    MD5:BC22C6C95473AB42E83D616BDF40CF43
                                    SHA1:70033010F6E73454C9C2A1478DCD93A5A24B2F64
                                    SHA-256:0BAFFFC8CEFF5B6454DF7466AE4C6E4990A9FC05CB694F9B8B91EC8548E38E0E
                                    SHA-512:24CB4CC07EFE71584341C0FE2E5A78803338791F134BBEAC09A0EECD8258E8531A3922C63A56573D7F69389D1AF7EC601DB38AF8FFAA30455971F3C8EAD528EB
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0 0 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):76
                                    Entropy (8bit):3.796994443350909
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQ/ZT2VKUuvUfn:aNWFFK/A9uvUfn
                                    MD5:0C16120043C1F0938D00B7155C50D6C1
                                    SHA1:2BE8869940A581C4ABA647DB9D74B9AF3C06DDE6
                                    SHA-256:CE9B309561802F80C07E4F3863A12D004E9BA9BE8099B993310328FC8F3A26CD
                                    SHA-512:48E57874FF0B0E2414FD2D6D390127488D3D42A4D7E7239E63CC75AC069E560D67617C2500F13349C311DBC88B94B89A3DF148B1A24ED6891C2882263C906408
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 0 1 1.0.67 0 1 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):76
                                    Entropy (8bit):3.796994443350909
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQ/ZT2UvWn:aNWFFK/AUun
                                    MD5:40ADE21C0F1B2AB34CC95798F3C04447
                                    SHA1:C9A16567F2AA0AF12713AF70A880F7FB6895DD7D
                                    SHA-256:E8FC30BC7EF70C2F7D87F7369201746D3A88EC752725BB95CE151B9AFA430F5A
                                    SHA-512:839C8B68081898FE0FBD81A264053DDF9A0F1237159438CD0A023D5367E6CEDAC6F866B4AA15D657049E254B94D04E39CCD9710C509B845358FD0F06EDA385B8
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 0 1 1.0.67 1 0 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):97
                                    Entropy (8bit):3.844532821859125
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQ/ZQF4SvSuAUuFVF2Ufn:aNWFFK/uRAUuFbfn
                                    MD5:B9FBACB7C2E46870F3247B96A98A71B8
                                    SHA1:1B8E8E8CC07FA855B43D179BBBE30DE4AF3F5F7C
                                    SHA-256:4177C21673485593AB177227FEC77BE3EFEEE187A7BDEFF10F7001D7EADF7013
                                    SHA-512:37C6F9B438EDD2D978FC89F7D4831019BECF2ADA7F387FC5900C1AC69DA44D3E4A3F416420D8D50FA3A5DF1C3680A6C968A8D226B680C39CE7F07B665ED403C7
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 0 1 1.0.5 0.67 0.67 0.67 1.0.67 1 1 0 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):172
                                    Entropy (8bit):4.092073600910882
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNglmRXjVx1vBLXPgQnTcKSbYduToFVnVbXQGn:aNWFF1xjj3TYlY0TovFJn
                                    MD5:A695B31F7BA7B05BF45D4377590DC577
                                    SHA1:0794DB66F632F032C7821DD352143917CF462781
                                    SHA-256:E7143E971D069512C23991E0F9891F953605C620AA531A9D7FC7B5E86DF0E811
                                    SHA-512:E227606B4D6240C9860F30507CBAAA1A4C280F44951994F03E95EA42B5942C8DEA1C70FA7C9B73D162A1C3203CB41856EB6EF27F6B6D89B43F8E35F1F9EDF2B5
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.2 0.492424 0.3037 0.136994 1.0.4 0.74902 0.280947 0.117493 1.0.6 0.880909 0.563001 0.482738 1.0.8 1 0.855548 0.603922 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):300
                                    Entropy (8bit):2.822714379319598
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOLFZVVV/ZVVV/ZVVV/6V7V/TVVV/ZUpU1jEY1hVVV/ZWYvoCVXvhVVV/Z3:aNWFLIA61jE/fCAvUdc+C3WvS/X000/
                                    MD5:C3868791D36A12630C5445AD150AFF42
                                    SHA1:DBADA8E417CEF9D328914DDC236BF785FCF8FD4D
                                    SHA-256:6DF630F96BAD9CFDA7F577F97ED22E25E54D67B793E138C212BE91F821DEE509
                                    SHA-512:87F8F4350AC1A7F67CA365C778F70DABF4B7C7269A23D7BFD2F0C3316BCEE5C0390E892B8D32F7AAC959E2B6F695B844F54E33733CDEA218B7A0AD37397B89EB
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.200000 0.000000 0.114118 0.221569 1.000000.0.400000 0.000000 0.365817 0.470000 1.000000.0.600000 0.000000 0.564000 0.438980 1.000000.0.800000 0.296904 0.800000 0.075200 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):441
                                    Entropy (8bit):3.88975941172918
                                    Encrypted:false
                                    SSDEEP:12:p1SekieqYLUETUCxCBB74jCePZ4d6QVxoe+P+TdgwVVLn:rSDvZLUyZ0HQPZ4/se+P8NBn
                                    MD5:8CB10FD3EF571460ECE375AC954E3EC6
                                    SHA1:9D4671A05622757DBD7E158602DF6CC5FEA4DC06
                                    SHA-256:64F5DB0B61F147F221BF8B8B4265C34DC9D2AC4191306D60FB17555F040A7DB0
                                    SHA-512:D5E55FF36DADC9CFA7137408DC2014933E3F134AB241C51E8942BD91091D2DA1AA555959F2B24D834BAA99923AD8773F0FF833A563C4C39B08BCBAB2F4FF9079
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0 0.0196078 0.0196078 0.603922 1.0.0894632 0 0.141176 0.752941 1.0.17495 0 0.360784 0.835294 1.0.264414 0.00392157 0.635294 0.811765 1.0.355865 0 0.815686 0.65098 1.0.449304 0.00392157 0.827451 0.329412 1.0.544732 0.266667 0.839216 0 1.0.636183 0.615686 0.866667 0 1.0.727634 0.905882 0.886275 0 1.0.819085 0.960784 0.635294 0.00392157 1.0.916501 0.988235 0.356863 0 1.1 0.913725 0.054902 0.0392157 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):173
                                    Entropy (8bit):4.051467566440636
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNDCRigTFnfeHx5lsFVL71LTl/FEzNYK292PfIn:aNWFF8wgTJsNsT71LxFEJL292PfIn
                                    MD5:B1A009CF66182E810F7AE61CAF6EC767
                                    SHA1:1D28181B943612473D26A8EE468A3B3F7EFEB758
                                    SHA-256:3DC0DC2F4A4FAD27625C95297BAC3E0E7BE0FBC06479D5DBE9DFC5957431ABD0
                                    SHA-512:1E569BDD420203D96559CAF988D44F05BC521EB008B3F4F82540F87C2159D1F8B083E1F9B2681267282395C1020048E707B3EF243E1D573E7990C090CF8AB91B
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.3 0.168223 0.27335 0.488636 1.0.5 0.196294 0.404327 0.606061 1.0.7 0.3388 0.673882 0.77 1.0.9 0.90909 0.909091 0.90909 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):465
                                    Entropy (8bit):3.886483417870995
                                    Encrypted:false
                                    SSDEEP:12:p9FroabGSWD+1NVhnTCoj0NaiQNXS9gzJU8XI:qVSx1ThTC7NEiCJU8XI
                                    MD5:25598B82B5F415BFEBECF9BA61086D72
                                    SHA1:700EFDB3592C08A9455014A7A598BB4A897BE1D4
                                    SHA-256:AC7F2D14F41493EC75299FF7C62896C87A0A3400974FBE38ECBA878716C7C7C9
                                    SHA-512:C14F80239D75C26B4199ED1918B1542045C7B9F180AEEDAFEDDE8F0F32CCA3CF6F4956D7AE2ABF94E617A8E5AF81A54E16CA10A703F145133EEA9701D2BC5518
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.076923 0.43564 0.135294 0.5 1.0.153846 0.87128 0.270588 1 1.0.230769 0.93564 0.270588 0.729688 1.0.307692 1 0.270588 0.459377 1.0.384615 1 0.570934 0.364982 1.0.461538 1 0.87128 0.270588 1.0.538461 0.601604 0.906715 0.341219 1.0.615384 0.203209 0.942149 0.41185 1.0.692307 0.207756 0.695298 0.698082 1.0.76923 0.212303 0.448447 0.984314 1.0.846153 0.561152 0.679224 0.947157 1.0.923076 0.90909 0.909091 0.90909 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):345
                                    Entropy (8bit):3.3989097364934953
                                    Encrypted:false
                                    SSDEEP:6:aNWFLIE+sQLb/a7HwHlcqG1VVUkqCX+ZQDX000/:pLa7Lb/mHwH5+7qCuZR
                                    MD5:FE28B726EAE1E6B4E2251FAE04A0F9AC
                                    SHA1:5D1CEAB251DF1C73676C1CB4298DF583CAD317FF
                                    SHA-256:F453C931793129AE6889B1372972C994EDF4E9323DB1F410042BCF0E1001979A
                                    SHA-512:DACCB914F53E0C034933F28799C41606E19F89DDEED19F58C2FDD19DEC49C4AF29CF9347219824AB082A69C4882B8F6A7BA5C1D6D609AEC713B49BB4AF36F67D
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.249755 0.415686 0.039123 0.260631 1.000000.0.435847 0.893000 0.371488 0.371488 1.000000.0.670911 0.966000 0.742223 0.401856 1.000000.0.806072 0.764765 0.913000 0.551452 1.000000.0.903036 0.673834 0.826000 0.576548 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):133
                                    Entropy (8bit):4.206210381070251
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQRWMFsTU2dKvVxiUdzKA5cUiUgn:aNWFFKRWVRwvziUJKyliUgn
                                    MD5:3CA3CA3124A920A44C2A5F8076274FEF
                                    SHA1:9BED4FD938AEAD0B36213841A31CE9519A58FC0F
                                    SHA-256:83984DF033D75EFBE76384195256D9A1A3F23E28291BDA7540100174027604B0
                                    SHA-512:3AFF5CABDB1EE44C3D0DBF78DEC5951602EE3B5C51EDC8D1E4BD266C2BCA5209423CF62E526AFEEDAA6F3D8603FC90182BFD51274F1EA9EDB68E2B7308D32F88
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.333333 0.345098 0.109804 0 1.0.666667 0.737255 0.501961 0 1.1 0.988235 0.988235 0.501961 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):50
                                    Entropy (8bit):3.8337863204943647
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOF8gUVu:aNWFF8gUVu
                                    MD5:8F24F926842C11D5D298CC32B92988A8
                                    SHA1:390680D9FD08B2D1ED8CB7186E1D00E031A1370E
                                    SHA-256:5623BE7CB7652CF7B999BF5B92C0497AD72EA1D9FA6D82B5C0D911A9006F5626
                                    SHA-512:335A8F9D9DDD39FC70D55689DEB2EB68D6E60CBF7A3074F49900901B0EE24AF8EC4FA7350468F49C114DB2DFB517882BAB0F6286F04BC3BF0677A793DAC92B9E
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 1 1 1 1.1 0 0 0 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):62
                                    Entropy (8bit):3.7933252882600437
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN18gUfn:aNWFFOfn
                                    MD5:58758CEE22802A4F6748A0FE8D0382A3
                                    SHA1:3EC80C49646B146C2771985F8A3EC2C9399AD5DC
                                    SHA-256:D7BA75F9CF89AA87D1DFD7F70E4007A7D0E5876A21375C4487DE074DC62B03F3
                                    SHA-512:93DE93393FFADAC327B516A6937AA042938A6BA9DE932DD1CB67DBD1D380C9D6D0BAB1A55576B5E3E930FA407BF36B6D8DDB51681FCB507D6EED712197438066
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0 1 0 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):76
                                    Entropy (8bit):3.796994443350909
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQCuV2VKUuvUfn:aNWFFKQ9uvUfn
                                    MD5:1BB70CCD4244A9D7300EADA996E5E846
                                    SHA1:AC8458A868BD9DD964AF37996DFC6BBD1D2D99CF
                                    SHA-256:8544A9C076AF1AD206C6B857EFD6F5271C52DE354FD1C77E7DF9A6FAC7A32011
                                    SHA-512:A0F4F27C6AF0D3C2F43C6EDFF7D484BAA6FBC97E11AF5D97EDDBD2FBBBA07F1D5F99B0E00200D1BB533272A3689E85FE95CF98EB36D5F137303208604EC374DD
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 1 0 1.0.67 0 1 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):750
                                    Entropy (8bit):3.3736168090749636
                                    Encrypted:false
                                    SSDEEP:12:pLwoLqzuvhT4QiQiQ6Mnnnbar0ZhhhCglD9999eO4ILWyRYPgDD8V:lwoLIuZT4lle+gbhhfFIAbDG
                                    MD5:15BF141499F35F8795C2BDE85D94AC81
                                    SHA1:4EE29687F6FF6CBAF1508E5194E7F09CBF10A165
                                    SHA-256:1B5D5A01BD875E632F880F51CA4731633C74204FE1BC5D077564A55589AEED5C
                                    SHA-512:11748F1054898174D2D08E835D62EFD07EDDF1A9FFAB514E849ECFA601EAEED35C30E03809B484BE5B8CE11DD44FD14B31494A272CE020ACF0ACB3EC7C34D32F
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.066667 0.031063 0.031063 0.031063 1.000000.0.133333 0.062125 0.456471 0.062125 1.000000.0.200000 0.068565 0.486275 0.068565 1.000000.0.266667 0.124250 0.124250 0.124250 1.000000.0.333333 0.155313 0.155313 0.155313 1.000000.0.400000 0.081835 0.580392 0.081835 1.000000.0.466667 0.085706 0.607843 0.085706 1.000000.0.533333 0.248500 0.248500 0.248500 1.000000.0.600000 0.279563 0.279563 0.279563 1.000000.0.666667 0.098976 0.701961 0.098976 1.000000.0.733333 0.103400 0.733333 0.103400 1.000000.0.800000 0.372750 0.372750 0.372750 1.000000.0.866667 0.403813 0.403813 0.403813 1.000000.0.933333 0.116671 0.827451 0.116671 1.000000.1.000000 0.121094 0.858824 0.121094 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):97
                                    Entropy (8bit):3.844532821859125
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQCuVM4SvSuAUvWn:aNWFFKuAUun
                                    MD5:A61A9B1EBC4C4DF5B2C3FAA097E72027
                                    SHA1:7CE104402E419F73BF6B8D99D74C0BD2082AE534
                                    SHA-256:4E41207409E09B1BBE704E2B6F89337F87C4D9419B13A0D792DDD69675CF71DC
                                    SHA-512:0867B787502676C306BF9588B508B4FBCE552D0E24FC37542DD2EE92B9C58642E94BD11E0A82F1A708D55AC305FB9BC063196B3DAF62307AD9ACD78FDC23AC36
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 1 0 1.0.5 0.67 0.67 0.67 1.0.67 1 0 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):76
                                    Entropy (8bit):3.796994443350909
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQCuV2UuFVF2Ufn:aNWFFKQUuFbfn
                                    MD5:F258CAA1D6F9B8A5A72CF9EA6AE5B16B
                                    SHA1:BCCD61D8D0899C351BE9C79DC2C0C3AA4C9B58BD
                                    SHA-256:A32811E0E21E6CBED82917A37F96CA1AC51B67E36B2158643C4A6B5348454AA5
                                    SHA-512:07BD8CF37E98F3254B20157D94E58D167256979C6E9513A5945BFB633608F9A913B4DC5EC5E024186723B2F0AA8265E53396EAF76044BF561237481281669F50
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 1 0 1.0.67 1 1 0 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):127
                                    Entropy (8bit):4.249363251576693
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNXYUfIVp5wVKV+SoDzJTlWTW62Ufn:aNWFFqUfIVbZVQmTW6zfn
                                    MD5:1536E23D3F8E8EA4F068567FD28BE0B1
                                    SHA1:822838216EE63846EFE9D50DCCDEB7CEAF4AA09E
                                    SHA-256:0F4D42E6AB91CDACDAB7D7BFCB7F80D454F1BC927BE996A8FFDF07EFADBD9155
                                    SHA-512:AA8F31D4C8126F8CBA93A815628ECD172115368543FFABEA8487CF0D599ABE51C5267648F5ADC3292D7BEB5146A409A26FD75653BCDC6370F6D520AB41C32805
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.344671 0.658824 0.156863 0.0588235 1.0.687075 0.953506 0.759686 0.363821 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):345
                                    Entropy (8bit):3.062623841957372
                                    Encrypted:false
                                    SSDEEP:6:aNWFLIFVaVwmVN8WTDOy0K8QMSAXyGAt8f000/:pLeaVjKyyzEt8I
                                    MD5:0BD556680A32A2C24DE580E4CDE19D59
                                    SHA1:CC050DBF27F89420FDD1F48F873E1E10DDE22699
                                    SHA-256:97917BB74407B052BF6E61BF2D9585D4226AFABD7490C0F155B452460C389A31
                                    SHA-512:127B60D20D1E2FE468D87F379A1F74C82FAF8CF657306ADA4398906DDEC7504E3CCDC488CB480B3383ECBFA96D4159D0D4501B4D0826836401E9D58BE0331FD4
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.250000 0.010442 0.010442 0.380392 1.000000.0.375000 0.611000 0.200762 0.424466 1.000000.0.500000 1.000000 0.321569 0.321569 1.000000.0.625000 1.000000 0.585822 0.322000 1.000000.0.750000 1.000000 0.911834 0.423529 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):378
                                    Entropy (8bit):3.4515320893769528
                                    Encrypted:false
                                    SSDEEP:6:aNWFF/FSq3Fh8vEvsTVYbAcBboUTlLTFMUjUL/W1TZScuvnvVTHUZcc4KcBuuElv:pdJVqsUU9oUTlLPpZSJvVTHUZtrcpElv
                                    MD5:79DAD2B301F6EAB877F0B50E78F96E59
                                    SHA1:ADEF444DABCD2A95E3E71C2CC126DD8469112A39
                                    SHA-256:0E9CC275475877EE1B3BB6B87D698CC9AE9FF7695D979E07275F34FD6E1CD7C2
                                    SHA-512:153527A2B9952FA27B0E6AC436E64557E86C4242CC0A6A54A6C5F892F24987273DCF4AF4ED7533D9AA9D3E7C61DC7FBF3732CB5ABA81D99A1DA00DB4B5C14F27
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 1 1 0 1.0.006 1 1 0 1.0.007 0 0 0 1.0.195 0.2 0.2 0.2 1.0.196 0 1 1 1.0.204 0 1 1 1.0.205 0.2 0.2 0.2 1.0.395 0.4 0.4 0.4 1.0.396 0 1 0 1.0.404 0 1 0 1.0.405 0.4 0.4 0.4 1.0.595 0.6 0.6 0.6 1.0.596 1 0 1 1.0.604 1 0 1 1.0.605 0.6 0.6 0.6 1.0.795 0.8 0.8 0.8 1.0.796 1 0 0 1.0.804 1 0 0 1.0.805 0.8 0.8 0.8 1.0.993 1 1 1 1.0.994 0 0 1 1.1 0 0 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):345
                                    Entropy (8bit):3.1005914472875205
                                    Encrypted:false
                                    SSDEEP:6:aNWFLIfgVTW54RWEyq5ehUVLwmqBMG+mE6uX000/:pLjEEB9nRmD
                                    MD5:FB8BBA6F58DEA8C1154A2B4354AB71A1
                                    SHA1:5FFC6FAF9DC198587D86B00E8BD2DD0B7732A392
                                    SHA-256:CC73CA73E27CDBAAB96A7F30BA163F95810457A6134574D0EE4789CC3FC53307
                                    SHA-512:993D62D3DEDBC1E90CAFE8E0D9B065D6F29105A38AAB28CDBF6BDE06125D89E0C3AD56D98FD30517F10079387F201E638B8FF9CF457886E3F1938E1E6902BCC6
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.250000 0.069760 0.380392 0.028343 1.000000.0.500000 0.890196 0.844403 0.111711 1.000000.0.625000 0.987000 0.714125 0.209238 1.000000.0.750000 1.000000 0.523212 0.289000 1.000000.0.875000 1.000000 0.644500 0.644500 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):896
                                    Entropy (8bit):3.7245588739554774
                                    Encrypted:false
                                    SSDEEP:24:RmkwezMOf5ZrjZkzRfD6dQOoby3Ld5clQpW9L:RtwgMOfj9kNfD6noS1pi
                                    MD5:E962C0398DBC24C2FB393C902CE1BD18
                                    SHA1:F2090022F053F09C250F6078C0DE3AA9A00DD303
                                    SHA-256:046E42AC13C04F456DB440B629CCE066C67EBD871FDAACB4125989EC7527C40A
                                    SHA-512:2635A3D4A7840371540640AA3061A0727418DF36A7FEF4908C5A80E80D0A991471FCB29E6734522D38B82188CE300FF0F4257F7656C515ED543C678CB5A1DBFE
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0 0 0.0313725 0.905882 1.0 0.112123 0.0722667 0.848722 1.0 0.19852 0.103777 0.804669 1.0 0.303304 0.141985 0.751263 1.0 0.395224 0.175509 0.704402 1.0 0.470588 0.202991 0.66598 1.0 0.540444 0.228473 0.630365 1.0 0.270222 0.129915 0.768124 1.0 0 0.0313725 0.905882 1.0.00229095 0 0.0313725 0.905882 1.0.0652921 0 0.172549 0.827451 1.0.119129 0 0.32549 0.678431 1.0.183276 0 0.498039 0.501961 1.0.233677 0 0.643137 0.356863 1.0.304696 0 0.839216 0.160784 1.0.369989 0.0705882 1 0 1.0.430699 0.513725 1 0 1.0.4937 0.964706 1 0 1.0.575029 1 0.741176 0 1.0.646048 1 0.529412 0 1.0.717068 1 0.298039 0 1.0.774341 1 0.121569 0 1.0.841924 1 0.137255 0.137255 1.0.899198 1 0.380392 0.380392 1.0.954181 1 0.396078 0.396078 1.1 1 0.396078 0.396078 1.1 0.781247 0.316289 0.507591 1.1 0.865812 0.347143 0.464485 1.1 0.919127 0.366583 0.437308 1.1 1 0.396078 0.396078 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):438
                                    Entropy (8bit):3.9993823740111383
                                    Encrypted:false
                                    SSDEEP:6:aNW+FQEWkUFCQXrnFiSeC0dfcUtFv/+I9d2MOPvFVLQgH0UpucRLcx9prGzycUor:j9XrFRe1l3v/dgvFhQcbAek6zycU6
                                    MD5:D0B39C78D3BE0F5B147BC5278680BEDA
                                    SHA1:4F3578AE3AEF55FFB62C49F314F8C18F0CE52F8D
                                    SHA-256:9EBCFDCD21E296660AE0E13918A2169926085C66768B6D9695AF6739257CFA82
                                    SHA-512:596F7EF65ADA40E747948B0673A60E77A8DA8D50612AD4653A0CFC4BFD4831BC177CF658DFCF81A12834C3388FB979B4572AC8655568957D3FE2294FFFE7D2EE
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient..0 0.168627 0.0901961 0.133333 1..0.0874751 0.32549 0.152941 0.141176 1..0.178926 0.458824 0.231373 0.137255 1..0.270378 0.6 0.321569 0.141176 1..0.363817 0.72549 0.403922 0.145098 1..0.455268 0.858824 0.482353 0.180392 1..0.550696 1 0.576471 0.321569 1..0.640159 0.996078 0.654902 0.443137 1..0.735586 1 0.752941 0.584314 1..0.829026 1 0.827451 0.721569 1..0.916501 1 0.921569 0.854902 1..1 1 1 0.992157 1..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):255
                                    Entropy (8bit):2.91201753603685
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOLFZTQovLV//ZVVV/6VsrTQovLWRVXFD//6Vc0VBdRmLVx6VnDVc5p5vD+:aNWFLgGw7GWRnDqK0mLOE8F00/
                                    MD5:70B476689174A595A1A27C45B043D21A
                                    SHA1:662166EDCCF8D847D1CC3BAFD973E2B0E3FEB0EF
                                    SHA-256:4EF2E4833B2BC312488EBA0232CDA7763546E30A6CB58B5E3BC6D883CA11E017
                                    SHA-512:B5E3C2E13B8B946DC21A7430EF2A4E7D9149498CA3A242A74D81A83D483B5030E221BF98C2CA5911C3760AF15955D94FD97ADE4198FF2E5CE932DA22731C58A6
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.654902 0.000000 0.000000 1.000000.0.250000 0.654902 0.342732 0.000000 1.000000.0.500000 1.000000 0.847059 0.000000 1.000000.0.750000 0.094507 0.886000 0.000000 1.000000.1.000000 0.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):79
                                    Entropy (8bit):4.252981971098984
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN12RWsDRI7n:aNWFFwWsD67n
                                    MD5:CB618646E789F17AB472A6347523DC1D
                                    SHA1:0820D2F32511C942F50E3CE75D0545C22A0B8841
                                    SHA-256:5A72A4137F31C7A45D57CA4A72A53252ECE938B4CC21DEA0F1739260F8D23C36
                                    SHA-512:204CEFEFF1FC908A1D2A3F686585C20BACC3613C9CFCF4959BD9F54119E3FD9BF8D8F70445C609813BEF4B71B48083834D0661679928C11BAE391AB6B4676613
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0.36863 0.6902 0.45882 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):2208
                                    Entropy (8bit):3.6816302749780236
                                    Encrypted:false
                                    SSDEEP:48:uHrnl8XdzCG1V1AyhsAj/HtZABNc2jE5MUN5jBYTYQrw:ujlloV6+TrAABMUNpks
                                    MD5:7DB13E5CA7118E290279388F401D3DC4
                                    SHA1:F7644FA123DE12CE0DC8FE1BC79EF0E7645EF81E
                                    SHA-256:7B5E30467D69EF06F8234D2AD626A37C4AB37063AF0812A1D432186E36C19A4B
                                    SHA-512:C52B2279B3065128482720A520F425AE60B0A965A4BC79A1280C1DB63E0C07A5BF47F2797FE386B8CA760726FA7BC9DAD94DBB84CCC97E29507C2FD989A0DAFF
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 1 1 1 1.0.0104167 1 1 1 1.0.0208333 0.956863 0.956863 0.968627 1.0.03125 0.894118 0.898039 0.92549 1.0.0520833 0.733333 0.741176 0.8 1.0.0729167 0.556863 0.568627 0.65098 1.0.0833333 0.494118 0.505882 0.580392 1.0.125 0.176471 0.172549 0.192157 1.0.145833 0.0470588 0.0470588 0.0392157 1.0.15625 0 0 0.00784314 1.0.166667 0 0 0.0117647 1.0.171875 0 0 0.0470588 1.0.182292 0.0117647 0.0352941 0.164706 1.0.192708 0.0666667 0.105882 0.286275 1.0.197917 0.0862745 0.129412 0.317647 1.0.208333 0.129412 0.176471 0.356863 1.0.239583 0.321569 0.352941 0.513725 1.0.255208 0.376471 0.423529 0.545098 1.0.265625 0.372549 0.458824 0.537255 1.0.270833 0.341176 0.47451 0.52549 1.0.28125 0.25098 0.486275 0.482353 1.0.296875 0.113725 0.486275 0.376471 1.0.3125 0.00784314 0.490196 0.278431 1.0.317708 0.117647 0.47451 0.254902 1.0.322917 0.141176 0.443137 0.223529 1.0.328125 0.207843 0.396078 0.196078 1.0.354167 0.784314 0.0862745 0.0627451 1.0.364583 0.94902 0.0235294 0.02745
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):74
                                    Entropy (8bit):4.194893819417817
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN1cV0ROzn:aNWFFfQn
                                    MD5:F1063F5E07CBBF25707FBE0E1FEF2546
                                    SHA1:E0CA34EA0E2DE5443FA551A6DF2EF09A0DAC0598
                                    SHA-256:EB57DCD4F29795A558D8C1B611AD2EDC73E37A07804A7AC04D94C588F77E41BD
                                    SHA-512:096383768497527A7085B7B8F3580A67E09C537EBF090BF5301587768F89F56EAE9F53C4834D87FD08BAF16D018DFE647659B02DE591589A67522F107B9D5B3B
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 1 0.07843 0.62745 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):255
                                    Entropy (8bit):3.1743148355000295
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOLFZVVV/ZVVV/ZVVV/6VsrWur/LM/VcDRcRXuRhcSNpXHcFSpDXWlUnhQW:aNWFLI/z/KOROJj35smhQVvLecX000/
                                    MD5:F3437CB46C53C67EC974EFE035D1C1C1
                                    SHA1:1FA9216A5B243D534C2EBB6B2F86D5F3DD53EBDF
                                    SHA-256:34D95301E25CEA83C0D0B21A459C5B917EF0B491547B1D7F4A6F91ECC4B2FE16
                                    SHA-512:1B8434DB34219A6A5A8FFD8F7F01AC2814C30527C5815E19EEE41A070FC307761B525A26A064CBBE1ECFB921AC4369A9E9FC756C04536FF9A1D2FB0A460BD1F4
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.250000 0.342401 0.066642 0.383000 1.000000.0.500000 0.494232 0.477970 0.823529 1.000000.0.750000 0.237372 0.614950 0.906000 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):140
                                    Entropy (8bit):4.108775839650042
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN/TfS3PZGRuN1RWMiW5awTX4TFvVuhQdWvn:aNWFFq0oLRWouTFvM+don
                                    MD5:5F9DA7BD539836D8660E90BF3B038564
                                    SHA1:F0F4431AF559FAE69C3CFD6F9EEF58652D9BA76B
                                    SHA-256:DD51D117EF74E37CBFA96301F0A4F739839F11CD805BCC58FCD2886D10D50B7F
                                    SHA-512:3B87D4CA4ED815611C735A655A6F5B6E158DDE757C637F9426D430EEB1FFBD3D687F82D9EF4F165030850F0C121F309807BCA92C781622CBA491BC73CA933B10
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.166667 0.265412 0 0.564 1.0.333333 0.391234 0 0.831373 1.0.666667 0.764706 0 0 1.1 1 0.894118 0 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):50
                                    Entropy (8bit):3.8337863204943647
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN7lv:aNWFFhlv
                                    MD5:8DBAFC1BFDCB843955F2F48469F9FFAF
                                    SHA1:F4B8D64C7566F0FD906B722E349E794A1334E714
                                    SHA-256:89CEB646819C9E9931A692E2CD1D77BCDB712B8BA094866AD9CA35CC55F3DE67
                                    SHA-512:C6034B3A1CAF5D4822A2BA8F0BA49BA5A015090882A1B3898A7CD11F015C2513C9EFF44606C7F55CB0A1081572871B61706548848A062F2986EB2E2D2EDC820E
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.1 0 0 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):50
                                    Entropy (8bit):3.8337863204943647
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNRn:aNWFFL
                                    MD5:EFB12B04A01E256BD4DDF57BE84A4B4C
                                    SHA1:63BD38729D89CE013B5131D43FDB0D7A61A44D33
                                    SHA-256:8CDEF294BD39FEE17398814AA0B91DB0D1A7068B66772CB714E29756EF581D63
                                    SHA-512:EC2A2B6E5F5C17E31B432716D85F9BFB98E086A344A568A1A3C34D750FCB13F28101B91D8DBEF42BF41AC25BBA73CECA00910F2E30676F46F90666C7D31F2A3E
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.1 0 1 0 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):50
                                    Entropy (8bit):3.8337863204943647
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNwv2:aNWFF22
                                    MD5:C95975715B85EDC7B1F7AD008DE09B7D
                                    SHA1:F54E645A63F4C03EC7BBFEB61A460858598F375E
                                    SHA-256:EC7C57796B6316F426FD792C505EF3AC3DC9C05FF3124D4CA37666B932D5AE17
                                    SHA-512:2ABB2FBE70D7686D5FBCFF0FF9020E85B696EA4E9F4EAF99A4A6E7EEB0DF968A975648E0ADB3A5159FB186D7314E92B516CE53EA0845A4205633F18C71709A63
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.1 1 0 0 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):150
                                    Entropy (8bit):3.5908702681686764
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN7QKVdiFUFVF2VxjUuvVLQFcVxTQcVgVnd9Zd/AMVMU+n:aNWFFGKXiuF+ouvGFPd9LV+n
                                    MD5:E7F2A9DC7DBB6C15CCEBBA13936BF6FE
                                    SHA1:CB636E4D896DEDA7FB1DBD9ADA3CCB285BF98571
                                    SHA-256:E10D7D0A599F14A41DEDB3B79430545BD69E7B9C984B64705AFD9B7882A3DD2A
                                    SHA-512:47BF3833055E2E4274C7306A23F3D0EFFD0AB939E2CD1336E70DB718A8CAB02C316A350AF4D7DFBB666C72F74DD483AE480B14529ED7EEF53B6D48E2402C9A6F
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.125 1 0 0 1.0.25 1 1 0 1.0.375 0 1 1 1.0.5 1 0 1 1.0.625 0 1 0 1.0.75 0 0 1 1.0.875 0.5 0.5 0.5 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):88
                                    Entropy (8bit):3.6949786416848402
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN8FVdn8gVnd9+n:aNWFFaVXd9+n
                                    MD5:E530ACBA4ECCC17B770A713CC920FBA3
                                    SHA1:43C4BAFF89E40540DEB674758B54D324B82BE33D
                                    SHA-256:F78FC020A08306BC28F79E36F2106ACBB3C502437A9D68F1D0F71835210D50E2
                                    SHA-512:FEE6F8C174E1728863BB1F270652DAC9D32F1DB480539FF67F3A407133D448C920EF849F68F8151499562636EAAB9C733BF5101202CF68B65E3606D7E65E8E78
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.25 1 0 0 1.0.5 0 1 0 1.0.75 0 0 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):62
                                    Entropy (8bit):3.7933252882600437
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN1cVdzn:aNWFF0zn
                                    MD5:2A8BCA981B92069F33CB84F403331011
                                    SHA1:1D5938A57F750588312760244ADD7121B0D4E491
                                    SHA-256:34DCDCB72EEB9EF536C9BA628ACB4D087D4D9947F8345FED052A008DCFE11E29
                                    SHA-512:2321A39C1FF69C6BC847E325D297B51B9990B0B8752FA2EA470E7509C3EDBDE9D16DB06481068D0D40EADAA4003DD49BF19B197C4490341D1BBA99083E1C32E2
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 1 0 0 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):97
                                    Entropy (8bit):3.844532821859125
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQOdn4SvSuAVKUuvUfn:aNWFFKOdPA9uvUfn
                                    MD5:D303BD4AA9654CD7781021EC293A4B75
                                    SHA1:BC5A7DD330C0CDAB91861DF4F464BE3432527E1A
                                    SHA-256:370C0874823817DC31E96BBFAEBA2DBF10E04E9503FF54B922C375BDD79CB640
                                    SHA-512:8182ED2620D7E51F2BCC6AC74B93D66C0DEA4F52F60EA41111FA2BE51A5D3554B02D614DB921AA47290A31EB828D5BE61D1AA5D37529D8E8A6FBAC211DDC72E7
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 1 0 0 1.0.5 0.67 0.67 0.67 1.0.67 0 1 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):930
                                    Entropy (8bit):3.1629086411817533
                                    Encrypted:false
                                    SSDEEP:12:pLuNYrQKp4DmbC6Tho5QBvaLzcmH6ww6Dj/j/MmxP0RqUI9yWTQJfWRXi9JN3:l4YEKq6VoO5qQqrd0kUIrTQJfWFi9j3
                                    MD5:F62DDDE1ACF44C92D5069CC1BC9144FB
                                    SHA1:6B9E56A771B81C3A4AF46918F793B7E01E68373D
                                    SHA-256:74D9422F23EB38AD24A29B0B4F54C6F30AB35E9A6195B7788F655CD427401CE9
                                    SHA-512:877D11706BEFE9C6B85287AD792D687EFFCE719F4203FAA52B9471058DD97F3DBBA49D3F3FCE1E4ECC7FB32D545D75B9B981A2AC371CF4FFC40E072D3B613550
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.052632 0.030000 0.030000 0.030000 1.000000.0.105263 0.449804 0.060000 0.060000 1.000000.0.157895 0.483137 0.062808 0.062808 1.000000.0.210526 0.120000 0.120000 0.120000 1.000000.0.263158 0.150000 0.150000 0.150000 1.000000.0.315789 0.570588 0.076459 0.076459 1.000000.0.368421 0.603922 0.077302 0.077302 1.000000.0.421053 0.240000 0.240000 0.240000 1.000000.0.473684 0.270000 0.270000 0.270000 1.000000.0.526316 0.691373 0.092644 0.092644 1.000000.0.578947 0.721569 0.093804 0.093804 1.000000.0.631579 0.360000 0.360000 0.360000 1.000000.0.684211 0.390000 0.390000 0.390000 1.000000.0.736842 0.811765 0.108776 0.108776 1.000000.0.789474 0.843137 0.107922 0.107922 1.000000.0.842105 0.480000 0.480000 0.480000 1.000000.0.894737 0.510000 0.510000 0.510000 1.000000.0.947368 0.933333 0.119467 0.119467 1.000000.1.000000 0.959608 0.122830 0.122830 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):76
                                    Entropy (8bit):3.796994443350909
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQOd3UvWn:aNWFFKOd3Uun
                                    MD5:30B9E40D4656DB715E8A7F4FF8D0FDE3
                                    SHA1:11DFF628C9DC8748953210196D028D84D463C102
                                    SHA-256:C2F963881BB03ED0ECB434541D4DD72AC1F2F730080D5467990D8092FC82A267
                                    SHA-512:1295E60AC60A49566FA5419BD3CC765CCD0C8D4958CEFC58EE9F84D02513AE5FCFABAE6F9FE736F0968830FE5DEB423DD6770D4A469126FD53BCD68AC28B528A
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 1 0 0 1.0.67 1 0 1 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):76
                                    Entropy (8bit):3.796994443350909
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNQOd3UuFVF2Ufn:aNWFFKOd3UuFbfn
                                    MD5:0E012F2EC7887892556B2146743BA804
                                    SHA1:C5577805D2E16FBD52244486EAF74D65C3EC2CF5
                                    SHA-256:3DB69501FA37077100FA6F8B4B67D6C671381975F98E40B915421B66BBFDE52B
                                    SHA-512:2DBBCE432DC86BB710929C9CDE72880215D3E4F5F4935CACFDCE85B0BF56AC10A7E039966B4D53D167CA0CCE46607B1EF62F76602900BDE6D4B5E024FD471DC9
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 1 0 0 1.0.67 1 1 0 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):345
                                    Entropy (8bit):3.0258101180622283
                                    Encrypted:false
                                    SSDEEP:6:aNWFLIt7RZUd7E3x2hVopgvmhFEc/V5vOzf000/:pL0PUdo3x2DkgvgEsoI
                                    MD5:784D07EBBEC3CFCAF06843AE5A900D7B
                                    SHA1:47D56AB15E376ABFBB2C734888520C64144CE898
                                    SHA-256:A959A48258DD0FB051EA7F9A26A34FC1F5D7524450DF7619D5937CA1C88A946A
                                    SHA-512:8C739F173F110727A203284C0A2C86790916E037D5F8E047997DFBD719F17FF77898D2DC5BD39FDF5BC2E47F78150DF8CDB2C86B554A40F3016BF97B98866FB5
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.286765 0.500000 0.266340 0.009804 1.000000.0.430147 0.785000 0.480598 0.005131 1.000000.0.573529 1.000000 0.652000 0.000000 1.000000.0.714052 1.000000 0.803444 0.268000 1.000000.0.854575 1.000000 1.000000 0.709804 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):300
                                    Entropy (8bit):2.509202534320237
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOLFZVVV/ZVVV/ZVVV/6V0HVxZVVV/6VCV1RWM/dZVVV/ZVVV/6VX/VBVVK:aNWFLI6K0lWMMSEskFY/
                                    MD5:7BACCE82C6A4CDC12E8C038BEA28E68F
                                    SHA1:B421947C9FFE7E2446583998053FB12788312718
                                    SHA-256:7A1756B0C151692504A2F492FEB13455C95FD75B92A22D60865717EAEE705597
                                    SHA-512:DFFAA5EE8D3E8148996115E2A73F50F6865F4AC7781DB5DB6590BACB264A68ED5289A596E8ADCB5385598EE74D48769F276590C752184F2C4C0F4C6DBFA45BF6
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.325171 0.000000 0.000000 1.000000 1.000000.0.333333 0.000000 0.000000 0.000000 1.000000.0.666667 1.000000 0.000000 0.000000 1.000000.0.674829 0.000000 0.000000 0.000000 1.000000.1.000000 0.000000 1.000000 0.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):255
                                    Entropy (8bit):3.2984013056067827
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOLFZVWsdvhTTdvgedXkrXQ/rXQ/rXcCcR8UDQ/BXdDv1K/VnDSBXFhKhC8:aNWFLQsjfnvkoCHUMnk/oBXTfT000/
                                    MD5:1A9CA98DF44EC0A479C8A9388E4245C4
                                    SHA1:4136DAF80756369207966C27CBBC539000BC9CFB
                                    SHA-256:12505283C3CC96885B33663C8191628FE9B9992B94E878AE9BAE8E76309387D2
                                    SHA-512:6E8E20075C079FD681CEC732E97C14B09F8790EB3C44203D255C8B2F9E2F094E36D89C07743CCF1E937893A4182744954B29A93BAAC8EAA3EABBF299EDFE7DF0
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.031318 0.031318 0.167843 1.000000.0.250000 0.250000 0.250000 0.295294 1.000000.0.500000 0.500000 0.285797 0.141000 1.000000.0.750000 0.729412 0.160185 0.414663 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):182
                                    Entropy (8bit):4.154176131366005
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFNgglTVLIHyl4R4yl5TvXJ2hqAEPujvo3LuwXQuvGn:aNWFFpVVLAyCR4ynJ2AAEPuU3St5n
                                    MD5:3A927C2278E0A77FE5022A77AC1C5C4F
                                    SHA1:C0D7E252A55C46C7D88869496DA155B33220E2FC
                                    SHA-256:E8A508516834C1F97B30A60F445C190186E7393D55FF822A948B83E251D0A27F
                                    SHA-512:18D0E9C244C1118C0DEA1B2FA711DA39356E7D11CC552210CB002418347F289F91A2C09E2DD78EC1156A22FA2AA121419EA11DD662F9DE3B222BB38E7E5335FD
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.2 0.149112 0.160734 0.396078 1.0.4 0.294641 0.391785 0.466667 1.0.6 0.792157 0.476975 0.245413 1.0.8 0.988235 0.826425 0.333287 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):300
                                    Entropy (8bit):3.4709209512680705
                                    Encrypted:false
                                    SSDEEP:6:aNWFLbERKx1XMvgBRE8hk8WQsoqWZxcQF4VhV:pLbwKxWYBR1hk8ds/fQF4R
                                    MD5:6D56657C005AF761AFE8554FD10C5B58
                                    SHA1:20342C38E950565C8DD71CFDAEB8A610B7DB4CAB
                                    SHA-256:F01BFC2F0BAADD43AD4CAE5A23A220D9DC8A8201DEE2A7EDD506236BAE7C5191
                                    SHA-512:26593D991C56BFF1E0E2D762B87D3459C78B53625CD65F29BAD884B2019EBA8DE0233C20C59E9E348A8F7F4E2ED07D63CC1488134980CF239A9FA966CC448B01
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.048443 0.069416 0.494118 1.000000.0.200000 0.023529 0.505882 0.611765 1.000000.0.400000 0.060095 0.631000 0.126868 1.000000.0.600000 0.517000 0.503744 0.026513 1.000000.0.800000 0.631373 0.047059 0.054902 1.000000.1.000000 0.866000 0.833926 0.847672 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):407
                                    Entropy (8bit):3.8947077666061567
                                    Encrypted:false
                                    SSDEEP:6:aNWFFL5v7FhzXQXjLTFkL9I9Q1V3K7EHWDgeVkXrCZpTFlcP9VOdwAd6d5u:p7QX3TFkL9I96VW4QC78TFGP+Neu
                                    MD5:06BB2CA1064303723E7B0BB391E44590
                                    SHA1:65C89216BE012D062BC65AC5A24C2EB7B23F0A61
                                    SHA-256:82A12F5C61F9C06AF4909416FBF8086A1842336E1F3409F2637663C3EEC42E88
                                    SHA-512:AB5BF755700556A8326BBAEB0DFEE449906189FC5371D6597ACA5569F50E373E5B1571640A2367BAFA97A373B71AF9693AE0317D9314D0B56B6BECBC481C4547
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.090909 0.885 0.024681 0.017629 1.0.181818 1 0.541833 0.015936 1.0.272727 0.992157 0.952941 0.015686 1.0.363636 0.51164 0.833 0.173365 1.0.454545 0.243246 0.705 0.251491 1.0.545455 0.332048 0.775843 0.795 1.0.636364 0.019608 0.529412 0.819608 1.0.727273 0.015686 0.047059 0.619608 1.0.818182 0.388235 0.007843 0.678431 1.0.909091 0.533279 0.008162 0.536 1.1 0 0 0 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):416
                                    Entropy (8bit):3.9158469336942496
                                    Encrypted:false
                                    SSDEEP:6:aNWFF8gwiNLpBFa7FhNR1c4eS89uTX6owum9UeaeVkXrCZygUzPZ+z9VOdwAd6fY:p2UNyRdQR772B7QUzPQz+NxHa0z
                                    MD5:194C2A1AF3A03D36467061A4A65D6D70
                                    SHA1:A11346F912E5AD5DA50074CA07A0354C58E57D68
                                    SHA-256:9EC257B20CB63467CA203B99E71BAF413C1C1B81BCA9B3F6B4080E1A6491AA85
                                    SHA-512:2E0B9E30E4121D27F366A1DA00D53E8E543E6A0FB1237D96AEA5F5D3D62CAA7EB3F61DF1980181D73341B92E942AC8ED408E93B407421BE977A91C02EFB802C5
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 1 1 1 1.0.090909 0.940093 0.141772 0.135225 1.0.181818 1 0.534417 0 1.0.272727 0.875059 0.840787 0.022034 1.0.363636 0.496666 0.898024 0.0742046 1.0.454545 0.307927 0.782269 0.316396 1.0.545455 0.281147 0.741558 0.76144 1.0.636364 0.019608 0.529412 0.819608 1.0.727273 0.0775921 0.114046 0.778973 1.0.818182 0.388235 0.007843 0.678431 1.0.909091 0.664988 0.21297 0.667338 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):149
                                    Entropy (8bit):4.123461419109132
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN9GiQadVpqU3gGFnWTh3TVXKUvVLjTFpQVcHVLQgIn:aNWFF7Z5qU3gGkTH5TFpQVc7In
                                    MD5:27463FC9F8922E771DDB8022E72FA136
                                    SHA1:F3EFCF7687432E54A88F912160042F9DD015AAE7
                                    SHA-256:4B70170236D253A122B07B44A6CB1D25ED35172B0D4F5D2DCEF54E335382081E
                                    SHA-512:582925A6F064D6D6C4BB46FB939D4AE0F0AC7D00DB43FECC3A37B351F63F2CA58BDCB7756511FB48D0FE8DFD377FFAD000B5B4E7489529F92ABCD3904F9D9BB1
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.25 0.059669 0.380392 0.293608 1.0.5 0.084395 0.65098 0.025529 1.0.75 0.758756 0.85098 0.560646 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):510
                                    Entropy (8bit):3.906138701959893
                                    Encrypted:false
                                    SSDEEP:12:pnh3jcAsW0UlGlfXK0PYAc3DcTfOjeeUdleYQVhviTlgg2:Rh3sXlf6H3DcTfOpUenDviTQ
                                    MD5:2740CF2954B44F145C6E14304CFC628A
                                    SHA1:91DECC08659280476AB5E0F8410F947F27A4EBCF
                                    SHA-256:DD60E36DF081E4BB04D410DCD187DDE4C4D28B8C417978C9B2D0D5CD53325C8F
                                    SHA-512:B05A46CA139486EACFE33E18E28F7E48B8DE6EB919F786C03E4D3430F0C0B12F3F78482EED0B0BE308DEB42DECFFDDD4EEF6A16E75FF9BA4733474C70D44BBC0
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0.266667 0.00392157 0.329412 1.0.122137 0.278431 0.168627 0.482353 1.0.21374 0.247059 0.278431 0.537255 1.0.316794 0.196078 0.392157 0.556863 1.0.51145 0.121569 0.576471 0.54902 1.0.564885 0.117647 0.627451 0.533333 1.0.60687 0.137255 0.666667 0.513725 1.0.683206 0.231373 0.733333 0.458824 1.0.751908 0.364706 0.788235 0.384314 1.0.824427 0.537255 0.839216 0.278431 1.0.938931 0.839216 0.886275 0.0980392 1.0.969466 0.921569 0.898039 0.0980392 1.1 0.996078 0.905882 0.141176 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):196
                                    Entropy (8bit):3.969405696039856
                                    Encrypted:false
                                    SSDEEP:6:aNWFFTcLFhX4vGyeYhBVCEQTLknbKQ292PfIn:pFgYGyeYhjCOb4sXI
                                    MD5:468369D0B4E61D159885C46FE71BBBC5
                                    SHA1:91940C376C78056B3FE3276738B64CDE1D3AB06B
                                    SHA-256:348D14B372DD03C28CD002DAC61C8231209132797B9228FA9B93892D7AA69457
                                    SHA-512:689B8E4DF7BE6E8BA408DEFDF069D1AD2210A6662A218837366E2B58BB6651568C00A406E0609484D3BC041F145A06639CF1E5BB56F322AEBDAB09BDBC06FBDA
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.25 0.484848 0.188417 0.266572 1.0.45 0.76 0.1824 0.1824 1.0.6 0.87 0.495587 0.1131 1.0.75 0.89 0.751788 0.1068 1.0.9 0.90909 0.909091 0.90909 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):392
                                    Entropy (8bit):3.9929234868297327
                                    Encrypted:false
                                    SSDEEP:12:YXBh1axBUcnvmRxZvFhQXM6HrMjKRjjdF:YX31axBP+ZvTQc64KjdF
                                    MD5:B1B0426262D3A7A4F71614ED6F1CDBD0
                                    SHA1:286634AF4886D06CF4F5A99312B73494774473B4
                                    SHA-256:CE84B8FF40FB14C3B1470B739F8A6547B74ECE0AA65EC8AD7F15CD215523D668
                                    SHA-512:61E1D15FB43245EF57F6B28E977F3C311CB9DA8E9D94FFBE3179CD129AB6167A2EF4AF2BEB2956B4346B51C73790797A1261C34A0FA38F67086E3D6391AC0877
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient..0 0 0 0 1..0.0874751 0.278431 0.0196078 0 1..0.178926 0.545098 0.0784314 0 1..0.270378 0.756863 0.172549 0 1..0.363817 0.905882 0.290196 0 1..0.455268 0.988235 0.431373 0 1..0.550696 1 0.572549 0.00784314 1..0.640159 1 0.705882 0.0901961 1..0.735586 1 0.823529 0.239216 1..0.829026 1 0.917647 0.45098 1..0.916501 1 0.976471 0.705882 1..1 1 0.996078 0.984314 1..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):476
                                    Entropy (8bit):3.974810094110253
                                    Encrypted:false
                                    SSDEEP:12:9dZ6cYTN1jsbYz3i223iDjKrGR6WOKSJHSM82v:9dZ6B1jsczy/iD2rGR6dkC
                                    MD5:E1FC021D38BE9C01CAC7E074BD8DDDE7
                                    SHA1:34FCBE1DA07354F48702C8175DEF0401EED451F3
                                    SHA-256:48C48CDCA202E1060CF15C1699CF78C016C36986766B5D36DC5F20800185A80F
                                    SHA-512:B297B49E9054565075E6216D5281F8BD5429C20C8A7B3A4F8FFC549AD9C4BA447319A32295B49547274EA52D2A4E25D1A04CA0A3F4F44BD3EAC87218CE0988E5
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient..0 0.498039 0 0.498039 1..0.0874751 0.294118 0.0431373 0.701961 1..0.178926 0.121569 0.168627 0.87451 1..0.270378 0.0196078 0.356863 0.976471 1..0.363817 0.00392157 0.568627 0.992157 1..0.457256 0.0745098 0.764706 0.921569 1..0.548708 0.231373 0.921569 0.764706 1..0.640159 0.427451 0.992157 0.568627 1..0.735586 0.639216 0.976471 0.356863 1..0.829026 0.823529 0.878431 0.172549 1..0.916501 0.94902 0.713725 0.0470588 1..1 0.996078 0.505882 0 1..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):481
                                    Entropy (8bit):3.952028845762392
                                    Encrypted:false
                                    SSDEEP:12:m5VVz2tGsMeEA5ksddIUcRZTmzAFZ2joNKuTi:GVJcg0EUAj2jOKuO
                                    MD5:157AC300882AE42E212D8FC53B339FC3
                                    SHA1:994F714D2EA73729F578A63A6C085E9C2A1F3A69
                                    SHA-256:8897415C008CCDB8B3A68C5DAA3C1774C1E032673A5081907E0D5746CD551606
                                    SHA-512:F6E50C70808F29E8DA30B3861458B3E42361D2D9941B240ADBE50707FB81B36C3200CB19ED6086F6FD7536500A39C89A68ECDE6290A81458BFAB73A1A6131F15
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient..0 0.00392157 0.0431373 0.419608 1..0.0874751 0.0745098 0.121569 0.756863 1..0.178926 0.160784 0.286275 0.94902 1..0.270378 0.247059 0.52549 0.988235 1..0.363817 0.352941 0.788235 0.854902 1..0.455268 0.454902 0.980392 0.592157 1..0.550696 0.552941 0.988235 0.341176 1..0.640159 0.647059 0.8 0.145098 1..0.735586 0.733333 0.521569 0.0352941 1..0.829026 0.807843 0.290196 0 1..0.916501 0.909804 0.121569 0.00392157 1..1 0.996078 0.0509804 0.0156863 1..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):79
                                    Entropy (8bit):4.137563606093125
                                    Encrypted:false
                                    SSDEEP:3:a3NW6XOFN1hmqau+n:aNWFF54n
                                    MD5:049A47C1DFACFEB532F512B3860ACB4B
                                    SHA1:D85517F652232E0DF88700246A5B6A6D414FB360
                                    SHA-256:834DFF36D9ADF17C0EF66BE573AA25983F51F5517926C43B38ACDA56016F3BA9
                                    SHA-512:B40BFEAE62CFA04B779879EA0BB31648D3B24F124E21C2EFBE3CE1D61D5EA6DB1EB448F019CAD09C8D3CCC576210466017B93683A75FEAD3EBE64EA3A30C46D8
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0.8314 0.71765 0.16471 1.1 1 1 1 1.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):750
                                    Entropy (8bit):2.686202376735773
                                    Encrypted:false
                                    SSDEEP:12:pLEG9hzQ88xIh11E8C8yCjtRQKRZKVdJS8:lphc88xIh1W8C8jTQKRql
                                    MD5:19407F5D39D1EE8FB23350B96F4817E6
                                    SHA1:E6898FBE105FA2214B8AE73301D76D0F8487128E
                                    SHA-256:C02D25F92C2AAA226D2829C77745D9B62E82525FD6D71086ABD84BF8D4A403CE
                                    SHA-512:2F5FA200443BA7CE854B203B0A1C2BE7D99E5587070562E46E8618E23931FDB42CCF4272B7D6A19CACA3CB94EB948AAB0B79CCEC675514DEE815FB3BC175A1FD
                                    Malicious:false
                                    Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.115573 0.148000 0.148000 0.148000 1.000000.0.125000 0.000000 0.000000 0.315294 1.000000.0.239961 0.000000 0.000000 0.503529 1.000000.0.250000 0.550196 0.000000 0.000000 1.000000.0.365328 0.752000 0.000000 0.000000 1.000000.0.375000 0.503000 0.000000 0.503000 1.000000.0.489716 0.752000 0.000000 0.752000 1.000000.0.500000 0.000000 0.597000 0.597000 1.000000.0.615083 0.000000 0.799000 0.799000 1.000000.0.625000 0.000000 0.705000 0.000000 1.000000.0.740451 0.000000 0.872549 0.000000 1.000000.0.750000 0.866187 0.872000 0.000000 1.000000.0.864838 0.993333 1.000000 0.000000 1.000000.0.875000 0.819000 0.819000 0.819000 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):4685
                                    Entropy (8bit):7.932291880048192
                                    Encrypted:false
                                    SSDEEP:48:pq9KI1xHQH84CSkX4AekJuhJNGN+Z3KQxKV+cipBtBnZ3jjHcBaX+rA4QQlBmjJx:p+BhFX4ANJWP+Q3RBZkBaXsm9JslAvbt
                                    MD5:B4A9022A46CDF62FC6442E887C60F22D
                                    SHA1:5F0CB848C76D356D119E9E026CC674A6CCF4BC8E
                                    SHA-256:AC932C398C24C18413106CAA060369BDAAEF4E37B478E71F0E82C04434D1A4A0
                                    SHA-512:DAC4BB4ED012BA8A8CF52242DFDD0F3A19DA57AF2807122A49519DFD73D6C9A8F041565943F8CB886F289216D87E1832811FC984DED1747E6533BC593811AAB0
                                    Malicious:false
                                    Preview:.PNG........IHDR.......}......0......IDATx..].X...W.VQ#...J.1...........K^F.jd....m..(.....,..y.j..RQ!..=T...su.....*[......r..9..s.......~....%..uhCC@ ...."..@d ..O..W..;v,++.........4m.4V......LII.q."....?k.,V.........rrr.z.D....{...l..........cnnn.>.:.p...[[[==.._.]SS......u{...9w.\..9cee....nkhh..6L....~..J....f4//..;w.X[[..5.Y..S.woUU....>`Fy....;2.m-.....k...z.........={.............~..J.f.N....Z>..s....c^...w.XRR..d......]z..Q..\...XTT..:u.....L.8.....> ....9..<.>|....so...E,.BZZ.<..'On..k.#..G..<X..Kd..`+......................m.a.........G..I..rQ....0A\k........Q^.z5z........sq.../.A..|....<x..U.V..X....f.........###. .#F.........M.6..2.W.^MLm...Y...W.-B1P.ys..]jjjP..d....?.....B;B...|../.A..m./]MII......Y.q...............NNNF...s....k.k.....;L..}HHHiiiS:.........e.........,.`....0\..a@.>...........~..j.m....EFF..V...{....a..g...K.u...f...._....L....X.r../^t....#7o.....`.p.....,v.._..2.\../^............W...#$........5o..w.H}.}.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):5201
                                    Entropy (8bit):7.943242006212645
                                    Encrypted:false
                                    SSDEEP:96:pfLOAIQfyf0ct+SnS5xLFQu7C3WBcObJmAfpXhVTruG64XCHDuRZ+Kt2JbTKc:VLOAIQfy/oSep17JBxbJ7fpxVTrukyH/
                                    MD5:9D4A9BD5C1646EDA80F1936F6673097A
                                    SHA1:8A7BAD985EAEB520D7ED4D42EB201B57221BE4FE
                                    SHA-256:A47E9D2479A10100C4C71A3AD0A2ED477CDF5E33791D3B3ABA217D43D4D9A19C
                                    SHA-512:07C14DC632D83FBBAEA8FF14434AE69E5E7BBF3502BE2F5FFFA3FF49F6DB11C95A0594D2149ECD1B672E11F9DF2702FE6DCA5875C208C2C7EE0FE890EDAD6CA1
                                    Malicious:false
                                    Preview:.PNG........IHDR.......}......0......IDATx..].X.Y...$...d).J..b......,3..jd.,1..\.......J..P#....e~...T......_..?......{..}..=.{.w9...<.}..|PB .J..5..@d .......@ 2(.iii.....D.Y...O__..R...EFFR......P555OO......Q.F....S...d.5k.|..g.x..5...'.;w..a^......^.r..={.............[.l.D....zCCCuu...$V....?~<5..A....s.... ##...'....X...vbb....<..;v.....-[...R...T.G..a...c...Ye..]6o.....0............{>|...Mbd@.Q{..._.NKK..L.2.i.w..E......-6.T..........(zyy...P...........-Z...E.f....i.......a...x....K.R[.2..0..?.....n.z..........gO.....Qcii....{..Yj:R.U.u.`......`.+W.TSS..?.VVV..F...k...w.&M.VQ.I[..<x@mW...\\\........_.e......;*===Y........*...D...Hx......w.............(P.W.*c..L...{+CDDD.V.N.>M}F.;DFFr3..2...J.........@0...2(....B.n.{.......@.I..M..l..\.3B..B...2..*.z7. z.%e.........{A, .......1m.=((..o..a..O........M.4y.......[.n.|.ry...'....../l...ZXX..7..AF1Cqq....1c.=c.>}.....v.={......=<<Z.j...B: ..!11QWW...E[[.....9;;......Q.F....A^...q
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):2452
                                    Entropy (8bit):7.786385010050454
                                    Encrypted:false
                                    SSDEEP:48:vvOZqfGe1AQ9MPUXxdMQpkV74UzMK0QHcwl7FVbR2yexV4q+04cg2bU:+oOoMPUkOUZckN2bxVYNgQ
                                    MD5:47E01F6FB5682A00DC1BCA8735450714
                                    SHA1:4028D42210644A8A07719E250E32842A26ADA35E
                                    SHA-256:5542022D7382E7AD394711D5D4449862246BF62208422FAABDF233AC702A1E40
                                    SHA-512:BE1027F042700FE8237EE19D69E56363993BAD3EDBC6E6BCBCFB4FABDBFF616DA82D6F2DDA964B3B6ECFF820B5B6F014C6893C4B147CD7DA5CCE0E0466166FDD
                                    Malicious:false
                                    Preview:.PNG........IHDR.......}......0.....[IDATx...H.....2.M.u.f.C.r.EEe..@7#.-... ..J...e.T(HE.VF..... ...n.D...6]..t.......mv..w.....=.wt...=.s^.y....n... .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .......>|.....x."..DGBB....5..........w..uss...f..**...B.@t.......7.bjjjdd.......b...r^.j....gggOO.L&;~.x?....D".7+..?---.......{.......744......B.......y......iSbb".1.../.}{VV...p.PQQ...C...NYY.yB@@.]....999...#*1...[1.......z..l..............b.V.Cee.T*-//...<x..1hV.4 .........f....7.....KP=..Z.....z..b.Vq......kq....(.Dr..%~}cc..;cbb....... .3.s<.F]]]AA...Y.F...C....... ......p..g.3.8........v..q..5. ...`..d....P8...b.3..xbP.T.......~..U.+.A......P(.n.J....yyy.O8.H.!((......,X.T*..p..:.....]...c<.."u...:--M..#^.."u.....g....p.....g....p..M.p.8...g..B.p.8...g........1....=...8D../s...*...)I7pGM"...2.8.......e.3Xq....'J@..~.W.{...* 'F.r_.......III.f......3.....M...=..{...7n.H.z......p.8..;....=...a.Qd.p...).%..mt..{...V.Zu.....D*
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):2480
                                    Entropy (8bit):7.765230297602272
                                    Encrypted:false
                                    SSDEEP:48:rXC6nvJOYPqx/UOqlrlp1h83wtubO8yWRwb/oFJ:bC6vPy6OqdZtMzdg/oFJ
                                    MD5:38B5BB6A0C925DCFA3DAF41A36432E14
                                    SHA1:90A6AEB00FF6C7816AC1F0763E01900CDBF6D039
                                    SHA-256:BD9D6C4FD962415EC57B120D381F9BFBC2F3D453A8EFC69FD185310DBC29A723
                                    SHA-512:6E3C9E074D0BA275905E17C6CA9A45AA8C1226104AEC72D8CBB56B3D331478549ABC761A3F513695ADCCF111A46D0050347F81A67DE2D6F5507C3C2C80A31056
                                    Malicious:false
                                    Preview:.PNG........IHDR.......}......0.....wIDATx..}HS]..}I3.MJ{Q[.Fd..EFe.Q.....AD..h.J%i!R...b ..Z.a....2.B1.wG.V.Kk.r..{~....>[./sw..~..=.;<o..=.6..F...a.&..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b...\.t..'.......C.@tDEE.3.........1...........j.....dmm-..DG__.L&.{7K&$$...`.`=......+33.............3.../(..H.0.f.S.777;::...=|....I.TRfOOOLL......... ....._!................f9...v...Z.......1.....jG.........2..www....F..2e....0\%P..D...;.x.`.m.T*.......?...k......2i.TVVzzz...S.=~...F.`...d2YVV.?S.R.Z.*??...........f.A..q.Q....G..O......;44..;x.d.=.uX?J.3..........o.........../.?~..L4{....i]]]AA.B.....<...!......>E....x..1.......R8...h.RiRR......Q..b.L..............p.8.x.i.&........p[[.g....."....ZZZX......g.3.T..m....H$p.8.H....%SRR.....p.....6.... .....1@..b...........h.$.S......>{.....08...b.3.. .8...b.3.. .8..A..xT..aP r.+A.C...@...;R..7w.$......{L.P...Aa..=b."C.pvv...p...tX.{.+`.....C......C........B...(q.p....0r.F.Y.n]rrrFF.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 260 x 125, 8-bit grayscale, non-interlaced
                                    Category:dropped
                                    Size (bytes):1769
                                    Entropy (8bit):7.795029966382126
                                    Encrypted:false
                                    SSDEEP:48:XEPy9NyOH2vmrHBrZDlyMZRLAdldkLsbNsI8vtNo:AyVVplyETsuFC
                                    MD5:26414314D6047E34CD2E596A7DC4163A
                                    SHA1:78CA4B3FC192B3C21882EA9258350C9C2F462D60
                                    SHA-256:985D19A5C20195E493528D75907591CEF09288EC4F7755545A1F55F2FC52E13A
                                    SHA-512:4241CB82528808D0141AA259DE8AF269D46CE24B6E23932BA03DFBF4DF2653A1ABB160C12268D16E2F6BD4CE43FCA6D39DBF7D8BB7C1859230205D8416FE35FB
                                    Malicious:false
                                    Preview:.PNG........IHDR.......}.....a9Bk....IDATx...{PTU.../.%_... J&..l.`,5E....`......X..".*KS....BMc...Q.......NZ......R.....?@Y...w..s..{.a..{.=.w~..b#..@...A ... ...@...A ... ...@xB... ...@..pg....P..W"..D....6h..!..z5V..B......dc....T...{.N(..;.^....;.ck...5.N..J..&..*........{.au.(..q...$SW..#.....,cQ.B.R......2...nI..&..l....+...M#.....C...PA.......|..]F....5.._.....aph.).u...j..C.+44.-Y..m........n.#.?qY<.aI..........L......v...3=oL.&G..p..g....s....n...v..]H.b....8+.$.{U..?&.Zh.....m....&..f......Hn}.\..$..+O..B.....`.9.....hX.r..]..UW..0.@..6....:....?.fd.C..K.......Z.0......a<...>K ...;..<.....7...;....^t..lw.\..h.*z.O...a.q,.:.._.@."p.1..v..K.....'.s<.....Z,.89X'.....|..w.n.x.g..v..n'......@ .~U...9^ .L..@......u?/...p....(L....s.l. ....Wd.?.X.h..-0......@.,...;..*.@7.%n..@.,..)O5...s,.&L...dQHy.......D[.a...&..y...G....B`..tY..#..>...c..>^?.m..EY.J_Xk......`g...xE.Y.?..3q....J,..C...y...^..Jb....v....).(..h(.M.`......&..Q....e...u.F`...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 260 x 125, 8-bit grayscale, non-interlaced
                                    Category:dropped
                                    Size (bytes):1711
                                    Entropy (8bit):7.795099318203276
                                    Encrypted:false
                                    SSDEEP:24:utTIWyORXNBqvo6tetXkcslYgP/7SSJYh0lFsXDj2tCc25eFIszUBJmt28g398sI:GyOVNcZQLA/7SSJI0lyfi25ps4SAhI
                                    MD5:F8BAEC8F20E965AE54C09ED029E540F3
                                    SHA1:8BE204C99C5724584FB2FA8C2E4A4AA780AB023C
                                    SHA-256:25E0FC4E7E01E0A67C1355773C4004DC3CAB33AF06181662AE699DF2B7180FEF
                                    SHA-512:B774E2CC3783074A0256B545D7C72FB5076CBA5E47240E77FD015292B55F32A875D55CFD8FB2B9FB9404EF103AA568F5B46D18976DA16C794DA0DBE4EDD14539
                                    Malicious:false
                                    Preview:.PNG........IHDR.......}.....a9Bk...vIDATx...{pLW.....F..I...D.L..U#2.hB.T....t.4.1.R.+..t..z4..g....L.H.A:Di+mH%...".fs..CR!/%.{......9.=...={.]P.!...@...A ... ...@...A ... .l..,'=yg\\TTTT\.....2-!.=..$.#jEG..%...S=..o.q.C...c..K.E..8........M......>7dR. ..F.s..|.!..lPu..{./K<./=ZD.?..4...n..YjB..2...F.....A.U.b.....7...k?r........:)(.l...1]...S..............4B~D{..O..IN/.5J....Wm.!o.=.t^...u\^...-...$.).....>...[O.h.^hs..XG..; =}].....c......^../...z..!..P;.].*..Ji.;..[......am.w^.j..N.6.P<...^i...M..7...p.....y...tMS8B..=.Y&6S......T2.i<.v;......"."\..0.O6k\....R.R:..p..9,..8.*.a..h....R~......}............]....?...b....`.,..~'.y.X.0.)..o............$E!,.. ....|w=y..@...".L1.aP1b...M.|..H. |.`B...|o.._....V).a.../..`.G.....Ve .k..rG.....5_....S..p...S,..5...'...:f[.......,...k..y].>E.F...Z...oM..v........n.<.Q........E.....cp.[gz8.?aM..;0."..%.c..~...VDx.x>G........L..B....T...?3.@...n;.......jhV>.p)...l..<3.....y*q..X.!M.|/..Y....8.....B.7.,.A.k
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1106
                                    Entropy (8bit):7.762860438597511
                                    Encrypted:false
                                    SSDEEP:24:HaYU6MbRFh/eZ2QSMlRO3gqx2Ah7Hi2J9n2:6YERLEdRyhH7C2J92
                                    MD5:C9E9B8D9B2631D30B49878F632EE3E1F
                                    SHA1:CE5D81159210E277214B0862E2FCE5F87B6FDB80
                                    SHA-256:DB2950963E74194171F541AFDF5BDD0016594468F827C38D04E17F543B7A17B2
                                    SHA-512:09B35E7D4267746BE8FE9AAD610831E0D3D6B9F504EA43D50938E684EA1B08C7755F6E6D02373F72F4073BE74866851DB5475F4EF43FAB51B7A5DF51893B2A70
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..[l.U.....nw..wJ.l..*./5.'M.....Z..H..(..%Q.U.1>....i.TD!b.F.j...%.RJeKw.;3g.....]P..'..........9K...h..x<v..k.....wn..g~......l4.Mk..[..-..7.oM.&...s..............3,c;.[vS.emM.Le.O.-._^....s.|.4..b......2.V..W..u._mko....p]4n..+..8.q..6wY.d...C...N...H..V....[Z......`$Zo.D...qV.0.6.....g......\......g...l..b.1.qp....`.....S..u...^$..4..f.%.].75$..}0.5.O...ayz....%.zv`.>..%G....2.....C}&..{a.g...YY.x..h..0...`.Dy .3..G>.<..z...<..UU.i.._y{.F-..W.nK.rQ.z.c~IX.L.......G......z.=-*.3..@[g.q..".+...*.B......l....~..]....r%Y..<....Nh.>.Z.Z!(f.\..(......N.W...8.#.<......{@wH.}T....i..Z.L).(......s1..._.\..3.Cg.............z.P..!.Z..E]vg..9.6gU..2...=..b.8.....-V.*f.:..XXr.\...f.Z....5.d.....ogYv...............bo.m ..A.h..m.nm..P...WU])..N.I.l6.{.5....2..EV#.;.Q3..........v.&;L.Es'~.. .Cf.....6;ad.~,.+.....{.X.k`.U.`..%......Y...wSy]....D.5
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):250
                                    Entropy (8bit):6.461832087016094
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwdshkx7z/VawvzN311tIbLz/pnoTm:6v/lhPZi+aWdKcdAwBNObHdDqUpFDdp
                                    MD5:A2A3E7BD7705826D3FF143BB52DD3D9F
                                    SHA1:07FE7162244E2B05E1586C101E9545A5FDDC9208
                                    SHA-256:94DC37B9A2D954DEAFA5223892905B1E8B2D83B88ECDF1C6A94188B95D488595
                                    SHA-512:3F927341922B54B27D3D4EA08A821D0FBFE098E35DE386E16F201C033EE09AACD81F75A6CB74E3809D95CF67CB1B1B0A66E418785A5EB583B101734F522D04C1
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf........K.....F..Z4.,..a#+>@....k.`.j.ida\>.....q..',,,..Z.....,.......C..\.:0.`+...D..b.X@l2...."...At*"..o..q@_..E...5..T.U.K.M....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):223
                                    Entropy (8bit):6.398799942519418
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcxaUjDvvV4H60iPQCu13ggp:6v/7saZxXtr0iPQz13L
                                    MD5:1C743852FC14080A177242B560D837C3
                                    SHA1:8D446967CA3D01D167619E0F86068FEE5BEF0569
                                    SHA-256:57B68F1F27EF229A7FC05ED0CE6F68D3579D95F060D8F8640272A4C470111C80
                                    SHA-512:61809D6A57914FD55CB20CBDE4865A183985D237D50343CEF09AB9D03C3489BBAF89703E34872920E51489C46BD80B0DC1CAFA4B17D712701C2CEE795F0F264E
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....lIDATH.c...z.....r1H?...2.......N9dE..l..U...._^O..A||.,@V.".......`.x.qY..~.Y@.8.ME..h.."...4..h.Fk...b....%.........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):296
                                    Entropy (8bit):6.746873141368636
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPUb+aWdKcvYi25Cw5pxk0JUnUkjM2xD5LUfdHitDbp:6v/7+aZx25d2PbDy0B
                                    MD5:C6673C8207DD7A3BFDC899FD5A01C683
                                    SHA1:F2F9C53A2431C86A4CD83353FA5CAE72C8667414
                                    SHA-256:1B307B3D491DA1CDEF0436D386D65CD42893D0E300883DEC5D1B830FEB6FDC8A
                                    SHA-512:3F67AD592DB9AECF1F63427A8ABF2D35F0D7CFDAC34180BCE370E4888DA1C2FE0556ABBCE33EE52FF6B8D909A82AD8CB1BF57745D3DFDEEF33AE1FC21A5F13E7
                                    Malicious:false
                                    Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT(.c`..>..8./.h.8...?.w.%l...\.0.a9.X-6.*p{v...W...[.O!..1.X56.]..@X.p...A.._.`0%.xV1h.....l.)4b..B%./.#p.{......\..B..m.*<K...$Q,..3.....P..Q....._..........b..p.a)C&...).....U...^....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):549
                                    Entropy (8bit):7.283369024087014
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZPQcT4lYTthdesj8LYShggLCBf8/AMyj/GdR6G4s69qN3Fz:HaQYTtVwL/zKMQSR6Gk9It
                                    MD5:667D4AEE56471B8D1865DC64E9EDB5B0
                                    SHA1:32CB65F26D5122463D577DB5C01DE6975B9092FD
                                    SHA-256:4D2B4EBF08036D42A00AA94A5226C6816644A6BE7C5859CF20F71E413C6E0F5A
                                    SHA-512:1928A6825EDD75E17F69527227F9DCD0BAD7DBF6EDA2BC4F5E8047566C9000CAC0A887B7E9A4EC7C281D06867FC6E178B70F6058EA5821F49C6C1DBDE41D5695
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..#....FX..5.h.R......'.>.....;fo._.>..N.$8...fdb...#..\|B...E.....1?.../...O..9.x0, ......Y.../...c...s7.......K.........FF.$E.33.zn^.?.V.........=.......n>.?{.>....N.......p...8XXX~.....}...[.^.......w....f?........j..Jj@....9.N[u...[...}.......O_..l.....&&.;..gff.w.6n.........w..........@..r...y........?v...u...#y...V6..gQ%W...^.W......K....cl.....3P..Z9_....M..7M\..Xo..-@C.s.........c.(..@......B.*$.j......qc.,.!......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):354
                                    Entropy (8bit):6.795413594247034
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1w71S2BJImyidQmP/oQDqPEzl8MZh8OfkNbDA1KxVp:6v/7saZ1YBJc0zBvR8eh8OfkNIg5
                                    MD5:D74E9E581C473BAE1DEF15699EB5AA2B
                                    SHA1:513B78C0CC878F42597556B7A168F187806E7EA6
                                    SHA-256:962D806D29BF95BA7DEFAD353523B296F0FAC02561C8C3EF27D7330934E6F642
                                    SHA-512:046D7210A0FB0FBB19212A262CD0C2308574A8AD3A051335C3B63145676CCBFD365B2C0DCA4FD4D8B879E63452814F7019C856BF47691D4AC01326BA8CA6AD34
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` ....|.R..a.........b.ET...F.....I....7.+..4..]S...k`...`f.VL...@....qZ0..+&d.7._EJvW.b..<..+&d.|,i{>V..i`....!........f....X1.,...S..;..b.Ypq.9VL5.6.....L'/m.....J./...VT..<..S..s.:..S..1)\..S...h...V..:Dc.T."Aus..Z..l.@.P..g....:1G....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):863
                                    Entropy (8bit):7.676585224606489
                                    Encrypted:false
                                    SSDEEP:24:Ha/jmJr9wOv/z5W5ib9A5OnVG17QHImdfbbNdm/:6bODv/wy9A5OnauxNA
                                    MD5:F463432253A825303A05937804E13114
                                    SHA1:C70E3D4C39C8920D6B66CAF8435DCC4A414D1444
                                    SHA-256:C7ACF49F936E01C3758A4303D807B24F9E6B4D89B34F2DA3E4FFAED77F411BDA
                                    SHA-512:D74ECD477651570AB0156F1DB49B5C2B88CC364FCBE3C18B33552FB2D2C7C6AB1035B35C5F9FD423E13668692F772ED2D85BF3E7BB52B2220A1E90A5B1559584
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...K.Q..gf..r...?.vUh..PICC4{.4(._ -Y/A..?..A....2....,..Z!*.L.!....H....].ec.9...2...su..;.~.{.{.]..[..G..q..6.. .c5OFf........>"...x@_x.|G...(.-tL..w.e.N.~.Ig.=.".N..~E.z.4d.>.E.Z.2d..BH%..#.h.%..2..,6..FT.."..7sV...YTEL .....r....d^...#t..HBD...Uj.r.......;M..D^S...r.G.. I3k...(r3....HZb. ..=.m....cp.........(.x..M^>...>U.N...E.[.fl.6.....JQ.3......PZV..e~..Rm...r[@....K%...^(..P.Fy.6.)l>.lP.&.7l....[P.5.\..v'.h-..Yf...*..F)."....@.....B........uP...'..$.h..-..X...N.o.\Q`x......{j.x".<..z..@h.....A....a<.I..........%.).;.F-...*.I..../...........x.]....JJr.\.M.$..z<h........r.JOYP..,.q.Q.C....(......p...}..IS,q..j......[..^.aN.P*zG..X.*J.W.;..~.Q.y.]0.]..x.(..0O..X.h...."...O.*.mq...E..u.oL...K.2.T.5~..Fr/..#....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):432
                                    Entropy (8bit):7.022433406427089
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZy1iirqwEmIS7T4pEeQG0ZE/dh/2c:HaUiirqFm9sp/QV6hec
                                    MD5:F1A38BFBC7C39AECCBA6BAAD013DD07B
                                    SHA1:8DC318CC5D5AE6C4CD8A8FB13DBE6C42A97EEE63
                                    SHA-256:2D996A5F900C566E37261B31530E756D3875F2CD48816116FB22F07DF43284DC
                                    SHA-512:CBB562846167F21955CE749C3AFF63C4E07C138F3E2525E6D8688F0221BFB2FF334818B6DA27D5C4D70757FA66F578B432237E586DA49670FA9125FC72A530B4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....=IDATH.cd .0....}...1.........P..P6..f......A1...Z>p....bU(.......`...T.$^.......`.T."..".3.....Rr}..U......kA.@j....X....B(.7...Q..U.....p....6@...o.\.I..<.|..j..z.EJ. ......M..d3>0 ..i f.*Z...L.8......Q%..3...~<.4.,,,_@...T7g..Ta..Pe..........l.....<;......3.On..@....f.c`..g`.....@.I..\B...Z0...<.2....$f."....w^.O.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):391
                                    Entropy (8bit):6.95337744772903
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc5sygba50UgvsOSpOCGkklVHuHcp0pzflxHXxY/kynWZzJ4xniH:6v/7saZ5BZysXR0V0C8aQzJ4xAJ9
                                    MD5:9A19C446FC6AF7EC2801105DFD008566
                                    SHA1:D0F53305204C064B3F7CB5227AA917BA3EC7C23B
                                    SHA-256:A0B242B7DC424C14D376E5CEC3C796CADF15AEF497D02FB1E5ED7AD7311D0230
                                    SHA-512:8208C9313F8A7B3D63E9E362BE44B447B21E25D6E282276715E4C5640F0C831875963A6D9779EE187D94188B6D2F3930764AA1C5542326442D55BF176CB045BB
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.....u@....B....hx...\ ..5x*.....@|..y.._..(.-../.4..........,(...$.B...D.(...@.+..B#y....i.H??...6..AKb_..T3#.M2....4c>Tb>.....n ^....X......`..dc.....2DP....C4....%...N...y....%.'/m..iM........!...v...7....R...E....6..w....3C..]S.6.....=...h..`..).3.]....v4-..hN...v.:....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):234
                                    Entropy (8bit):6.296885754046096
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKctNi+rBauvV/B2keImuxqiutYVP9DJ/Wadp:6v/7saZtNdEuvV/BDebuxZrp9DAaz
                                    MD5:B8E8F3379859A608CBA1D83F4BB34913
                                    SHA1:BC48E687DAE012AFBF733DD7040E34F7D215438D
                                    SHA-256:F3F6CA3CA21BC905917DF11ED0978874368D69A37D73489B9F6C20AF9E922544
                                    SHA-512:DA739D664226DD094023795E1780BAE422BDC5B51692924068FCFA68842DA526C0A8A840C4C23839F4EB7EF12B9661528780BDE9E73B2F0DA01F125108DB53D1
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....wIDATH.c`...`......@...yha8...........x$U.x$T..A..*.(?..<.m .. ....|.._..~r3..b..<.6.....<...<.f..L...L...Q.....'..`........Y......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):395
                                    Entropy (8bit):7.057270124013177
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ1HQilxcm85iSf7n1e1ddbqIxobK35:HaTwGiiSDnccuobC
                                    MD5:E932B31C319943E469549915D810AC12
                                    SHA1:8B1B3B1B043EA60097356EFEE4E80352E07F0ED5
                                    SHA-256:29F4AEF9D0D15012B8D146256380B01F10ED8035657EC6DF3035F992ACF9B8E3
                                    SHA-512:AB75BCC508E35891D0117C93CBD7319331257AB93E7526E3A71B5D7167407A2CD513563AE14BC56D289EC078DE6BC6FD18C76F50DD94801ED655BAB1CA107398
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```.O+......p.v.&.j..........\.F[.:k.0,.k.r........VQ.` .EQ.....s..d...6...G...N.n."..d..0l.f).%x-.0..... K........9...e.M.5.1..'...|S..D3.G\.?2.G.n....6...m...c........@........n.....}..n=...>...=..1!.1........._....6........p.... ..."...!9.q@l.......k...........M.-...5../......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):395
                                    Entropy (8bit):7.011693557019101
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ1HQ32pY9/tJLtZA8tU6GtbtFYnl1:HaTwGpYptVzArjtbtinz
                                    MD5:D0A6B5057DC9BAACB71C9C19ED00B21C
                                    SHA1:8D5FB4F80B314043BB45D207E3DC943C18DE42C0
                                    SHA-256:F243BEE3488E45268B7F23AEA2F6E6103D5A3CD16D943C1E1CABE010B1200347
                                    SHA-512:49B1C9D45C3BCE4129A72A50FFA2B152CC8B947CE7C5D117ED4325CB6C28920B2C932FF49DB7A2C0B6BD9C3FAD9E1A2427549A27FDD06CB11558909AE8A2934A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c.......@.......p.v.&.j..$X........`..h.4.n.Hc.|...;..b...^...`..H.......b#!.a..0....-..!,.....@|.%.).q.-... .YB. .a.E3...s._..@. j.c..N.8.a.. ...m.b$#...s...c.......f........Z.....M..(*x..313...f(.........a...f|..e0.K.+.e.1>..|A.K...8.&l...\8.H'&..h.l.......=.d....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):721
                                    Entropy (8bit):7.448808390963381
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ9XDEnQVKj93V78dXY7k8qKDhSKGQ42MikNEZCuU0wgy5yhK+ATv:HawQVK53doF8qIGQ4M8EZTU0dyEhK+Ar
                                    MD5:957773DC9D469F86A04E54E916592EC0
                                    SHA1:8E39DC11495A21E663D5F8A5EA740243B398989D
                                    SHA-256:83488EE535F319F9BAE4B6F93939FF59F1A87036A010E21185B1FC0BB6CA9E32
                                    SHA-512:9371790EEF711449B7EB598D2DDCDCAAE4707A2A0721AB4014EA1E7818D6EAAC4EAC81D7624967428374CE22F8A7C3356DC11B53B8689A47E194E3BDEB51784D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....^IDATH.c`bb.....X........y....&.........w..G.A8.o=..I%..01...."................jj`>.?....b...(.......n.1.n.3....fdb.....?L.Y...m.,....?.+.X...Z........-T|1yA.3.._.,X..,..<."....v.%...7............. .9...v...(h...>.{.X\^.......[........C../..,n...g.S.".c..&..`..... >..zF..}3..w.|D..D..6v....a.....Y....<.....s..%P.b.).8....Ov$.7-.s.L.P,Hh^..W5..[.2....p.@|8...n.....=.....D..#..,n............(..8...CK....]..0.`|,.p...!..i;Q,.P....N.NY..KLF.......g`........`1..&.?...PR%..F$.......?.8.G C..d.....>#,..!.02..1\b.Q..)*...9...FV*......S;...-+w....Y.....GP,.......=..#+.....)..R00.~..f...........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):913
                                    Entropy (8bit):7.677598234915074
                                    Encrypted:false
                                    SSDEEP:24:Ha3YvJK3Ww7NMWo9moWcVZ9YaRD/0A2UDeVAg7:6gWo98cnlRz2uc97
                                    MD5:DC170FE8A09DD78D0EA4A5A0ED9EDFEB
                                    SHA1:0A9ED3316315409A75ED2F91F1E661C6108D5204
                                    SHA-256:085769601B961616FDFCFA94382B41C6164E4457FD09AA898C0BF645BCA4672C
                                    SHA-512:27F31ED79CE0C4D555CF273A0B87E3615755C20AA9FE94B73113CFCF1B697B2B27965106F3D98F82BA174E0823C82AF3FA4BC19773E0717C449A4770C69DF5B4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..MHTQ.....4.{3.ot..0.Ll..hQ...F...*2ZIE.6E.....Q.}.a.fE.H..1.-...Rgt2.;3u.....%.9.......q.=...s...._./......%.....GAV..@b...]...2.Bd@..JY..$Q.V....31....UD.WU...A.....i...Z.FP...A.xJvX{.%%..n..3<...6.......d..s..!.@...(..R....K.....Wh..C..U.`..r.5z....UP.;{..#@.e.......I...e..t.z...A..<.(%..).....(.f2...rA....}..8@.^....N....@...(E;l.z.M7.:9..RU...;.u..r....M...{........r@[..w.l.8.Q...........U....OR.`....Z#.....G....1....?)i)K...p.<..T...Z......DD...T..|~...YH.(..:HnY.O..J...}8...m...{.K.d....l.g.4...U.jK\\'..CA.I...&..>....g..t'..{..d..b...|..~.n........e.....!....-..?I....p..eE.r.....d....0........]f... ...4...+H5.)...aR.Z....U...btY....B..p[J..s=.......3b......_..x.9......*.{..M.S.K.\fCL..L[8....."V....\.u.&....ela.......i..3..O...S.........]..=9jWg.P.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):361
                                    Entropy (8bit):6.9821963636663495
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcNhkNRO83y5g1WAl4E5hgBL9LgQY2nfJA/NRk+fM1AL2UOVa1/1:6v/7saZzyXy5g1Z7UZg2nWDk+aRLVY1
                                    MD5:EB9A5585C347526D179D4159B0908B02
                                    SHA1:D796BD218C57007683415FC1284B55BD96E7FAAB
                                    SHA-256:569427C23063A528A27D6A5CBA2F25CAA71BF0522FB2D8034E3C063D1B29DE4B
                                    SHA-512:3C5777C5B18DA8472C88BB63BE6319BFD644AF162A256D8B0C3EAD4C74B1476E33799F703F5DA5424905BFD00CB6042A0CC1044D92437971EF06514503529CB4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`fa.....T...B.... .G........**X1H....A....E..@.!.....(....n..z......<.I.T.....g...{.B0..S....IYE.]...4......'63...r.. 5 ..'%.(..1)..8 &.P...f.EA......`R3#..R. t|...[.\.c.......O^...ny=....Pl... ..M-.....Q-.....H&:..M%DE2...b0.l...2ky1."....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):452
                                    Entropy (8bit):7.285227731150245
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ894rjBvvyUKpQ+TQ1AMDTBlRs5Gogn:Haiy1naQ1Rpqlgn
                                    MD5:AAEE78C672CA805E8857896226C2099C
                                    SHA1:24EA344563F296A3903D3C1FD0073713112AB721
                                    SHA-256:C2D7F3ABA3683D15944880A12DDF0F7D488300C2C5B6D84E04CF76ABAA3D0618
                                    SHA-512:33A836A9A067B2F8CA72E24F61DC049C4DF19E0E115BE02E1D89B80EA75AF50BED69347BD1D42254C4553E69F64DC5B1E40E277CBF583DFF7BAAE3A3247247CF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....QIDATH....+.a....W.5...b...RJ.......de.G.;L..,l..[Q2.? V.f1.j&.,..T..s......:...>.y....G...D..Q.=..!NQ..@....y..Iw1...|..I.T.5=.O...g....q.c..p..r...O..J..F|z.A.0......`.G8..r.[.=..^d..u.........~...6............i.E.;F1.l...5%1..Oj.....h.x.......N.X..:...^+R..x.#.....[.2..|.....|\X/.......O..!.<2.....DG.......[.8....x6.......a.:J....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):177
                                    Entropy (8bit):5.969137605937591
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPlT/Xtsjm6Kp0qRthwShLKOWGEVwks+RjaOWFgyqwgwDF0xJoqpu2l+:6v/lhPXK+aWdKclAjlWF3qeFutHYEap
                                    MD5:C2154350B2BF58F4113638B8036172D5
                                    SHA1:77FF707C980C6CFEC94B533C2600BA99B8261DC3
                                    SHA-256:24FC0B2460761B1A9F0DAF5F15693DCD41DC4BA13A5415B120D8EF0FA0F67436
                                    SHA-512:46CFBD4F33D7529E2C9EC2511DF22B35A1A6283C1063AFD60BF1B97B39D6209B1DD8526DDE73C1EC9477014FFE6EB50E4235664DCFFA870BD8B6CB662B2E7128
                                    Malicious:false
                                    Preview:.PNG........IHDR.............J~.s....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....>IDAT8.c`@...H@...&....@...j@U._.X...?....H..$....:....@.R....j.=.*.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1034
                                    Entropy (8bit):7.734794645219255
                                    Encrypted:false
                                    SSDEEP:24:HapZ4JOeXbe0qxdEO7KCMfkKlgqG3G5Awul3kQ8:6f4JzC0qHMflvG3G5A93kP
                                    MD5:E18AA31FF223148C443EBBC9DA889B8F
                                    SHA1:A7D7A15076ABE042CFC6430D8920608C6EDCFAE5
                                    SHA-256:16B6CA9329F1EA799A68EA0C21AAB50EB61F7A61CC23988D7976957D01D0A399
                                    SHA-512:388E2A3582A9114FC83D43CBE1F00D528E4ACED37FC3F8DDA8921AEA3B3B64DEE30A3A3B93C1B366C47D35259927FDE6C866BCA0F7E37129398DFCF3B46C1AB9
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kHSa...s....,*C.4k......30..y..V..,K7*...C...nv...A"kv...fED...R.......Ns..z.7...y..sy.W"..b....\.r...W+^R..*.u.d......j..."C...O.3'Y...K..(:..Uw..........|.-K.]\..f.v.\.7...X..q.:...[p.7..0a..+.3Mh....8..lcrw..]..R...h..d^..E_.y....{....sWb.k.Z.G.4K.D...%.E...HeR..=.v.I.J.....7\mE.8w.jL...>....H_.......p4T?,.J..(U.3w.tmt.7.."06t...j..M..^.S2v..=.Wq.6./......}.B...b.|-I.....E..N..5 .4J0Vot.[..........9..<...v...h..t..e5[..{;....`h..C.....6.,.~.w.'.5.....^..Z.0&$.t.a.{.a. .6].."....D....w..~.Bh.\..v%...q..J...*2.S.I..T....G....i9.$...).1...[...gEBR..N.Y.N..%E.eQ.bX....... Q.....G}...P.....Y.........E3\.4.sf....{...K.m.$..u..rLG.......I.....yp.y?L...a...4-&......9.(.G3.Y..,.<..@....<P...?..z..p...\..x...M....!.....R...............v...;..x'..Vd.D.|.....T*...g...a/....)......m.w..?D. .^.....!..@N...K...W}....'.Fw.Y.sL..d.zu.-..!N.*....b..I..u>.|E."+.:..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):712
                                    Entropy (8bit):7.613545467596214
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZrret62b25ynikW0NDsFqv3rZzflmpuYhrOx+kdeHvXdRmcv4K0Cf7:HapwfbQ0DWU9QpuDcHvXdRmcrT
                                    MD5:4174969FDB24BA1C5D8DAC66C6C87414
                                    SHA1:0A515C4A935F67A08E84B0974EFB1FDB5F2103F9
                                    SHA-256:D22816398FED8A9F16C0B98CAF0BAADA6BE45BBD77D5ECF9059E5EBB3FFAA466
                                    SHA-512:F925B53219120A373766F918B5BC5CB3C25B39030CE5F2DE8A5CD6C9605D814BCDDE8916F45036551D1D8B1ED0114340DFF5DA713160DCA863116435CC18B5B0
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....UIDATH..KhSQ...E....<..D.".\.B...D7E"EP...B... .QPJ.... .q!hA..HU.....K.....o..p..h(q....9g.....8...H.....WC...(.R.~...Q..(....y...,..x..X.....0..^W....U8.. ..$..M..fa.l..>=.....$......z...N.:...J4(.68._....]...u_..p....p...#x..t.+_l..5m.......TB.><..R.......:..c*..%hWI...K........}..N..)w..5;[.@..j.P#.nb..*...*`V.[.U..ZF..].u. ...>...x<....L&W.'..................~:.cc.h#I.`....d.&0.H.&.....J...%9.....?...;F...O.G"..M@....s...".oVI6.c.......d.....Rl.....%0.Y....m.....o,.O.|.k.Y.)..h..Mv...e....=.k...!.;.....v1...*....0...._.O... g..k.J..4/..N........s...l.......C&....0....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):214
                                    Entropy (8bit):6.121521703688993
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc5Ai/UyBSS5emlULuxeiyTp:6v/7saZ5RcyF5LUaxeiE
                                    MD5:63B811B3D4BF104CC6BF409E0D6FDECB
                                    SHA1:FD30B0A772DA243966AA8CC093DF89009689F5BB
                                    SHA-256:234F565B79842D4A6411B68739CB6A390FDA675A2EFD0A517A33200B15A5FA12
                                    SHA-512:C9B97F8730AEB6E1CC5FEDE1B2E9B71F285FCD73D156FF29EDFE0A406077519FE86A3C297BD0F7F92CD522E014D0097FF96A5BB3A3D8D2635CD57A623D7CDC55
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....cIDATH.c`@...wcb.8.&........d.pY.M-A.H...-....I."....."., %....4.......&-..e....=....F..h.,.-.....s..B.s.e....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):400
                                    Entropy (8bit):7.016748459858045
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKctLwH/wF+1B16o7gUFyt0lPgF6g9bgApeHCbtnsO2RwdgE3uWVU:6v/7saZtMIFkTcUAWPSfsibtUOq4U
                                    MD5:D89D713A14E737C662E4280229C1A74B
                                    SHA1:08F537BC90EA5B765F8966A51BE64A2AE53FC872
                                    SHA-256:5456BBD8BD1790A742D01A4229848418E3D2F923631177F07B3142784896C3D4
                                    SHA-512:C4C079B8EF3B2553D0BFE8B7F076667DCBB19077B9A908E5A44A5D8C090E7B7BB5F0D79BC4644D23B82B09F315B5B635199424307B285ED9B867272095AE8640
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`aa......X@@.DC8 .,...r..]..>$qTIt...6.q9.n.6....X..X..`b....p.._p.'l..M1>K....8`bf....E0.1.0......8...3.....7.........`..7......|...".M.p...E.........Pb...n..TD.. .a..........YBq......./Z..Y.Q#.`..$....J$#[0....p.H.aHF.!"...g..B.`..\.....3..UTp.p..i.0.....y....G- ..Z7[.Jp.C...q....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):486
                                    Entropy (8bit):7.170472697648373
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZW699qguNFVzmnyRDzZ0h1T/P2aGGFYnlgUM+:Hao6sVzm80hEakx
                                    MD5:BAA6164F13FBA815DFC6627419F2AFEC
                                    SHA1:5011DB35431AAC1B5C76046C753B7964AB5DA685
                                    SHA-256:9D506E7E8D8AA813AEAC8427841A28AE2B858BDE208871B7CF113E4C52D3EE21
                                    SHA-512:15AB7E68CED3F52FA91F1A1326C170239313A654921BAD68D1C18957D22AA8CDFF9151CBD6B6ADBE70CB6AF854E342A44CEAF4EA189239B532186A3C3ABAF2B4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....sIDATH.caff.........F&./, .w\......._@...@h.10..L.............TyX@.H1.........UU......,...&.n(...y..N..A-@......'....k..a...0....}...B.....0G6.......p.c......0....0.%.ha.?.d...z..d.].....Q#...A@...0}[E.(...w...b.......9..0.2l...K.=.P.......+.P4.U...a.s.@.........&..P.........fX..D.....(>@N-(a.'.`.s.>......d"B......4..>....vL..*i...F....q...j....(.).i...1.(U.......'~......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1238
                                    Entropy (8bit):7.808915422534312
                                    Encrypted:false
                                    SSDEEP:24:HanXtZPcNqHGU4qPgpf0ZJImFt4MPJAqDRQGmoagfGxCy:6nXLqqHrNYoIEyMvVQxoarCy
                                    MD5:92B9537C7ABAAB5654CD4841B8304A83
                                    SHA1:D396624ECE2D994E1F7C65F284808C4C0A617CDA
                                    SHA-256:150228E68DEE137D1FBD1D895FF70751D188D610050B350AC520351D61B93904
                                    SHA-512:FD760A1B3723CCEE45E80E619867125AC7BDD5F1093515FCFB126212C1CB54E4430E0AB17A046659CFA2D1ECB709AE875F541E26AAA1B6EFC849D1478E5FE42D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....cIDATH..VkP.e...o.......q........b@"..9.#..*...(.....x.I.1C%.t...lr..~...4M..6...}.|....f..~g..=.<.y....G..-$[H..V.N...l8m.1_..6.h0j.U.U..:..j..3h..;..T!f!..T.$...b:o4.~.$./..S..o...7......O&.Kjsn96...........&:t~'.]...R.......nV.c...P.ZR..au..q.T.. H.....P...^..I..F..O..k{.k.ep5..$...J.<.i.-..w....{..z.s'...6@..O.J."a.v...wVSdl..?..v..I.+@....'..MK*.(<.F.G......a.3....-.W.A.s.iA.#....$%{.'.-I....D7f. .v.=.......0...R.\. .........[.)<.F.e.T.<.u.p."AR.P..........|....<..%D..X.....=.?..C.}x...p.D..O...'..i../z....\d...<f'h.VA#.u.T..2.D..t.....................{.]t..9..J..1...I.`.7.2..w.0.....3.u.{Xd....._.xR.F..I....D..et....|...^..J_.S...&.H..m..r.R.*J..X;...F.........J].....JASbj...~1..4p.....XuS1.}.R}..&...U.LD.Jw.s.B...$....h....c.U........H.bM.......E....U...v.).N..Y.2..9..@.`.hBw.....G.>....}...)#/....c)........WFV.=X.........K.<..M.....Y.{e.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):316
                                    Entropy (8bit):6.791312583826091
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcTNJ2NRF48MqF85+ChfsHZmbFHMljGRZDdp:6v/7saZCNRFDL85JhEHaojGRlz
                                    MD5:65E360571E63460B00426C87DF35113A
                                    SHA1:CA09A029470CAE48D08FAECC1E06FE843F99FF59
                                    SHA-256:221F074CACE52746BCD34A5E98F5656C485921D8579F10E43BC8F444C66A4C7E
                                    SHA-512:E00693D4A619D07F74E7FA20D5099C71D76B3AF41DD8CCE64A3816AFFDDBE9049051104140DD8C4712765A1AA2DF1AB1C75EE708223D20AB0C70F1499F9865B8
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` ...b......I....$.........8..5..c........AD....!..P,..bJ| ...X...tA..%6..b./...*4.g..>.*:H(......@....OH. .....3......r....Z`...E0..E.1.,.Jv...I..1.."....K[B..U.....Y@.B.8.Ql.M...V..q....&.v.jx......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):786
                                    Entropy (8bit):7.514285909712526
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ4ZRY2VbLvZ8znm66wLcT/ayfgKjo6f6C6XC1FhTJHQZXGpxarRUKIpIYc:HaeVxQmRwLgayItUqC/hTF4ruhN5FWj9
                                    MD5:7F4225C588D46DC3808075B735312610
                                    SHA1:44C9C2855CFE398F7B85AEC33434192AFC7B3DE3
                                    SHA-256:94DAEC623321502A1CBCCB2168B3FC471DFBE06322AE43CAE2446124B71E5F09
                                    SHA-512:E9D676C318949D8B74F08633B4C0D9D7DC72CC30A9096C2786F1CCDC401D695F2B29A3C03C55F8754D5CB9CC2661FAF8F970D080DD7F80DE5060111B0E9CB562
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`@...C9g......A........r...........L...n.x0-..........YYw.rq~....... .....$..x.&.....A.p(n .......QiP}.\\\.,,,?a...g........W.740..8...=ruu.....G..yz....0|...'.|=...Z^..!...F.......<WHHh....u...?|....._.._..H....A8t.....Y......,(.5....z....Gcc...?._.......{...r.?...F9...L...|...o.>N...v%.....4.y....co~e.z.........=s/.g.|...}...w...8...??..U.w..`&r..y=f..s..;?j.w....=..<.}...i+...{............q$.H.9...PXk.....?...w..i...%..O=.......;::~...@T2E.p.t.'...=..c..?....#.H./(..La.j..:.."b,....r`..5.....T'..A(.A. ...8.../..}.lLD*j ....!...2..MET...H.i..R.N...F..L..pR.?.+bAl....sq..e.....b....l.~..I...o....a.3..?@=..}.\.../..b.......f...e.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):689
                                    Entropy (8bit):7.574530374290251
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZnizlgDaH82JDYgnLI4hWaFC2HKnnCaIXPRVeYbd0AWWnvdHXWCSNB67PA:HahizlgDaH82iwF6CDX5UYbd0AJvdHXK
                                    MD5:54E3DA1A498729DB27A2BF10AABCAF76
                                    SHA1:DBF8D742769EE071AE7A85E79F95E46CDC29B759
                                    SHA-256:D590BBDA450D7E69633384DD1B512E84EACA60F32A18A4E0C558518A9DB2DB6E
                                    SHA-512:C22E57CFFB3F325BDE09DEE301B5B095B9012EAFD354622B4C327AEC5DFA556AF26888A01FECE033976FF0323B447F81324061C284158604E706F3EC5A5C8130
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....>IDATH...Y..Q......,..L. %JJ."$ERc.......7<My@.D."Q.&.VR...D....}.y93].~..'.n.v..~..{.=.g6.5../$...#0?.0./1.."....zlB."....d+...j./.NaK!..Y..E..b...2:D.h\....M.M.=...x...9..1.U8......k8....i-..y].@..aq.T.3*.?.p..S.. ...,nTh}p.....1)bc....>CR.. ..N.......m:vEG5Z.>.@..]K.W.@.U....&|.._k,-.]Slx.]M|...~b.f.N...K..........a}.......6?'6..c.1..l)...4...}".Q).s..-..."Z.;Z5....y}.[g.....@.F|@..G...Z.v_..U...x.-<.$...Q6j...B.M~}jg.....%...r1...O....}..-.5...Z~..@.......p#rW.d.w4............h..O.6:.k\b0...\.'.^......$.1|. ..b..?....I.Q.....2.Y.*..K.wD?....g~..o.p........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):654
                                    Entropy (8bit):7.5246396249978655
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZsMb3rCXdR1/iuIQgv2YDAo/BWNeIkhkR4iLawLwaUp8rqbij/1:HayKOdR1j4v2eAo/INeARTLhUiebij/1
                                    MD5:49CCDA35BACF3D49C1C208365F9EDA7E
                                    SHA1:3C3FEACA3A8A97752B48794F84004558F6782FE4
                                    SHA-256:E38F7304BD70D2B68D78ED098B3D570F465AE39C1681DF64A11045FC8B664706
                                    SHA-512:3DEBDCE3FD946B90318C74ED6A40563E8248C507EC702196E12760ADEAB3043A18B0426380D994BDA770CF6315908610B5726BD494E7D2BCE73A96DEF9524765
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..OHUA.....2MB......B&..."!.E.iSm.t.R.`(Q.Z.m...=..... .."..MF`D... Mxh....Lr.{..[40..;.|sg........c...V.J.k5?..2.P...........g5O..@..Wf...<....&.b`.8.q..{...X....D..vm..."P*<.<.....@....+..6...o{.%...5h{.....h<.`{W|...=.."..._..l._.X..zac.7dC .`.=.....t..a....mPF-.'.#.;o.......U.1..3./..r..5.&`P.0.O.#a...&....N..h.>.NI..(...k3........D.......r..q.......g_...\....t..?.Ue.W.~.....g..}.E.@..;..W.w}.M+.V.. .2...@.....m7.P.+.V.....{.n)}.0..S..."v..........._............=.R>.@#0.G.....9....d.,/.v...|...V..........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1468
                                    Entropy (8bit):7.782463629931873
                                    Encrypted:false
                                    SSDEEP:24:knpiJ2QS2Hv6E9h1e4rsV8j6GCh3sbWImFacV1eLnQ+DEzwWc7E59z41JI:CiJ7yE9hQ4rXY6lmpveLQnH9z4k
                                    MD5:32F980D9976D4C4F0B4F9790A057B64E
                                    SHA1:EC6BAB082550827366726F08D73179DFE845D7DF
                                    SHA-256:8AE2D99ECBCED167A3A6F2619EBCE38CC2DFD3B5BB78212DB8BFA65DE0DD251F
                                    SHA-512:33F5A73D344F86E8D25B7B3A18B6AD619272965DCDEC181DC345B20FCEABA651424CDCA654A4D909FE17EC709124CDF18AD349F7D99FC8014A47F9D533361DB4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....bKGD..............pHYs..;...;.........tIME.......B.....IIDATH..K..9....Uu..s..5i..MK(...6.-B..;.K... ... .........4IwN....^7.l.8=IgX.%o,...~........-.!.L......G?.'.=>.yzQ.g....w...{......_rrr...8...<..%g..#...-RE...W<x.SN..>:n.=A. ."F...W.%..Xr..O.=..Fg.....vv8.h.".ggS..2.........-;?......W%Q.0E....aL3.tc...j.3..?.UN...:{..vC.{!..1..n....g,/...sL.}L.... ......."%Xh.r>'{.......E..2l.tc.8..sK6.....;Ks.O..M3.DJ.H.....Z....9..rL. lv...q..D.%..q..S.3t6E...t@......b5..\]R..m=Q.B.....TR".6X...5xkPA..B.0DI.....-.V.yeXT.AS.7[..6N.8.1u...<()P....*..........R.s..d.[.X..uhm<@/.....c.'.V&.8%hvpFck.u..G....tAQd..H.v.1...X]RN.Y..Ls....E7..i.F{.w...P...u.............G....1..6...7.\e5..v$.$...9.%.S..st.....G...J.)..IQs.4.v#v.6.?..br...9.....g.....i...l..]. .....[A.}..6.eNVhn3K............gLG.\.-.s.F;`...^.&.z..9../(.F...>.[.3.e.3-,.v<.D.....=!.yI6...7.^L4B.v.!k....C..C.g.d1..4.m..~...X...d^Z&.e=......O....W.__p9.y53..Bv;......#....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):810
                                    Entropy (8bit):7.624675630247123
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ6pMo17C5y7fjS7XLkEH1iICVOcaUYCr1dZYIAf0:HaiM67Iy7rSjBrTcaUZrUf0
                                    MD5:7EF4A9E3931FE5E74093B5AD4FF425CD
                                    SHA1:B72FB0DA6EDC04ED7EC79328A6FF52A3CD36439C
                                    SHA-256:CAF33A8881B0BEC193AC1BFDDAAD20A459BA9BF03310A4FC4DC95E50B1662526
                                    SHA-512:53B9C5F73D6DD45EA95C0C6BCB6EC2FA28B0FDBAA5BB6A3729D98946FED88C62B83629288F0356BDC1841CE3390A78E06BA02900694AE6081B56D70C04AB8799
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..Ih.a..'..5.$3.$bPp9..I........E."....QA..PT.....q..V.....d]....R.6.Kk..&M......RL.<.1.6.7....FQ...hd.....W....s.D.s. ...$....S...G.G0.8.K..\............\..A.....f... .2.........F.._nwp.v,.10...=............E...~.....l?........HN..91+.A.x..%._.g.mp.\.....g....x4....y7cV.....E..8..A..+.......Y..ze.\..T....H_/...*..Y.k.H.~.m|:..IJ!.g....`..{7v....Y). .H..k@;...P..T.1.Z.....D0X.gJD..;...<s..e.-.._.w.A0..A|....L3..$...^9i..G.q.{.......q..%/FYH.$.g9.rL. ......+:LGM.Q...M.\.......[........D.^.v...6..V......j.;yC.G...1....H....a.]......1.lp*.p.d.b.n...V]........W.t...T5y]..~....TH..x.I....w)(./....M^....E.&..,b{~vr..)....p.......L..wPILr=..+%.%..Q.lk1...ct.....(....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):190
                                    Entropy (8bit):6.084337839265734
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwRshkxTDVQ4f6n3zfEQ4jmzAqsulk:6v/lhPZi+aWdKcRAU64SKazkq6xbp
                                    MD5:95A4E320D9D3D8286913EDFA013C86F1
                                    SHA1:6260D268ADE34FD4F6CAEEAB3280904C74059FC5
                                    SHA-256:1A356C588CE0A9F60DC1EA052CAFD7BC9A8EA86C2171AC752ED810B125957DEB
                                    SHA-512:46F822538DC6FA6328F36D0803BAC9DE9809044C5CDF3524A6900C3C909EAF64E4C124DBC72E02CD6F89C464261E7CFC11C184082871176C982C8A9716D8FB52
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....KIDATH.c`db..........'...6.6...ODc.E.-...B.......Q.F-..`.Q.F..C.F.Z.O.f...*...x$....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):766
                                    Entropy (8bit):7.559452069599041
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZog+eu6trniXFwLtOF2YU5alMITk3s0C5c6neKj9YcgnX1bR5RLFvyKkEk:Haffrni1I4DMITk3s0C1nJScgFRLxvyN
                                    MD5:65E5221042B3D6A197409FBEBD6FDBD7
                                    SHA1:EFCC5A3F89D3DB224EF86AC1F029877F4DFCBB2B
                                    SHA-256:FB7562D00A714EC795DEB429F585D9CC5531EDB351517316812162DEC3A27DF1
                                    SHA-512:A832437E018CD8755F2C2A413E1F64CCEA7776C13F2DA4CDF3F5C2E2A1046EFD4AF4F8ADA834F49B3DFF7B45DCE2AA7ADD0CC8CDF2135E7853E643DC238530B5
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.._H.Q.... .....}..4.F7.1.?ta.EeP..^.UQ...B..).AD]........@.A...f...DR..T;=g<.....Z.<..}..;.?.po..4.5V....@..\.@...W.....C...q..C....j.o....4E..@5..8BS........n.d,.F.o.).%....;. ..9.Lg...w.........D.c@..k.'.b.OC.*@?d...?.2.h8.Ls. ..44.....q...Y...g?+\......k.L*.1...v...V1V....n....26..m..Z...\~.....>._.o3.lY...:.........3u5.w..E?.=.b..c.G....+. .........?'a.[e.K..0J.N7s..@....:M..~..:s.L...6hi..y.&G5....%.^_.........~..i...8..np.2............:.I\z....-...wb......e.g8.L.&X....3.....`.1~.n.......3.z..Xlj...r{ ....F..>....:..i. o.g6nTh.Yk......K.,;.......3o'...&....J...q..W2WVq........G.-h....@...I.....}.2.J....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):203
                                    Entropy (8bit):6.132488327722438
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwCBxtlHFaOFowGsmTXXx/T30qbs8E:6v/lhPZi+aWdKc6hFzFo7DxT3RcSgVp
                                    MD5:129CCB5B1D1D906A66C7C0C4D35517BC
                                    SHA1:33F1CFCCC64217965726C9640BC5FAACA2D348AC
                                    SHA-256:8F31881D29D52A152B6EE3C0064A8C75230EA1876FA1EC9B985616368BBAFBD0
                                    SHA-512:F201A4C7D4B06674198DFDEB24DFBBC29F39EC2334B1C262BB8E441699BEAA49DA7F516F5D4D126F5CED9D9BCD51CBE8FDCD5F45ABFEB505469798E10BE1F937
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....XIDATH.c`...?.....wC.... ....a.:.......k$E..YDG..h4..T....@.Ql.........`....`p..=....m......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):535
                                    Entropy (8bit):7.395960654127153
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZxdvAtmfpvNuahkzDGgFrKMM0opm9tL:HaEmfjuahkzKgFlM0oGtL
                                    MD5:16149E4A047174835D6EF72F90E6F1F4
                                    SHA1:90908C54F4579BA54E0AA839690A4B69A1EA569E
                                    SHA-256:467EF6BDD23C2F8BD253468AEA3A711C2FC99B5DD4B4E48F5DC3C52F2201A01C
                                    SHA-512:3543EEA908DC3BBBD4D94D6F8607867D377D2E4FB6794427F1F9B7EAA6485A119C793200556107613CFB3C1CC5477DAD5A58A994075A4A7D7C410E508CEC97D5
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..V1K.@........M.."$C.7\\..T...J)...Apu.....D...B...V.5_.wI.f...#...}w..V...;...t.....tr.a.X..j..%I.*..9.~h..aa........(....9.J...|........>..H0.-..q.J....L...1..<O^.w...k.F.8..i....1.E....A..9..IQ.K|<&>..[..X].1V.!Q....(..f.!.v:.....y.0..&...v.XP....<.....]......)...b........x.N/-..'....)QS..D...KTK..mz.tv./5....A.}.W.-...&Z.H...d0...+.,F..8.s..vmY...m...5H.m..W.kabM.\8B..n4ARue..7$j.....'...^..!Q.`/.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1065
                                    Entropy (8bit):7.768185648410783
                                    Encrypted:false
                                    SSDEEP:24:HaTIObTYIO9jPpiEfYGMxIlnDIi4eYgQeAEhFBFtcOYGnE:6sBPRrMKlDIi4eN1Ljrc/GE
                                    MD5:049193D11682B9BCB4882E04BAD6F212
                                    SHA1:CD9F3607EAD93D5ACF81A6E23C0BBF437C530CC0
                                    SHA-256:C74503CB1AEEDA2220C8ACE2AC7C917E30E1AB1C1E981947794AD787ADD82772
                                    SHA-512:4F65F49EAA3F41493D54BE9C3D5B7F526651D253A014D314A507AD3E696B83AFA8540BB25CA589432DCE8CFFEDDCA82001365EF54ECB12D18A375094962B7223
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..mH.Q....S3_.l.\j......P...b."#(t.....iTT..F..0#...B...........4gc....|!.......$..v..}v..s./.......l.g...mjj.6./.6.h.m...u.j....DN....h..E......,.'.......r...N...KL.......A....&!..EE4........*.DGG.3.L.pn.MR.V...#...q.2.FFR..-.....L.O..G..sS.=...t]...uu./.vA#J...4.1.i.ng..|>_.1.....z.Z2.,.yma!.''.b.........V....7.mh.F......>;['d.....h8..X..,...+.P\......a..h4....N...q....G].*.9...n....~......j.2.(.......4..F... ..O.@..KX........!...?>N...k6._....D..<....;:&....7..m%.....b...E%%%$.JY F@.......x5Dx.4.......3.....o4..`zz...^ef.SS..0....r....lqp..fcb.|....V..+)).uZ..s?....7...@<...{...'.w.......O....._..dwg'96n..F...[.q..ms3..y`......H8q<%...#l...!zS\.s..m4.j.J...\0.G~l.....N'e..u.ju..-j...S,.P2.0...\.;..*..L1.....6lX.R.....\..I.Z=..9.".y.}..x...yy...._/).k`..XIx.:.....@.Q*#...}.p..S......;rs.x......GkkkY/....h.[........Aw.w.Y./#..x....t$....e2.U.\.......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1603
                                    Entropy (8bit):7.8374788195207925
                                    Encrypted:false
                                    SSDEEP:24:Hanmr6UUQKuz/1J5CSXQaaJg7Srd9cx6PTIzYvajb1WYsBiH9gJnlgrNc:6n2WvurT5CbJg76lIz1hsBixi
                                    MD5:7560F5AD9F56DAB28A0069979FA6A9F1
                                    SHA1:7B152D8DB21EF7ADCE36175DE6136F830EF4652D
                                    SHA-256:7B0E09520B108A41DBFB762A89E1B6E9C1614C3A33D9FFBADD9FD099FE4B8AE6
                                    SHA-512:DB4029E07C4694FEE6BEC99E2672288F5D532281ACF05230E9DF95D6F988FFA2C4561D5F5741004FB640E412E40C3030584907114E74391DCCDC67D4AD613A32
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..yL.W...3.;..^,...(P.D.@Q.........U..1ib..l.x.......I56..6...bS(..R.@@Q...PaQ...{.f9.B../..M.N...~......).).$.....4.fQ..5Z.^.l..2.RyT..."C;...d..SR...sWK.....7..;e"..I.4.)M.V/A..,.Z...f6[...."-#S.....aS..p.9..^..G..fd-V....Z[..E.......F#.5=FJN.......1q......L....L#c....P.SQ....../6...9..3.@`.+sj4..~....C.8.1..'..]=....W.L.!zh,..{.m..v.c..H.k:`6G....t.L*s.!_.4b#a...]..3h.{f.@|..r.qD.E.....I..d...*.g%......TJ..FSI.........#5.(h...S[.<..@Wm...DuP$.#.C.............\...q.Qr.._9..?........m.....t.....6....1 .C..B.#.<.y|..:..<...o0?..V[H.......W.:.I.z......).M.Q..1....$|@._.(t.+....Y...T...R......+E../..FO...N..7.@"..71..U......*.0.... .8v......&.|.D.@{o....gK.v..s.*.mkclu.v..A..U500..7.....DQ.....%.m.....,.f..!!.W..i....9CD.A`(.h.#...Y.V.f.}..q..b...(.OJ...,..v..__S..E#.9..E...pr.. ..2mX.eI..BI@....k...f..t..I..%..<...a..B.....M....)..4R=..A x...p...OY
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1172
                                    Entropy (8bit):7.759849502368421
                                    Encrypted:false
                                    SSDEEP:24:HasxqeyakJTQ4z4HvEEgNzUWnaZL88SYt2Ro8vCSjf3HU2j6VqGqwnDHT:6sxREmpgxU568SYt2pv30YFGqwDHT
                                    MD5:3409761C84ED977BAA6BEEB20B5F585E
                                    SHA1:16ACC8A18196DBDBDFBE54C387FBA77CA11D2F26
                                    SHA-256:778B48EBEAD8CCC45F3B5ACE0D1F8787483A7945C6B3036E6D3039912BA0FD9E
                                    SHA-512:51F4F68F881D593252F3786091864C84F9F0F1CC3E991A0F442012BA93D734D90DCC80244A82129ADDED38DCB1D1469DBFA0547FBD3D51B94FCDD8BBB4DD2374
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....!IDATH..Ol.d...'-l.6Z"4.$.j...+E*-;..[....\...... ..&@.S.q...!.....':q....l...m.m..Kb;q..;)...O.d..Ez.:R.{........Z....^|8N.H.sjul..HI6RE"...yT..._......rOOL9..N.(.......).j.]_<=...Q.....w.....nd|...Y.k.Y.@......Hdr..2..k@..].K...%..Q...m|..dSS.......E.`+...~D......Nme...Q.O..F.b.!X]....)8..Z.*...S.A...o.j.....g.|.9g..Z.....Ck.2.....$.b..E&(.p!.&.z...746.%.8..H..0.-...w..J^............+G.0}..SC}.z......>1.."I.J.....d.PJ..x,&...y.vL]rLs....S]V..{.;..X...tQ)...0.]H......X<...1\...........<Q..Uo.<..0....6..a..`.hd~'..-.`..E....b......NO.U...........,.XO.. s..n...>Z...(..,0Y5t.>.._GgG...7..|hP....0..........F.o...O.4.D._..z..k....'.'p"2."lY`2.,...sN...8&.9?..-O2.........4P.pv.d>..>]...?...|r_3,"..SQP.V..r.\.*..;.....c..X.b]........F.25.(.\`...h".fg....O.......0w.!.B.k65.e.F...?[..W!.u.k.J..R..nF#rX4.....Bt0^..._apt...k.."g.....7..............]..9..z.ob(%. ..]G&
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1145
                                    Entropy (8bit):7.791035376643333
                                    Encrypted:false
                                    SSDEEP:24:HaxSAAS6+xnFi/WpCsW6SanVgXYOY3GHXbc/MrZ9:6xSe6+zi0W6S8VgIO4Mj
                                    MD5:E662D82DD26AAA00CAB3D4F7AE5208F6
                                    SHA1:6C6CEA9F1C501676F59E7D3CECC68B1195145255
                                    SHA-256:D9F1B9C4B76E96097C7DF727279ECCCF336A5F256B12A11504EBA21538651AF4
                                    SHA-512:C5DEEDAF9D8211A3CFFA3D96F383F6E53787F370C2EDABC19CCC5C00074B9918D87A4B3C49A124F56936F002C9495EB5CCD538F224DAEC276EBEF8565A5FD27B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.Vmh[U.~...I..%I...\....6['..@....aQ...CA.!."...V.....C...S.v.K1esS.X.Y:.6]]u.i.....k.fY....p.9..<.}...X..).....j'`e...om$.c....NvC-Ol...e`...s.M.A..$In.i:.......fRJ..h...,........qI....w..1k.X."[.....S..-.A...*.....V.P.F.c......*.50.H..?.8....+.%-.!cB...JkZ.B...d.6B...@.G...Y3...FbZ..^yY...'...1..<\r.......L..}....%..5.X...M../..<..9.8..a..'..|{..G./N...<...y..w=.)$...'..i.4_}k.Uo......E.S....@...9....H..^7.L].C...`.9....s.{.z-rK.au....E....QY6.J...3....{...S..8...._q...?.h..D...F.&.....l"M...dY..X....._._.&....f.u..M.S.Z...Y....R.Y'...]..;.....H...._....!."7.U..h...x."....8GB2.[.]$.>0IN...g.Mj.4...6.o.$.-*v..>..1U...aY.S.Wo.`C...U..|.D.y...a[to.:./..@ht$.].j.p.._.l......S...O.y..N..#}........-*zU...<%.[.'gw<.1.=..N....bX...../....:...d.3{.k*.;...'4<..8..2...U....h.... ...w.*b[h..].....'...WJ....2t. ..Mc...c..7I.....}...}....Mf."..4...Oz~.^
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1146
                                    Entropy (8bit):7.786476294904737
                                    Encrypted:false
                                    SSDEEP:24:HahONJzBpQKhXBe1Opt5OdRTlxQFU19tIQf5cEz6n8O7HsZfUR2J:6hONVJhXBe1OpzOnlxQubqQf5cEz/OdI
                                    MD5:3E78D4E415FF7A9F0AF99EED77C886D3
                                    SHA1:7C6538ED3906C20C35944AEF525F3A737A97990F
                                    SHA-256:3397B359E80B5B0B8ABC32F597747E396285B85248A47E7DAB205546DCF8AF63
                                    SHA-512:3A6F2C5D0B44F1A1BDA60B0106B59536AFD653605E65374FC35F82A9BC59B3C198F1E78D59528A455C741A450152AAA537CD4DF1137A7D9AD3B16FC84E52D4B9
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kL.U..[.-...\[...e.e.,~.h.u.OK...-q.Q.....L..b........3......na.c.]+...Ba@e@y..<>..Y.F.*o.KOO....s..D...."G...d......#-g._.q!...F.P*..,...8~..0OV.I....).a.1.vl.........Fl.|..~g.t....\5RD......s(......3..U..W6..qd=.._v..8$)|....Z..\..j.n.....n.Xd....yO..X.;W%#....5.....-2v.....8..]...A..4z.tc.$..\.i.W...]GC.......FB..l.>.b C........2`2l...m#.{vo...3.q\..6u^..z....;.|...=......'j.8#......J .U1q...........3.......z]Fh.[s..m..$.}.)@Sp.F.|.eB|*......H.....P.3...K.\...o..~g.<.....\.x.S..uE.\........r.Y.$...P#o...!..%!..8O....t.U..t!l.....i......_.....L.>....`k:..%..Ov...Z...\J..$...9..e....R.r...W<).2l\...;Fl..A...1.X#L.'.[r&M7Z..[8..].M.Ha...\..."..T.rz.1&.....\x.^...&.........0.k^g...M.,.7.2.^..t.B.*..6...F;4... cZ.[.....1/..+..j.T.?4.....O..L..[R.......9..n.a....8S);.Zx.R...7...CSM24...ok..\D.@.@.o./.....lI..y.#...#..X..f#.......R.T..s...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):729
                                    Entropy (8bit):7.6074646615829895
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZXu23k9jSQQZZnahvkIil5AsHLQqYiBNvbvniGCjvKMNqRc:HaVk9jm7wkNtM1inbvn9CjvKrc
                                    MD5:EE92DF969C9E766AE6B7095CF45016E6
                                    SHA1:4A0EA1E27D423F0944E0544BFAFAF1C58223FF36
                                    SHA-256:75DD178B98DFF7A3410DD33653A7D7F50EDE2AA0A8D818C9B7FF1E6862532880
                                    SHA-512:309B3D836776BEC778D5B8183AE4AF4292BD6F34B39B28493D2860EF21C48333CC7BD91C63CF0E072E6CE1FE3AA06A943B247A82DE7E87951C03AD886ECA7082
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH..Mh.Q..7j..V..n.C(..A..A.. .B.P.... ^.oJ...x.<x.bE.C...B..c........~E.;.6%..i'....M)}.c73....{...=|`......W.A......ka.~..T.=.]...<.../.V(. .(..w...va#t..-(A..n.&p..'......*...3+p..(iC..a.V.*`2b..}....A...ZA.A.V.E......C.{l.mU..+...A.r..e.h4........4|.....)......a....0..X..y..7.. Ej....S|.8..(......64.!..........$..9N...>.k....|.y_..J.fm..a...CS.f..Ip35.$....o;1.h..<...C.......x.8.....A5..G..=...[...^Wr9 C.Y...Q1r6....5i....i..=..x.3..a..*..D.^?|.Z....>Y1..0.*L .....9l......oc.-.;..4....:.J..<.i+...r.(j=WI-.O....."d...U..|.....\g5{...Y.6..fM2....l....._...$O....u.>..g.d`I../j...I.%.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):657
                                    Entropy (8bit):7.3841004819796785
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZmosqrw3azT35SBMfWNeoe1s3n2EbYZWZca65WAV3K1SbET6:HaRUIT3gB4WNiwn2/adOK56
                                    MD5:3839890848A28DE380925E6117CF6FB3
                                    SHA1:4A8C8A8BF05F0A31F081EB06985A35F0596DE671
                                    SHA-256:569F9EEBC1EA3954DAAC7538BFAE25F4F72A9E08570A315F5A35C8BA787BF62D
                                    SHA-512:E75319508C5A753C47DD6E470B199F2935E3178F9722D90C51D9C40AEA319E4AA4290A4592C70E4C8C7F423D3E69864B6BD3F48AE360E04C3B8C953F16BE870A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..;...UT..iG...P_6........?..#P.c ..Tt...IIq..}....%.\..U..@.p8..(.~]CC.&..1L/......TU..,....pH+T.i$..d..45%14.m..*......16f.....tOQQ..w:.^..\.Y0..h..]X.8!....P..A.....a....A.w...... .......w..bs {.8U......M55i....u......lw(}|.........z..A...;(.af1...]+.u.K.&..k../H.r.h134Y...&.....22.@./.?....%y........i.......H..b-...P.FB.....1.....}P.. ..u,j.@.,..mh. ...zE.Y...$.@q.%.@..@}...[....c.t7..yA..UT.......~B.rr....H..7..X...0bt....2.6.....-....@.....l>..7`.S.dAc}=... ...C.. ..a...4.....4..X=......4.1..K..<...-...3N.5o%H....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):611
                                    Entropy (8bit):7.4810435786950755
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZS7OvVSDolpVJKP/AUCufiWxhcT07r7IuwI3EZPLmDZG9EAlr422/N:HaM7OtSDOtUCuf1F7r7If6EviYEJ1
                                    MD5:446A65D381142D651DE4D85B98962228
                                    SHA1:9431379015F8E4D25B34431559D031138459FFA0
                                    SHA-256:8901F209566425BC26486B34A71BAC3A6DE7F5FE2551350A8926F3009CA18D4A
                                    SHA-512:C90DE1A23E28A7B23A57BB09F1D447529A1C4DCB162300F9FF71A6C4EEB2BB611786CFB7410589D000C6F45D9A8E74D2791B8F2C4C209C7F0C4B45B2F2473C4A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..T=O.A..X..v&.X....1.....Z.hb.....?..#PQ..J....h..&.Y.u.w....B.z....}3;..8...}..6.[6q...*x...DbS8.U......;..*G{)..Jv.*.Q.o...E..S.D...6.j..R..a$...z_....39(.A....^.x.n.`..'B....l....=.J.ym..hv.].u.#.pdg..27..dXtL.Z....=..x......F|h....B.E.p....-.m..E`m.P..v....59m.i.3AiEz9.u.+.:*..........oi..)...7...tNC/.Z.-..Ki..E.......(.g.Pb.L..u.P..S,...o...u....3.s.L.I...90.P..r...>.....y.Xu...........|...6..1.4......G.G...XuhsK%..:....Z..H......8.gq.........4..P...C.M:.,.y...>...F.T.k.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):300
                                    Entropy (8bit):6.84897701377742
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcjAspigL9DyOwMrt1XvS2BFp:6v/7saZbigL9mOwMrt1XvnN
                                    MD5:8D3BC3537980CA5185E0D68D64928E98
                                    SHA1:F43275DC6C7BB095B9FBA2778C811B57CE770978
                                    SHA-256:54D4423340634D65355A24450AD7A19E30986FF78B573F06F19F2BDCDB19AB07
                                    SHA-512:F763C222CCA9459B55B0C22623F5EEE4B158389B7F09802A22886B26FCB31B3EAE8EF82F6D39F32DCE4FBC39E2633A3CACA5B2D92E8CCEEA29035F8E2794A13F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH....0...Qh`....... ......Cr.].....$K."......&.@.Z{....V..8.......d.......=o..=m^.!.,C.$XG..m..@./K..@...w'../.4..p.Ui..[DQ(.nYt...;.]..O.g..OpE........\..z.Sx.....j...3..Q..v.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):321
                                    Entropy (8bit):6.8471270857138125
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1QeDn0HgLpmqvRXZcl2IQDREfpiPJZTp:6v/7saZK80HWpRRX62IcEfpS
                                    MD5:42D102E2CFF494EB1AD7577BC251069C
                                    SHA1:CDC8B8F5E65833EB29A5B09D150D2E8047861C70
                                    SHA-256:7FA8044E5EC834405079D11D691B21872106C818A2A7168374CE7B1362FB2807
                                    SHA-512:FB67B5CB9F24A097BE0FBB398CF400610EE17C4177800D4DCC57C3A1B803AD6DDFCF9F498E3A65B77AE15261488F8947E49A58A603ACB36C7E1C81E92C526D15
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.....0.E?t.L..@O....0C.0...)J...7X.!R.o;EJI.LY.....).....8....=.F.....L8..&.j...lB...2.>^....`..."..<.aA......2..U... M....B=..]n......z.zA3Y.7......M....2....{3.........NS..z.z^L}p......d7`.o.......d.]....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):676
                                    Entropy (8bit):7.465661084230229
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZFUUHQGg1dXDBnfQjf7RZukye9okjTXrbtnnE6IDlPCItVAbh1BcHpgXc:NKavUPjdXV26kPokj7tnE6kl6qAbmgHM
                                    MD5:9110D5D31B11E86091029E3121532EE7
                                    SHA1:A4B0AABFBCCDAA7BF3FFFE045F75B57C3EF0BEB8
                                    SHA-256:85646D81C6D18B8B200D29F851FF5A42723E6E742FB02BF55A35D8CB28D00D49
                                    SHA-512:27A79395BD62293FE8C29988A010E64C8AB0CE35FC4DE76FB188920AE929A3EE5759AA3C1FCD76713C1F182F029D22CC1EF405BF5522B546CF28E8DECB983B83
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....1IDAT8.U1..P...6*...Z. .V..+.i..A{..k..U.b.w....KK..ll,.]..7..,)..Z.......M`..0o.7......:.%.....A......r..OD.#'.$. A.n1.T.....8....WDp..Yn...G.f..(j.3......t35.o3...*.........G.Wt<....v;.....&.f.A..|~..!.|>#.p8(..,..N.#.&.....1.(*...}.U*.r."-N..5bf.....r.A.LFI..`..f..(v>.G.M..oW#..h..R..x.P(. ....p...r.D.^.#.d.>.v..j.:..b....y.V.U.j..h40b2..#'..j......88...T*.ix: *.......r.9.s:.._,.....ba0.4...h.H...J..G.Qx...b.V.t:..^...jz...... .......n...m.... .......)...B....4....C.0..v...)........db.Z1..L.D>./.H@........~?t.......p8....r..l..v./.R_.;.....>.vN....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1239
                                    Entropy (8bit):7.791857072030138
                                    Encrypted:false
                                    SSDEEP:24:HaSf2A5cmSStzzvHYCejTdxf61d6nzTkPeB0LlAr546di3m6:6SPQSt//Y/TXy1wzuy546Q3N
                                    MD5:9DD2B2C779C67620E09F358C9013469F
                                    SHA1:4A8AE8D6A857D6EA61DC03A464A303BFD1ED7B7B
                                    SHA-256:CD1E9036A086270948F9D3F9081F40FB887327DCEE78811C4323C47AB5636E47
                                    SHA-512:CF964CD583CEB87DC74EB1B94CE4DE837898454FCA5C0725A229A2A947E44DFEA089814AF16171F045719FB80F8FF0AE44ED56D23D2886FD35628D8FE4621FB9
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....dIDATH..klSe......a..vcc.v.....j.Q...t.*......11&...cP"!....jH.8.>..).....}..^..6.zY.9...................-f..:.MG...$.C.P..8.Y3...SArk=..`^...>L.J$...w..r.F.X..id..9...C<.4o...*$o%..'B@]...hW.....u........,c.U....]ql. .h....mh...\^.TZ..W.\U.6[n.r....C._....M.Vo.w....f.n.2...8:b..!,......T|..9..8&7Y..P...j..7.....K..R..G.xNr!i......#.Cd..HE...f..d@4Bf..TV%1....l...v...$(....7A..T..v.1..e.g0..N...B...<..4.*...(Z.....w...j#..AWO.....=.....qb.{\....Ea.....T........tV8).ao.z...gv....!.u.(=..;_ngT.8..>F.D_$.xD8....E.KJIb.P...IX.4.fG.8j.....-.Z...q....&..h.U..Xdj.z..r.Q8-....%#T...>..dV.._..G.V......b5.;+o..Y.S.=g.@4L...(.C..H.$...q+)$..v...;..3,f.j.B.nW...CA........p......x.4.=.....Ql.....Q|\.5..CW9.@...#...3Y.=.['..h..,.G+^LK.......yf.z...{`....S..np:...D...._ci.Y...3..Y.#....E>....#,..OL.....$..r..p..<G.1..~.......\..*\.(q..UX...2.e~.........n\.]...~d
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):450
                                    Entropy (8bit):7.086382681459327
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcUiFyieEOjyFwcSkjjKUIHP4CgrxdHlvYrEqxOpsNC5vj5cxvM/:6v/7saZUiZOjewcSF7eHlgrF2sc59qq
                                    MD5:626A62A06E8C84FB936F6FCCD0869041
                                    SHA1:56CF9A1717E96BB7B13B40F1D6F7B89F61FFF124
                                    SHA-256:CA2AE75215EC1F095A89A7EF480E43E3742979745CBD80C703FF0A884F6EC98E
                                    SHA-512:46AF61687CA4A1B579842403EC07AACACF490BAAB2B2606C567DF2E404103AA82DB81BE7956F1288D5719C85BCF075FA531CEACE8300B9B0401ED636A30CDFA8
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....OIDATH.c` .X.....1P.....$.....ex...)P..... ...|.....O....3#.;../ .....x7....4.....\.....EHq...0...@|..9p......A3.......&..u."4.L@........b....G...TAm.D....b.J#...?..<$.-@...W..z..7..F.. n....**.i..g...,..Z....82.'..`h..*..........;./..@\H.'.$..U.R`&._.....$....(....b.&r...X)E..P...r(.A.9..A..@...)q>._.V`..x!.-...}@....C............IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):733
                                    Entropy (8bit):7.456549392815813
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZZkEWt+itIBlmYb15aU+kJVRg8iYuhZvCbbpVYNC3ZGT9GomlpYAz:Ha4Ew+WIB3CvkfRg8RuhZv3NUMT9Gokz
                                    MD5:F5C451948DF5F40E9A1E74FA9FC920E0
                                    SHA1:C5AAD00CDD801CD135794DC071CF4D8C98E7CBCD
                                    SHA-256:ABC7842FFAB37A074EAE9C71292E0DABA4CDEFC3027F3463BDBB5B814091FCFF
                                    SHA-512:15AD40EBF32CB3CB43741DACF78B24BFACAEBC0B78370DEE55F3BE8F970B08EACB6981CCA3817A92AD7EE060BBC61299E71B1B136D4D2F1511F992E9DC1918A0
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....jIDATH.c`..`.bF0.J.......o...;.q...C.'/...^..l..o...~A.-h...$Xb........*...../.5..[..._........ KPt....mg..Y...+;.....W]l...l.......<..?...?.?.y.. ..(+..-.".R.n._.....p....]S..............+(..0....Kl...p..Yf."...'8u...Zt..l8.8.....jx....%...k...E<^.A...-U.nb...A...h._R..=4u.. ...#.,......'.....?.I.0....dZ..@..."......y..@../X...,.5......w..<......6..>.[ I%.4b..H-`.....E..@.... ...........X. .-..{u.8....a...V..L..F_.=X..y{..I.9...bK......*.K...Z..[@iw..@Ek.....'........1a.,.=p..............[\...u._....T...h.......q.. .z...?...[....P...6b.%T.>..Eh.6 ...g.U. K@>.....H.F..I.."..`|FR. ...X.~.a.Q....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):642
                                    Entropy (8bit):7.341688074420382
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZp5AMieRoKdKnv0hPro7NVLIpCpsWksLss2k44hUH0hCZEP:Ha35iUuakBVL+YsWkHk44heEoi
                                    MD5:619371FA5791AFD73C6F551CAC8283F3
                                    SHA1:A03F3CBA0392B61AF93C90160312CB71D3A55AD2
                                    SHA-256:3EDF4E0C4FA01F7867B1CE37BC800094364B376BCBAEC46D5DE401448D6CCDAC
                                    SHA-512:86B33F6A4644E5E52E4AAE4261344ABCE70EC5BB79AA83D70389852C31F6682549106142D9049309E59BCEF88EEF1CEF55A975F1599545BFCCE1FE5F732BC880
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.L........RSs.a.YpSMM..if..e.....yVD.c.bsR.wedd..%.W.0.0+T.#...d.d.i...LD.".......2.3..7..9.........YX.......a.......`,%%._NN........JJJ..u..M.T._\R...H..311er.|......K..k6y..}.....E..*...r..MW'._{....s...........1....[.o.6.....\.l_.X..Q.gac...b...P...........b.......[........a...G..>...}....IGR......s..5..?. .W.v.Rd..8.X.6........6...k..Wmq._.. ..\.....&...F.9xX..-(F.%.Vv...e:...B,.YD.........j.c.`..4.gd.r2...Q..MEDa&f...a.?Az.|]B.U.....T31..+H-;..y -FlFc..EX,X..X,X....fF.W8.....iY\..0.*.UUo........#.*Cw,....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):619
                                    Entropy (8bit):7.376649917179011
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZtFfo73Shm+OIlZ3EGgweW89YaMFWjCCt6S+9P0I0b/sF/WL:Hahfo73ShAID3EGeya0kSTB0IeA/WL
                                    MD5:B0C092A6869976A6147F2AA15FC599B4
                                    SHA1:98043849EB34E44286E0BF55B319FEE950FBB954
                                    SHA-256:4BB6A2754559F012447A689DDAF91D9CDDC5CCCC679101D6663D78089C275E72
                                    SHA-512:C2B95EBED1782B87DA6A697458A555E9BE99151EC336ED1BB290486BB264C70CD48B7B718A04BB7699A7793DE26BEF13AA3D52857DBB66F245C2ADE9974F0678
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.L.........V.{q.|..b....Am.X9.?....?yg..N>......2\....Y......o..'.......<,_...B)5.....bx..mWg.o....f.+..M..........\...x......-^..../_...r....8##.7 mE.7....O<...oo....n.k...,........B..%g......_........_~......[....e.../=W..q.7...VQ9....\n..I.QV........h......T..i....>PB`..........3.h.............`...n.! ((......O...D.......}....n?.[...U...O;...i./.-.......'.J._..j....II............)'...PydIva./.s).....;K.w..._...\.%M0........./.l.5..._.....$sXq.F..........[....W81..23.d.O...4=".......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):710
                                    Entropy (8bit):7.545466302392075
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZdb9L6TsbsER0jpA0j902vsvY7J++9qfFcrinPL7ECr/XdIPLdJT4GKN+z:Ha7bJ6TQhRqpN02v+CqXECcL/KI
                                    MD5:C6CC59A8EF2467937B0114EA55169E23
                                    SHA1:EDF4A73A805440E7CF507EA4C88571D38C8A1558
                                    SHA-256:14AF05E8ED91A7B4711A008B10EAF8EAC01A225E7D05E01BBFB92DBE97197B30
                                    SHA-512:47375EDD11A410203CEB8394F7298F7EE4CF64BE8C9531B13ABF6C260E38B15163CF614023D9E569D1D522A40EAC283D62D9328BC58AE0C4B08360946E1C37A3
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....SIDATH.c`....H..b>.....V.^.?'/.S ....[302...V..f!..._B-.Y....g9'../_..?y...^..;Py. f%..f1........D9..........p.=0.X.s.`fa<.+.~.........j.O.5._...l8.Wmq....;_..4(.r......X...^......R..b0:.Y.%....>...}JF...Y...../.....9'..5..=.4..r0..e. ..K...._b.?s....N....\.....eAH.>(..".....H.f.- ....ek..2..}..A.t2013-..g;....RH.....Ym.. ..lw%.@d.......@..A.,.Y "..B@......m.?.`..F..K.,@."aX..q.vJT.H.D.Q!4.p.. n.R........,..1..@Wq..cM\$W.#y..d.h .....<8.. ).f.O. ...h2....h.....(*.1..lhQ.N.....E.).Xr.C/.8x.../..Ff..|"...-.`.5...v..<..?...m........Q.....bZT...$.......~...4.Z...H...............IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):734
                                    Entropy (8bit):7.4827952110986455
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZNWACAKm/wJxEpNGQfN52iJOLGAfrTKLXJAsarm7GhWlYZF/aBif2SWJir:HaQEJHHD2iUVDKXx7GhWlYZWiuWr
                                    MD5:3DB9E120D3C9888216166548D55C208C
                                    SHA1:C3CDAE75FFE01A3512D8F916B4F88AA5DC43A082
                                    SHA-256:06C3F27AFA7BF8DE5F2D62E3FD29A5796FD378CC3FF40D4066325B4AF7E6A8EB
                                    SHA-512:1A33F8B5D6FA88CFCF9BE25206844D040F28827C4542DA49D68EA43DEC559438476E8D007E33228A0A6371732D561E2B414FB28E5A0BA84B6BE8009C83995C49
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....kIDATH.c`fa.......j6....>..C-.XPXP.....`......8//.....[....A..l.H...q.ow6#..n..+!...E..`Aj...**.o..@,..~[W.,v+)...L......b...."m.[_....v..b...8.Y...1..uu..S..P..\..ZZ.ou4Q...0..0..-.YBQ...L..h...V_....81...%..\..o~......Vv..[...d..$3..|..*.- ..........x..&9..X@...O.....`.E...+.|...&]\..d.6.<........:x......'U.}.-8p........^{..........n.'.... _....xA.x...Y.9.o........@C[.QC..e.b.v...@~{D.8....>CR........`..:....q|z....qV. ... ......V.......W.... !.f/.r........l`6..`..c..z."........fdd.........V....!..>@X.QX...ykv.....k.HH....G...9..b...X}.......3..........7.....M.. .z....../"&....`.....Z.....>.......lR.^.5......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):698
                                    Entropy (8bit):7.518126295736683
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZd2dC4t4nyJ689VSwgT0w6sKj18zdZuYjCmu1glZzS7WItrOEp/pCRIvDV:Haf2A4inW94wFw6sKj2zpzS7WIZOEpxt
                                    MD5:40F667F7B35CCEFD634C3E0153161E23
                                    SHA1:9EE4D3791AB5821D8D88EDC9AF4A8FC3A6FAD6B4
                                    SHA-256:92194B6A74270A2AB89B27C4E49AF9266E3CBAB1AE97A4446ED62575A0F5A8C9
                                    SHA-512:5D7706958A75D44744DDD1347C9C1805DE15C57A116DDC7CE243764036F94A09D9DBA3A6226C08DF8A4627C0D1D59E2B6E1D9E3241DD93507EB60BB52FFB6879
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....GIDATH.c`..`fcZ...z...c..X..*._P.....@m..,D..M...j&.....,.Ls.8.......T...p..S.....q?P....y...$..v.-.7.3..'.../Y....l....)..A.e...............i; N..).?.6R...vW......?b-.U0..'...E.P.?'/.I>..k.k.q....=...%8..2...;y..?...j....E..]R........311-G7...3.A0.H7..".W.....4....... ..t....E9.Z...T..../.?..d.+7.....~..?,.........D..Y.(...0.z.+AK"...CC./`.b.n..w.S-..2._..(C.%dA.L...|...T./....h.q>Q..@~.0%.+^....D......\..x...x.db.....+.....O./Pe,.9.....;'....Ob..$iN4.o...t9.;.S...$...q.......[.\......M...G..n@...~1._@...+.`...$..E.] W...e....S.C.....wC.A4..P....dL.8....p.h...##]f;fw.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):398
                                    Entropy (8bit):7.029883007598753
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcJmNmWnKItdok+1KByv1EkibfnaGkWv14FZDUJOicp:6v/7saZ4Nmkogyv1Ekib9kk1UD7iO
                                    MD5:EB772D82CE1BA7AAD6D67A62D7883681
                                    SHA1:319BD07610C4B2E7643C8EE00F6154F76FF08433
                                    SHA-256:B714CFA1940D423CFBF61700CB440CEC3995FA97FF652BCDA7845EFFB94A93E1
                                    SHA-512:5155A677B5FC067E6A66B43D18DDE1348EC7C7EAD7FD73AC2EABDDB0C086BAAB566B5678471071ED4F59A2FA02FA26E785DF52C2DED63893C08394E0FDC454AA
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.....0..#..+.,.......3.,.........5\..m(w.....k.Z`.m..0j$.._`........?9.#.!.Y.?^B. ~.@..PU"....|.Q......].s4\"."...S.m}...s...:W.y..;.........nS>.h....S....$..zE;./.Ig...h.@....y.45:.s..{..B.{..S..`..e9?..~.i.......$.)Z"<].s..8...".%#.h|..../p."...\....X.....kE...../.w.k...[....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):829
                                    Entropy (8bit):7.632884519003374
                                    Encrypted:false
                                    SSDEEP:24:taR+f+NQzi51Chwe39FhvY3DcWWsY/tUnSxGGNYTqlz:wR+f+yz7wSnhwI+Sz
                                    MD5:4BC18ECA2E9BDBEE05261132C2CDB835
                                    SHA1:6CF8D44DD883763B6C7206F95484649FB2D512C7
                                    SHA-256:CEBD547D1FBC6610732A168612A2B30EB14B724F5CB99EAF26DEFA09327C729A
                                    SHA-512:B290CB4EF896D69AC3A866BE03CAA3F7EE7898FFF8A48903E3AD1CD495FABCDDE98697B6F567A44B534B1B5CC5A860CFBA14FDE0DD0A17BF66DD4980E2080927
                                    Malicious:false
                                    Preview:.PNG........IHDR................a....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.uS.k.@.~I&.&..n.............y..._..G.......<....".....E.'.z+.Em...l..$3.d.7)[..G&o..}.{......G.4..0.x,..q..........?.^O.z..i...BNJ! ..h.A......1M..|..2......{N<s..O..k.'.up.U ...RHO.....K.t.../}....l......~...;..:0..N....U....i.`V.YiZ....w.,=yp.r.K.V..k...Y.1....A..0....i@l{.......a.@t.,........i..(..........Z..%g{.g./..Y..1`q... .i.C....G.!K)p.g..!.B...`.r.Q......rL.#T....D.}H."`.!d*...$...9..#.t#...py.BdY.IYV.....@..R..h..."*....A.Gba.0.../.@P0l[..*...".d.t.[.1....'..m...u.2...4K..P...EZ..."........@...#Z_._...<.Q...2...b.U9...b.2x3....Z.Ir...N...=.se.1El....x^.P.).)j...HWJM..1{....._.=...8.nnkR`.Uk.}...5.R..<N....-.3..r.Q.vm.4.s..:...Y.]....q.#...#zA.pT...~..2..........q..2>L.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):615
                                    Entropy (8bit):7.402133733424993
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZXaQ2wnzyklOWRG1joXT7W9VbC7M7mQlJLIpn5NMCcTD:HawLwneuOn1uWruo7LLYdcTD
                                    MD5:9E4B760FAA85346B6DA85F8998C25C61
                                    SHA1:7FF7DC78DFEA140ADB6485D91F53AFB6FD54CF29
                                    SHA-256:DD74EE139078FD3A9773881E7D724FEB19B30EA1B8AF179E15ADC76B3F27CB86
                                    SHA-512:2CCB78371580F3758776CAF8A1AE09267BECF3E527CE8918B0A2AFE0D035DAF9F03A0ED29E70FF7EE0525957BA81FEA6B6A75FEC15D12FA1FA65FEC2467DF7EF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`db.......j6...i.i.....u........4..o.~..K.}f...6...........\......O...(g......m[.B,.u......SW<._.....MO..,~@...So...._-...NB/A..=........t",.O.._.#.d...y.........../e.I..KN.....!v.\&_./c.M...N...1...........c...z+........dI...X-.p....5.1-P...j.I.....o`...`..y...^aZ n......8.y(0.`.`..w...j.b..u....x.....>R....8,...[..c.....N.Bp..*lA..=.M..c...;8#y..W..b.....pP....w2..LA.....]F...khWT ....+. .....d.....W\.M.....3.ZP........2..q..........[... l...\t..(..t.F(y.P..u....`[.g.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):613
                                    Entropy (8bit):7.429512649476687
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZQAbB7f2Fa/Ye0MFrEgGxHLCVvqfCzaZSctfYqeRXYUPIizlz:Haq2B7f6ErEgGB4s2dRXz5
                                    MD5:2CF489DD7D0B7213732A72A0D11F8C7F
                                    SHA1:70AB89C395AE94C74C869389C412A65BC35ED7C3
                                    SHA-256:045EB4C4EE8FDD6688BE60BDA92E5577990E131E9795A4E76AF5C909155F1A6E
                                    SHA-512:41FDC8C3AAD2DCB9202CB6B7ABB87B21FC3603367B4C373159D29F5073AFC8E143766E1B4BB4715B7C37C903995A31E07257F9121A79206B781FE21309646073
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`db.......j6...i.i.....e.......+y...0../.a.. 6H.8.1X.Y...../m.._.../...1+]C...So..K.._.&.$..:....a..r..W..".....o.u..j!..a...-p.r.A..:...a...`.0,..8...yX.I.R..q...`..y.i.r....j1,.m...b.......u.......$.M..,......m9...'\..'\...... ...T....>...g.....*.|..C. l.....11>K|f...'l.=L........!.N\...tL.=g......V=Q@K0,..w.....Xq.G.C...3n.1H-H.....X|.>.....O..m{F.....;.."f...{_P....._.........daP......Z....%...+.A.6...'}....O.....{.......*....yk...|...U....~.#... .\..H..u2U*}Z7[...[._;.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):594
                                    Entropy (8bit):7.382412668392323
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZUudAwhObscBhxH6STldk2u3+a+yVaGsfTJmA4wnn28kXb91:HahdThObscBTxkjnbAFfTUA4qbkXbb
                                    MD5:3274DAF104B51719D762312A2DA79A70
                                    SHA1:F4C6A2F0E6ED2D91DF4AC8DB0BD722E2D41A5B72
                                    SHA-256:35DF664A90B9E28A0B37C17B7D34EB2E41E0B29EC42EBA4910EB6DAC2FA2CA4E
                                    SHA-512:B22420283F5E6A3E5D074CB18DEFF89E5F5D62510954B60292A89827FB2751B51EA266DB563BA8F4005C54558853DD8E0BF36A681B1CD8AA317177325920C7E2
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```.OcL?.p.q.....l.X..~&...9....?#B.(e..l8..@....`zT.....s.=./....#1.?....2o9YX^....b..'+.d]......}...K.=o..%..NV....._...'..$|iwZ(?^...c....2....>.....Pzt.9...$_...8a.f.......X..Z."..f.bX.......?..L.F...l....ll.@I.R.@.PjT...R|<w.'.R....%...sg15........`Xp =2...,..30..bX.l.o.0.....4....eg[.-..i....H.:.4.....\l,....(. 5..gN.Z....x...7...(}.+..;P..*.H2<.......`A.OT}p"7..WS.6.(&..wU.;P...p. ..'..../%.n.(3.S..n/Gp..J..G3.h.@...].&G.......P&..[O.8.2.....i......"}......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):732
                                    Entropy (8bit):7.433670846967776
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZPW1se1T3/khL3KX6R7t/7FrAH8KSjuTo2We+xd7/:HaHe1T3ch2Y/hXio2W/xd7/
                                    MD5:1ACD907F486136B766107DC58D825A62
                                    SHA1:B523F228DE06C410AB6078137B4C941E6E847516
                                    SHA-256:25FDAE5A43DDB6E954AC9C423F2CA377CDC059091D3905B84DEC7223AF53AD45
                                    SHA-512:C18058C770E8E6E16A9612A23F1D4DE5E4A4865A1E26DEC41F7B6F100D340237F9BA4137545B81A6EEEA128735F73C9066A505006B6EF32D5CDF9BA4B2023B12
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....iIDATH.c`fa.......j6....>Q...G..m.......{..AlB.....DY.2..............c..3........Z......}C.........,hx........[E.....v.@....d...&... 1./...........~......e.........$@............f .zJ..p.....\$=.q.uF n.....o...RB :...u.k2...9E`.ohi.?.`5......{..2P#6.N.........1"..s...._%.-G...-.....m}`.o...O....c`.?)............A....0WS.....6.d..].2....U...4.6........2..I.".0.....Y@......3...d .. .l8^.....a..u.....D*0.I(a.P.^..0<...1....::....H-......j....... .........^\.5.....Al...G..........tt.._........y...@ldK0,@.sgm...!......>b.0H.....b.4....._....<.......F....._p.....s...QA..W@i.Txy...x.9..B0..5["....*5.-..'.2>[......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):531
                                    Entropy (8bit):7.374379882795916
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ7eBSKvggc9szTqYqkqUBHMhhdDb/KuaF:HaFISKHdzTJqUBqX/E
                                    MD5:8C625FB2315C6025BA9D126A8CEA0885
                                    SHA1:86C2682B9DA5FB996A4784013E60FB86CF4199D2
                                    SHA-256:8E89A630AFCF89FFB0DCDFA7AD288A5803CEF9CD94888EF75D0701A734C4BD58
                                    SHA-512:3871FE4B802F5C989EB1C3AF9B3E1E905E64B074C0D02B17E68C7077D4B7D18E0FFC2C3F6D9F78654B6CD957692B5F4D09285505DF39B09036DFC6AC51334D0B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...JBQ..?.&...,B3.z.I..5v...@h.+43.I#/`5.2.)4z...Y.i......`.^...{....0_v..x.z..............`/.1..v.......u..H........c.} ...L7....uq...6....|...{.kY...<.8aY.....v..f.g...CU#\.&.......y..p'....GJV...=a...,1...'..gk.E.g.Y..N4~.x.... .q....Z.o...-.......U...Iav...S3.%....Z..P?w.-..A...~.....b.....:.....^.]'......w`c..f.v[.c..............I.x0>....N....zKR...R.ki.STi.....z.n>..i1w#......H.*....../@,|.........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):641
                                    Entropy (8bit):7.466226236806226
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ8e1YU3cWe+5IAp2Lzv0qN/pbej1T7M86i/YaVwdwJ:Haaemx+5IApEso/p6jyiXwdy
                                    MD5:5E03CC16AAEA091DC7885D3D2BB28D62
                                    SHA1:59DBD9A9255495A2B11324EDB36465F5C36ECB99
                                    SHA-256:A67EB95B3D5EFCF3836C1D10E3151F9EF773B7334275BD5762AF222B20FF0BBE
                                    SHA-512:A99DBEBCC3E03E0DF2B3409A40D178DC6AD9BEBA3BACA3DC9F09BC47C3ACD954D1ADD24B99A52059A9947944F5F5C9FFDCF7A55DE942F6698ACED2C6C7B746AC
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` ...q....q8......(.Ci.)S.]..+.}..U.U.`..`Z.- ^.h.....:..V....9XX.x.X..N...4.?..6&......v..<ll.D....>MYH..(....G. ...B..I.........q.@.?%...m!V...r.]s.R....\....n......@.....<0...Pjt%....0#DG..A*Y..&../w"<...|X....Z.,....LY.Af.mX.....Br-.aQ..O@......]j[P.`...W.Y......gX...i.....`...+.}...E6.. ..Y`"'.......dCp2...AM......day.O..b.(.Z.l..~/......k]......R.EV`.vl,,..B._(-...{a-..q....R.....|.................... .r...@^..V.c...Tp.2tGb..~..s.11eR+}^NV..R....`]q.T.,...f.(.Q...30...:F....(-K!.E.8..........V...3.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):634
                                    Entropy (8bit):7.526327450209149
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZEuKezHzNywoo5tNsLHzkQqWFclJluYuoUv/IqyPp01:HaD/TgGNsL1vcleY7Uyp0
                                    MD5:FE47A1F7263878951707B5EB502E8CC5
                                    SHA1:A43BBE234311AB30FBF74EB9A5A1D5A7845E5F87
                                    SHA-256:1874EBDE17D713FD1855830E3B8A2A403A2D5BD6F5905685D5F710DB03A9C422
                                    SHA-512:4FE232572D15234F4D858DF1D5F728416131FD868F7A23AD052E64C3C9821E528BBDC94C0352FB7FD1B94D2C923FEA4CD9A6E471670227A6A487841B55B22E69
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V.N.A......E.0xB/B\..,....D.D..F..$.?P...*.5..`.&?..7L.....#.Jz...u..z..../A...Y.1a:3.... +t.q...3IZ..hr.E...$XC.=........t..#..J...l`..]..:\y..AQ......S%...B.^K.I....4..s;.4D.....K...']....>..h..m.._.H..........V+...>.......... .....W7D..I9....MV.N..2]..^x..w.........W.KJ....@...8K%.X.HX...]..3.....a.]4d.H..i..@,..E.O..</4..U.x..zP......L...bf..&.X..6U.Z..].....(\.".t...).8.R.>@PQo..b].........P.5(..b..J.a'.j.Z.E..N......q+....r._.t........a.+.r;y2QP.\..c..C.V.qap0.....A.j..kA..uA.o]...].......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):424
                                    Entropy (8bit):7.018311873669045
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZIt/WbXS1NhHdH4/Alrta49N8TtImb1YG6VG8N:Ha28CzRF9lrta492aa56ku
                                    MD5:E4F480DB14ABE5B68D7940CD6C1B148C
                                    SHA1:D014044A4E744036E1769CAB2E8D43932A4CEEAF
                                    SHA-256:2FD1ADF5914F936425F50FC6DF2AB96B5345D86FC7D211ED1A29FA1417588379
                                    SHA-512:91936D1118A0BF6AFC0FC3997BFA44841D0B3AD5DD20780CC863049FE144F17414FCBB785C824482D989BD6320BA475F1427CFE1D0C9882F1BDC8E60B2A05B30
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....5IDATH.c`fa.......j6....>..C-.m.......{..Al.Z.2.............Q...kA.f.V.....c..$F.OpZ.r).. ...4..........AD.HFO..w...x..[.\....;.5._.?w.v0..I...A.N^...ny=...0K@.6.....U.. 6.%DY.r5.`CSK0..Ab 9..A.....1....\..<.`..\M.H>w.=.S.4...b.ap0.0.M.E.....j....... 6H...C...R..A.k..1......|..*..K.T.".- 5.I."r.).H.u...M.je......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):492
                                    Entropy (8bit):7.219897003910568
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcLaRmNgSlzyIiRTJsDai4yO8RJnB9xKjfwGgoHyv/uouVR293w2:6v/7saZWW/G+a8OUnVKULiou4ASWk6TK
                                    MD5:638944B7E75F6677279EA83C1795987B
                                    SHA1:FB3E1A632C0BE4D87B068A37DD6B202F045428AF
                                    SHA-256:B3272D237730CCFD00720835C0671D78E63B462EB7031A7C375E03BC518914DE
                                    SHA-512:E51732065E3F59A1A420120B02C0D0AD88B38B7A3E9E0DFF8083FBAED5AC6105CF7126EBC72D5C4CE040CFDD8B02153D783A9F2DE1ADBC3263E53CFDA3EE35F1
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....yIDATH.c`fa.......j6....>....kp.r......^.>T........S`.b.[.>...[.j(...*....v.@...^...c"...kv.@....o...1..P.@GaX.r-.......!Q`.b..\....h.....k... W..VV..c......X@. "'.I...dJ..0.~.......I.....p...>....hp..;..`%U.pj.jQ...LLL(.....Q1.<Qq.7k)P#...X-A..i.(.F.%.....+...?y.j0..)......U.}..........3..w...... 6N.@....d...>... 1\......-..c.....-...d...%... 1........$....`$.....*..n.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1232
                                    Entropy (8bit):7.783721678283317
                                    Encrypted:false
                                    SSDEEP:24:Hap+fvIZSqNA2zLsumQ3zlVn9POyDulQJVzXxrjTMcy4vKy6rYugN7:6AwZSj2zLFv3nn9WyDul4JTMcy4x6rpi
                                    MD5:4499540F1B0BFA87369A97CF8B8C5608
                                    SHA1:55ADA1A3EC0F7173FED8D6D9905C2BF200A4E0E7
                                    SHA-256:E4A0C51802F58C088F5B7A084859E59BBDE226DDE477203A933854C0A96D65D0
                                    SHA-512:879FF35CA0A95A86D16145825163AFAFF5693D057248FDFA14BF7326A6528ED91BD590FEED83C383E20AE0401F704C6702EFDE6DFB3C44FDED849047D90E33CC
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....]IDATH.V.O.W.&....5.Ib..d.\2\.f..V..,...0....u..!.)...`.@....e0.ji..:*.JK.E.`...g..o ........9....<....m.{yya+OFF..bc!IK..?<.c<^.._....c.-.u...BB.[Q...50...#..{#........e`.=Z#&.......0..SBc@......CCaS.l.pWgCy]..%....M.....?.btfQX.7...%...T..R.+`v,x...}...^.."....q..x$.JCVA).}Za.......c.*.V.HS+f\....z'...HLJEh..........2P..-..V..}BbSP0..0.F.6..r .L...)......m.[.D!..eT.w..NF.;.Dk'&.(.cN7.....q....g.1..............DDE.....q..Z....0....0...................,[0T..K....y..6SR..U...R.@c\x.6&.i_..6cD... ....Z...}.m...1?^....v.....:.Ij*.....,........p)GB$............;-H=..O.O.BV.......tA T.............#....&..>.\.f......g..b.& ..Z........h.....'kA.h....2.8....}..p.e.6..*?.y..#.b..oD.>......ni..".du0./....H(U..3...D.W..-F....J$.uH..<..OB..$.5G.....r.T.[..b....l5a......N3.`...........l.e7....Z\.....j...../...~.Y2..BYm;.=....1.#.01.4.\....`..?J~L...5....&...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):430
                                    Entropy (8bit):7.111129987047386
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ8WbkCdK+Uzjr5nGVd/Mlwc2UXt4W:HavkkO9i0yFg
                                    MD5:90CDBCB74FC1D6A2F25EEC8D93F02964
                                    SHA1:DD1F1679EBC535759C16A0E655C27172CBA1C999
                                    SHA-256:B972A63743F9EF46CF7A114CABAAA20A4B6A6EC30C76D15AA95C62CDF5DBEDF6
                                    SHA-512:AB13D2CCD06E02E595D115C57E22EBED865BDE89D7AF3E691C4BD5C3FE780A79AE88BF0FA48C066F4E1BA0159AB12A9E3BC062CD71F4E838F45C0E9278FF3C1D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....;IDATH.c`fa.......j6....>..C-.m.......{..Al\.N.|....-.../.. >A.@...^...c"... 1ljA.&e..w.... >^.@....QX..7$.....Y=.. .A. ...k.. W..VV..c....!.]..> .....W...T... .P..d.V.:.......z;...dY0y.j....l...X....-!...z...\.2X....Al......X......Fb..].g...x..;.,...4."F........>.Z.........$Y...o........F2A.(M.X-.%..Q.K?]..R....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):573
                                    Entropy (8bit):7.405492291603919
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZwS4oPrIuDMZlt6tMXr9XsQmIwio6N8nphNB/:Ha9DIeMvUteHmIxo6Oj1
                                    MD5:89E7C41B0D55FE4E934FC5FCA2E52EA9
                                    SHA1:90365EDF8995E654948DA60770064120B188616A
                                    SHA-256:80D8315EFEC2084DE5B737BD430D571966B10EF4AE70869A395731E601F5B0AA
                                    SHA-512:A2AE086972352598EEB89AE7BC4749DB1760D1C9ABB9D6F11557BCF1930B499715372C369C9BF635E2682D2EAA2CEB2214C72D0173228A427DDA72634AF8001C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`...03|.R..1T.*.....j.^...........=.Y....@IH`.....l...+"...L.j>...J...O.r...u.j...iQp....(mM.....z.@..!.........X...1c."...31..|.f8.....RG.9>P.`a..<..?>...{.O2..#..G%..F..?..G..$..Ci..D...;I.......Z.in...%.h..8.j.....kA.....&.6.S....v.{b........V.9.......@..-.....NE.h...{..Z....Pf.S...h.....(-..I..T.m..}G....._A..%P.8)....?/..&hA.....6..r......9F.....0....HK..*.%.4.Z.67..h.3.as.<......2.........)....Xf.zX.s....{<.l..eD..G...5.=..A....Qn.C}e.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):719
                                    Entropy (8bit):7.61984902090932
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZxsDJ4zve33jApRS6iGvv3wdN8vRP/hIm/LG2nrmT4+NqETDODYkRl7:Hav6gvIh6nvvgdy5P/hJ/S2r1ETDO57
                                    MD5:408BC3470C7A9494E04A46C9CA712E52
                                    SHA1:0BE20775BEF1B7D5C21584FC783120D9C5D2D64D
                                    SHA-256:46DD35EE144F1D1DBC6108C88D2618FEFA12499781C75F02C9FA6D1790C7B20A
                                    SHA-512:94627C0526905DD000EE0E358F29E6D0D5F3FA576FD9D46C2BD7B6657FA6AD3E26584335BC4357CB087740ACECF2A4B4652D4A49D2F877C92550B7547DEEE790
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....\IDATH..]H.Q..o.>..>..-.j.$=....DJ...$i...J(..(Z>(.TdDl..!k[m.....`....jh$>HQ`T.....6...^.1g.....{....u.BF..H..%....1.#..(.L....3r.9..../..q"?.?.D.....=....h.Dd....X......g87.$ .|.......Q....=.......k3....._<.Y...........A....R.._o...P...p.b..[WK...sE..ga.I5h_#..3.6.-...N.7.......D..Rv).yPX..x.a.Vl~...n.z.....&?.l...K..y.j..I(&M.k-.AO.0.U......I.1..o..K...J.PLZL.......<......x.<....;-..4S.../.....4.^.w~..b....W..<..k.%....&v..p...7{.!8...........JI.1.H.......6x...\.~...8UT..*<.v.K..l.*..........r..'!..#..PY..}...3P......Y2..6.9.ZIW........."......!j..^.X...F[.y..v..'...g....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):493
                                    Entropy (8bit):7.338040208632571
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZtAdzaFoeTQmjxiQphKZGm7G3ccOY4:HaAdzDehjxiQpcGm2IY4
                                    MD5:FB2A292E78AAA6EDAE419768C4B0D3B5
                                    SHA1:34BE3FA1C63B0A5142722C64D8574D5B32BA5A26
                                    SHA-256:F46AB9578EDB7B60DE27BE3BED49D6310B921D9A9B1BB684B06B1EEF12C405C7
                                    SHA-512:50845213A4908FD3120337F8D3DF36EB18CA4A58D75FAD7A3A9CE641B2CD74EE1B2CDEE5392E6E6936FF639C7BF75888B29D774EBF17BB9676BDD95F64878A89
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....zIDATH..1K.P.....b....I....I7]...B.'.:XKq...T..f.)CQZ-..W.....v.&.l...=:.8...w.%D.$..B..!/[P...E.h4.....-.^)....3.)VX.)..[..o.hqi...Z.....St.......8...@...ST.M.m..9...^.WkR.T......T...M&.5Lj;7...Y.u...cW...Y....#.\..e&C.....0..h5...B"...C..}....]#8.`..Q...o..p....L.#.E...].....c.J.#...4..P.B/l..O-.<j.n.....ZY..Q.g.....]#8..g..6..Q+......(b..s...4.K..5.......q.f.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):574
                                    Entropy (8bit):7.415864782969201
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZu1x2zRRRLc8nF1bh2SGg9VzKo/cjp028L6592kUg1LIvjJ7:Hag6zRRJc41Mbo/k0I2kUg1LmJ7
                                    MD5:2EA51B3C1F5B39A83FB2DDA6E639094F
                                    SHA1:4F91D35D241301B818415238EF38F5948646C218
                                    SHA-256:1DD1FD88A04619F3D624C2B12379AFD7B476E4C09B8A684B2F9E631016963ED2
                                    SHA-512:3C9FBB37CA3FEB84A5854840827C79DCCEF3E7B54E83659DF27C58FD6E2AD19FD4BBC7184B5E5405FEB56B731A4F3FADF8D630716AA21F58D2CC09CDDD0C9973
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.....S..m(....33O.cg....JB.....>g[.._....`jT.4V.X.?5.eWr........E.q...j..5.z.f.....*......,...C6..;<..s..<..cFw......FQ...T.#.....0.&".rU.9..q..|]......s.=.'....l...|P....|.#.z.-8...I.. ..d...E. .Ls.@-1.. . ...8.j.....kA.....&.6.-...8..aOl...6....:.x......A............=b.s-..wUh(3...O.. .......@....w...Lm...._.....L......Po..ty:..ac..*.H.....1..._.....DZ..Py(Y.)...!..@.........V........?\.l.Ny}...2#.........ag{|(#..?j.P\e.N...................IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1055
                                    Entropy (8bit):7.724487431866351
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ35sxuWFyi432G7GBs/UFGe3r0/m8EnlbAWyHwPBgl8DexKkfVGz6IR64K:HaP0uWFxeUNFG+QcAWyHgB2xPMWIUmQ
                                    MD5:D6FA8EF65E7A98C839098898B8DB9A29
                                    SHA1:FBE0C6AE11ABA527F646E442F46578BDB6717D5B
                                    SHA-256:D6F31D0C9C4F2C55A3ADEF59C57D73BFCCB77327BB9C9DD0BA603A2AC844C5A1
                                    SHA-512:97AAFF326CBA0B94BD5371B724C7439BBA8D54E9948DF36FC1482F26ED04568A25A2BBDAEB9399F1E84941DF5127475104014B883C57167A516D7F9A43C77FBE
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...OSg...3...e.so.f.~!.dx.AP.........8...A.....qc..2.......:....".....h......W.{..87XR.|............dddd$D.A%.3.~<.!...6...3.3..b.....G.....Z.....d.!..'.TSy..Z7@v.M...d........9..1....5.No.=.DQW.Sk..{.....k..4 .I.....D.4...c^vp.N.nK....Q..K.iKRbY..k...BZ.....Q .....o...p...$.-.4.tn...d.......U..:.."y..d.G.mP..T.Y.h.:.|.x*b..p..l.<./@v_e....M...{5....z)k..U.8t....F.".OV..i.a...Y.S.LN4...:;.{#.....4.."(w....[.........Nd.R..-[..g..*.7..}..z'..?.$..F.........~2.{.........K6..U.."........s(....bd.8.gW.P}3.7.Q5..oR3.' ..'. ......Q...'}..~.....@,.=1..|...>:......h..1!..29- ~.{..p!..t+6....K?..~.b{..r.N.X.....(.....2.1.....T...GL........V.B.H.Iv;._..y...bL..1J.t.).c...T........... ..y.....,.c. *[8(..qk...'y...$.'..N...Z....s.m..CUd..q.`..n.4.SB\...+....t.O...k)....Z....2.:........t.{8=...F...*.....$(m.. g*...+.\P.+..x..<o.}.K{K....X...IO.#z.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):697
                                    Entropy (8bit):7.53325744462456
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZZNAtqmGh8QH8HbE0bGgk0WVpkkMdBXwYYkwxagjvhnteNNAEP8rSsM:NKarNPh8LbVk0WAkMdlYkMagjvXeUEEo
                                    MD5:7FB2FA6CF1386EB4BCF192661D3D8DB6
                                    SHA1:FBF94EC2510BE4E43A09187F86A200C42446454D
                                    SHA-256:BE2DB4F1F3105E79DF4CE7FC1138B9FAAB60F35271B2DB7BCA4F4F73722171A6
                                    SHA-512:8AF5323330B6A8A1A120EE7BFEF1D72D65E62D716A8733D15D6FFB9681CD0DEBCC016F0DAB94ECC52186B8412FFC2CD13129C049AD663BFF4F5100FE4A5CA05D
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....FIDAT8.UO.aa..........$2#e.&.4e.,e...fAV...y5...46JJJv..N.,Lid...Ub.V..7.zs.Ko.;3'n..}...s.....O...!..N3.$.,.?.n.cBD.l>.{<...s.Z.j....HE.L. .......%x..f4.A.J..r9.b..h...>..}}..FA.v...U*.$.L&..n..B..g.j.|>.\..0.`0.d....6..........p8L.2.X.......jE\.\>...e.T.?.L8........q.O.&...4.....+,...|.....tN.S......8.z.F(......l6.h4.$.x<6..n...l6..t.8Q.^..`./p..J.R.Z..O..AeB....;..`.....L&..K$.N.C...P(.9.#.*...HH$........$F....Bp(.z......E..8E..j....D.......'....F.$..(...E...G.X.)f........R....f.m8..D"dAn."..5^w....2.....o..._U*..P*...Yggg....W./P.N....avg.F.7.o?[{..a......C....7.^....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):555
                                    Entropy (8bit):7.444773704293754
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZD/0xASD/Ciha/9JIq96n7bJ/GyMyHPH+Jt:NKaN/DSzCiha/916BVRAt
                                    MD5:C96D689AA6A82A88C361601BDABACB33
                                    SHA1:E05E915E73CA26C585E873D4C6B31EE0C8121231
                                    SHA-256:EA3F14D90D3FE8E330B0F226E1E2D392C81ECB1FE1C2FBC23F3B5311A4D1CD51
                                    SHA-512:A30636A77B3D2EAF506111979CB97882A76C6A9EC6BB3899319CD60546C5CBFF90C6C75A72AABFB6A6EA005206231830A8E677ED81F71F4407DD669562EC9477
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..?k.@......(..".......\].....*8..N.,....\.....R$..E.!. *.8.......&...r.7w...}...'w....O.(....0.VI.g..f#.b.V...dF..G....;.N. ....t:.s..a .....'3.Xl<.+.q9Q..0...H$"...h4.......@.H.....).q.r.k..*.........<.,.0.R.....xT.P.j.Z....9)v&..7....v..P(../.V..r..x<`u:..m.\..P6...#Y.i..X,.Je.^k....."..y..[,..Gh.v.-.J&....l6.......{.j.R...n.>b..]..AX.-...q..}..j%.....f...M........].z.`....@.<2b6.n.K<*......f#.=2....G u.p8.#..~..e..a....u.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):523
                                    Entropy (8bit):7.4247542434162215
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ1BGC6Ql8uWEaZW1y0g6T+stGNPQP6pIg3JPKv+d6V7:NKaTBV7l85ayIyp5d56V7
                                    MD5:7F4EDCDC5912F3BFFE10111B1D74CF28
                                    SHA1:FD161B08DF02E40811F150DF7494624EE9E7BE6E
                                    SHA-256:9A6D18BA0217FF7A4CD17BE21ADEC9C5501F147F71F8CAD8B0016D1A7864EDE7
                                    SHA-512:97A079DE59FC5E3CA643BE4635E4E9A1D97DE471536818910228609B7787A7599267D3F6ED8005A44A893D389265F340202A00ED12C705561D1C66C5B9C23A7D
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..T-..@.-_....*.@.E"..". m......U'.$.._@5..A.kH......@...4w.-i ..t33.y..:...y.2xn.l.Y.m.7.....~?..|..d.B^X...*..\n6....`....}.a....R....}.&." 4M.y..h4.....c...t.t:..e.'....2..r.;..x.t].....N6...&..n.H$@.z.&...6.J*.Z.V...o<...S..].4..p$.)...*.B/.0...v.p[...F...^.o.[4.@)@.x.z...t:Er>....h(....W.U.)@. .u.'.N#.P(`..j.'..y.$..h(B0.q....W2.......5.........G./JiH{..L&..#......XxF(d..Q...%........Y.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1080
                                    Entropy (8bit):7.760001011131461
                                    Encrypted:false
                                    SSDEEP:24:HakEv/VebOvVQDFrMnjBcs9/Oc707PYf5mouo352wu8AW0Z:6v3VPvVWFrsjBc40LYf40JOW0Z
                                    MD5:693670B2FE6D65F4CB7BAE022A2528F4
                                    SHA1:2BAC72188332BFBCB7F68772A2B7F03D5E03078E
                                    SHA-256:AD52B061776B98857301D897C3CF8C0ECFB1240A6109FCFC9C425556A2FAE6FE
                                    SHA-512:4A5297D3CCC42F7D5D5712950FD640997F6BA47802C5756E2E5C34716B734874894950735ACF576069AB78F55B046C20589947AEA966F1CD95671F691F08791D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q..gwfvfv...m.(...$...,.....=........eO.H..P.*.?hO3.+M..K....*..j...2.....s..s...9...E...(..-.e2W...j.h4..`.A.@.R.....L>~...L..F...z9.;.6jd8.r.E[OB..b....Jj...-...B.......G....9..0.#....B.....J6Pl..d_Va%.{V.5o...6x....[............._.e./[x^ i......l............NW;.._!...>...../h.h."9..H......*........z..^.[....<.}...}.x......}..`...8......t}......5......t..6.=....dDH.0...k.(.1.d....y.U6'....3.%0.d...n.6.'p.f.K..{1MiJ.:.1w..m..Uv./....v.h8...T......Q.v.[..1<.`.\.+...kHa..d....\r.*..b....]J.P....q........w&...f.wK,....=k...t.Aj.bK:y^....G"v.........A.D..!2r....K.4..W"vcF...w.!..|..E.>i.:I.'.....=.vC.H>.:..c.z.+..'.iD.._N......\....x.....\.."..j..)'..........S.:;A.s..B2[..?..1**..._dSp.;...Msc....v#qFf.........@....9....`.N9j...u..>&&....d.(..iF:....o.X.`..9c..b...E...Y....R.."...q/.....>.=.....nS.r....../$.7...........=::J.....X...;<&.|..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):314
                                    Entropy (8bit):6.784929150611978
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKcd9F10rj77iGO3vndSX7pss5LQT4noC3EGMiWYWmOx8up:6v/7aKaZd9Fq377+vnwVsUVfHMi5Ox8c
                                    MD5:807B340018C2B3159E533BE8265773BB
                                    SHA1:3039E17C03CC775C98D2C55FD40D7790F288B5F4
                                    SHA-256:B91575A2CEE1DB89C940165653B371BA08A9B52FD002BC870F74E4FA38A15FE0
                                    SHA-512:C4AA7C69323178EBF4763D369CA70159C2DB2E2EC0415C90E20C9B09AD0BC4E59727F6D5934A1D3AE3D96091767A441ACC92CF2E49F0AEB49AAC70357E790A5D
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..1..0.Es...)so...C%.......Z..R.qL...H!$...r.?...x}..`.V.......$..... (.@...A....A.9..i.C.pG.....6=.&..Z.L.;.\dP...b..].hl.8..-l.H|goFA....A.Sk.w.....Fia.....?.o#.Hwa..9.....).P..j..K}..C.<8".F....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):314
                                    Entropy (8bit):6.721368144178752
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKcd9ONec1iJrRSwlJqGdulFDFj2fYRVMUtKGisoPZVp:6v/7aKaZd9HccJr02q/0f/HsoPh
                                    MD5:22A148D6CB40FA988302C8F1073B14A8
                                    SHA1:48CBE8FE474F031C104C96EF20115B163A35B1A1
                                    SHA-256:5ACA3235F1AEF0B5713FEE3354495297EB76ED7A7C3FF43A31EE3E9CE8E1481D
                                    SHA-512:8C0B8105F032FF4FE16C1CDC3E28B91E1CB48336853CC4C34C62FF5ABEB74F150A23F7CFEB3C05781B02AE942D13916C3D8F84C992D3D3AD982BF93E4D408217
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v.*....#.g....n.m.. BSjcc....c.. .z.. .=#.@..2P\.n.L....Ak+.{....".:4..N.........{z.`F.a..B@.o'N."d.....l.....Fv.._.\....5<).........Tm...H..............6...t4.."..I.l..............*..B..BV......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):401
                                    Entropy (8bit):7.114487442979153
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZM32Toni6sJqwMU+evHuYBuucDNWEKerH:NKamRi6odvTuudEK0H
                                    MD5:2D068C94CA482206EB6251538EF7688D
                                    SHA1:E8D6446D6730AA24EAFDB89DB777C9682B8943C5
                                    SHA-256:04752316A907E6B750F6FC163FC6FA957A70E0F3D5ED0614A9AD9DF75E6CDD9E
                                    SHA-512:1068BA7445C02FE28E4F970BED96243185F263A792EF39B232D438F48E6F9E85FAD3243907CB479E327E04126A852DF816E8803E3854B9F61B84597DA8269392
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..=..@..9.,..3XQ{.c...#4..-..p6.h.....'..dY.!.......cf.CQo..</&.....T.......c..o...@z,.i..8n.........B..&I(.....(pFfD[...s:.Q8k..j./..{.=.#PY.A4.o.Y.!..,..@.6!1....ng3.g.O.3..%.R)..-l.........I.D.../J]=o..@.o..."#...d.b...M.._B.$H..Y)..\Wt.LeO...D\..l...h.X.4{.FG.\.v.....&...x.1..h....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):805
                                    Entropy (8bit):7.635351047843189
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ9v3COOblIHYv935IN5WHiu6wrWjzFg5jFp/hKCjf8axlRdZR24:NKafHoD13Wz66xjzFImCdxlRlx
                                    MD5:2D57C7CE9BD8D41BDFFAAC04292475FB
                                    SHA1:B63ED926888CBD58BFFC083EEAE5FED7189606F2
                                    SHA-256:34B1EA8F3C5D7861CAA6207D6BE751D6C44A9BB1FAB23706DE0589B3989FF197
                                    SHA-512:B7642F676C7609A123BFC6729A322CD8926C40DC13CD09BE235722C9D2ACF9BA68EB9D43FB2E960D151ACC9B52F62D025AD72F634885B4B1B49E84D779BFE555
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..OHbQ...,..V.HQH.?......fd6..EC..00i..E..E..E.A......7......J.4M......8..|....L&..|.s..s.=.2.~......X,....\...vr...H$I>',.x<.hKK..;...$..F[[..x..1A.. ..R...`.rc#......L9#.L......K.....L.......I?...)..'.vw}.un.......S..1....V.hll..]...@7^.9AP.....T...dnoo...l6...Q.H..*..)...cP|q1..c.T..qJN.S*....3J....(.N.{.fS...&VV.D....}>.@ ..L&..-..VkE.-...&...t....H.?fn.....v:.......l6..>r8.Dc#l.J%.-.RQ.7..uuu.h4.|>.TC..~~C......<8...A......X,P.fs..>>>.0.0G...^..T.X,.DB,..2S..}zz....$....R.`.h4.........rF....vt...h.;.T.........y..B....Z]_...]...(.......R..Z......<...W.5..ea.$.]....Q.............0.......B..../,,..PEF.l0s8..?..........V...>M|>?.L.|.>..@ ......j.j_...z....A.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):864
                                    Entropy (8bit):7.6639437363856935
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ7lnTXNCWJhGn/kG3vig5Oxmb+LDWt/g5H9vTMHEL9llPF2iNOK3oeOH7:NKaJlren/kCKkO9W+59Yov2yOneK
                                    MD5:9F76954B5A93C40EA9B093ACED4781B8
                                    SHA1:13706E9DB0399C8C3F86E9E63ED8D67A150E8B85
                                    SHA-256:A3D485BB50745547D959028B354A1E60F3B8F840B35135F828E1E5F42840CEC9
                                    SHA-512:38360EFA8297E4CF8F82AA198BF01265064FAA39683289C72880B23E126624E45704836DD1D80C7DE11DE4A151DF7C0F48727440AE919F8D1386EA93850ED5FA
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v.*....#.....:t..}....,...."""....`........}. .".gH...>ZXx...<5...N=#.`qQ..N...D.....CC.=yB........m..'...VQy.i.9....a...,ii.]..11.A.....P..)Q.}......[.}..)rp.RQ...........<..u..L.....i...." [XH..mU.W.Bds45.JJ...^.....e|..,%..@...jhh.........@.G.fIIu..............X[..........*&.h..& .eM.0*.TU.....zS]..........ee.......ATTkb.Y%..66.6m:.../!.y........;^W...G.^PR....p'L.`gm=KNn..T...0..ed :sml.........{{.(*..U...W999m..gKJ.Q......Dj.U....IK?9s.K`?..;.......2kkkSS..g...t...F?......n|.....N..n..s34.....x......n...{.Av......n...m...F.1y...?]......L..b...s.~.....#D............@.@..a.............EG..w..80q.....al.\F.NLl....%&..d.jk..Z(-......FT..r......pn..|..D~.....E@.[...a.......... ..eLQ..0."..2-ZnZ.....M...t(.g....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):993
                                    Entropy (8bit):7.676951484144662
                                    Encrypted:false
                                    SSDEEP:24:NKaP+ZPR9CIhRgUHjuBRNU+hc1bXFPtThcTjal6+h6zyc+4y:nP+RR9bIguLNUec1bXFPBca8GEq4y
                                    MD5:E2668B001588985B96C9C578E82F9A16
                                    SHA1:68662EE176234B5BFB6748AED882B126A1769B6E
                                    SHA-256:F3C9B45A5E7189968ED7AF834BDCF0DB0EC6C0E9A7C2146C223C314A3F71740E
                                    SHA-512:B7FCD3F51C68F5748DE2C331489E1CFCC254B8D7B6ABFD3AC65728E3BFDB5DE168E87DA7A23653F97189E17FC169B882B403A23EF7A0FA0E647813BDC26B519E
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....nIDAT8.UIH[Q....;...M......D.....+.P...jD.B....Y.... "...b....I]h.....O~..VL...=./%.......w....w.......S.1.[......^.o$....e.....J...8=....|.Px.z.}.....$...:;....hHH .....szj...eb......4..7.....y`.4SI..l.r.,&.1/.Nrj...HDn7!...\\,++c....ccp.**...o..."?.0....BCCCBB...-;;.6..r.L...om....@KK.b)//..joo....d...l$i....R......eeE.R..bYgg.`y...M.B...Z...0..B.dxx8.o....l....O.{W".....d`.......R.===.....W}..2...y..|0......q.\..B..`..AC=*.\Z..,.:....`......u9<....tvvF......=*...ddD.P......r....9==Mw.~S....t.M..D..Vaa!8.....mkk.............@..{{....#..t8.........C,.....~jW....T.\U*...B.....588x..I......!....a.^]M.Dtt4.333.B......u.\..JP0a.......0#..fknn.4%%..v{.Y.V6...T*u...W..<..{3.........BO+.JT...o.YA/.\.!\...yR....d.r..Mf>..9ollDFF.TSS.=(<M.H.XTT....F....}....iY.V744.#t."..B.......K".h...............b.Do...-........w1.rN.W..8...m..[.:......!........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):473
                                    Entropy (8bit):7.259950302851813
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ6XtHPSVQg+q2yOdSRzqjNMWN7Le:NKai1a3+q2yzo9He
                                    MD5:AA53F197A2A1238E53031A3170DD9218
                                    SHA1:D4E4E2A3EBDCA1E7D30A34982116D03F67BD0F49
                                    SHA-256:7FF9A825EFCF4158C788A7861B5298B40B35197C6CAAA3D6F5CF4EF1BFA7E152
                                    SHA-512:7E9F5C853EE59CC7AE8624CAADABA5CA2938864B660D771C2B5388D8C157B2928478503531BF1BC9C7E3664F60F891E5C2C5E1865D9D1ABEFB79A88184E7E83F
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDAT8..1..p......a..B.Bm..GppI?@.. ........Il."p.....LIh.......E4..w..]...@.._)...Ei..h.mT.Tt]?.N.F..T.U...Bz....v..@..(.....gA...z=R...4]*..0$.Z... .rA.'..f.,..x\.....4......Jt.I.......^.j..(.a..vK."...h.Z....v.....TU-..9$...a...C..N.4M.....1bYV.(..r!..|._).q.m.n..`.i.^7..<m8.3.c.X.q./.o..~.L&.Z..*..(v:.M.>....\.u]o4..E.,..ev.e..;...F_._..j.d......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):986
                                    Entropy (8bit):7.664476910364052
                                    Encrypted:false
                                    SSDEEP:24:NKaCPO5SOn3ataq/81f+2/61+qdNJkEIf0HXajABD:nCWl3ataqMf+2/613XK/0HXae
                                    MD5:BDCCC26C63565C3F7AC1440DAAB49D19
                                    SHA1:FD9948EE8921B6B31A4C7437733187A567B170C4
                                    SHA-256:C4AE5317ABEFAD97C516BB65B82AC6CF125653D890A8FFB34BE37E79095D66B6
                                    SHA-512:94776D25077EFE80977F046F316E648D63B70E9A75EEEFAA90C0C6304ECE7AF17CB4DF2155AEF9814F6B9839B8215FB2542941579581282E8218C3CD8AB48175
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....gIDAT8.U}(.a.......y.l^.Hm3-...q....F..Jj^v(.G;.t...D(.#)..h..3.e[N....>.s..|{~.y./....|.#.t.?m..4_.+..r_}..H........9^..;........6..@g...t.........S.....@1.............@.{...mv.5.D......R///.......................I.......}R..........[EEEoo....;@......7x{{.7$$D.V.....`.Q.L.Z......PWWG.:...b..k..rrr.....'.J....7i4V...`@...o2.\.!....8.............I.).,+.YYY....GEEY,.G..@D*...4....JE!.........j..===.G.;.p.N.#..pgrr...%...& ...B!8B..{6...pt......,==.z.......4.....366..#n...%,].q.+9.............I...h4../.F.K.@L......W...KJ.5........b..jjj.........00...LG....E".L&3...o[*% n....k...}r2X.....d.TUUu......(.....?6RR....b.`...).H|}}......{.._.f...R(.....a0. ......0.tt`...W...........lmm..??....G..Q.%t.l.t.R..........G[577S.TtrQQQ..I.R.\.I.i[.........yy.t.B..PZZ....b$.....?4!OOO.....AAA===...SQpE|>...+..=2j...Q...P43...=...i...^0J.#......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):628
                                    Entropy (8bit):7.420835398015451
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ1imbC5HMuCvsQfy3ppL4BCx7HXXFiCStYS7RDebuI7ufH45/N:NKafiWqsBCM0xzAYShebuDw51
                                    MD5:83BE2CCAA86D59636DC435E046D80D34
                                    SHA1:9E79B14484DDFB91DEEB3102A8434FD2B9486D87
                                    SHA-256:F0A7C89C395D05B24BC6E623467C63E9D622C2E4F36F18A752A783B37E60D0D4
                                    SHA-512:E8141D994366F7DFF8011E879898909D3F51DD64AADEF67C5A594B23ED5DB52447393CDA385FD8433D65C4E229A9C1B7F0E3E01109F98F118524280BE8005B8D
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v..8yx.H....p..@...8.Y..f ......A,. 9FF.......AZ..D$.n.30...!5..x. zQ\..@Q2.(.A,!. .z...../9.!+}.....<++.m._........\..F.]]].....###!...w?..pz........=.....%6..........e............Ys..%6..{.T!((...`.L.<9''.(...F ..r....jPPP@..G............_`..g.. CKK.3P...R..\@V.3...8.d...a&H.A.?'*.._.T.... .a4k.,....DL....RO.>%*..........IHH...<y..k.}..y.......l%%%..I....m......P[[[555NNN.40......E===@Y^^.....@SSSUUU.....3.......7op.#QQQ.%.u..........-...y..y...y....:D=.l....4..........z..;.9.;;S....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):485
                                    Entropy (8bit):7.287755682887798
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZH39xdGeZgokXp9RadGSJqlK+gQKNFUukbAY1BBkc:Hax1Tyok594wSJq0LUXff
                                    MD5:2DEEF8D75069483C6938D90ED54E5915
                                    SHA1:AAEAF07506F52D28699B8E08A80B912DD4FE4DF3
                                    SHA-256:CD0364492E6D8CCC7D9F7C010109FAAA4209E89F1A81A475AC4BF1474D77F131
                                    SHA-512:B73A3876BC2DB077AECD7183C3B1BBCDBC204404F47BFAAB28F677F5DF0CA03FFB1563A496769856157E480D19CF0EF611F520D4AE2247BDAC527E1585C00037
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....rIDATH....oL.....>W..M.~.<C...._i.t.(.D.`.......t1.D.6SU..h..Lm.].N..&..4.......p.....f...&..q...<C ......_....Cx..7. ..4q.{...8b....6.`..b._q.....g.g.x.W.q..#.h...X....h#..V..m...*>b.s.0.@....G..>.F...F.]..Ib..6|..X..^a.?.@.].3..x.@..M..&. .`8U<......E .x.=v...X.n.+X.-$.....l.4.+A....b...y}J>9-.O.....QT...b....+..c...NF'...N..L.*....Z!9zZ.d..%J.(Y.d.4.+A.....`..6.0....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):615
                                    Entropy (8bit):7.493522472360833
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZXp9NWkENMuISGwgrprT3pAkq3KtSS0L2481z:NKaY1GwgrxZB1SS86z
                                    MD5:1B0D3D27E658381D0EE4A03471B9B6B2
                                    SHA1:2695953AC84F774608F89259A9C7FE9F726DD7C1
                                    SHA-256:304A95FA52102AD85438BD787D8F987624147583B0217CE9A88ADEACCF2ACFDC
                                    SHA-512:784F83D1735727F86D93F8E21F8B143CCD0877BEFB3597265749A844354E485F925D2C3680E1468E3333E10F56A1A117DE20E68ABBBB8CC15FD9D76AD4FA3B04
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.SMK.Q... ...5]......6..[.W-..P.@....Z..... j.."F\$.+.I..!wB...S/.......8.{........Y...,t..0..)...yk9EX....`@.....#.|.h.B!....,.."c.......1+..o..6.=.U......EN..[k.IE...o.lMQT..x..i....fQ,...5..r..1.66,....aT(..9SL&...k....~*.|...?.z0.d2H.T*.....h4.6.Qcm..F6.|M....Q2......=....!..Lx......Q..|...|.....F!..j.<...l..y...r..V.....*.$.....+....D(f.DQ$...."....0:...o?.H..f..w:......A...:......D"A.B.I..#...n.K'x...#:A..t.N...~....p8.x/....a..>..ql.|..^-.}l_9BUU.+.....i.f..... .QU......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):851
                                    Entropy (8bit):7.592368176556942
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ1nSeXaEu7xD+up53sQBpStE3s1xka2PuXAQad9azNDFpnD2qL5tKbVtl:NKaLzXaEudiCNS8szDAQa/G1DHeoi3
                                    MD5:FA956F1A722FFB5D96710094E8D510FF
                                    SHA1:DB54EE566CBE4045DDAF78F98BF648DC3B6C2013
                                    SHA-256:177D3183B5C677C5A6E3308DD4B8846DFDE8154D25DCEA61C50807EF432ED457
                                    SHA-512:13FCDA8618266DF5228395EC6F8CCC2BBFED32E613F3DCF1BCDCF056E1975393CE2F44AEA3FAFF5B8E39DF75103DBED1CA656D9DBB55A2C598EB8D926747A6B9
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...MHbQ.._I....?....c..Q"..i#n..j.6.(\.sQD02...a\.(.e..f..."...E.)-.J.2.ox..2.A.s...9.s..........D..L...yaW\d........G...CR-//.........K...b`` ??...uww.KYY...Z.^XX.?#i"r.. ..............vuu....6...............b............&..J..D.......'A...zUU...V............Y777KA....9...Tl.....0....".,--.....Ur.z....l6.Z\\L.......D.BVVVjjj8...566.yr..LNN..W*..B.T@.........E..E.T..!.).@ ........|..........@..C..`.....}...-..f.488(m...$..........Laa!.@.i.......tJ_.C.Q]f........F......;....{...D.MLL...S.....K.###yyy.%...A(......H.....2.@Y.......B.?.Q?.}}}. ....U......#...h$..(..i4..T1..`W.........%S.h.......X,...T...M&....0g.P(^.w...?ZZZ......2...nzz.b..JCCC....?~..6/....v........q...xzz.z||...........{..<../?e.......{......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):611
                                    Entropy (8bit):7.381981068805649
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZOvGkAZd9ySe77yxJCJjH/FZTFxtD87UCWxsks9:NKaaGV9ydaxIJjfPTFxtQ7DWxske
                                    MD5:A6180E3C24B9C22B27B63C6AEC01B45F
                                    SHA1:5331930AD50DF8F1871AA0E6C212AB41C13A6E41
                                    SHA-256:B78549B89540C61655CE5777848B6CA5F2CEBB5DA4E71783D6A0B9F107F6BA72
                                    SHA-512:0DB4227A51D3016BC7327AEF978EDF1C634B8B7B806836E0312ED6CD5AD5BAE5EF0E8E78FB5380A9BCD31BFE4DC70D08B7A3C644433A5D39801E357FA57DC24B
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v.$......"@q. ....={......7...2...........=C.O.<...gcc...<z..3.@..f...`dd.....@sqy..A666@...'.....+V. '..}.t.''.O.....*....1h.-@Q;;; ....@...2.A.v...k.............=....:..K....r...."ooo...k!\777 w...@..wYXXXYY.2HFF.(z.6T.......................;......9r.(......;;;33.c...h.n......?...............RvMM.P(11.9.O.0...qq.........B...h....e....Q....._.:t..b..+@...4...v.z{{....X....O.........{F..3.......?.......g......N..l...V5[..V__.....$..V...r9._.yM/...8......9....X,....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):718
                                    Entropy (8bit):7.57373170308176
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZVWu4GkCDzCsgwe6NJXfINhjYlEN3wrhpKN40X7ODNfQ3mgCLajSlzgHc:NKa/WuBbSsFe6bgNhs+lq6LX8NfQ3mbn
                                    MD5:DD2A12F20833DD086DFCADB2E1AABFBC
                                    SHA1:57255E0D800E248FDD20D91CB40CC7EAB7FE1CA8
                                    SHA-256:787365ECA2AAD7E65D6D9AD02039E3311011801267B0942DBCCA3BE1FEA6E430
                                    SHA-512:36E9D49CD3A31E4428D8F2C92A66CEBA516BEBD62AE16A59EC7DEA6A85E664B0AE475F2B2C6C7B0E196168186059EE703D86864EFACB5B21E198D0D7568C8977
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....[IDAT8.UO..a.'....H.Cl........(..E9h..`m+..D\...\..H\f..0..q..=......2.3.d.v.....{~...z..{........P._Y.^..so!.S.,.n...D.Z.E..O..v.....8..x.f..m.s...Q.RY.zuu.\D.6.....ZK.I.=::.n4.7.....Y..B.P..^...........<...5.L......9(..+......s5&.?....V..P.x\...d.......R..l......... ..~ .(..{...fP.t:...@w<.K$...Rk{.u:..R...d..ju>....h.V..V*..r.\.^_...{zz.`.X.....b...Md.h4..d2`4....[.....tv.l&s.1..!..F.'....d2..b....`0....!...9..J.F..L...J...l.E.....*...1.N.....r...#........@.D...www.:<.)..8.........N..M .D"..SS.......<jk..\._f...h4v...vk/.R^.c......2.....?;;c..KE*.zr.k...c....{.. .....__....~......?B'......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):660
                                    Entropy (8bit):7.487874226621958
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZVAK4P3gx4QREhQS/+2c5yPScNhFV4Q05cgBNxRzHtgWX6/xz:NKa/Aj36HRCZc5ylh74S4/RzHXe
                                    MD5:74F875662E65E7AF52EC157D5089C563
                                    SHA1:5B4034DE6733C742CF7624DB0639B4C73D824CF8
                                    SHA-256:8AE60E1D38A47D941B714CFED351BE466B3E3EE314CC8B5D11B030141952511B
                                    SHA-512:F01042DFCFB45DA3F9F3FE6C0D7AFF9891E727C351C7C959D8FF994E89031F7973424CF5CFC1B1131B9D00DB8A0FBBA15522C70BFEFB07C922D219F5BFCC24AA
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....!IDAT8.cp.v.*....#.g.....A......n...$.GE...T......a.7....rSE.6..WRz...3........!.....TU.. Y).^*,...K.]..........w..._..H...300...x....ZL.......>P......$''..b... {{{......4....`.:.:. x......7o..!}..q.ziii.t......?.>..Z.j.P=0....NK.bg......}`..&.\..(.T3..:MP......qq.tp]Y...2$Y....A...!R{UU.....Pt...{.......[...YY..4..e...AEE.qjj.......'7l.PZ.`.d..-,,.d.".p.4iEH..];u.(./..s..AFF.k.w......_.4.d`&.. ....,.r..$.`N".<....j.o.Z..f....J....@m...7N...?...S[...W.....VGE.QR...I/...,. ..4.......@.L....I8$...d.>:........@..}..g.O.....s........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):643
                                    Entropy (8bit):7.480465914810552
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZFU97Kxp0H+ub868kN826ZTjoviqY/qVLrjYJ5Ta8zo2lQWl7:NKaTU60H1868d9joSyJfYJlaCLP1
                                    MD5:8F0A3E1C69420112A8B9A5E16266D75B
                                    SHA1:D23BFD6EA53F6E37DA64FC75630282012B6B0823
                                    SHA-256:6722E529B14E2B1535D8410335F1BB7C47A58EA6D159DAF5CC9D3E6DB56FDD01
                                    SHA-512:DC4FA2A0E12BEAA4FA34D1190C12BDCC651091E7D6E68AB46CCA279D1BB8F8A2D4B9A9A064208D6474C4E0A3BE15BDC6AA46DA551C93D5E4011ACD5F9606D846
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..?.ia....R.1.l.;0..a.,&..2.K.LJ.1q.n.{..p'2.D2.....@....o.s_.W.s.=.<'....|..P.......|.......(...*...EI..v.}y.|>......t>....X.....O&.. .t:E"...c....%...v.gA.{u:......W.....Y*.f.....Gt...z](.t:..."D./......S.o..$.N..j.....&.....jI$..z..s.`0.x<H.....O.......j%..r..\.^....H$.B(....n....>.p...u.\.0....q.ud.J.j...xd.B...0....M&S2.......e0...U.TW.../......V.j..(B.....6..v.. e.4..m.t:-..x..f3...f...F...H(.2..b.......f.HxXl..uu.\.....L&3...@.....Cgo..D"!..'.....t.^_,.O.r8.*.Jr..#....LFm4..B..V*..M.."......o.._...+..4:....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1124
                                    Entropy (8bit):7.695799649655058
                                    Encrypted:false
                                    SSDEEP:24:NKafNd/+lwL9BhhL9tTGBQ+v90hFTgMPRvzPVy0T/c:nl5Bhh9pB1TTVvzdy0Tk
                                    MD5:793FBBC1B6A023311972D56E9B65B751
                                    SHA1:79EA32112C777BE797D88B3F678B736249696565
                                    SHA-256:4B7EDBC9DDCA89D277143E84690C043639C21E1707381838F0E0C33CCF10FCE3
                                    SHA-512:134659E779B738C020EC57A0B702574AE0B8E14C42D8BCCD795F39E93F21E181BE7ED2F3E0ED96D77CF83938AD60ED68431455B8623B80D18039AEB2D7D7C170
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..YO.W..}.B....\pQ..#."-...)b'..a). ...5.P.bl.T../..\..JU.V..#..m157i..8M*V........C..8.7]>.Ks.....[......+..>........?}#.O.P..v.a........;::2..---J.......A.R...,--.4..q....%.HJJJH..............|........o<.,...x...5......Gnn.XMMMX..`0.......?..!c.I3Qn`.b..K..t:E 8{<...l.......A.~4sF1.$;.O.8.xrJ.Mf.R..........F.......G..Z.bg...?.QM_.WWW<...b.X~~~aa!r....n..{.i....h.....@....../--..OP\.<.....2..}.4..d..xo_.V..[..@.@.....t$@....2.(sB..<..!j.o.....`".-.......t..(.F|.#.....s.D.)f....u..!R.......N......Q..xQ'g..<k.....n.@.....|k..Bh..L.....a.1.5.=......c6[.....[t.d...mooO.Q....Q[[..GbqQ...D._7.p..V..%J........r.d.Ao.....2t..._WW..z.....4*u125;;K..\h(D.......Z.d2......[.....n.K...zp..5."..!...-7[...q>.C...&..&..gq......\.QEE.J;..}....'?.../.q.`.h.......z{.Y-..6{.(..T..moo....k.S.br..ol6...../.F.m.6...e...K.U....ZYY..2uww.d....>.........j.Z.. ...i........u.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1122
                                    Entropy (8bit):7.744597577510679
                                    Encrypted:false
                                    SSDEEP:24:NKaGdleKuX/r5iHUhbXs6oPk5t47C5TC6FKRIeDi7mL+Zk81:n0fU/roHUhjFH47yTlneDi7mSZk81
                                    MD5:41F9CA64544CBC78D910C5859776EB1F
                                    SHA1:ED50839BB9A9E0163ABD62607035F73F23002179
                                    SHA-256:7F8A325E13B5C36EA2AD0E13E860F072D5E5246D44758B3750E0153316E2AB79
                                    SHA-512:1222110B06DD2C988EFD5150F3D56839EF26F16B39E19FEC71170D6231832F4B21E12198F310F3F4D275D0B468317AAD6B994299431725EB462B12929F02F24D
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...OZW..I.1...'...K4./.9h;..g.....X_(f.5..!..2......ef[T".!u.8|.....>..F/...\........C.....~.{..\.|.........9.~C...1..$...b.i.......<....z....M*.666655.d......e...._.rrr..AYYY4..............bL......ol>u....x......e..Vk~~>X---..E..TTT|6...."....Q.&.....L....a.......kzz.l6.2.d6..CQ.a~..%.g..V..H.kkk.~..Z.........q..8@1:...|...:......D"..........b....p..,(...a#HR)Q......(.....P^^n2?...9.... "L...$....J...;...zQ._.n*.B2;.t...$. ..f.....U..].....%.^...J.1....-.,.!.[f....m.H..S.......n..A..-...dwTWW.&.x...-...u..C.\j.!.,B.a&_..:...."..V6.L..8Q..@D.5fv..Q.>E.ggg&(..uuu.....@*;ne.t......~...a.....y.><<\\\.!'t.xRT...$M..."408....r.2....(d.RTjnn.J..2..zs.T?..uu:]$..4.....c.b..;.2.FG...~.a(.....n{mm-..w.y ...)..V.o+.o-..}XUU...Q...........W3.@.......p.`.s..-S..K.(h.OJd.n.....F..s*.B,...dBA...x..Q.a.rA..r...n...}.VWWqy.......D...<.p|QQQss.\.W......<m.Hs5Iyocc.>....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1110
                                    Entropy (8bit):7.74470888827379
                                    Encrypted:false
                                    SSDEEP:24:NKahYvsE+ZScsGdj3+dASuXETYYVSr63iGYHV:nevsE+Z7Vj3+dEETfVSr63i/HV
                                    MD5:69B272E8E1083CD45E542DE16F75BD08
                                    SHA1:42E188086C45DA6AEC1B7DD707E9960446F0AF97
                                    SHA-256:458795F436359E7C95FE00F29A4AF65F5823FC952C77F979F901DEE9EB0800EE
                                    SHA-512:1377EA697694DAE2CAE2C86150938E2A2FB69237190123EDCB3795A1549502EC77C308478B9226A372D74F92F5831058DD06C110C66CAB6E394C3307ADB0B4F7
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...OZW..y.1...'...K4./.9h;....0...Zc}..U.N.....0@+.R3..mQ.4..m..M7."]..36ui..\..u.{/0.....s.9.s..s.. .8..?..'...|yl..q..5".d2..fc........4i...F....M..766655)........h4..8......Deee.H...t~~........1./....x....2.......@ ........`...`...NWQQq{....QQ&.c"Q&.5....b.2......n.;77....i........D.....$.9...F.\.......O.......TVV..........+...Y..W..j`...'...@.X.........M....."#..f....o.m..D.@......r.....A'.%.fH.........j.Zjz*...~D.W.7.r!...f.0.b;T..cf.....Uj.$......@....34...a.Q4..zt..L...(ZYY.hgw7. .,PJ..U]]-.........z..J......yG.X..)..H.L.A.He........r..9A!....A.S.wvvf.h.....'.d.wC.L^...(...I.a[.......E$...K..H(^.............y.0.N.P."Rsss.4Q......o.wF............/V-~tMY....../......z{mm-./r.Hwo.cJ.r..;Jo.K*..TUU.jG4.......'..=.......-...(...?..j..v.J@A.|P..qegg.l6#k..".R).X,.....@.......s...+..........shh...W".........]TT...T*.Z-.B.X.M...').nll ...p,..p....k2..bq
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 32 x 32, 8-bit colormap, non-interlaced
                                    Category:dropped
                                    Size (bytes):657
                                    Entropy (8bit):7.309095706915046
                                    Encrypted:false
                                    SSDEEP:12:6v/7snWuEHT+E7c3c8BysPpDE37hekuxNER/P9q3+mpiav3p+/a8mqi:hnci6oc8B5pDE3tekeNM/P9A+mp1BH
                                    MD5:A3AFA72C0D4B0924E8C5728ECA8FEA3C
                                    SHA1:DC6A712205AFC34748AB86CABE304DC936823328
                                    SHA-256:5148C375DF089315451A3EE3691F6773712D43F005DF0C31191CA3D852940455
                                    SHA-512:42A6E3C4CF6454D520AE7802717E75FF3A6DAF6E47418556D0F626F7E10B5AB15492E0F239BC334522EF8D3BCB3895ABBF903A6649DAF970A411DDA6A018AABE
                                    Malicious:false
                                    Preview:.PNG........IHDR... ... .....D......KPLTE.3..3..33....f.....33....3...3.f3....f..f3.33.....3..3f....f3...3.3.f.f.3........IDATx.S..0..cg!.0...._Z).....8$......{...f.0X.{.....%..lf|..%B6k(.s.....U.*...."vn..X..-X.+.bw..+X........z.........../..gg....fqX].d.....A.P..M~.E....~.;5.._...:.....#.l.r...d.&.......l..H.".W.8.,..f].Y.[f'}A<.O"...-......x....I...:.z....7.jE..Z0...T..=......n.\"E.M..T.M../.,i..kP.d2.y.oE.....FK...3...0.;..>.....J.&....5.]YE.G..y`t,@.%... .3X..>.IK%S....N..ZB.Ud...$........zM]r$S.-...+.}..]....VCC..&...`#.....8m..m.8..]*...uTM.j^.....".f......d...p...._.,.e.I...[..XJl[\7..{.....}..............IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 60 x 60, 8-bit colormap, non-interlaced
                                    Category:dropped
                                    Size (bytes):2267
                                    Entropy (8bit):7.881694929189102
                                    Encrypted:false
                                    SSDEEP:48:mwMgXc66itTkY4WZDeA3tM6wNAju7a5iAg73Faxf2HSDrPgIXBTubVALV:h96iBzdKIMjNAC7aAxVwWSDrP/TubKLV
                                    MD5:F546D38F79F365A25D25DCF368659993
                                    SHA1:5171F5E47F17F8CAAAC88136BC84F19521BA4C9D
                                    SHA-256:3B32D6E3719136CB5B949F11600BCAB6B3E757F86507BB366129A9167E7958F8
                                    SHA-512:ADF8919B58851F7DCD9642306A1A0941F8C13433EC810E3CF10E186A930A88A67283DD6D2443352360093F553304CAE1419049E58BFFDFFB00A892849DEB56E8
                                    Malicious:false
                                    Preview:.PNG........IHDR...<...<......")@...`PLTE`.....s...... ...........1....."..3.....C..2../..H..X..>..B..K..^..k..X..y..m..z................U.Q...6IDATx.=.....A.K..F.........=..Lw+I*U....R|.z.K._..0$...h.\.Ik.s.........sr..TLC^?:.N..h.u......./.....w21.<O:.....Q.u..7...K..^I.8../.........m...x.T....b..c.....]r.....D$A."....4.5.V..a....DZ..z..lg:.Kr......RJG..>.......M.!.@.|...X...dj.M.b.....x...&..y..!O..$j.."5YM....:.#.."gn...S*...:.s&o.m.r .. g(.......H.8?....`[c.....'O..J].f......c.....K*...8S3@..^.DSF.....@M[Fm..S.G.o.zo.>......).!*.u..)..>./.9...Cc...z.g\.ey......kcJ....!..?....5Ig..p....|...z...;..f..4..t...M.P. .g..T......r...}...Cj5.D%H;8S77..l.\s.78...@....s:c.1`...*..t..'.w....................5Ad...*5."]...Z.~..S.@.....G'y.#.z.....Z..:...@...i.|.....u.S..:!.*p...P;.9...4.Be.E.ZG..-.....c..:b.(....g.=rR<..o$..q.f......m.........4...#...b... ....C..j...5*ts....,BcQ.W.1X.U.......E..9Y.J.1..<.y...e.S.^...7.s.Z.CX..y...,..5.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):240
                                    Entropy (8bit):6.542858130603722
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPW/sj+aWdKcnASF6oBgB6+cs57kvZGe0Hv4gfK4dp:6v/7uk3aZfFRNImZGepmz
                                    MD5:F93C1E09DC0859289D652FF5E64F9B7B
                                    SHA1:45B1899CF21E0744AFC9303C391996555E889405
                                    SHA-256:C20798AB61B591F83DD6CF5DA97BE1C2A0B45ADB7ACF8C8A91186E62BFD1D2FF
                                    SHA-512:02F1640F5FA5A99D7ADE18211461793EA3B1F4358B3AA8F57BC6F07C8BEB6BA71249DF17B713919E4A1E674B8AC4664BD98B9F2CE29CB8F466E686163A9D4237
                                    Malicious:false
                                    Preview:.PNG........IHDR.............V.W....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....}IDAT8.c```.O......F.". ..A.A.\;..}?w..._..3..=`6.....6.,.............M...M.......7....X.v......Ez....(L...A.@.../.X>$.......gR.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 18 x 18, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):282
                                    Entropy (8bit):6.749845265114627
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPi3sj+aWdKc9E66EFcDvUOL454DPBcZaLp:6v/7aOaZ9XPFEvBWOPBWal
                                    MD5:6315C61A230ACB18ADABCF018A342F0D
                                    SHA1:D94D92C8560D0FC391A96AB7887B828610A3B0A2
                                    SHA-256:03E217B1EB5E03E2917DA62134DEB0D3E5D7316148A23364B8CD42089BF99A28
                                    SHA-512:B56DDE8172AE74D106649550AFEB51ADF862447C7C89A45822F7BE23800AB338B0F8722743717F50BDD31AA8816B302154FC1E46D3FA4F714EC7C6B34774AA13
                                    Malicious:false
                                    Preview:.PNG........IHDR...............F.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT(S}...A.F..(. $$.8A.8z@cP.B...@`h......q. >.B..9.q...}.E!.,...6&.......U..Ml<P.:.[7u1....4.t....7?....+.s..W.-lS;.......C...@.F.LQ.....E.wM..j.F..5....@y.(.7W...........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):650
                                    Entropy (8bit):7.525427473885113
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZBfrOPSV4jo+HvWCzb7gYwbhcS9j5c5CooDLbWwE7FAYy:HaMSwpfHgVhco6yDLbMWYy
                                    MD5:32B5AF351BD79608E0B57A7AF52AF882
                                    SHA1:AB99613C540A1F58DE446F462DAD45B615B900F1
                                    SHA-256:FF9A453714CD54E0697FB29C3BCFB00ADA60E703AC533D174D3B3AB24E03E045
                                    SHA-512:22B99255E587800F17D3CF09F01B24C3E0653370EEBDCA8C4B9244E6853E3A76F57FE9677226FB39D07E2DC5747C8E223FADBEEEC47D333CB385D20165855FDF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...M.Oa....0...z.#5...F.FJ1.!.K4...H,.B6..b...[...P.4a1..c.."Y........al........9.9.a.6hp..d.<..d...........]j..557....Mk........#.f.F.gc&...-.(..l.ZL...v{e...l........#7k~x!`(v....4....R.B.......1)'P..tc.......Q.f..c\.q...?....B......q.o.S...4.^<G].^..............k...h.[.....q.g.._.6...<.;!..C..?../8........H=..$.&I....AD...Q...bTI{...Ab...p3..W.......&N.&..".Ax.wt.W......`l~2M.-y....Akt..(..Hq.V..i....&Dj.1#...]Q4...?..$9...3.......V+...9.S..%.0.E.N.....#........$..?y.6.K...cn.6G..*..4IN.C.?.o.'v.U3......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):584
                                    Entropy (8bit):7.443760110402973
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZot2v4QU1zBv7P9dLUgZbpWupPzNw6mxZH/08t1P007:HaW24hlB7VGgVsup5wF5/08te07
                                    MD5:C3C3A26EF1B07274D60A2E4C4A4B6B5C
                                    SHA1:F025C2014A32F582E7CA6292A9B1112F30850BB0
                                    SHA-256:1A1E6244841FA12D283D584871FE4CF9EBB5894FD0C1F01D0BE6DC466E6670B8
                                    SHA-512:88CABC63789DE2217B56FDDBE0A417CAC3A2322141C0D061D9AC7A3486E0A6943B9D9F6E47C198D75AB7999751828EE526CB62DB2BC28F76389F076588D97C74
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH....K.a....&......m5.dB.D..*..HHT4D......A-.$T..A \...B.eI.Dp:...{........y..|x..a.Xs.e......{U.UjN.$.b1x.^.,.[+(..p.\*..w~...fS...x.7...h.....A@.T.l.Dn.....r.W...5.].a...-"...+...9... .2.k@.G.%...... .N..8.<.Q..3...om....,.~?.v....dRwF...S....T*..e.*......?..h...S..\...*.d2.....4......H..C.P...A...m...M+.....)f.X.......&.. ...a.?y(.L...x...N......N.\}.u..`....br..o../.G...X.@...w.\.b....GO..bZ@.w......s...................%k..V..H...7rh........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):209
                                    Entropy (8bit):6.261838814231255
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcFNyLk1p0sWwIOQdReJljp:6v/7saZbyL5s8RkJlN
                                    MD5:6CA3B19B68C7FA450B3362F5B0FF8414
                                    SHA1:BCFC66DD1CC0A4E15C1BDC102174417657A5176F
                                    SHA-256:233240163DB2E1D94FDF069A93BD627EBB2C105A17BC80AEEA26E776D1D5B707
                                    SHA-512:D8A6761172F7F70589BDAA7C8E59CAEDAA69B81BACD690C7D897E6A2DCB49B267B20B82881B0F22F10E51AD387273B9DB660EDD57251AAD7C04EEABBEA63AC34
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....^IDATH.c`bf.......j6....n4.P.F-...\.........UTH.A........$c.>.,.....@.F}0.Q....Z>.yiJ..........>-.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):723
                                    Entropy (8bit):7.57625040753958
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ1N+upwspJ8n2ecPXE91cj5K8D1p1wOij5qJaDV+s0cC2nLDpC5qucjm0Q:Ha5nwspJacj5nDn1e8aDV9DIQVwyGx
                                    MD5:B4C9FE6E0A3AA30C04C87C7B003602F5
                                    SHA1:6144B19A3E30264167C13C09C13E27C62BEDA708
                                    SHA-256:5650E680DCF29C4D1648FDAA45A3AD06720A263E3191068D2B32F3518EB9FD73
                                    SHA-512:BDA82471C4118DCEDD91415D27543DB21FF075196337653C53C5424011BDF18E08FA126958532D95BDCA9E4130E71810AD1A453D0C6428707ADF78BC6118A5DC
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....`IDATH..]HTA.......]+M,4.....%...*....1.*..$.@.(z..|...."..."$J...QD_....PYAl.z..]........:...9.?g.g...<.:...... 7m./.......Gk^.&7.o&*.r....`.(.....E.c=.p.1.L.k.E^f....D.O...L...eKV.,...A..3.....h!Ql.&[ij.E..M.....n%n....FL?..<..Uf.H.$..MDC&=.:.`r8..{.5..>.-.J.T.".....!.U.^.n..iq..M.-..TI.sC.n...~.i.O....X~.%............MU9..C...-.......Ql1...c.... ..$3.2.4x..`......d&|........:...(b......s..{...$_.y.....}.m`Y>..n..h.2........t#pQ..!...A...Jf8.O...`.7..p..(9F../.....W.Q..t.p.......t...(....lE<.$...pA...%T.....;.m.....'T.iY.T........z./......!.........l.5.@.0....xY..g.fk.:.P...y.C....}....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):250
                                    Entropy (8bit):6.638352218274784
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPUb+aWdKcdAsmIcTHjwMaMLHilHDpup:6v/7+aZd4IcTDwMaMJ
                                    MD5:56790C420677CE6C7CFCFC7B2EC2CB28
                                    SHA1:674393C84C23CC6CEEF18C97E50C2F0C3E4914DC
                                    SHA-256:AF67E464FD386CE8085A0D030E02AE5EA79BBD369D209783E4B831E76849478A
                                    SHA-512:42E46FB28F9CFBC4ABFA9A2B617EA5457E0AD9A039096E6441BB93E5EE0B6C0424137422B25668CBA7FD8E8453E15476CD8E7BC214DAB1B033EA84558E88866D
                                    Malicious:false
                                    Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT(...!R.....7...!.L^.d.F3y..m....L6.&...F.......|.`......1.."..$...w.t..j..V."....+.A|......N..Q..U..M|..~.Nu+.Y...z.q....i.<'. 3.;..8....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1017
                                    Entropy (8bit):7.719031051833791
                                    Encrypted:false
                                    SSDEEP:24:Ha7eE4xJQFF5pGcn0y0BTO+CbelXhy7iJiIfmLKGlq4:67eLrY0cnV0BSJbe5hy7iJF63lz
                                    MD5:140858A57C162A09569D9591A6F1D2C4
                                    SHA1:F26E7BAA9C7F6347AFC25747901F5077E860D4DF
                                    SHA-256:026C5F82D05EC1C6DA5E6D0A14C9DCDE4D92593CDBB1A1696ADF0B3F0AAC27C0
                                    SHA-512:F7856C3E0608C3FDE4A9807EF7C471B2AAB7B76E31E768F2F7CA90C84BEA80A601691E10F87745F7196981F7F66C235B34B2D1740A61F525FF1CB701B78EC8A9
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U.K.a........:.I97)..'.9]..X.R...Fh......A...%+.@.D.De~.>..].U.....}...^..4'.>p.s.s...;.../.I5I.J. %...1$J.<..%U....y.A%j..l./....*.0..e.*.>....L.i..[<$.2.;...].s,...^..........g..6...v.|Z.9.JY.w..X..>..N=`..#.r....bu.C*A.._..Zo... ..3,.q..j.e.7t..v.a....2..P...pHJ......(..R.!.2..5.$..7..%.A........|.....(1..N..@Hh..V. \F6ppt.bj.) ht.d3........7..EB..S........9.,1...r..[]...Ko..Bp2...rn......7.l....D.q.p.4.,..c.F7dv....c......00.}..5...R.h+.>........$A..(S.R.j...>...B.V.\.K4.'r.n......4..W...`<....+...,FA..m.m.` ...0....o...j....Oa.#.C.\O.PfP.....*.b..(a.M......\!M.?.......c..t3.?.....{T../.W.......AK..c..:uRZ.....Z&?.y..-..zl.C...2S.]...Y......%X.,..0...K...%..n:...........4..~.6X|p..cB.d7.....$t(.2GBh*.:..e.I......@.J.......P.....;.........~nD~|..e=...'7K.'.Z...?J..3...K..2~..o..^X..(l 7[</.#.t....5e.H.;b.v0&h..>rq/.?.,c`...V.G..D.../p..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):290
                                    Entropy (8bit):6.656455341947266
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1NIzrdlOuVxJUqKxxnz0l6+PY5zbBh4WGp:6v/7saZ1NAckxJ6xnz0A5bBh4Wk
                                    MD5:118770F7532B07D3952A4F23352A1640
                                    SHA1:05A0C13874E6FF9918B02FC67B5334CE79A897FD
                                    SHA-256:D2D51C0920A4C2B93BB1F2EA0B15D4590229F55CDBE13F97A921D0D8CAE7C99D
                                    SHA-512:811A1A117CFC8973B4F5F33F635A86E0C174A0336640B44CEDA00B4A0E6AF44AA8B49109D2C81E626C71255F4312F56D198C1224E86215E824325F7B6E8255A2
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATHK..A.. ...?....r..K..(.2..)56.|.BB.#...cL...K...h..\.yiv\.=w..............2w.....J.....q[..n..p[....k.........7....yhG.1.3nk@.m...7.Q|.7u....^..M.......@$L.i=.........1..w....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1237
                                    Entropy (8bit):7.77646665153383
                                    Encrypted:false
                                    SSDEEP:24:HaF9PPLwE8RO6J7QMCO/LioxcAxJ0laMKb8VZRVkmV2EqlfRRuVCuaFU/:6vzwEuJUM8AxZbqV2EqdPw/
                                    MD5:1FC020764D36C7C31E71716E635EBCBA
                                    SHA1:CF3F930D66EADF8712271DEF957162420702D244
                                    SHA-256:8082BA775B8545275BC71BEC7A07A323F8B0C2400ED160C960D539199DE3EBCB
                                    SHA-512:26260EEE077587A872B03E5582593A8EF0664F16504306CC28A76BD82837F5A362064DB3209AE6AF1773394A099162CB74CA3FCAA34690C690A87509CD2EBC7A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....bIDATHK...SSW....B..~k.!,.d7.).H..U .....4.B."KX"..!,a.aMD$..eW..R.[..*T..S...7g....P;|xf2.}s.{...;.u..[,......Y.Y.:..E,..o.....8F.-3.~4m..b.W../..,..]..4...7.Uu.zCb.s>....{....~..-......Cb.....(._...$...I...8.~1..p.f.Q....~Z"...#F.......`.M.Dh"......KH..a..$B..#X....e$.G.$Y.M:.i...,......_.3...E..s.&9..+......Q...KHl_Cv.....T%z......Rt.......?P..-.S..r$9..V.....o.!.u...o.f.F..;..m`...W3;Io7.Uz......\.,Btw.....;.....6.c......H.....M.?{....(..DsT&..Io?.5/.;#....T..0x.4n..IF...A.W.6...I{7P..-!.....>7?..7rJ.Q. Gqn+=F...7...qG7T.gB.]E23.....1..{W../P...M...%&O...'..nO.\.".V-@,.....vs.g.e]...~ ....M....:...9t<..z...3......V..OM.0}.....h..SAj...2./Q....r..9..%.a..............3k4.rh...c.|7.5..j......^a...AIZxU.m.`..Cr.OL,...#=*..Y".....u......l4.!...|...^.X;.....3.h...{.|...a(.,%=*..)...,,.>.......?.^.4.!2......]...nY!+........8....if.u..c..0.<.f1cl.w......?.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):659
                                    Entropy (8bit):7.517554215764761
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZbnZUpXS04gdT+HiOZxAVMgstoKQfFdQFFWJF6maCFP5SWDQgdV6kpU7:HaIpX3aHinvstoZlzl5OS6kc
                                    MD5:F77CD33941835B968DF2C90B4BFF4186
                                    SHA1:35D64B698CB6EBA7739287CE27601B34D32BB648
                                    SHA-256:B79B756B866DC4B5F5037B993A0669294D5DBB48BA8A3BC74B49EEBFAC05F885
                                    SHA-512:65212BAF8CE9D5B920C0FCFC1F03281C72E686C3D88E57C45B8D86E39AF9B89D89978304FB82C039A95994BEC5D2A8C997DDF4014B70104D5451E6375E6054EE
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.... IDATH...K#A.._B@.A..A..X..r......B.Z+.P.P8......m..*.kN....BP..G.a3...l.ds;ow.8.E.<.dw..........A.;......MW..kc......"f..C.#.....-f.7g.......~mB............N..}.L....h.<....D.YOE...h..l.P.g.x+zz?.... .f.../..n.j...........K..q...$.O.Vv.......Wp.....~..i.E.8)..::.*.....TRt.3;$..Sx..k.....m.0.y..q<....4....<...#J.3..Z%H...#...'...n....0.[..bM..)B...V>..SCt`:-.....piY.....x?.w..R.Q...?...KJ.=I....A"hM.+`C.._.3....}..^.b.?...x.......B..).U.H.9C....N..U..8.Q..Z.......\.....'....&.C..J...2\. ......p,.......4....,../...Lq?..-............IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):870
                                    Entropy (8bit):7.67200330665294
                                    Encrypted:false
                                    SSDEEP:24:HaHPLV4xv0J1q7aRI6kmlkHUeJsk7ghDPLc:6HSOJ1m4IvmlCUeSk0Bjc
                                    MD5:AFD4610DA6393A115F4CBAFE8F3DF682
                                    SHA1:60A1B348B5DBFE3A513EF55BE3F42A475C28ECA5
                                    SHA-256:7FD6E7508D3A0C48F3BE40951E5B5A3CAC710FFBC636B34BBC22083BD50C2E31
                                    SHA-512:83E3F15C5D17DC4DEDF7D995B92BEDB461D037C2CBAD9E74582369D5F67E3CC2EEDF3686B5CB516042ACCE34E42C5698B11983C73CA27AF21BC89C4A828461C7
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...KH.q..?........,.4%..D..RA..K.N.!.....5......]....D.E.=.....iR.>Zgvf:l...P!.2..........I.#..T.C....X.>.....R.d.l.gX......g..."...7..@j.|p.S.H...,..n..K.......J.....r.k...r.y.R.p.]0)..9....!.... .|.*S.H...p.o.....6?...*..A.C..n..N../...w..W..@JI..MA..4.*L..L..../.bt.......e(.1'..A6x.*.We.&.?....3C...ce....nf....R...X.....s..wjJ.\;..U63......5W(...|......4W..S...q......(X..<.e....y.r....{A..6s..~T...72....-...^..V.b..a:......y.0..o.-..tC[+=.F.|.I..ECKp......T........@..-iQ.HT.....Y...M....vW..\.y..B5..U~T.D,../....xzF..p.......r...^....rH...:.G.x34A..(..a.]....Z@\3.xe....U...XA.R....8.?L.v$....B...Z.fp:EK....%R.w!....0-..8w.'y?..w#.L...A.....,/79.....y~.'.N....#..g-.jps...6.?.......h...^x.~..i..A.".il.o......\.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1156
                                    Entropy (8bit):7.777950812326851
                                    Encrypted:false
                                    SSDEEP:24:HaeTPKmVZYBRhgbi7Ha7l8teZoeOUYduJzhDihgCLheB6Y7mv:6oPvVZGLa7l+eZocYdipihlmK
                                    MD5:6327AD1155D27DC14AA190A9093686D7
                                    SHA1:A6EB221B98DC56E427BC162EC53A4CE52BDDA9DC
                                    SHA-256:1969339528585083FC6CFA694913BB7694640FD277E82FDE837C12C9B51D0D80
                                    SHA-512:EC46CA35554DAAF363B8123F65F8828C03179376C5BFBD39CE3D6FE22752BF580A57884A8FB3C9178F3989CE667E0EBD86BC5EFAC9D55447E0A3906CEDDF0548
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U{L[e....{K'....4..be]xU6TJ).x...x..N.6.D..F%.W|.%..d.d..^.m......0c .......EW.P......V@Y..%'..._...yT...aX.....Y..'....).z.|S-.%Q.h]...n...@...l.3.UAzJt@.9.b...b....4:......F.........9&....O..W.`.V...G..\'D..:........[z?,...C..d'.D.u.V....'$?to.,.t}Z...O..+._....3..[..A.q.nhZ.T...Z!.....). .!..%.....g.e.....[.=..$#I...XJQ.iZU........3.......[..9..0..Go....A...I.(..L.:l..Qwk1m.>.m...8<CS7C%"w.....g&.T..Y.../..$.6._8..:.a....`II..Y\...^q..<..f.1...1.......!......n.l.N.B.$.'p..E....Y...........^...M7..z?......k.fDlE...d..Z...R....Os..p.a..g.@#q'C.qD.....r..t.xN..5..a..FR3...#y......[.%...............9..A.W.x.1....UQ.#...bQ...._.3I.M]..N..a.cb..m....6....vu...sOAm].....,Z..g...\r..........2x.l.4`.$H^.".4c.`..-.3.}C<x....b8z..Z.. .f.f............L7.gg>4.s.m....:..3.....0..ld......N.'....K...b..bT...p.*h;Z.{..`..v8x..'/T..>7.R.ou:`CK..Zf..cB#...$...=
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):531
                                    Entropy (8bit):7.3285789129552406
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ7ZNXiDnAaUsECLZUsL2uBwVfb/CkvfgpThO0x:HaFZNo7/tbLLwVjVvgzx
                                    MD5:2D5E4D0268B968430FDED70E0C5D5CF3
                                    SHA1:D71A9138FBF82F629ED3A0DEF78DBE3517AC3170
                                    SHA-256:E28B85C25EEA6EDD302C2A5A3700356AE0094047DB86DEC3578BA3C4AA8BA0B3
                                    SHA-512:68F4A60CF016BD880B6D5CD9E57F4A71C3DAD8D38168D2300F6262364651B6D2F99A1ADEAAA948464D0CF602227AAC924879BDF59725E173558B08B6ECD264B6
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c...$G.v32..'.@.......-,......?yyy.z...ibAqq...........nA...M}}..........c..B1,.......P.v.1..I ...?@...Y..%...tA".M .......].H....e..? ~.$......0..v..w.E%D.>...'....-...k2.J..c0#.o.....X..C...6.@^...J..w.....]Pu.....{.G.Y.F!.A(.u..t.;......k".......;.......r.....W.]..jH...@}c..[...%)......x.....*.....ik;..../((....66{H-.1,.........^.:9]..^WW.?YG.b.\..mTWW....idee.KMM.KN.DT..li.....1.,.al.!1.../@.*..H....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):235
                                    Entropy (8bit):6.441444203662517
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1XHhCDOgRMsyHvTaMtXFc3/0up:6v/7saZ1XHhoesqvT40c
                                    MD5:BA344FC149BD007EAD91CAE0F0CDD150
                                    SHA1:22B94A568AEE26A2F19EB6EDF3BD25A919E0327D
                                    SHA-256:88A8F0798A54EBE64D1E9B52C6A620783DEAB93C9F99F9C192BD5BAC8DFE7FBD
                                    SHA-512:B68DA315C1C983DC218F26373513953921DC7A303BF8DAAEFA43966C6999CC1E2C3DF54A0CD2E3AB6060A495820AE4D88A5903E32CAFB8EE73A687E8910B57B2
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....xIDATH.c`bb..........3.......>....ZD...13.....E4.`..~..pp.._p.&....y.i.....h.....i....4....Li........i.GKS."..5...-../...G......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1148
                                    Entropy (8bit):7.7962229428423075
                                    Encrypted:false
                                    SSDEEP:24:raeTIXp57oJTC8qaI1Pn8mFB/GSsnUHjqAHiHnD4TO7kn1qE:2eT6p5shVryP/F8Z9VD0OQ1T
                                    MD5:002F8AA5E6487BFAB769EAB17E1AD381
                                    SHA1:E55094B347339932837AE346237A09A18A28B467
                                    SHA-256:EA3A2A23DC13D85A38E1C8142DAF6C38A6FA9AEA1D35B70FA3BC7BBA229DE1A6
                                    SHA-512:3954E35860364EC10D216457D9023ABA7D8B1F627FD59074CDC53371BF6B05E36F6819074E34A737F8B77F287472FB846C526815F2E7A7E3A7490D3E228136D8
                                    Malicious:false
                                    Preview:.PNG........IHDR.....................pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..mL.U....-...i..%.)...[....P...k..!.......xQ...1.,3~.%.h..1q.....u...F....x.}4...{o..[...$On...9..9.....%.L46V.....F.h..$<.{......r.......9.M.R.....X16.|C47A4..h<..{5X...{..|+...A.&@.4...G .GQ[..._..7..`.a..'..X1h.]....r.. ...m.....,..A.D.qv73Z...X...t..w?..N..g.`....[...: :N..wB"y........#..:%)..`l.N.\..s2...'.Xt6.F.9A.=.O.@&..U.......HVD...JI.:...."GLt8Z..sJ..x.c.r...-M.+&...P..2.mG.#.e....`..HP\..*e.^|!.M..av...S....a...~D...?u....~..=.(,.....!D.s}.D.*.#....`:.Q. GZ.....c.:-=......~........b;.:.a.U.)p...3....g8.y.....AX..E.<..(.Ip..n.x^.....(.I......&...`o.....6.....n+RS...^<..0..k.......m...=..h.S...d.GmyXQ......[.Ou..m......5c...+:....6s\.+>.....{...YO._.L..f....\.....W..qbcE.D..5..{.R...-..p.W.S.....b..4o.#r...).........>.,..u..nK...T~...OI..k..../%............&..........0.|..........7..X;.7.+.....P6....n..............q.l..tq8.I"..g2
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):991
                                    Entropy (8bit):7.682924149319847
                                    Encrypted:false
                                    SSDEEP:24:ra+QE3Wrr33ebPUNIEv0d5PjZrhi70avrNzLZ4Prj5DzG83zv:2Trr3SPU2U0drrUxJGXRzh3zv
                                    MD5:C07FCA4C320B5EC4430B70E71ED74278
                                    SHA1:076E6CAF7166255128329886A94CFE78AC8468CE
                                    SHA-256:ED0B60F7B41A49BD2D3244AA4ABCF6B4119FE5E812617255A2734A7DFA966E3D
                                    SHA-512:BB478600DEA79AF8F1CCA936529F404FF2306EB52B7BFED1B44D39BE45A3F6A9C993AE835B688A7A24BD2EC0A7261DC3FA0AB8DF0132DF67E3838785EC749D0A
                                    Malicious:false
                                    Preview:.PNG........IHDR.....................pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....lIDAT8.m..oMA.....T.Z.~W..EbA.$D$~$V........X..H...H,,$$.b.FB...$..V._.O.3s.9s....|....|.3.)..\..gua...FZ...;....V?.Hw.....s...b.m.{.(!..K3?;.`,.,...Ds4`tt..k..).{o...C.*... D.i..z8...".....^..=.2T.i.^.y......,...;C..#Af.v.j..P..*.;W...!. ..(..H.........N...$......L.g..oh.......P.....{!O.......0V_|E.,..8*E..l..!0.V..?.|.-Ad,D...l4N*........W....P.e..(.8...d.V.....kBX2k.|.U......c.(..K..6.h...7..t~].6g.`.i.........*.~n.....jq.{..=...GJ...L...Z%.]....,D..H[..c&.7...e.P)`.E.r....Y....+}E.K..-.9L.b0..r.......`..v.Ia.s.VT.)A...V.2|X..}V..I.....r... EL.C>..8&..pt.T.c..O5.WY..!VF.tH..x(.I..m.,..K....?..dC.W..xP.|(xUB9b....'...j2...7t.xX....A......<......h..\....x.i..-i.'....[.;V7...i>.k....?E.6.O`......l....$.t..k.q..A..pf=}D...CZ.<.TNM......HM.E.O.K.....vj..........N6....l...+.z&.....r.J...n.-h.Zh..-F..C..>.L.4..w......Z.e.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):900
                                    Entropy (8bit):7.673850601276888
                                    Encrypted:false
                                    SSDEEP:24:rauKrjsoCd/SrmyCEioFT8u3Aww5E4Fy+:2HjQYkNodk5E6y+
                                    MD5:8393CCCC2CBB476579353FACCFD27301
                                    SHA1:93977C721973326E4DF51C02ED49F7DBA34056D7
                                    SHA-256:850928AF483CB7777B661BFB39F7404F32DA374E64F2C95E1382E389389901E7
                                    SHA-512:2A34C3397D6725BE7AE6FFC568E40EF03F6CFFB1951511AE6CDDA843BC6393468BC79E7A23DFCDB69911A6A46301C631FE237ABDD9EBBD688250BAE4254FC9B8
                                    Malicious:false
                                    Preview:.PNG........IHDR.....................pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.}.OH.A..3.o..e...4..0..Q.C...W....u.R...[.V.DT...._...Z.K]..H:..<.|>wgw...]Mm.....g~..f9.i....../..r.O....O.wG117..3..T....%.q....'..H$.....g.k.J..`..E..g.q.".W...|..B2y.$9..k....]d:...,.e..H..;...<.e..+.N..r..pP.).>. |h.?..mS.ZHq.%..3.S...U..V..v.&(a,e<^3a3..`6......N..U....l@.I.H.$5u..H...(C."J.......>...r..^.Qa.T...ys:.6..f6.uW.qM]y.-.....V4\..XI.lm2.6l.Q.(...hLB&..?mCM....6.mT..&`.....ku5....s.9JY..4.g..P.I..7".32o^S]..Yk...e.h..\#.(...P...y..\.Vq..da....J.K.~.."x..B.2/.P.......PV..RT#.Z*......e....{w.0# .g_A..E$'...|.}.......#.R. WE..cX...X.!.......!E.}^.V).%..W..u....=.h...bU%U}..6\}P..pO.b.%.....s.......^......f.M..`..&..}..A/O/..B..C)...Q..BH(..L..'.|.X?..C.ug.F.I7....|..>.....<#.$Yk.Y...+~.+.`."@..A'...`b.D>.#..$.N.}?~..n.lsa..Z.....CD....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):363
                                    Entropy (8bit):6.930901404804559
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcZinYcYiLTlK9W2sLkwlhd8dDh1Tqs8aQ8oLOs5yiwfDO/1DJkg:6v/7saZZinTRTl48Ld8dXQEsuY1ZN
                                    MD5:E717D3ACE4F3A4CC0F19F0F16AD77C9B
                                    SHA1:6D57E2D8F7AE675CF02280039AA1E8CEB86309F6
                                    SHA-256:7692948887AAAA9C26069968CCEE53499AC5995EFB651DBB0AFD1FA98721B331
                                    SHA-512:46670EB321694455A525CDEA50DB6CAACF20966F03BBC4600733C1EDEC4C60BA0402D506642EF4E8AE342A53204274C8E33DE227D5E70662BFE894294EA79355
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```....i...1..?^...}.....U.._...y ._.......U......m.,.....=j.H........\X.@....E-...j.......r..`..#...[..'fdd.....o.......]aL.Vd "...b]...F ....@<..yhe.8./..@..@C...7.x3.....N n..@.....H....%...`f.L..........C...+F@...h.an....[...D.1..a....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):335
                                    Entropy (8bit):6.7357667016278135
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc+Aw68zIyo7kKoXYrKHJ/ooUinLoheHUZrp:6v/7saZ+A1EIEK1k/cicgHUv
                                    MD5:532FF39D96824E846B94267CEADFB2D1
                                    SHA1:96D8BE5BB519EF062D58F502BE22220E5BB1E565
                                    SHA-256:BCFB8AF5F2A65943901077D905295D35DBF2AE06F2F62BE926D3D33957E103A9
                                    SHA-512:AD087A5C1E50E454D9FBAA2F93246E026063B629E9153FD519EEEA46176870843C2708FD2162AC7E7AC8E7C152554699A5F67E1A5FCC00C19868677F7EFFF47E
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..d.3 .......`.X ......o.bi.x0._.._.b%r-.........PK..q.....? 6$.W@..e...s ....H.I.........Pv.48...7..CS...\..=Pv....... ...7..G ~FN...b.$.6..B]..|PZ......5S.34n@....ki..Y.X.J........!....c.C...F...........G||.&9.!....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):340
                                    Entropy (8bit):6.7888357277761395
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc7N3SXsnkhkoTozQWnfJk7kKoXWc/OA3m+RGmdANp:6v/7saZt8kz3fakKlQOAWu7S
                                    MD5:0CB0F22816427F3201F4CA37CC705DC4
                                    SHA1:55FBFC7E90D13EE02AC42351557F6E8D8A2B0475
                                    SHA-256:C5108D1F42D88E3A9E5CD68EB8B74FC3D13E26EDF22B1285D10505ECBBF7ECC7
                                    SHA-512:3F3AAFE715120E9743CD7BE582759450CFC5832888E444721934CA840FD213BFD614A02D1446498F6D5046408304BA04A7EAB5E64195EB77607C27FA6B37A873
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```...7...h.*.n.2....>.x......h.D ..-}@W.d.x;....m@,......P.@.Dn.m..eP.W..j...8..........W@..e...s ....H.I.........Pv.48...7..CS...\..=Pv....... ...7..G ~..(..@..]...@..u9..Ai. ...".,*..q....@\K........+.F-...p...B|.........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):232
                                    Entropy (8bit):6.293423098250012
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcvfGSFegwRcxvqTMFS1p:6v/7saZZKhq8
                                    MD5:C6BFC7B72C718727C2BF87766F7800B8
                                    SHA1:B122ACD8D0AF84A9D8980B3A5F48F2DC3A306009
                                    SHA-256:D74FA6B34AF3618EBA78F301727878259A53F8990D6E6297D6E07E183B93C296
                                    SHA-512:CEC41C876F4347C45377193D6C96319BC4BDC7204472B61E40DF99963920B2659E65B9C906EB97472064974B5194B88333923EFFD81C06687E14208550AC44F6
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....uIDATH.c`db.......j6...i.I.UTP0.uP..H..S..$Y@.&.Y@. "..X@.<j.., 7..d.,..]....`.....V.....X@. .~9...n.z..=......-...M.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):246
                                    Entropy (8bit):6.474495464903845
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcZwaRmNNhAYPY17ipmvMgl2dEPUTPK2Vp:6v/7saZZ1WNBQSgkdLTPK27
                                    MD5:7E3565468855774742364E5DD622C024
                                    SHA1:9E45BE9B0AB3D4DB30458C075D90469279C8CC62
                                    SHA-256:8D758CB95C80536B88655C8BC8E9C818F7E5AB0CF79C7048345932F833AD1435
                                    SHA-512:5188EB71C722CFF934A7AA1EF497BF7DB88B22AE683175032311B9A4EE3B3C07288BC166A66D11605D4632F84A6BEBC7072658F3B8BC2A60E75B033431B06073
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`fa.......j6....>..o....P...H.0..2.-........X...)...- ......J....AD.H..DY@I8...h.D.(.)*.I.3t........ ".. 6.)....h.l...RKgPMZ.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):387
                                    Entropy (8bit):6.929897289976686
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc9sQjOUzQuYHAPNQfKXaXWXJbZP1pwlzFh6CbMM+eY7TWEkmysh:6v/7saZ9rjOUUFHprmbd1YphLbJhAD6s
                                    MD5:BBB4B37870F6A541867E9110D055B888
                                    SHA1:AEB373F055D745985DEFA4CB29FD483808A7650D
                                    SHA-256:A75E8CBE29277EC6CCAEB0227EFB80EADEBDF550B91AFA4AFE11084385EC325F
                                    SHA-512:547FEFC1586854F815784852252C38EB275AE37A8D1D94123D09877BCB0F160635F44DC5484BD5D3A9BE2DEFA620A16F4A8859085C08D964091D1C8D5E777246
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf........C4..~.$...4.8.Y./........M].G.. ...E..0......v.".....>..D#.t..Y$a|..G2,Ba...p.].g^.....E.......d .x....rr...,,,..Z.../>< ..|E..|.<`...s....01....;\. ...S.\.o.......).$.../.( .....f.(S!.....y;._.a.a...9....0F$c...#.q...@\.X0L,.wn?F..e>.Y@NQA...\$.v.cS..r.t~....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):184
                                    Entropy (8bit):5.914742316746099
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl9vt3lKm6Kp0qRthwShLKOWGEVwfZ3lI9Vpqqpqc6Z8By2JPSdp:6v/lhPa+aWdKcfZ3Brc9Byu6dp
                                    MD5:E583A3AF6887154119FF083B97CE6588
                                    SHA1:6AD434AEA5E009878008E6526E9C8506D02F897D
                                    SHA-256:0A5B85EC82E5967D3EE4616C9A78D5575FF8B58F673ADA6D591767FF0EB22AEF
                                    SHA-512:B4B444340C5463423360CC46882FC44E9230E5EAA6352DE1AACB141FB6E3EA4B76110AEE3C0385827A732B7CB790C2E679D36B1A644506172A9944416C16DA2A
                                    Malicious:false
                                    Preview:.PNG........IHDR................a....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....EIDAT8.c`fb......`ZT....0.O|.F....C.n`..N..`.........0...".@Y..,.,.*...RC.e.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):217
                                    Entropy (8bit):6.353147907859688
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc9hkozcySr4le3S769Tp:6v/7saZDRYbosS7A
                                    MD5:F08FEDDD543516EAE3F7B62C9D83BAC3
                                    SHA1:272ED041DA4380BC804873AF98DDB04B92A13CC0
                                    SHA-256:2EA354C977EFDD92D0EE9405C2C6A6C7C64F3AB387A3C028B96378EC3EA286D8
                                    SHA-512:47617D22B303F8DDCE683645CD1F4374AFC06FAFC1611EB9B75CBC565A54722EB96747CA65DE6D938817BB1C2055C8C948402C983B66ECFC4CD08BB2E75916E2
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH.c`fb.........e..L.j.a..R...1.. . .&.]Uq7.....ZY....C..P.0..V...O.H.....h4.....T4...N*R..Z@.f..@.:..<.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):246
                                    Entropy (8bit):6.52071577801275
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcZwaShtwDzoAn+N7NbqU74mLl/Vp:6v/7saZZoEDnuNbv57
                                    MD5:CAD897172B1FBB2D28F561100E7A7324
                                    SHA1:7041424F657C2FBAFB5F80D0F836F5333AFEDF3D
                                    SHA-256:363643F1ECB47F52893B5B3A900531272D07779830F5E2E9F0B770D72D487C42
                                    SHA-512:605A567675C5A00CCDC4BFC89C02CE47E59EFC240FDD07F98636ACCFC43EFCE3FC6DE68A1311F72B7E5610F68E88CC94CF6055895E6A2537AF6266ED32CF99C1
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.cP..Z........E5.0L.....1....T..J0.B.......]..}....c]..n..8....A.T..g$i"9.p...........%..4.....3.".o..a.6..Rv....u5....8.....7.OA......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):674
                                    Entropy (8bit):7.4988813850995175
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZJjFKLsJxU5iYxSnez99FtYkViljHxjAMxmt8uuYO56tiSz:Ha/oLsJxxMSnez4kEPkMk8pYO56tiI
                                    MD5:EDACBF218BAA4FEA8ED05033B79B143E
                                    SHA1:E1FF7FE0F851501FED10115C7A84E3A5EA5C9890
                                    SHA-256:51D47712D9CC1ED869FF435A4CF371C270E56A4F1FA6E229A45C839D5A1B21BF
                                    SHA-512:44E7875D147AF1B6BE38C69BA422FBF38F5775B637EA2FCFD73DD2CD66A094A0796B747676228FFF69EF28892EBBE6573DDF8220D6BAB135D56A952E8AD6EABA
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<..../IDATH.c`........D..L......................d.Fn6.%..,..U...O...0-..w$.._....f.;...`Zd.....P..Q&.\u -.......P...p...wv../@...5\FPP.@Z.rb.E..=..r..Q..Q.j8.v...]I......$G.?....[...8;.l.Qqt1.L&...Z-...cx..jG..D...`z..j...........V..2...Q...vSU....`..N..S...S..`j..(-.......p_.[..$=2.....lO..........B}.ha8.. .3..A.....+n6.........mA....>..C."".EU...}..D....\L.2..%'..PjT/<'....67;...]...J...QJ;`.UB..A......4R....*XJI.......0^.....\\...l_..!9x.8'.9.Z.h{......uu....CiQ..4.......V.(.M.u.g.P..3xgR..ge.......:.........?..A`S.)..!&....3"...M&....2.e.1d.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):541
                                    Entropy (8bit):7.443697536656715
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZL0OLP/kHWULBku6CwxDgtVReWwoBDJq7f4t8qF99:NKah0fLFsa/JwcDJq7+pN
                                    MD5:A475B0E24EDFCB5F56F605AAC8A368C9
                                    SHA1:E915BC9E44218F1944183040F26622629C5C6669
                                    SHA-256:8C940165559EDD3C72DEC3259EDCE529B6BB3BA4E8F52C1AD891D2CEFDE11628
                                    SHA-512:0FEA7AA3D3D00C40FBDD62ABDFCE72EEF93939590BD1469AE34EB15F01440ED52C2C8B947B58EACED86CD418CB04BBDDFE70A39C48FCCDC756B4BFCA8E4D0324
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E..@..Rm-.%.9..g..^.3.de.. .=)....=)......._.p....?.....A.2"........i..no..7......$|.E..Y[..{..?!.....)8.J..4..1.@...;...c1....I.........=..../o\.O"p..jt.A1.MK}.Y...o.y..(.)...q.?.....(.Y.h}....n.X.b...K.0.....(.].=...]..$!.b....+./.j.U.<u4P.jp.q..&.....s..A{S".DE...C.AW..`I....;./ ..o.6.....|...My...i......H^rqZ....cPV\...x..,.Z.l...hc...o.N`Z.z...;..{ej/....Z`..z9.......3&qqp(IJ....t.O....k.Y..^....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):578
                                    Entropy (8bit):7.38626092430479
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZVF6PQlsbsrMM1Pfbds98uvw2FKcxAS28dkc:Ha0PR9M1PfbIAKKcxTj
                                    MD5:69B9DBE4EEDCD554CAD12943EE58547F
                                    SHA1:1D63EBA859CC3C088E30598751F18D59FFBDABAF
                                    SHA-256:CFA5EE1FDDF0C36165B79C14F4510B03C0F753AC3C1EDD6361943D85190B41CE
                                    SHA-512:FDE3DBC8A64632CA695500FA3488DFB3BD018501318D18E25F477E3DFF9E357703A6306B864DBE51D7590F2518ABAAE60CF5F85D2D9A2C2769BD209B4A456D4C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..@..{.7;.3.&..I.zs..EG..P.J..1.Y..10..L..:..uvn....a>.w$......VA.-'..... R.f.de..+!...0\x....}I..m...D....2QST......X../.N...k.....V7..d...K.}v..1.i.....r...I....q.5.'.].........4+..t.v...vf.).`.0...d.0,.fc{.J..Z..R."0,...=1.*..N.(....;..a.............`.0......d.}.....(.....?/;.zl.4L...(.Ez...Y..,`.bcy...D...1~8s2.Z.N......X.D.k]!X..,P.E..q...E.....~.J....|..*.AE11...*...DJ.....`.....7.........#8B..G..j0J......(yP>......D.r.......`..F..3........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):290
                                    Entropy (8bit):6.61847269335982
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1N92z4Hs1gtH93Oof2h83Yltmox1bg8DsENp:6v/7saZ1N9ess16H93p+qoltmSu8Dsw
                                    MD5:04E012CD1CE292FC0FD10CCC0E34D3F8
                                    SHA1:0F4F564426001D9D3D6FB3C81C88BBB9D774CEDF
                                    SHA-256:3B16633A3BB07E09FFE90B76BC9A51D89EF319FAA2B79C89DB5DB3CED7A6A3F7
                                    SHA-512:F3AFB9551A60D7D74104A520B83953BD47F9C858C36AC63C88A217C8A6ABCC89B1033BEC625DFDDD1C4584A41D638DA3DC6F14412F119BD479D559A89035D0B2
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf.....T..G...~.d...x.8.Y.[2-..A|......;....c.%U-...~.@4M-.E2z.S-.i.L.aN^...dFff..DY.R...,.1.D[....w.yUp...(..d...HS.@rX- .4%..bS.L.M-.E2z...d.- 7..Z0j....T$.4...!..S.l.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):927
                                    Entropy (8bit):7.674600493975985
                                    Encrypted:false
                                    SSDEEP:24:HaofdY7h6daHwKlYXMU2fSXaj3XFfGRRtP:6oFC60QKYcU2aoFqRtP
                                    MD5:67A41061A03844FBDC9E0A33F1731E5C
                                    SHA1:375D0CFE90F3C1FDB2AFAB06DDEC6A2678F7BAC2
                                    SHA-256:49E4CFD6C8D5DE852AB88A34137348253E7B915813E41B17D0A5BD4D8A26C010
                                    SHA-512:8D630BC7D80F899C053D4DFB9FC86A80E67C9C76E2248CB751E3829265DDEDA26F5E791071941D7C7DDD188A32925ECB11F38E5462B0DDDC1DCBDD96B79185C4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....,IDATH.TkHSa......ls+77.5B,#.b.n..(.L..V.E.....$..F.d.p...h^"...A3).2. 3.b..k,Mc..s.fts.W....]..<.{.......ai.ZA.s....ad(d4NZ.#.JA...4......(\.tXp..Rhb.Q.X8.0."n.....Y."....-...D.#....d...FP...B..#...D..$.........1UA}..L.]"....Fyp.;...b<....G.rX....Q?...F..f.......!.=..`%B^.!.[2=.......ZhU4....AF.tH*...8,......y.G...............|..M..,...]j..zL..T..}'.Y...1:.v .{..6.../".O-.,...F#F.LH...._~7.."A.&..v..$..n.A.49..5D}U..+..G...D.:..x..-.r1.K#....c.b9.....b.-.O....}...D.2....%.A.9=!(X+..d.K.",.=.v|..!f(..E.v...(...]N.....h'E.(.>...L..V..X....+.m.:G2$...p..K.t/.^/..F.I.N.."^..I#.MJ(d.7..3.z..x.J..x.p.LB.G....i).Q._+[.Ve$.g...r.`6.0.y..wk.s.jL7.....e......TWW...34.b. .j.........9.@.D"..j5*++1.}...!.V.#.^.....f.GN...2g.mc.....nF . ...*.}.H.9x...:.....^...m.m..Z4...[..V.v|....o.`.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):259
                                    Entropy (8bit):6.636436356860917
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKcBIusgGTFm7Laho++6jwh9lbQzq8llbp:6v/7aKaZBCm7mhRSQd1
                                    MD5:B22301F43B6332418B119E9F0A76944F
                                    SHA1:E1C64D59C00A14A2B4B67463FBFDB385A9BE7654
                                    SHA-256:3D3BBBB58E40420981ECAB1361A0B78068775F723EB684950D4D3C78A5D9A5B6
                                    SHA-512:FE206A529F48ECFF5FD1C27FD9E4D2D183EDA2143270F2F8385830CAE7C6E2D3C432CC31DEC4528044378166755D4062A3D04C5486D69FAB9964B68C8C992085
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E..0.....nf0.....2.\."..J0....{..0.2........MD......C......=.....f...@O`1..a..I2.g`.];.......5...0.............e..D..%.,yFVQK!....lmZv......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):541
                                    Entropy (8bit):7.443697536656715
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZL0OLP/kHWULBku6CwxDgtVReWwoBDJq7f4t8qF99:NKah0fLFsa/JwcDJq7+pN
                                    MD5:A475B0E24EDFCB5F56F605AAC8A368C9
                                    SHA1:E915BC9E44218F1944183040F26622629C5C6669
                                    SHA-256:8C940165559EDD3C72DEC3259EDCE529B6BB3BA4E8F52C1AD891D2CEFDE11628
                                    SHA-512:0FEA7AA3D3D00C40FBDD62ABDFCE72EEF93939590BD1469AE34EB15F01440ED52C2C8B947B58EACED86CD418CB04BBDDFE70A39C48FCCDC756B4BFCA8E4D0324
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E..@..Rm-.%.9..g..^.3.de.. .=)....=)......._.p....?.....A.2"........i..no..7......$|.E..Y[..{..?!.....)8.J..4..1.@...;...c1....I.........=..../o\.O"p..jt.A1.MK}.Y...o.y..(.)...q.?.....(.Y.h}....n.X.b...K.0.....(.].=...]..$!.b....+./.j.U.<u4P.jp.q..&.....s..A{S".DE...C.AW..`I....;./ ..o.6.....|...My...i......H^rqZ....cPV\...x..,.Z.l...hc...o.N`Z.z...;..{ej/....Z`..z9.......3&qqp(IJ....t.O....k.Y..^....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):268
                                    Entropy (8bit):6.55143743125411
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcDN92z4Hs1gtH93SeQj6fr5EbEn8up:6v/7saZ3ess16H93Rfx9
                                    MD5:0B4A6BCF1B7F3B6DB8D479908582E1A1
                                    SHA1:1371B68733E1B9238969509D051E98717952C730
                                    SHA-256:0F72CD8EF488DCA7BF8FFEFDF3DAF0C72C46EF6989769C8A5A03C56A7BE77E37
                                    SHA-512:928427CA6A9ADBD7B1C9F1EFE0EEEC0AAA2ED37BCCFA85D799538278EAB90AF3EC777CA6FA2836C77AF224D2151FAC4E794CA2A7BB8036A3D6D01C5863B6D829
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf.....T..G...~.d...x.8.Y.[2-..A|......;....c.%U-...~.@4M-.E2z.S-.i.L.a..$LRfdb.L.. 5...$c./......q........c...)%> *....r#.h..M....Z...-..*M..?.8...|....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):931
                                    Entropy (8bit):7.727893120799397
                                    Encrypted:false
                                    SSDEEP:24:Haf2bWSbQLIFlACUuYXGGIc3Xde/TvAg0SkrdRJXiGs9:6ua8VFlvUuYWGbcA3zdRJSGs9
                                    MD5:D1FAF83DDD2D3DB762FA66400F3AD981
                                    SHA1:529CFFBE0C1A8EBC5D08FB666C9ABE78B8A3C483
                                    SHA-256:56797304D5F0D0FAB060096CF9684BD68E08A983A23B1CADB6D70FCAE1029742
                                    SHA-512:777836FD29AA3E76006E1F5392ADD5FE9025776564E3924D513737D001EE6A721D5A65BD0C46F53CDDA9444798BAF10FF8567093D3B645755DD8160CA986D8EF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....0IDATH..kHSa...\7w..P[.;j^J.9.a^..K.tSC.9.)..d...).R..B&.2. -1..~....o.%*2.n.>.g.9#..|....}y...y........$..yBb.=.9..p.h....&....p..t...h.#`.Aa.,H..o...>./.`.].f'..%......[.S..."i.p@.e.~..3...iq.^}j.+.......s$..p&.8^.#..4Pdn~..).W.xiy.F'z..u>\...Y.t&.........$.U..*.A.6.z.o..!h.)_........r1P'..f.Z5.hT e...!b].Uq*......A..UG..DB..<Rlh....T.[\..b..UVx.$......".....T..\.0.....6...,`$....c...<.......No.M.7.A.f.(<..T.'..';....6.z.;.R..k+=..(..........j4.}...<.9..PJ...l..U........,....$......D...h...oOv..c.(?......P......R.Zy.J[n&.)r.M.9.c...J.N..co?/.k.. q..l.<.S..$D=...~.."C....a....v.Z.7ZM.pUQqqdH...[.H.flr.....,..........{...!.Q}E..F...!.S\..j...rG..}e.$.U.M.......1.].{...`7.( ......~y..|G.X.V..:2.#B.-.C.......".V..Q [.&e......,_S.D.O......n}.......3;.u^."......t..7.7......o.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):844
                                    Entropy (8bit):7.651683816838416
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZ05zJr10O0TpWcALKtj/CS3jhLDEbcsAJAXaVINYntL1ceBSk3:NKaOj1+pWRKtjaAh6c7JzISLTBSC
                                    MD5:AF9938CC5C47683D03024554D510C1D8
                                    SHA1:11807D39596C39B63B63C513B6346ABA558AE509
                                    SHA-256:BBA9239D1064EE1818FFC0BF018ED6C106BEAE2C94A8B1050E69AE775AFD24B9
                                    SHA-512:AE556984C55CEACFBB82B7A309B08339350EC10E61362D0FBD27C33EA850D1098C4863458D013CD921A23850317C0A7DA9257084FFC00848B73E2683AD946D7F
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E<.........n.$. ..Y..H#.&.D.k...$...bb.?/...7.....b.........................@....'%"..D....I~..O?.......s.v...p3q..4."`P... ....@.....^.........;....p...D..my....4he....`[[....g...+}...x8.n..)...y;.4...*4.......W...6.4......,.q.T.d.1..N.:./.S....A.i.!..8..............0M...j.%.k......".|.]..t...QI.4Sb:L...tdE......xS...8....$..XC..k.k)!*.U.`y.`....".....A.Av.V..k.mC..i:..`Or..Y....P_......3..U.....Q..8L...jw..05...;...''...$$8."|.yh.O.:..32b......$.Z.......q....\.....7...........k......P....j.'..........6;)..h...H...M..<....?...7ndgf.hk.:....bP..yVj.....? +?.Q..Rlg.L.P.....L..tp..iKSS;5e.Y ....W.^..,.....]I. ..4........3..j...m......#.{IB8.....G;6..............).5..8.~....P.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):584
                                    Entropy (8bit):7.460976541370829
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZot4eYqeQtNBKXEyEz/dL8tvTIme4Dx2qt:HaWWeYPuZMbfD9t
                                    MD5:15D67DD421614AD563290995033F8030
                                    SHA1:F39B51333F47A30E5FFB22A2C2537FE5F6C7CB40
                                    SHA-256:5F94F9076DC29D0B24F82F9944B399C5F367BC5513FCF585BD4B16074C296706
                                    SHA-512:4556A751AC8B7136036D5346CC21AA7911A1DDEAF1F98F50C11D86E16DE4E0F4EFB35CD435885952BD0E2A3764AAB10CAFEFAA7A0F368D1DE95D59CE0BD9D5E9
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V1n.0..F.T.S0.;tb.....W`$.J.....bhQ.^.R.VL41.8M......il..,}........qV...j5r.&..../....:?<"].{?Q.u...0`.F.,.U....m[..-#@H*...~'...Z...GE..le..v.|.'>{....|..:......4M.K........|....l....A@.F.j........wA..5g..9'.q2.z.N.1)WA.~....4..h.....o..mJ..Q..Cb......r..J..by..........V..|........C.o.}.&...D...x+E...........:..A.S.2... ..q.R.S].\..z.B.!.6.J.lHF$...D...$...$<.(a.E...a,.c...Txi6.|k.n6....V.U.\.d.r-...r-L.I..G..&Hp#.Of:../Ht.G..-..eA..kR....-^.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):270
                                    Entropy (8bit):6.599121404178277
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcBwfjGJCeTM1wiKluu+yWzUdreh9p:6v/7saZB8jGJC6NuByWzUwh
                                    MD5:967FAF10AB12D968716D34FD3BCC6168
                                    SHA1:44BF9DA02D56B2FCF2C05D78D2D7583D67C515B3
                                    SHA-256:DCB5F641EB8233FF5C299505FEAC8DF71DDC2DF0A5B548992BEAE62FB9375EF4
                                    SHA-512:3720324825059029AB51127D27941E478E2736A0B1A5F096DEC23D20C9A55579572A098A116C28B045FC4EC07378F4DF8D663E478ACBF09208561986BAA59E5D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c066^..........abD.;0..P..........@.vq0.- +..s......5p.....a.... .....x|.... qb-.6s........b..TD.8.y$30...|.W$......XY..KE..H......`.G.{,.p........441'.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):441
                                    Entropy (8bit):7.2750299273531365
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZAyz2F+MOOhUGIE9lNpSVrQGGMGW89el6TMKoaKM8r7:NKa+MlOCrEvssGGMGF9Q659J83
                                    MD5:1450E62C558441714F6E7887140E37F9
                                    SHA1:C2C79EDD0DF8AE8C442377CE8B78C930E1F4E724
                                    SHA-256:DF0481CB1F675A387C2606FF2934EE1CBE8B24D65D7BEF40977043430A378E35
                                    SHA-512:399EF31428A325461A37BAF70C8A28BA90955335DA95175286E339EB8A6F7A213BC0C72E4E80094EEC687805B8C0E0086B2991ED7FF874F4A5FE2202DB81A3AE
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....FIDAT8.c.O.000.L.".......AT.........g...9..5d.&...l..+S......U.K..........yg.......4EBHpn.'\....K:<..2(7*...4..?/..1...A.p....A@....`.O..7..b:.M.G....0(.........[+..0...s{b(~.>~....A. mu.....M.c.4e......M.....3.T.p.?...AwV,..AD...o]}. ,...../.....g.M.7.....k.....t....T)....e.W.^.TW]...S`..65...&..=D.!^f...l..A.@.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):416
                                    Entropy (8bit):7.146883608164431
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZEsyy6mc4Z4IM3q5BpkhXCbU3bRVfK9B:Hagy6B64xMfQ3ffK9B
                                    MD5:89F6F48F4BB08E3170EB9D304CA802D4
                                    SHA1:B8D4ECDAABE86B0F381FAC4D679F96A72725ED38
                                    SHA-256:CBFC0CEEDB309625E78DDE53F6A3F70FDA0010A54A3E67B7ED926CF4D899991F
                                    SHA-512:CFE72FC2BB2D4289F4D28E3184AD297EBED8088ED1E463C5CB6FFC580999474ADA93711B1658DAD6A716389E1810BEC1E58491CCB4F3BF36068215AAA7E3EF65
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....-IDATH.c`... ....2......+.Q ....J..nr...$....};U.?...u0-...........j.R.h..3|gR.CiQ9T3....c......7.........0.....9.P.. K..}.YJ.0.N...6..<...].2\iOJT.,.A4..|V..<.M.%wS.pE..0..T.sP..........j....P..9().R.()V.[tR.p..0..p...)UL.v.nls..g.`...j.z05:.9.A....?...yyk.|....oObD.-*.NP...<.l.Z.N...o.......Teo1&....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):321
                                    Entropy (8bit):6.821435526019302
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1LzcySZCZv86JcuGQvGNJb7zypnKQwCsD7gbp:6v/7saZtYcWuGQvGjmpKlp7g1
                                    MD5:4D9C01A44F7F8FFFF2B10337F45D3914
                                    SHA1:8A42628DD2FEDE09E629F10EFE2A38142D44EAF6
                                    SHA-256:450510A3A26DC0D4E4B53BDC7FB3F0F3AFA2CCC6D52C908FBC624945DB868284
                                    SHA-512:9119D76D4AB12EDB2CEF0367C653BD9B03B98ED8F546FBB2BAA97FE2ACFB7BDED31BF992CB387C9B7FDC18D8B95C2D203A3FD9CC23C362EB0CB00B11C7DB047E
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`fb.........e..L.j.a..R...1.. . .&.]Uq7.....ZY....`.^v..0o.m..c..$G.. .n-........a...1........H... 65-.HE.HF.`.E2).[.;Q.E=....zJ.HE..#.....R.zJ..,"...".l..I~ ..#.W..""#...b.Y.5....4/.....T.&*.......:6..a.}....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):391
                                    Entropy (8bit):7.143478711342228
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ5ButDAu3Pcbc5F8bDWbPOKM4cJxN:HaQtDxt8XavcTN
                                    MD5:6239C6F5999FEFF7AE9F5927F4C2A7D9
                                    SHA1:C2213B812A16F5FFFEB6CA99232C32A454FE3899
                                    SHA-256:B16D267E954EB0F966B92451979672374907C78D47455C72E5A0B5F4F0C5E6F7
                                    SHA-512:01DE90742460659B548710460670B8E0D2BEE4A73F373829DBD47BFBB37F4A316A45162C55D7ACADAC4F3DBA5747AED227EF7D70736D740DE8E1E88F0BB2A737
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..V;..0.5.......1q...10!.....4.312...CQ..u."..*J....l:y...x\.|..**.5r.w"I...G....o.|f.qH.".E..W7Y......$I`..<...b....d.....d.`..0.f`.7...h8Sx..W=...f>U..;........0.......%..k?..}.*.....4....J...p...R..).^...=.......@M..2...u...u.\$Q.y.M....T..9kL.........x..Q..F..Q....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1239
                                    Entropy (8bit):7.832004468327275
                                    Encrypted:false
                                    SSDEEP:24:HaKOAg4wwlCCnguCG6ix+qJFOmsLjZzrN941Uw+l2JX4tXHY/rFMFz:6KjCNlG6Y+qJ4HZX41Uw+wJXKXOrFMd
                                    MD5:CF4B6951FE123AE03E02ED33F473E3D6
                                    SHA1:5A62ACD07018D0CC72015FA1856F5BCB323D4D44
                                    SHA-256:71290249E192C85E9F0C75648E87B21964BE256818C4E570BF37B97D542DF862
                                    SHA-512:9542A3684FE39439F71DC41662862BEB3F8531AAA62EE65DAD30F5B7574DE08E23631BF202AA206DAD044DE8138999E8598F70846F09BABEEA9395F309BF3389
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....dIDATH..{L[u....}...>..-P..=y....Dp8.2.c.J6.+...8....hfD.'s.....04c.TM..fdY41N.F]..8 .0..x.m ......'i.9.s......."../.'.=v.>....rib.K#...Dz.........y...a..!....Q..lV.u.tkL'tu).<[,.4t.J.,.Z..@.._.......U.d_............%...f.k...=...j.\~=..........c....U.h.....a.~?T_6._...^|2}....p..K.*X....H5.u..w...J/p.qvmC'..Mm.2...8. ....nZ*p....,;.q.MT....d......$.\...@(.E.}...=...r...J.-T,3.>+.R... ....*....oO......E.@.n.N.....E....Y.J....6........;.F..B....k..#..C6....>w........-.~.,.[.U12.f....4.=.".(.+.........<.....F5.j.*..?......A.A...~......9..-..$..GT.*.#...KQC.,U...c.2..7..x+.K...|....z.S*.k\....*.b..#....'H....x...0.W...p......Q..l...{}...J~V.c.c...XIQN......zF.<%w..5.J.T2..!..dY....6.f"py.>.T?.?.x..+....w....e`.E..V.z........7...oNK..)../.f...s....$....dy.]3H..sL..XDa.#+U.....+H...#.R.,C..j.x..<..~.,s..y.V.]..*...U......AW.(.^;.__.7..`1j..z~..J5.<)..Y...M.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1278
                                    Entropy (8bit):7.730830042212621
                                    Encrypted:false
                                    SSDEEP:24:NKaB9LrOJHWj16XJ2SDf1ApR9dqs7hONxqU38NXkn/RMis4pFuaTNKKsN1B:nB9LY+1UJApRPixqUMNXknpzs4pUa8Ki
                                    MD5:64B58FA6866A112021A70761B448A33F
                                    SHA1:1A1CA94680AAF18B6B03179389BC4DC4EA90B6CB
                                    SHA-256:7274BCFA312DD4C702DE853410A39AF1E80C74979BD6DB18BA90BC8DF428A9E2
                                    SHA-512:5F72397203D6B42265961616BDE78A01DFF9CB6FCFBEEAA9D4A13CA6920C2BBAF7D84CDF309B6F52CE5061CF57484640B4DEBC164DB6481DF3A7AAC1DC84056B
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8...2.?......&..^.`km*'%.i.wW/../..3.q.....v^z.k.^.=x`.d...(#../G4S.O..u+/.KG...7...../...q.0.d..........?~......<'..I..!.......p_......Z.E.YE.x'..}...d..4...`..........C...^RWW''..k..azJ.k./...)...f1@l;Z..dg.#/+.................K...)J..../..n;.s...;.r._'.y......'.p..TEY.._....>.v......8.w..%.............t.6v...Fzj.....M.......8Xn,..........4..t..A.O..k..n....._........;.t.T.CU..\[.)...z... k.......A..........$.....h...+V.....4..LlB...}M..r._>.?^..n..PWm.{W/CLY.`.....7.$D.f...M..i.!..k...52z..k...~%"A.M....H.../...>I!...&.........PuY.m5"@.LK.r.5......xt..e$...A..........q..?..f;0....,}.Sn.)..II.s_.p...~.vX:.O...5...._....|y..........E.YoL.....'......U.`a.x.....Sf.11-..!2b......T...L.>.E~.(.6I..-^.xq.....}.I.'.M9{..0?...?H.y....'..(..0....%.(.0..f.g....5. U).s.......+.3.H..*.s....3..s.$E.dD.+.y5T.}.p.8..Az....=......)....-U@.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):195
                                    Entropy (8bit):6.071182236715599
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKcRwXgki8IEVk4xGQq5i9N0Vp:6v/7aKaZRAO4AQq5OO7
                                    MD5:B3D900409BE71A73D4401B8BDDEEC205
                                    SHA1:6C2B714DE75ED0595839C4511BFB34BA559CD423
                                    SHA-256:85328D65160BC64B2D4AF369887DA922A28748E02DD881DC2EC7689FA2533243
                                    SHA-512:E6FD5BAA3DC9756354C5E6AC4FC1FBF8F36A82DE873050F3CF2B6BFA4423BD0353A5DDB4A479E03B0679C7E1D927B675A189D7B412A5C9046EEA79EA9A8ED5C0
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....PIDAT8.c8..E..0j....rr0....k!...p.\.i.b.P.?..h.0.(J.A@...A..6.c.....p.`>.-!.. .Q.h=.J......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):193
                                    Entropy (8bit):6.056973920208479
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc1hkop55C0lBPbogFcw5p:6v/7saZrH5w0LPbVFcw3
                                    MD5:FE117A6CCC528E8BA952B1A686A5E65B
                                    SHA1:B046E3D5550A4920EF14378CEF4BCE9A58ED49A0
                                    SHA-256:ABCE8A2DCD4CA8AB3927BDB5B5909AF7871973940F06F7A2304525E67891002A
                                    SHA-512:D8D1DA15269156815E4B2900DCA0BCC9DBFE194A4241F70070F8180A913797A702217BDC7D65141FD4EF3C36A3227E0349E000313C1D1D9610E8436D7DAB4B9A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....NIDATH.c`..#.031~.R.A.`ZT..............`.....hXR.......h4.Qn..."..C.....`$...a9.".*d....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):319
                                    Entropy (8bit):6.715977842662184
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcRRyuo93Yo5WrlggRe2SPGbXzR5WNAraOhvNbp:6v/7saZRkR9ohpmMD3W+2kvN1
                                    MD5:5576B053262674F22AF8229411C372C4
                                    SHA1:373EB33E71C99918A014A4E8D922D075A5208304
                                    SHA-256:E25F814ECB172936ADE7B23FC8C68C419354A1D7F93CA929AFF52793B85D3D48
                                    SHA-512:7AF459616F440D6C9A145D9612715C48A31F57C01BA1D00C6EB516F74B1C6B1B73FE37852502CA03BC4DF0D345CB3A1379FB16EAF8403EFF743AE80921355FF7
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..#.033}.R.o..... >..#.5.'..k...0.R....t.7..............D.#....qn.`M.v.`.Ab.N.`..'{.K..G..}Yi.p.Xb.?...E...h......0.Wd[.......a1.`..../..[$..D$Y......E4........K....F..T-*@..%...O........h.R. .{....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):197
                                    Entropy (8bit):5.991426632099323
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwIsNGAY+vavfxmIP60lsyb4z10QU+:6v/lhPZi+aWdKcRNqx5C0lBy+BDksqp
                                    MD5:B48D9E2D512C4AD569877C57F24E795E
                                    SHA1:EF002CDE02528AFCA9714813AF01FC46F6063C17
                                    SHA-256:B811B92907ED6414F5C62FE3448BB903CF977DE03CD4F13DF54F9F066135438C
                                    SHA-512:3B0FA476830E82883FD2E268FF40B3985399FCA150BA92B432A815D21B68365CD0DFC3C0BED1D6D69B159BA2F4553508676F6E3793F456B43395DC4902F3D7F1
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....RIDATH.c`.......-.R.A.`ZT..............`..8..Q..qC.8.......T4.S.3..gJ.j...1........ai.k....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):374
                                    Entropy (8bit):6.920188451872822
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcVgOtsCtnhjvo5OWZsqVIHN+r0cRh2m16tC0Ud86OppDp:6v/7saZKGtnJDWZ5VIHNXcRgQ1t+6OpH
                                    MD5:84BFCCF763A8BB0FBE20169067D84B09
                                    SHA1:E09CDDB1DE8CE8857D2D35DC6020FEC01AE8E87A
                                    SHA-256:38BA8EBBB5D1A8CD7A2AD3B20D6009FB400F238202FB92EF91B70DCD65413983
                                    SHA-512:D3A20F7556FDAF09F31B0B1029DB1042CB3350236844BD7EF7FC776E18825EE8CCA4B7511D288A02722B4DAFD2C0BE1C1B22ED64BA4DB32BC954ACC082B42D60
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.'`ff.........`.&F........@.....O-...v..}.?#..`Z..w.T.1............ CQ,...h...B...8 .).X..1.@..ZP0.d..p.&d.......A.l.I.L.......P..c..."..`aN.....o*......b.>.SQ...I>HD.N.R..q.M..HET...FX..p".`..,.YB.p.N.&s....v.zi..[.......j.B.`.......#E....3][*.[..f..S.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):935
                                    Entropy (8bit):7.693438365611039
                                    Encrypted:false
                                    SSDEEP:24:HavzMoXz/9nHBU9JgwYAEubEEYMtWsO49m:6vNz/rUDTYAltW3r
                                    MD5:2046B3E74D8FCE0065DA8DE0DDA394E2
                                    SHA1:DFD45E6425B88109C7DE5CF622450F084F611999
                                    SHA-256:A646C35F0D6EA0E7A815F81E1D5E13DA45CB3C58D20A3837EFBEDF6F74328FD5
                                    SHA-512:3FE4C6C1B2992C338C05E507C0D6FCAE7F7C21B4702547914A77BD184A5A94A063D0895C6AF3E611AD259AFBEF9E8C44239B3848E21037F1164C140AFD440574
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....4IDATH...O.Q....po..(L..A0....... ,U.h.`R|@......bBL\.....gI.%P..>..7j$j..x.m...m.Y.......s.=g8.X..8.y.......v45.1..hx...b...*.ql..N...b..}}....lC=.....:..G..jV..q...z.Qo/}...\..|..\.........?..G.PS.P..l...!G..Br.B`.F!.....vlC.... .C.....AaA>.P.Y.!.....0V....|3.&..>......t.......1..P....0N.'.G....c.Y5.....v...^Ur>,..k....G.c..+...vl.....".;...,..).%.v.^..x.e.~/..B.A.f..I.n..Y$.H@...?.6.5..p.(5....ja%.]t,tP......~...~l....){\C.....C......., .} .P$....h}T.%.$.....&..._w`.AB..E..7.T....A../...."7Y...Vv..MZZ[...o_..E+;Y....m..."..........1o. <#.~7._...I...%XwL.......|0..TX.i..Oeq1l.;.F.M&.k....kK.=.b.(..N..W..~R.# !.........."+..3.$\..9^. @D...uR.s..p...!4.J..g....`.|...U.I..BsS..9VP...`..\]....9.,..p......6..z...[..d..(....jYzz@....o..4V|.M?..6...,.>r...e2.T*.f...".J........... .>D....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):272
                                    Entropy (8bit):6.58332324360963
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcHwaShtwDzoAn+NTJGuFU9yWygzea/xp:6v/7saZIEDnEGuFU9yWnCa/f
                                    MD5:ECC2A36D953FAEDFF0520E75F15D664C
                                    SHA1:C1BA9ACFDD0FF7AED0D2C4F8075957143186E166
                                    SHA-256:FB4999D575DAB9E9131E50ED92E5A346E27505E4A4A2AD6C65677B9D9B6E7B10
                                    SHA-512:CB6BCE517A62C8F65EE3D33F50C5CAD5CA157EF3EA1B60222F098A3779CA25C18E8A72748678557D6E401ABB4AED0ADEE9A33B39471AD3CF523D8BC58E466046
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.cP..Z........E5.0L.....1....T..J0.B.......]..}....7Gxz..y-.#..lb.,.j.H#.......$N,xu.........b..TD.8.y$30031~.W$......XY..KE..H......`.G.{,.p.........&..v.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):949
                                    Entropy (8bit):7.671578907093583
                                    Encrypted:false
                                    SSDEEP:24:Ha/1APoDV2O+WxjsE14mDrQuXSwc4XHIji5:6/aQDV2q4mDLXoji5
                                    MD5:5E5A90047BAD90E4B5F924EAB7D26B3A
                                    SHA1:1E16A010DFF27183563D5C2B0B6A792B7F9AC953
                                    SHA-256:4B92FEF6453D501C6B43FD8209CDBC5833D2D0DE6A2E35F918D39E163BD658E5
                                    SHA-512:BB891B7AC7EA6899D43FFABE0A5F9E6A7BA18A3B9932D9B0D0C6BAF4CB1DEC0C2CF1C36BCC6CD2B5EA56ACE45C52F4734C031F710D608215CD60B0890B1A9406
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....BIDATH..U]H.Q..Y-6qJ#.B....zP.@.G..,G..&S.V..h..Y....PF..00A."E..+?..si.....ps..so..............=.s....E....r(44t..b.8..5$$d..x.C7.L.....v...L&......A~.#.AT'.v...Z]./..MPYYY..R..{. .t.V...F..s...h..g....B....'5.!<...E.v:i...,l6.........`..8.V.KI&.^SR.N.111...W..z..`..:/....T0(...Q.*LNNn....F.ddd..^....S.u.5.o.~.A.ji.. .....I@.....\...V.{_*...|..|.....`W__.........d.....8.....X.H${7..6,...6jL<..I.u......=W...z...I.si........Q5.o..J..d2s...-...z.~...oU......o (...W*...K|...3.v.l&#X.:.6.L.iB.K..X......,...l{{;`..6.. ...:Ei.y..=...W.Z..Z.....Kpp......oo.....W.67;.G..........(.....x<SBB......N*.czz...u.z.wGFF..:@.*....QJ.%...Y..Xe{..u...t]AJJ..xo.Q....pb.#.....h...V...]]]...D.KJ...8.z..._..h4f.l6J@.7!0.U....b..=h_Jo@..e... ....sh../...||.n..!m.Hmm.;,,.S &.......z.U..S.=k._l...Q...HD.Q..1......'.T.uwl1.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):320
                                    Entropy (8bit):6.7386073527126475
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcXwUrRVwY/wL/UcoDNZROpXhyk8LJHBhcsOtp:6v/7saZnV//wWDxOdhykkF5OD
                                    MD5:8F12468990C7CF9F1BDF01646BE26397
                                    SHA1:55D8C141961E1B018F25C37EBF64332DAE383255
                                    SHA-256:BB980C3DEF78983FD8EB816697A5A1FDDF4D822C755B822FB226E5B916AFDFE2
                                    SHA-512:428894BDB348577055F5771A6B2A500CF34A0C87D1F8A96099C96DB8A3683B8BBC4DE56966D9EE90DCCF53551C3B81ED4C435F53E797F16DE6FFCD6976733BB4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.....g`af..U...........wcbd5.6.k8.z..c...>.(.(..........JE.UT.@.4.S..` ...X....TME .s..H...q...s......US.-55%.......E...T.3...A..W....{...TIE...,.YH...h.JJ.4).......?...JQA.........TmUPR.....o.....3....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):217
                                    Entropy (8bit):6.324278495387383
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc9hkp7N8gmWrLbdLWcDwsPnup:6v/7saZDy7LmKb4cdPc
                                    MD5:BE8FAFE61D456CFC208BFCA0A862B8E9
                                    SHA1:0A85BE5B2A12B19E9035B05C655205D9D348E5F8
                                    SHA-256:4E93C1ADB41F70CA15A5B72132675CD9A47ED9E317AB6C272A61634FD4EFCF38
                                    SHA-512:2D90A6C82048CB6093BB8C2B5230E651CAAAF88C0E6E317BB49C7EA88854AC914A44E1414CC56D5DF44D0AC33D750B61B2D6B021560CDD218E57EEAFFA439A4D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH.c`bf........K.....F..Z4j....m..c9.7]...srq..OXXX>...d.....0..Z0.- T\..".> .OF-..`.[.-r.j....3....F......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):675
                                    Entropy (8bit):7.487089357496866
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZA2zZruIqT9WkDChSRfWHro3nh+dfxcTIMN9EesbMGS8B3uNqRb3sRyt2c:HaJ1qUkDCEWHM3nh+RkIIiekMGS8lRL/
                                    MD5:2AE495C822BCB8DEFF2E7E591D9B1408
                                    SHA1:80C6DB987F51C9B28885E67234D6C4A21C91D1BA
                                    SHA-256:65F9977F672A9F92F621B3490E74F5C21E822B094FDFC69808299CA72D4E8274
                                    SHA-512:CB12CF5F42AAF383A525D89428C086D5E5A472E618ED27969CABD0366BB569662232083ED9B56CFEEDDB4BA85D42047F2D11AA1D48E256920F86C9FF3C64B8AD
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....0IDATH.c`@......9yYo.r2...fy...z.....(..@.`a.b......!V.w.....K..g....a..<H.';..W.n..@..$...Z.@.k.Z...;....w...$......G.....o..l..O.Z.I1._..K.&...[].[.)....wP0..u.V..j......-rNQ.....P.+..S/..g~..l...$......PX.I.7..z.....sm..}d......-....A../.Y...9....8..cbe.......e.v..y.l...3.$*...........!8S..S.0.~....."....`P.%%.........'..N~.oni....9..o..../.....^...o...?...)...4+;S..7.2j....R@....P....&.@9 ..b.+AIw../...@....b.j.A...r.. ...@,C..d.z6..l ..h...Q!H..>.......?..=....,....$.....V|[E.+.Zb.5.......\.`.....j.Q%.#y..d.L.d..+.rA3.F.3.,\...E.U.;.}TH.-.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):783
                                    Entropy (8bit):7.655849766017428
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZk2Y6EaDV8kzfvUvncAHjiHvS6GPolQ7guQOrpVUoM053uKEMqkmjD6mI+:Ha627DXUvnViBGPEQ7fXrwoFVgDlV
                                    MD5:C2D47B2BB3A5598A6A2FEFDB8E68AE89
                                    SHA1:54CDCC3937445AA88BA7545BE25CADFD024E0538
                                    SHA-256:0545197DDC7D4AA252E60E5E2E98140DC0371F08DCB2B9311D96AE82719C6B9D
                                    SHA-512:D40C64A5E9A34E53F68F20EA0BC1F35C560C2AAD1D93F711899C6892E4E869CD1687E806F1A584BF2BA1AF23E9A9B2EBFF4BF3D64FC38ADCE639B9CA6DE3F40B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..]HSa....x..tmV.Q.....6M.+.L%....."....... ("".&"..$....>.........m6..yW.....}..... "..A...W....|C~K...q.E$wI.D......I"....[..~f.)...).......;..|A..b....Y.....L..<.....^8.Y.4.R.*bc.NV.R.O...B....J....)..YK:..\...N.4..T.x.....%.J.......].E.......%y..+8.....3..\...|....lE..]7=..9..A..p..`63.>....!U.G....t>V.3.p(.....O.%...+....0\ON.......1Y.L..:X.2>.1V..%..H.Vq...,......Y1....f..e.8T..'Z....a.0zV,..0.pgXp|...=_.-]..c.....{Y...Mh..M.V..L..G(..........r.L........&...v2d...2I.,.}...U..ggB...(.:g........x... T..p{.........(../.{.HE.p.........Oc?..1........d....m..o.;I.T&.U.l]o..=nD..q7...b{.6.1.z..*?Op..&..~K...4...?$..4.J4....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):787
                                    Entropy (8bit):7.49484754631625
                                    Encrypted:false
                                    SSDEEP:24:HaTRuoG58HRW+vkPYMH2XA5MfhOI6yPYKJMEwFw:6TRIWkgMWiIkyP3MPi
                                    MD5:F7B53ABD5EB6261BEE04321A7E68C758
                                    SHA1:3F35DB614AFE45C7B96A51E26BA35201FF49E625
                                    SHA-256:2570EA19B4BFC9ABB18D0440CB80ED350EA1B185CFDA14F809810EEEA3444643
                                    SHA-512:BA3BC9B30F1350367487C0DF5D8D0D4C5B79F28AF38127771337A66C664754600891948EB833AB17A2B4CDCE06D2F1835C8C61BFA8EED727172B59AB7547363A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..f ...@\...P.....A6.WA..X...A..j..G....6.bu(6...A..4.x.......?2..A..@..".8....[E..3@,.., .G.+..........^........X.q....,......lw.G.>.:.X....b!",.......6.7...[.Y..$....i..4.2.a.H..(.....u..Zl......E..0...H..g...8.A........U~.E+.G..L.Y...cXpKU..2.b.'3..3."....Z.k......../Y ._X.../.u.....@...0114K..I.f5.#E......pe...]...<...H......J..XC..;,.P"....Hfff..Qd..o......c>np>x.R..9..@......7..q.~g!..^....|...6DX`..-.l..!v._p......KH....ph1....2F..T....0.$&.......Tj......wP..P... N.'.|........u...Kq......W#....lw...Y.`.b........:({..kB...X.T..r>pNR.Z......n.....8_.....[.I..).C.ZaI..|.....p..*.@......!.px..2<..t"...K.....|...UX....,.... N........#.@.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):563
                                    Entropy (8bit):7.3034711187336825
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZtHQiw7TI0um7XvYRuwPvUi/cE5ltl+zlzgbBp1qyc:HaLw9KMXvouwvZkzlKpk
                                    MD5:FEC3D3FEE393C9106C2576E7C5F40E56
                                    SHA1:66B4FE505B1D701FEE65AF63A98CD48532ADB51F
                                    SHA-256:54AC3F4A78A40E68A1643E47FE69E36D69A98446F9F1B744941267AC4883393E
                                    SHA-512:B6DE7342F4146F7837F713FA6E5652085AFDA804C52DB8B42227471F8C757631462A45F960B95875F33C64CCC44E2CEAEC821B8FDA0A92F4D2E939DE9D5B9204
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..f ...@\...P.....A&..@..X...C.j.j..G.....b](....A....P..4.x.........P.9P........sP6..@....**(.j..d.q8...x.....1...6 ."..k n.b.$,....`-...a..T-.....`/..,...C......,@W;H-.......@....+.H.c..[.,`.b^o....v.....e0..A8...?./.u.H.c.z$[p.~.......NI..X9..a$S<. 'SFv.......`..[.d$.......yl.....[.eo......np...M....:..72...E...P.q...&...n...9.m..r0.#..cacj....l8....:..f...6.bu(6F/..Y._.J.(..!....S...Q...h.$...lGJ.dY@. X\S..V8..x.Lj...>.*ehG~.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):380
                                    Entropy (8bit):7.104571499447948
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc0CoGJrw9UETD2RoyCgIjkkUaI5cnGlRJB4DwiR3Crp:6v/7saZ0r4U2EORrIjvHIPlR74j3CF
                                    MD5:942A1B12946890EC1F254F5C16AA84E2
                                    SHA1:1A029C0872D7E8673AAE26E55ABD8482BE83D9FD
                                    SHA-256:10E821F3C10BB5939920EF7C3E910CBD34875E91983F27634B6D67D08433A6E7
                                    SHA-512:92BF7418E7657C96BFD714BC4E2423412DD9341EFE1715EF3B6E22795056459A30A1FE8A236F896A6FF9D56733D8E1B30A2B2197A76D663F6DCC1CF912A2A2F4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.....@.F...XC@=x.).....V...`...d.F<Y..x..8..aw1......8.!....,m"#.D....2.$68.....m.#.....C...A.(}"..IT.O.........{..@..".....y...^"8.].A...1ly.TO).\..KP..SP?.P.....[.P7...a....%;..K...1u..1....3..L..D0...&X.3.....{]GD.D..D....q.l..G"P#.:..T.e...?.0.)+/.!...!?:....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):384
                                    Entropy (8bit):7.126131615252493
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcIiFea91Iyfjtrujbu+V/GBGCAtQa/hq+pEvBxZTJbp:6v/7saZIzc1IyB6jQiloZJxZD
                                    MD5:AEEE1D1310D3E0EE92F15CC40EF48204
                                    SHA1:D844B95E8B9725E4564B26E5D8632662AAB32CCC
                                    SHA-256:0A082A032FC90AD3C5CF5DD6C8E8F8F8B4821A2FA78A19AE08612E80F7E714E3
                                    SHA-512:8E7CA6695205B3E5AB20A49FE254DF4F4BEA464F6D4C92F0ADA7135C453DF83BFEB755D58FEFD3574EE62DF1D9A179A463E9CD699A55E25DD0C5B3B0184A92AE
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..;..@...&..3.....>.!^A=..v*.3.[y.5V....q.u6...fv.P.|.f...1.z.,]"'.DZ.O...F.....H...{k.s'|.cb.b.....O.X...Q.Z...W._=.....%.H.{b. ..;..D......... .5...VYs.z..zg./P.76...4........9....mSN.....`Jl%..c.&X.3...a....:"z r..6...........@.`...Y..?.."P...9.+.'....i}..Q......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1028
                                    Entropy (8bit):7.7483677316269395
                                    Encrypted:false
                                    SSDEEP:24:Ha7n+6cf3q5Uz0RKqYFwj6e0QgZ3VVc0p5PDyX5H2AHIHYVl:6boPaUz0RhWW6+C3jpPGZJ5
                                    MD5:96EF1FD77C06C7DBF9B2D863791038C3
                                    SHA1:15D2ADA362B0AFB6DF07206E13725F5A9CF17737
                                    SHA-256:DE28E2521485EB29D1AA48715D84CCDA96EFB862E09E81453B3BD7145D0B1CA2
                                    SHA-512:A584CF8AD0AD8BA52AFDD45FEADB391C96CF671B2EF6E51D4D9F4A8D6A30958108F94FDDA12FE3D93BAD1CFE3BE08AF1BA5C215375CCF3910AE3B7E507EC3614
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U.KTQ...{o.7...I.R.C.\s.D....5..4j.. %d.bh.e..KV.@.D.De~.>..-...@..1.f_...y..f....ys..{.....E^&.j..P. .i../J.s<..%U....y.A#..[.6...<.*T......}.X~.}f......ym..<..cl..<.=qg...|ZS.,..I|Eg..6HzY...i.&@.e..9.c...4.?.....aU......._#h;.+.V.*.:..w.e7.1kM.,.....7L..T....LTa.....7.q....K)v.(C.hJ.....A..t.%..k.YI..&%g.yQO=3.Pb.c..2...D...A..lp...iM...3....&.3.3.Ro......J.....1r.Yl..i._...K/.e....x8.)....N......7.."...F...6.,..U. ..0.j..+.s..Z..;...T.}^.P.7BY.....3.......H|..W..>1.]..D.....#@ R.N4.'r.n.....e:.W..^`<.q...B..&(...M...............,......f.Z..l..zJ.2.J.I.n*..b/.......`...4.+.......1....a*.L.......|.*...v.%..6..-...\..i.....2..,.7n...c...b........$@..^..J..,..0...K....z.n:...~`....h..J.....8.....n.D.$.I.P.d...Trt`%.."I.F<....+..B......5...M...@...T..eE.F..G.\.Siq{:..E.Mk......c&....4'3...........f...o...a6...7iw.vl.c.....#....#.2..@.,.\
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):205
                                    Entropy (8bit):6.257560642821402
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwAshkxTO9flBnE/UC+7mXdM0+gT8u:6v/lhPZi+aWdKcJhkQlVG+pzMIkSVH6p
                                    MD5:43D9FCE3B598A39578EDE7FBCD8C2C5B
                                    SHA1:6C41E83F9645A6E4EADED5054F51F93C4524AE97
                                    SHA-256:6914DD1C36CDD5F00F03427C6685D588CE62152C17EAB556BE7CEFEF9677B9D7
                                    SHA-512:7A329D2D2D9C4FA3047C0DCCDB5D1B3827EFD29195330B41AD66C5F37603C4A39960E49215A0CEA1A134A58B97251CDDD1F3B23FD6901CF35432493108707B29
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....ZIDATH.c`..XX.?....b.~........P.F-....K.L.L.."/.7A..UP.../&...Q.....LD(.....`.@...B.h.4..h?2..W.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):948
                                    Entropy (8bit):7.721333434767267
                                    Encrypted:false
                                    SSDEEP:24:HaaoLtShDfN1zlO+itP+b1xJcZ80FUe6fT4pFINjTku9:63tQfN10+++reW287
                                    MD5:425BFF7A104C29C2D231390A3D9FB26C
                                    SHA1:4632BF2A4BEEF3EB6DD67015E0429AEAE0CEDCA0
                                    SHA-256:B836166F15CD27E8FB651972FB864FC5438CEC61B5AE550DEBA9E93949FF20E2
                                    SHA-512:BD57363AFB78B2C5748E59EECD42CB893B0BF192CA7A9342E2B6B84CE1CE690FB12D7E829DB50E1E4B0316A6F2237CAD33FD95B20EBCC0B8AF17AAC41724E4E0
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....AIDATH..]H.Q..g...g..f..Jj...Q...R~.$e(..H......f.ZQ.&.aI...C...}heP.DVB..`A=...l....m\g....qg......8.3......~..;qN.%...Gs.6_.~.......}]..s...0.t.W..KV.k...{....s...`..%.,.cl...... .A...V.....!%%E&--..N'...BVV..\.X...l.U..tG..T.S.Ii...{..JQ....L&S...c....z.7@...n..!.0.......^..>...z)..z...*...az..gb.6W..0.P.@.../E....}pf..............<....A.H94.-.....b...qu.._.=$.x;.N..F..P.q.......?...l..2A.E.&.Xd..;{.4...4.f.P..6'$..).d..H...oLo.Sz.@.....S.dT.&......g..!.^X.%.C...dJ......W&..Z..........^ E..EQ.X"........M.&.{q...A......h.{..f....38W.Z.(.t....h...Fr.R.+.t.k.t.....!cJ..:Z.(..x..#3.........N.E).,.s.J..H..c.*D.r..UA....U.......7.....#.Q..P..N%......y...|...O../.k.>....I..5._...lO@....Y9...;;....h.I...E.&.V....1...I..7.M.43...U]."8|."x....?...X.y.Y.#.E...;<.%B..f.#+bVu...(.jS..*..=...{~.e...........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):857
                                    Entropy (8bit):7.630473976778439
                                    Encrypted:false
                                    SSDEEP:24:HaCVfKyBM5dm5/wsnqEy0CMbFfzkp+4Oz:6SKndm5/w8ZyeQA4Oz
                                    MD5:0D3F4D375AD1B906C63CA0F093267E53
                                    SHA1:9919C2EEB6DC5A0FE8A8A0E763E956EB66BBD792
                                    SHA-256:5AB0D91E9EBD6DDCEF21369EA6C9608B5C6BD653BF1EADE0987C74187B5F7424
                                    SHA-512:471B9DF61A1420AA02267BE6B0DA58B9C21634229AF87B7504691744E45EAF6A021DA750A4E09C692DA923018763EB25AB8E200700A6BF14E6FF59161C737D47
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..[H.Q...>;..8....../.Y.B.......Y...@0.H..-IT.A/....YQ...../.>XP...4......i;n..t.c.\...... ...5o.......P5e....i..8.q.$<o.&.........M..k]..Y.!.".....e....W.W@V.....qJ[_..M.gL..#....p........).....0..>....9.........yg..z.....Ihy.a.X..e.I.j3.Z....:....E).3.H..o.E..E......:.....Jh.&.....n...\n^..1.......+.=t..Ew....P.)..PHx..0.1D?d.3.../.W....n.;........p.............^..)...7......!..w...*.[......J'2.n.^...-...{.Ig.f....rW..e.s........6..=..%m/..j.DQ...n?.y.E.....gd......\..6R.,..h@.H...bciG.((D&..aqoH:g....%y...k.,_&.b....7..".*(\_... ...Q*..%U....8...F..S.I..,.&.y....]:..]K.&P..S..c.,.w..8h.0.`..A.DI.Y.5.....-..l..0..Ot.....N6.J...wH/rY....._.j.....=8^d5.f&EY....Mq7..,..`....+b*..q..%%..Q.......(.._........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):493
                                    Entropy (8bit):7.205985693009607
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZwShtc/+l9/yLKZrL/4SZG5lNz2BnK5ddA6z9:Ha+Sht5/y2ZwsG5lNyBnK5/Pz9
                                    MD5:07843EF7E80593C221689266D6676BA3
                                    SHA1:4F0CFDF7817013367E9CD73FD9870249BC040D89
                                    SHA-256:C6AD5C20777850004432E290DD8F560FB2E51151F61DF1CD23C07D2B62541888
                                    SHA-512:3E617E2977C3E241161FBE2E17390EBD18DFDA8023CC1C9425E3024E036AA0C9141C174781E0570E85EFADB674326686D10D8E371253E353AC412EB84336151B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....zIDATH.c`....$.17.....v..G@Z..j..B....q.|eba*..Z..e....o../......e.PL..j..._........n........5P....+}.Eh.p...../=...tZ.....1.............R..i..E.g.....t..]7.._p......W....@5.0......p(...N..S.f..zm....k..EX..\....^.kw..q.....{...D(.f.d..Tg.R...E.......;.]-..}...@.z.+X.0...,....Z...4./../...D$..mAx.!.H&A-......M|e..K.$.E....9..RA-BS@..0.3.cbe..Z.&.....v$.._q=......AT..N.V....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):316
                                    Entropy (8bit):6.748312662816778
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcTN5UDMoT4n5OVx1VUblpkoRVaSwRqdDLuLhf82Sd2bp:6v/7saZvUQU4OnYkkVXBLapBS6
                                    MD5:E8D6922C81904BBABB10D14D8A57C12C
                                    SHA1:3B34130618CED92238F34B57B23EFE6F2FB7930E
                                    SHA-256:6921904E251128C114C01113751F480AF3565A29A03F72093B04BDF88E9ECAC2
                                    SHA-512:5EE9CF922E266626982D9B93D018E3423A0BB85C342E1F0B4FCFC06F6829065349E07A10CDE3D7F25548048FE5B3EDFF7D50084C7CF20029844EC334E4032788
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`af...............]..i..]..&...X......p.f...@.O..H..Q.p\q..f.A ....>..~...fbf../.@...q).&.P...;...R...p./...........*(j.).... ..)j.yF...Y..[...0M.@.x.hR..8- .....[@s........q@...."Y.).l.Z..V.Z....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):221
                                    Entropy (8bit):6.280963957721208
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPa+aWdKcZRyUGhuoj5hdtAXhWMVd7vCkup:6v/7maZzrol/tzi7vC1
                                    MD5:6D33BDE9EAB5EC01735868D53E567EDD
                                    SHA1:B3756107D2DC9398DB176E7159C3FA163B82F6AA
                                    SHA-256:D4D78A0859368D0F0094477E89B70524B0C3DDB9CE586E61105BC33A73B91FA9
                                    SHA-512:A97E614A430E9CC50E5C92997338FB5E4CD84E8BE45144705BC4D20EBF47F32F1324DA309C047C9B84D81A5608D4BFECAE2D3F29879A8CDC0F8AEA1D71DB2D3E
                                    Malicious:false
                                    Preview:.PNG........IHDR................a....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....jIDAT8.cd..0..g .!G3.......%%%....I.\\\...pQ'..A:...`..b.R.b..|.`.u....(...U......'..(g.....@, .0j......ob....,....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):303
                                    Entropy (8bit):6.811158010147474
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcFbh4VAU5ronCWkncWHVyUitTAkrCjp:6v/7saZFNFU5roCHncWHQw
                                    MD5:50ABF9F4EB57CEB2BB19742556CC75FE
                                    SHA1:B64231B070E61708C5EE7B02151AC965A37BFFC8
                                    SHA-256:0E232D8BABE6C89D38517B1E8D0A1DC976FCBCE44FF3B08A0D7C160E8B41A611
                                    SHA-512:EF54C26C304EB5F8228545DA2E9BAD45B47271E2E56490FBEDE53AA8D9FDBE2FD9811198638D4C60148EC63951D2513292C1A2E079EB6952D0C8B546D146CAA4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..A..0.E...6Q.FJ.M..z......UK.+;.......<.|.....`...wB.q8c...,J).!6!...s.x.'..>?E.....*.Q....5.C.j.U..Oi.)cxzu>*.L..X..uH...|M......<.....a.....^..,...>..H......E..@[.....c..9x.).+...-.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):782
                                    Entropy (8bit):7.651813728098983
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ5mqk1bYTFUsFYDT03zmzYbvwUHoRq3ysLVnwz7y5AeCpSsnSZ/S:HamB1b2GSm4oUHd5LFe7IzGBnSNS
                                    MD5:3A9F7E8B21AAF44AD7DA8DBF60D28AE6
                                    SHA1:721CF85B2FACD931503324939FE9B5BF615EFBDD
                                    SHA-256:FEA1D1B9CB56ED7BA0AE0331D217D470E48F8B97155A3AEA13BA244371CCEBCF
                                    SHA-512:804E1BC6581F4052396E8EAF4363C8860CC5F9994257663F3609AD89C196287387A6B10A704B4E3A62CB08E00A61D85505FDEFD462A4F40169224D8B1F04E167
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V;H#Q..l$.....C.B.T.].D.Pd.@..*`.......U....B,l\a-d5.6!.#.|&.5.I&.$3...{..i .....!o...s...q._...(7.gTh...;.ss.x...\.).<...E88.lC8}...>.......vv.H...b.g...tuu5...m....T."...9...jEooo.g).@../n...[*.."..L$02....$..@R|....!...ln.?0..n....v.u........x..J...9..I&....px.....D.q...E..UP..H..3..[..J6.D^R.u$......}.T..Ji..#.&&..?5...p....\."+.., 4=....Z71...VN.p...D"..Y$..d......n...8.$E......z7..@.)2._......*yt~...b.NWw....6......O.MMU.....e.x...G.-w.*..E..H...,...v.[Zd&............x,..V...Z...`5.g....... .*uT}...{<...1k....X,.y'<v..$....y|u....;V........./.Y\I...Ur:.J*...n.....h4..y.n".....x..f.......5t....s.u.....w[|.y.A{..........]VeC.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1068
                                    Entropy (8bit):7.723136693175827
                                    Encrypted:false
                                    SSDEEP:24:Hat1Q4l+I2VAWWeYQyjIT2DsKW3Uy5lzTIzx/sX:6zsIgAHeYQycT2YKWzzExsX
                                    MD5:B68B881F1E8AC2097FC7A5E393DB085D
                                    SHA1:A2A50912D650D39689013A601AA752BFED1C807B
                                    SHA-256:459130B6B99407E3DB65E8B1E31F980F8BDF458707EB6DF07197E374B9838A6D
                                    SHA-512:61C2EE031F8838239193113EBE186DB7951C10694DAB471F84E5E1FB28986858CE1ADBCB4E7D4CDD6D23260D1FAB977B0CC3B235FB77902D775C4229E13573CC
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..{LSW.......mo.n..H[E[-....L..`.......@.9......1.......>..D.q...#>...8..-.......R.".z.or.......<..S..".H.............=@...b.......H,...Y..O..kD..L>P.,>...w....#.......a0.ca^..fg.......P.*.}.....Q2....4=...{.`Dt..~....J.W..?.a..Cb....bS.H.1U0.s#.m#.w..Q....w.].w..H.w...e.....?U....0[.`....|4.~:.Y9d..F..:?-<<<:...X..S....!A.7....yX....Uk......BF....@.x+.....)Y<..`P.....xg..|uZ.i....g....o........9..Y'....S......]:..\......9.....p...*...."@..2.F.bi.).*......P=..T...v.jL.2Adv..z(.,6l]...K...F....L.F.....l.)=xt/v.....mC.^F.,.6..Z.W.$.4d..J...Kr.C...zI.Nv.H......`...C.....B......'.......,..f#3g.(.....]..]..N..?...CE....I.DQ....=.$.F.x...(U.Fj....U..-..u..-..$7..O.C.Q.......[.R....V.W..\;..X..4....}l.......k..X......W...K..!5}.k........-.../...BM&Cs...H.J..n<....@..7GnWa...m$..C.....63.........J.0.y..c..../^6....^.....lm&WD.../H.m<.j.....[s..[S.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):695
                                    Entropy (8bit):7.5150265960205465
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZZehKR04ZPYqCKwHMaBHL6e3B03YBfQD0y3S6Rj3tKZcGs9haSXJu94Em9:HanehKRvYqCKqMKLSISwt6xMZcX4SZue
                                    MD5:CA3E44222B9766B67C7032C701541C4D
                                    SHA1:7DFADAF1CA802996014D4B68B7EA15DC91BA86B2
                                    SHA-256:A768847285C61E24492527347D16752B090D021B873E82F8E62852D2B3768201
                                    SHA-512:27B66CFB9405EE6BE97E0AACB5A8EAC7ABE1A18C6A5431BE422B315F177EDF5F419FE7CBD6A09002F9A3DF83E8386EEF7CC7F35EB40E86B7DE90A481097070B2
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....DIDATH..K..`..{A..-.....pY.Y....X...s......+.o..ftE.q..a...r.F.E....m.qh.|..JJ[.:.&'m...|..9...O.8w.="'...ui.."....d...:.r........wn.....f.|^..B..;.TJ.N..X,J.|.l..d2)1h2.......'..[.DBf..R(..r..`q.....x\ak...,..*.....nD...3I...7N...B....d.`@2..A^....U.[e.$...)..h42 ..Z....g.A:D..E.....|.....}..vY..d.jU....l.......=7....4M[....s...M.EO..q.._."...SBI.(.Y..Z...6.k.S...E.`...........dTs\*.N.j0...g.P;....H.y~.D3..s\.p<..z.*...<..|..A..A........].V[v.p8d~......5..q...M.iTqJ.T.Tdl..`~..h.`C..F.. @..a....";=.p."...,....".M..x..G:.V...Z..".M..H...}...*......j...}...g.^....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1033
                                    Entropy (8bit):7.7289281772419995
                                    Encrypted:false
                                    SSDEEP:24:Hac265nejCUtL5ApkBex2mEl4HKVkRPN9XsRVb:6c265nemajleTFvYb
                                    MD5:D17EE1A0BEA19747C5D4B1203C073824
                                    SHA1:AB4C65A20AC7370A4E799A89358278054003F7C3
                                    SHA-256:31157DEC6F9FDECB468CDFBDE069389E7CD05C5A91714D700B3FAEBA937E68D9
                                    SHA-512:A1AA13656A1BB952AA6B46060704FE0A3DB5EDE5AC830A9F7D3AB10E4936F78D14AF969501D8826DA22A566FD25A86E133E924EA0463C441CF5961226C253277
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..iP.Q..-w.....Q)uo...{c...i".Q.1..S..,.2......)dIc...4.(k..1v...9w...............s..y.......Z.M5$?.?..h..G@.p...Z...GQ....B)..w{.b.....c...}0B..H....>..g.F.......WQ.)F.Y..Qq.0..*@..0z...M..A....X\.....q..-.[.&.m..........c&.......=08.....R..N..Mv....g.2....GwA.a#.`m.J..../...( |..R.....@.V.....9'.Y93..g....^WQ......8<y}.I.6....>F[SR.....g'.{R.(y.....;$....c.RT..@..1...b...<......y.GN.@..XT0..\].."$...uF.).i.)....?..h........!=.....)..ni.'J.R...............2.....WO3....q..$..b..b.O...R.h....bu!......N[..,rt.q..Y&q......\[^\...F..^Kn..........c..uL"])]qs.....I..}"5.%...^..1.I.p...zwF{...x...w..=jP..H.W]..1x.....!..t..9..."..!95..a..(....w..F.ma~........It.5_..M.....g....[.}.....M.........lU*.`d.Q.k.CM..F....4L.`Of.OK.q...y hjJ.h...h.wl....H....,..d2sc-.tlS75...m=.....D........}`;22.7...}hzLD.M....>....L. :.I.o......y?.O.N.....|"E..`.9.`...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):944
                                    Entropy (8bit):7.668014193939864
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZZSL/ONx//yNDxTKCT7SKGzbG5Tm2Ixl7GN0mzOrQa3oI7YA0rgQ1PGX5k:HaVNJ6Vx1fKXAaHaeR8A5Va1
                                    MD5:8D8287DF128380B33EDB3E936FAAA0FE
                                    SHA1:2B6656DCBA9D15DEF203509E29359479BFD3D1CC
                                    SHA-256:6BE276730352E48EA9E17175D8C98C93698B43266BB7970AC3C6D2545984CCA4
                                    SHA-512:31568BD60961AEA47B422AB43D0E21C861EE63EBC103A26C2AA9330414C7B6A05FD8E993618FF2EBD17B5A1BFD4F76810CCA109AA7B235B56462DC708B6ECCED
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....=IDATH.c`..P.,.....a$5...3k.+.......O...f kj..y...j.R..n...RaJ.....I.,.u.P..U#.M.VW...u..B..-0q.~3mO..kw...*...U.3..I.b..U..0.V.1.`..=+..@!F..E.e4.N.*...a)u....<..,.2R....(......d..<......+[...t....R....|.D.xm.Y.m...pb...,.o..bE.....d.i.s.".....?$U..J..~......o._B..".86.CCC..u.?.>P._.@.,....YR...'.....M^i^aQ.>..E.c:...eh..T.;.-le5.....>.-../.%...p[[cI.{..v..#H....LNX..TR..k."....b.%.y.0.VK`ot..?.D5...[1,P..mI....;....~tyI%.".+.......,...4.;....b.JW;..x..(r.cX.c..|...f...E.y...3..:.~.4....&@...H.IH.............Wa.~..j....z....6S...b.....<b..x..k.?............#m..(.|..L.3{..$V.|......'.._R......W..t.$......Z.EX....&#{......D...P..#..@A#......5....s..R.j .e.2`....W:...p.'....i.9i}........K.......E^_J...7.Q.Du.t,.../..._..]QK*....;.=.....W....})C.......+..Y..ppp`....:B..t.....Z41....a.>......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):999
                                    Entropy (8bit):7.694173553938531
                                    Encrypted:false
                                    SSDEEP:24:HaPWeQ3JUXIhlatMhCyZzJspDBmqsrvxRBfc+3MsEG9:6PWn3JUX64zOstBurbBfzf9
                                    MD5:4619092A7260C7F51747222F3BDFAB43
                                    SHA1:D98F8E033900BE101DAB04208777D6B9FDD8C659
                                    SHA-256:373365068B3BA4FB7DB26EAD65FBE3180F1E6DFC3E087824506096FE29E1F3A7
                                    SHA-512:AEBA06D1900DC789AEE602483AECD3E93BBC0DDAD835722C3D6569613F1C2960FA5313288A992468CBCE071BDF23DDB78C72BE647DB556B2374BB15D59F272E6
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....tIDATH..kv.0..GO.6....Iv..t..D7.Uu)m...~.w$.....s.m.w.%9..8...}.........H..R.%[ddrK*.$.".$....7z..{.....'..m...y.{.....I28u..8l.u..j.....xF....q.LN....8fi..t..`.W......SM...P[.0..i9a..%qU..G.K....0@I.m.....j;.w.....y.[56.B..(F..h.5...]......sZ.. .H.x...x.d.V.!..r*LP@.J..0..........K...*.+..u5\W3#%'...S.&X..5.3............y.. BZ|....a. ...kB..f.ng...*...L......|.w3ef...th.W.....y!)"...;.87X.3ae.......5... .-U.Z...:&..A.>r...;..._...%.........\B..e.=.GKK............"..gv...cH........0....(..&\..k.+.....G\..`..g..@7.K...d.q..n.-.7.....MjM.v)n-....m.0X:Z......;.(..-./.vH.g..w..j.....:[8.1>...2../...,..4.nya&8'..{....O...r...3...=....?..bz./...n8}....6?.X$wh.....'.......D.......p..)y.........h....?..C+.....32..,....7r..hK....Vwi.h.....K..v.WJ...e8...~...c[....5.f.J.....vg*..S..t<...;.....p....0..{:@.......//t...}.z...M...g..O.....?..X.~.X.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):461
                                    Entropy (8bit):7.3045672023
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc3K+zrl8jloF/gt+SI7WdZbbHYWlzVgaXK7aXT6AeVPtHrKSp:6v/7saZdzryhgK+h0ZbLrVXwaDBetUY
                                    MD5:3BD32856BC8F30E088208C05B216A6EC
                                    SHA1:93A32CF8AEB1D2FB850967D5F380B471FCA832F3
                                    SHA-256:B8D77227BBCF02BAF84E8EE462DD86E0FB34D54D16B6275BB46674211106CDCE
                                    SHA-512:314D6B5836264900BCA2269267E5A6422CC3912719F360DF9B648906F39AEB225D637B65CE85DE140D7E21DA74A409F355A4ACE8AB764F7BA6B6E943CBD957B6
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....ZIDATH.c`..C.p.q".....'.C ...j...Y...8......#.... ....QD..s......T.....``...sc/.../O.......7...v....0..3..5|K.v.w..6...`<.p2.&.j.9...`.V.D9.Y..+.|........._.......;.5a....G..?.D>.Z00a.`~....s.....,....t...}a`.H..j....9S.............W....0..[]Q.b.D.Z. ..z;w.-!M......U...h"E-.0.%=m.....\.i"E-f......=..&R..&V.l`.~.(#..IQK..^..(....!MV3yC4.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):592
                                    Entropy (8bit):7.376149039173553
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZmAkgt1baar2Rw78gzNChUdSk7geWqLWlNA8RAtiWlU:HaMApA40ASkceW+Wlqg3
                                    MD5:DDEA67A9E977BBAFD6EA78A66B82DE4E
                                    SHA1:3A5122F2E773F28D8A59690891C32D2AF9E3A20F
                                    SHA-256:C8A46A765B5AE7E29E77634F03B3B1627D22D0123D2EF0DF424F12AF794A1B20
                                    SHA-512:4CC9F78F6DFD6ED23A1490985C0C0EA182159BA614B9F9E6A8D9475FFF2B7029013DA6F62350DBF7460B1950781BB064ECA0BE597A4CC172D957FD53129B3464
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.D@..k....y.m.3.?...P.....q;..Sb03.7.........e4..313.G.... ..2....]....m..kw../_...&B.f.\r-...?. ........8...f.N.,....p.N.a....M,([.....M,.a.!v.%d..F.f{<.h.K.,H'.. ....8-...Y...9I.`+Hsh.>N.2g[#.@<..].../p....5.... ..!(."Y..O.....@..P..c.C.X.(...f......K....._NG...VW\.....v.v..D N...b......t.5...KX.-\f.2.S.N..5;.f..t......].@....<..O@..!0u.6.qQ..0....,....H....$.&...h..c0`..5$ ..6@.....x7..../%.....T..;<..A..5...eP.. >......}.X.....d|..C.*._..^...<dI.H.1....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):217
                                    Entropy (8bit):6.31276163977255
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc9hkNRsogA8It2fgmTq0dd8l+Cp:6v/7saZDys8P7iq0w
                                    MD5:24267F3CE2653D103E81458E77E6FA15
                                    SHA1:ACAD2F526F754A51221AEC8042FC5B6EDED8C23C
                                    SHA-256:878D97DC9D9BE8F04DA58805193465920C60C91D7F0754BE680B153964975C4B
                                    SHA-512:DD7A5D097053A76F8D7AFA7956D72F97FF1A3376ED3BE73C74CAE80F8C77D70FA4DCF41B6B54CF2752110EF28A605FFC9DC73096AF30884B9EEB4C5BD9E19AAD
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH.c`fa........K......Y.j.H.....?....U...0....."N.Z@...5phZ./...T."l.5.3.r......T."Bq2Z....J.5.l\48.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1579
                                    Entropy (8bit):7.8497345876928
                                    Encrypted:false
                                    SSDEEP:24:HaJlLpXMTG0MX6rLINwUiOJQsrEA8XwFP2QGGdzmBVpAxCjyqAGXmsJGGit:6TLiyZX+INwfaQsQApp2QAkx83rgGit
                                    MD5:B762940F74DAB1162C586807D8150FEC
                                    SHA1:0912019A43D7374B9E83534555F7140DEC526092
                                    SHA-256:82155FC7C44B836396B99852AE6D446DF464137F067F1B5253EAC0AE2952C125
                                    SHA-512:5B7626B093E193BED30EF5E21FC981FE0E0EBBE759322D2CFA76E15A05CA154C7010EFF9BBA9277CD0E5E10608EF7676D971E73E27E15D1B74D9090375A5909B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATHK.V{P.h...........#K......[*..C.v..l....)RI.6IVJ$..(Rll.&*F..U.........;.v.......9.w..|......7.>.xn5L.l..|..s5........'..._...,.3....z.F.l....1.s.|5O.[..`....r%f.....c`~Mm.,.v...../b..*.i....Z.XI9j.6`w.~....4u.Pw..*..!1%...'./u....1..w...ap.)2r.q...Sf..f.7!...J.~3..UJL.g.... ..o.G....YZ..y.....`<.|...k......~L....1R....Q..b...?.bK.4.V...Wp..a.=C`X".......k..l~.a/.D......vg7f..Q.......0.....}...@..G8~..........!..U..!..f1.."......G......C....-tS.._......4M6`..%4..1.h=...Bpd...i...."3%.....g...N.8...!>.......c.y....d.C.c.......Nvg.>.........h[.2.V..U.....MEnQ=.9.,.U.bE:.tmwA....`.Z..t..G.O.C...N.2....k..|R..X.1{..gC.<...(....\.k).xu..S*.P...V8f.@.6.R.L...#..-.k.S..H|.B"O...:..fv.....3X.y.@..6..=..o..<......w`..,.,.........).1{...tW.,.+E4K..}.C.ev...d.....n.........v.....w.j...MB..x..-FFFH..p.+&.z.=....}.4.Hs.J ..:..~@U..oF.[._.I.....^.......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1702
                                    Entropy (8bit):7.831845141466342
                                    Encrypted:false
                                    SSDEEP:24:N/6T3KvVHpr7ie0siKZ6ohLufCaKlphxdT03fHRYoweZ4eXIsavzKJW+e8ZUe9+d:N/6TqdHsKZzhLwzwTOfxL3ZIebBw5h/
                                    MD5:2294265BB983FD86C56EA524A9357D12
                                    SHA1:CCADEED98C5A439FBDC42188C23AD354589DB531
                                    SHA-256:739D291EF57C30D4FD1C366944C6411FD2AD7BF1AC3693B8E6E0A5A362474485
                                    SHA-512:49C16F40954D7CA2346E2172161F1DB23AB94DA07656A4AA014F61F5FA9A534D83D35F88AB103265BC8AC0A6AD7A62ABC2E10F6B3465A2019E71A98366466D3C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....bKGD.......C......pHYs.................tIME.....&.@h.(...3IDATH...o............k.w...q..I.!2.#...i.D.z...H....E..&.U...g.E[5J.J...UCJZ..i.Bpi..b.....zm..~.....XK.......{....#....i..R.Oz...C.1..;..0n.....0.Yp.1.8.t.Rb.-t........\....>C.^........5?.F.....OL>....u...{+..>...G..._.....T..r.>.u...).>.&{........A@..x.>4U..O?..C.19...../.....p..k8)..?....E.....'w.jm...~....h.8...J ..D.(..)bH$.p....n...e......'_......U....p...~...|.k..o.>J...o.,.....-~....!............w......8..#4...q-AH.Q.Ja.L....[@.[@.%1A..#..&...e.....~...L.vP.c.9~..yu=..#.l.*Yc...8..%.j..@<..`}t.U.t...QE.\$.w_|.oN|.UU.u.EQ..n..[.,.E..AF?1../>.k.8.".;.....s..6D7b(a..4<.-.q.N_e./..pv.....8.]d[....x...ps......WQD.W.{dB..[$B.$.4=Z.v`..w.M=w.I..H@v.5.a...Y.S\JQ..f..S.4}z..>.[.?...*f:@].....".ID3.6.H.itQ'jx...nO.Q.7...2..D...Sh..mX^...u...jR.,.5..D.g.....z.ew...@J....D..Lz....;I..8/....^..;..l.\.:.....td.......59.D)....E@@.oayUn..z...2....p..xv32s/
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):813
                                    Entropy (8bit):7.570851377012235
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ+pex3qmzm307SBeG0dCg1khFHc97DoKzToJp6mhCrnEULj6I5HUk5dY/H:HaEpex6Pf0cg+THcKkrEujdR5dYYob
                                    MD5:D2913DD5413A13A5CB10E993AC64426F
                                    SHA1:FE3E9A7032816A8452B2FA988CBEC2C72D275F8C
                                    SHA-256:14A7034A005483F6D117C3D94BF2E24757BB952ED27F0E89E5F40B0F2933DEC3
                                    SHA-512:4B978EE27AB239876D3E8968B9C27220DCF76ABD2C81DB020F4C89EB892CFA3351906A1DF8876687F9A6AAFF46D3570636760AAB9304E0BE21875983B91ABC71
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..U[HTQ.]g.2.l...?..H+.@.bbPZ.D.GT.=>...#.(...~%?....%{X.......G....|.;...3..3.0..as..p.:g.}.1.K.|.(2.FK-...BR..9..+.FG.6?..&.d......3..\HH...h...Fk:Z..$..#....|.<.N.{D.x..J.HNa]:..t....r........:..'.E..X.B..U.$......;...@.4.<n&..!..]..A..u.)Se.Xa...Q(.......,o...loytX.g.@.zOO.I..r.1P.C, v.rr.....d..o6..8......f.o....X6..HD*.r..F{.........].'=..g....M.]..s...m.....Ec9.V..(.O.j.P.3....p.)..g....;#$...B.......L.........6...<c..<....$q....... q......?H..c...x=..B.......D#.)@.A.lOi.....7.B.B...h......jF..yP..@../;.r...o......42Ms......'..j....=.......;...@.V.)...0.....5o!.N.....N..3....z.{.o0P. .....x.Z..7..O4...R(.!}.....I/2.|....fXg........*NDA.2.....3........ m....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):783
                                    Entropy (8bit):7.616588971497248
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZk2ap253F5TDXhWIoM3Vxcg8OHuUWbDTQSkP3rvdOeZW/P24bHD/G6+WBs:Ha62fBDVD80ut0TvdO9e4bK/ESWev
                                    MD5:5C5B218ABED182BE649512368F4FF08E
                                    SHA1:33033ABDDDB14E7624CEE395C142E29C477E094D
                                    SHA-256:16F38A29AC2DC8179AE843233DE80BBE0950351FFB1FD6AC8878D349EA6C768E
                                    SHA-512:5BA196BAF1019FD5E55B0976BE45080D5DFC61DC0172AF81CA3053A7361D0F43C3AA22F2DAA9262A3A378FB9876BF11EDD86BD939FBE75DCCD609F0554025596
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...h.a...vwnV..8?oM...M.N..aa.(...n.....u...H$+E.!.W..d..?.D...j)a...g..z..m..S..<..}......9..[...>.g..........U..@.@.p..."....."..#.v.(W....m3u.'..p\......Q..b. }......N..2..=...&....W@.P.eE.+.[....L.:H.h.e7.pA&....k../S...2/^.%a'>....yNUs.l...t.T............5.}L.:.Rp.|..B_..;Ua...i. iE..Y..mn...SV|qK..I.'.........W...G0.6i.W..*K....8Fh..i.(...~.H.M....h..g..o@,....5....\.P.....s...*.+[...%....3...n.x...-..6..1..Iv5..../.>..l.N...A..P./..tSX_b.A..,O.U.s8...H.b....V..w..`..I.....l<....Q"..I1..m).5......`........b3.X`..M\..&.Rl.."...r. ..?.b........^x..d..p&b.y.b.......e.....j.^.Q.7E.v..:".[..g9")...s.3..2a9}......].}.....b...8k*.........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):295
                                    Entropy (8bit):6.649884229559437
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcJi3qZKdWqGEN6seCVeBQUhV0lluLDu+FVp:6v/7saZJiaZ8WqK6DULQTq7
                                    MD5:7DEA69F7FEFF54901AA4540DE3A26B90
                                    SHA1:2B3C12117160BBD00BF4E49273CF1BC6D4ECC27C
                                    SHA-256:4E199E512497192685EE27FC9A8210A071D6D6E249DB3AB52517750512F79EF1
                                    SHA-512:708D8F178A6EE4277BBEBFEF2872643FEFA022B211EC642AFD6A2181E4D5DB7D22ABDB7C359585AC0AC42A2750D312DA34CFB83ADF976F0E464E49F9EDF64FB1
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```..../...c."....../.@.h..........81.c....a..\.S.....8|.. m.C.L.. .d.V.b..,...jX.d...- .t`..].!.L...d[@(.........8.....0...%.<.L.....8.'U,.a0j.Qh........:.(.........O...d=.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):848
                                    Entropy (8bit):7.5568178818775165
                                    Encrypted:false
                                    SSDEEP:24:HaUhtqUkvbWR9gSDNJ4Ii6o+JATBve2nFc:6U3qZv9QNiJ+CFXFc
                                    MD5:22D1F372BADE3CD19D8D4EA5449195B7
                                    SHA1:FD728C6D03F4AF1206EE5691556EAD13FB778DDE
                                    SHA-256:81B45BCDF9A18AA38373AE2EF09237F4317CC2D1A136B3830E67D664F0E0D54B
                                    SHA-512:D7DF2E7DFCA76337A5136DE629AB1F00AD056A8BAF486E340CC0DB6BC443B19EEFE73094B7DB9D11788EAA59E786E6D1008BD454F5B142F74F28EB78021E8172
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`@.1&6.K...s.......@..$o...l~ >......a).U...S..WuM...'........3..bFF..@.'.f..q....E..!.....|.?...M.x..'...3.[4...'.5......Y88\.....p.....G0[.3.-.p....l|". ...40.q.....i..D3s.."..x8...es.._df.... .s....@H.;#3.~........8.%I@..+...Xz..9...p8A..B...........+|...+.*...h......8.....;ZH..Fd..a..7........TG..\.%..!IT@r6.p.... .C@b............p Pefa=&.m....-..@>..U@l..*f6......X.8..H..P............[ll.QPq. ....vI...I.....o9..].(......"r.A..W..o\..?;.....n .#.Dff.p$n"4c!...Fq.._ .%..@>p&..,lkX.Z@L vD.?Fh.-g...B...xr02~.6.......s...P....M!!1wh..Z........cP......Q....d.kD.....w.H.......Id[ ..=.d...o.O.u.?.?._n%..)v.......A.........J.G/... G...c...,....@l",,......X.#..i...l.$A...!*...i........p\..1...3................IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):438
                                    Entropy (8bit):7.1454922264990035
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ0WACAKm/wJxEpNGQfN52iJOLGAfQKTcVqymTpc:HadEJHHD2iUVjTpc
                                    MD5:369657CAC8AB19A28E26CD10B1ABFD70
                                    SHA1:B3D69E623B18466DE0F6A4DBF224D250483B92AC
                                    SHA-256:38380C649ADEFD2939965D573B2639BBE7363CCDEF8AE7697C5D80A7A5E9D903
                                    SHA-512:C38C52AA86B056532FDDB53B2D301D84416D456A1B5EC4E788DDD10C0EC4C225392EC350FD252D8BB98A834CCF5860EFC37A278B8EF68E044F2DD5BAA9BF292F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....CIDATH.c`fa.......j6....>..C-.XPXP.....`......8//.....[....A..l.H...q.ow6#..n..+!...E..`Aj...**.o..@,..~[W.,v+)...L......b...."m.[_....v..b...8.Y...1..uu..S..P..\..ZZ.ou4Q...0..0..-.YBQ...L..h...V_....81...%..\..o~......Vv..[...d..$3..|..*.- ..........x..&9..X@...O(...|B..D..., %.Pd.1..2...O(.."+$.,.|..Q.)...l..>..-...$..5.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):819
                                    Entropy (8bit):7.635704166545616
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZVNX17b62WALbzsH0RH70oMGAqr24t/IxQXyhFsM7Km8xu0xeikxGM5cFV:HaZXdBfsH0RH75gqr3OXQMQEi+GucS4
                                    MD5:428FF2A8E1C428A65F0238A67D626687
                                    SHA1:EA6C3107060FEC615AE9E57B6F6B9D2795D58850
                                    SHA-256:F73BD8D903AD6E5CFD440990BE8207CEBB21DB01E7C6F9EC502B022F990088C9
                                    SHA-512:510EC7DF27C6C5CDFA6EB156E68DF2CDB312D966581069A3CF272B48875AB3C6C36749A0CF9FFBA5294DFFB60BAD7AF9FC3E79B388E79F85D44C22233EA21E52
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...[H.Q..pk7kwg.......zIE"K)(..nP.].@B..I...M2.....B&Q..[PA.C..m-$..n....[D....?.-,..(..~.a.......DD..Q......:x&L..p.gX:.....,.u0..@=........U.....\.w.'..._..t&;(a-...~..S!....,.F>....)......D~.5..a...Xz..~........pY7.(mG.....:..|......5..8....,/.....rh.F8....^../...d.{%..R...P#...P.d..,.y....^Q?..dA../....Q..wZ..l..._.Q..P.z(.(....].....e..0G.....5)H...ZxI.8jcyd.=.p....|.7Tp....,.L.\..1.5...ZB.....K....X.$...[.v./..J.e.n..h.......H..*.......>...5..`.6..B.zz...(.m..v.R..M.}.x.A.0....#."ifOF...&xI7Z.8.2xY.e*&...2..#.......4..=p.|.L._..KZ..$o.b[...fu.K..5_..7.,.....-.._.OI.#....#3UK..#..L....s%.H..&..?ey..3..Y..........#....v...._9....1..>90.|O.#.vh..;...7..I.....4~.............IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):955
                                    Entropy (8bit):7.678938775213358
                                    Encrypted:false
                                    SSDEEP:24:HaGdg7vCEGoK1SWXMBOkzv1G1rurCE2whDbgy2c:6Gd6CEdK0Wur12vzkDbt2c
                                    MD5:5E161199F7BF3EC697D7454803E16A45
                                    SHA1:780FCD972CD6C76EF4EA111C60612E547604B5FD
                                    SHA-256:AD716CDED42D9358C2FD198499BF5A4FB67E73680CC9DB0A29CBB9E8249B7F13
                                    SHA-512:394AF75C35EC53B7F8A7C0FBF4F701069C08C02A1120C9112E442EB3B1D0DA8440B4E7EED00A0233EF26902B4AAFBBE54CD6306E7CFB8945BCB22DFB7FD03BFB
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....HIDATH...{L.a....9u..2Vs....EM..LCE..J.bn.njQaS...J.+...m.iki.........G1.E....i;k.F.x...g.....s.......q...6..]`..C7|.y.. .....a...o6...w.h.........2..j.q].bw..%Lcf.\..[.../b.h.......1.<K...`.6...........?......C.dY=....W....s....q...I0......K..........p...x...#A..P.I$.....ld...)p....)..._.v\.W...7[....:./.7...R..7R..|..y.Z...Z....c..(.L$5......H......(..F:|u.....B........V.\SA.."....w......\..A.5.(.l............S.O.X...56...L.@$7hO).J........w.Sn]4.).N.7|hO.+.. ...}..];ie.....!t..A*x.0.............mHd.......#...4.t.r.4M....O..j.."...I(.....vXY%.+.GA...3m.\`..`.`B./%..........V...D...{.....t..`..:!.I]^.T..r.....d.E.x......L....;,.....6.....~47.698H....0.M./r.........H...t.Z.oM.....R~....3V...........7.Y[.MwZb.pN.D..!......3..?....=od...yP..x......?.]...r..Q.`r.[M3..[.....".f.....[KK.*OO....~.pm`o.#.,....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):852
                                    Entropy (8bit):7.6502777375247275
                                    Encrypted:false
                                    SSDEEP:24:HaZqVMMxXARkEAOAlE8K6kFdztpFTS85Q9JUCOa:6ZqedRkEAOAOB3xppScQ9Wfa
                                    MD5:1682448020FAFC44AD2698704BD978F1
                                    SHA1:C943E219766FD441EEA7130FDCD8E4370ED80841
                                    SHA-256:E5D4E6E6D637E9ED03E552C0D0D7F1DD88E13F0C0276DC77717B9DE13F8D16C5
                                    SHA-512:233387F10B15A929AD3C487594299729F3903A8B3BF2AE0A0D22358A9F6F21D70F20060336DE1D820E9FE2670DA58A7B2572DCD7196174DC45C493F7C7EB3F66
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q....7.0."...gh..aj.+..%i*....(ERI1...,.>..E.~...7.n&...,I..2$.!.....l..;...~....?.<....Tj..rA.R...%K.\....E......8..@:x.dZ.I..+z.(.6Q.fL)1..,:%....@#8."x.w.l.'.zo...n.n.9ij.r.:a.m..l...(.W.....4>.'.V..L~..`........A...s..t[<.;..............A~X.\:...5.#..a#A......O..w..5u.g...W.w)....+[="......1...`.(^..5......e.h.3.."{N.s..#...D..<...=Ox.?..T...-...dGN.!Bs ....,r.s.z.Q.>/P..`..,.USp|.^....._D....c..Do..{.,Z.....DK...H.......i(:a(.*.o=.,$l.......n.<_I.G.Q&2.v....C.b.......m....L...H...qqa.....`2...^..5..[..........;.f.....)z...S..A.f%.0..X..V..|.l&cL....Va.8...g./b.....3.~........q..t....MC.F..,..6..$...?.GE.dE)g..b.eI.E F.N......e.t..g.r.Wdp.e.......\..A..a3...`...Q./..\...k.........P].8....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1272
                                    Entropy (8bit):7.805905219435155
                                    Encrypted:false
                                    SSDEEP:24:Har/vpjaC4G94qhbPSSBR5hoBJFVKVtWcrCkgbeH5vQ5q6IOSU7HWPXJz29LK:67vpfLuqhbPSmsBvVoYcjgbeHQIOSih0
                                    MD5:07316DCEC4B7A791703D32A63F60C99D
                                    SHA1:FD5BA289BA923C76479B382449F01217FA298D6A
                                    SHA-256:8419CE5D7CADAA7D5170ADDCE1A6E1A53E738D504E9EFEAB63B3EAFB60EA41B2
                                    SHA-512:B1D8C3AFDBEE5E3CC78044731B69DFD70B46006CA78A9CD125A7F28776A237C695BF042F4B8F7C0008518EA44DCA612A155AC47AF5252EF302BD8A3552B937C6
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V{L.e.?|..].wn...Jp.4n.`h.$..)...A...........Lf&.r.&t...$.T.L(3.....-.Z......P>=...........>.sy...{^.j...~(TXX..(....(.j.KMQ~......5..f....n-.J...5IA..W.p..~..Z-...u[..85..G..E....].. .6..$k.U..].}.p.?.....t......N.bV.+"..e.....~..5.............k..b.....=i.U..j...QOT...T2Tw.BT.u....s..TgT.'dF..8R.G.^...[...H(.8.,!....^M_^..y..\.'.".).]xe].:0.Ly.....J-....{g....;....VJch..Tc|~1s.3l[.?Z..S.../7.."..d?.@..w.Z......+...........u...f.....3[....'...6../..f.]........o..@..q....C.^.9J...{#.....]..u..5....8...lO.......L....-.....|\.p...< N.........Q.*i|..}[.EM. (.....Y'.)i...}. ......z..f..#.....U...<.z........Th.j;..n......PoVF...... .*.x?.X...n+,M..pG.. j..C.Y.i~E.z..^n]..H..X.....s..O....I...F.......<#.....|=Z......7...%>?x......8n. ....G.G,.Dxo.............V.E..c.D.>i....[.5Q..O..x..8.......3.^s.....rh.z.v6o W|o*..+Y.s.....>,.."....Cb~A......h..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1210
                                    Entropy (8bit):7.797403183791096
                                    Encrypted:false
                                    SSDEEP:24:Ha54P/JCe7IcvpUGodv2vbAIXc3/Ccsqr8FT7v4//X4LYpe+ttyq:6mJL7IcvOXAJ22RtvAcA
                                    MD5:353CCC7351B2B66BD405D3068C1D73FE
                                    SHA1:A06894386C79A7C50DBBD6A3A16C5AAD561536B1
                                    SHA-256:5EE98476395C8980E580D8E65E738AA5045F8D94C789FE5CCF5ECF05C3A807E5
                                    SHA-512:BB3B02D59CD6B4B6A138A67AB66E6FF450A9F1BA47BCBEE579F8026BC8B0AF6998BE7DBAD21D93BA3D5BD5206B5914D8C34A85A704DA5F89284EEEDAAEB70717
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....GIDATH..V}L[U.o..{}}.X....s6.c....S..U.lP6'C.3&:...cl.. f.h..E..8...&......N.\.&..4.9.RZ:...{.j.2...nr.{....9...}*....$Kz.k...tK.?.-.3z.8..\+...$..LQ....I..O.?.qigS1.w<...<..y. .l.1Q..+...H.v...8;;.......&X...0.S.|t.e......../....@...P?p.<./..6q..P'q...iii....S.....m..M.....^...O....N(.\.e....;W!.g...t...O.G........j.Q.....#_7.....<...5.W4F&.i._x....!^.OQ..r./.U.......Y.:Gs.A.Zu1.~8..n.Y?..h...._.IY. ..h.k....tHg..U]YQ.Uw/.^......e.F....[~.9....C%.:+!.kCh.Y...l.M...sEI..{.HJ-G .......N.K....w.....d._7>..%.'...&.!.C.....8.....M...v....%.YrFN....Q.p........#....D.YI#.x... .B.".d..2..h"..15........,t.....;...E....DP..<.D..(...i.xz...*.,.h.x..H..Sj....w....J....@.C;...5.[.@.E..-?...%.#.<.!.B..s'.4q.m.x.T..qg..Y...Q.W.?A...W.wB.@.BP...{.1@....usAd}Ik.w&.Bk...0.X..2...pJ.-|k.iZ....L.`.u....y......{V...{.*...AV5A...9...`h.z..7.f"b..[.......4:..$.Yb.."....>.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):616
                                    Entropy (8bit):7.443433882018433
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZI0EdQ+P2zuqZnT4FutCrxGxgILodO2JUN:Ha25m+P6uinPgxGxPoQ2JUN
                                    MD5:0A28DA391C0B41F44D9DB40A89730F46
                                    SHA1:0E8564EE9D1AEF4698C74B050A93339A1D1BE081
                                    SHA-256:88D3B02C5BB1E488833F260CA1AD60BE75530622F5059C004BE5D67DB12536ED
                                    SHA-512:073C4ED98726FD034ED92EB327AB483133A8EEAC0A732F6EFBC85388449A27C5BBE34229C595CC85B104326E17476CF032041192AB200603C56798EBCE8B94D8
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.i...C9yX.s..bag......(......?.c0...K....7m3....{V..........[........P.H...\,'5..;6...s..[....D.$[.....S..+S.7..._....G..?e...|".X.~P.Dn..\_._..n....d._..._8.YW...X....Q.^.m....wz..h2......(,M............W.....f.......2.x....V.o..DM..4m.?.,.i7....z...."X.....\....]Dm.jm#...,pJT.....Im...b.....A.!aA...C.n4.v#.e....Y...r..O.........M....g.......RG..x...~r...=...o.../.@.....l.....(.&EVN.....(.d|...VvfPnV.F\..K..sm..............Y....8..-../(.....)....X4Ogfe....h...8.J.N...........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):660
                                    Entropy (8bit):7.505490499073369
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZVAqFBVJX2RFsYI1Rw2VYatgFfLAgxQ7IE96gE92Az:Ha/AYwXQRw2VNgS37IoLI
                                    MD5:6BFC1F0ED58680ACF33DEBF613A57148
                                    SHA1:56E760AEC70ED7D8C65124554ED80C706BB5D2CC
                                    SHA-256:902BF9B0AF9DD955E2DF20181FF175CE06599738767DE91218B1BF2555F1BAF5
                                    SHA-512:5DE9C029350EB4231CFD56D8F7A722B5D94508029BA1FF27EFD8FFD95D1A4566DBDA270247669C5590E88ED6305104E65EFECA3462A2F78F46FB9E03840F3B2C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....!IDATH.c`.N.............Y.>q....a]....b.r-.`eg.q............W.........6...i....#........S9P=3Y.,8].v...n.........N../X.._FK..;7.^..6R..'r..].._....'.<..E+...Vou..b&....y!.."..@.........g..o.%...s.~..P3!(.s2...1...%E./......b...?.,.[d...O@1.jZ......r....... .4...`...:..l.......7us$...J=......N...l....r5...{.~...P..`J......O.T...z......rf...h.l...q2Y..s.......d.? ....b...I...{.[...s........B....yIw..m..o.../.{.....q....r.......b.`..?.....l1........<....@.\..;.......}..(cN.T.,..Dd...-...+.....9...+.'.JfV.?,.L.....8.....%..V.....Se....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):377
                                    Entropy (8bit):6.927103825066419
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcrrcOaeSUEz25zWlletybKidVPzMk7d0WvMlnn/vRsOAdMoPUj6:6v/7saZ/ciSUEzmzWlkLiDzMk7d1M9ni
                                    MD5:7A3A02A08C59BE3F7C4329CB10D8B19E
                                    SHA1:AF608974F496CAFB45D338E7312415297716E310
                                    SHA-256:CB59BB21593B4679AEF82AA2B4C7886AD746B913683E033075D5D537D774A182
                                    SHA-512:950221A7BFCE6A317364133D330477823C4737A74FA6C782319C5BDCCC25D0E5CCA795FAA7305A8A165FA4D365B24FE056E58531DBF1F429494595386BCFE86A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf....@...f.........^w.......... .....$...Hc..7.0H..K.0........``.%C.s.wc...\.<.\...[.).&.@..'.....9I.%...(S?..-A. .(....S(OE.Dez....a....3...E... ,$..P..-\.1..z.j(...D....`.....> ..l.S=..a...>.....l.A..).ar..R.-.y..$508.@......hn...".N..hM...Af......O-Z.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):613
                                    Entropy (8bit):7.485960849218955
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ44oFSt+MvaJrWSBNbVFrI6oULDPXJKC7VfBv7UDN1Hmz:HaloFe+HJrbl33PXECRfBv7UDNEz
                                    MD5:116E10C815F01EC18503E5EDA39F2B42
                                    SHA1:C72F96CFFE84F253DD1573F4B00902E389EBD42C
                                    SHA-256:633F0472936E4434F95DC7D417B84F4A7ABE9B96AF16488FE8C430A6B441DF6B
                                    SHA-512:B4F4EE1A34B171A3A011E728615D08078140602D1D8D582A7C37E050363BF093990B0C96F68B643A103C7248BF239A10D70B117408031C2B5462D4B8BF79D791
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..?hTA.......8H....),SK."Z..M.b.B..)..D.S..W\).I<.-,R..C....y/.......s..C..............A.(...R..~.j.+.#.[._.$..........S...x......@x..gL..u.8T..<).>.>.c...Q?..7.^...H.(.c...E..J..b..R.$v..s...s#.1...w..z...0....<m`......9._....<.a8.@......,.ZL.l.....#..........0......i......F.p.C.#.NBA.p....B#....5<.Y.....N....d..m..j......$....v.....v..I..i..[k....Z.#.I.d..G..."..5..{....H..... ..v.....<....4.q.{p0..S~.....E1..I.&)r.....z.1iBN@p.t....9.c.^. B.......u.x..~...._....-31.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):577
                                    Entropy (8bit):7.3423909253899
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZzxpD9vUVXvuX3uFswJC0psrx6+Y/YIGLum1BSwZM2dUUlN:HaxD9vYvuY0+1/YIG4wB2U7
                                    MD5:A721568DE444D543B710252AA03D748B
                                    SHA1:D8BD4BE2E84740150C3F558C4AF008D846FDFF32
                                    SHA-256:C7889C62624E70A97AF8F9FA35EB1396FF134FB3DA8D2C52B88CABCCD0C035DC
                                    SHA-512:DF6593C262D51F49EEDA0BA4B32BB814B1A5C27E845C1B3C4BA7CDD82051E14086CCF23D002987427503D3B03F1B1324D75EFBAB1C13174AA7BFD3EAF3F23FA7
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`@...wcb.8....0.Y@..XX..X..ie.../..n!..L.L.D...ex,.b.`..>.....9.X.233GS.."...g..;.x...=....X...a.....J...l\,....~m.:......5.\.8m...6N.%...."F ^.SW........ek..Wnr..gdd....(.d.....;..7....^..`.#..~~..K............;..[@J*......|..e@..8.H.. ...K...o..O}.DDD.......*`2."-.....D..5._p....n?....5..,.M....._q........v.R-..3.##..11..+/...p(...N..|..h..lIQQ.V..k.........mw.g.......b....G.O..yz...]......O.d.+..U.....~..i.-.s...ZV8.._e.X...'..@"-.~&.Q....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):206
                                    Entropy (8bit):6.246485617263056
                                    Encrypted:false
                                    SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwBsUXp/m9ywb0fx/pE44XjWdVXK7M:6v/lhPZi+aWdKcB7RmNQZ7RdVa2N2up
                                    MD5:1BB90612C945D71E39B134FD84989B70
                                    SHA1:7B694DDF126D09551CF17BD776EE68F8F54242AB
                                    SHA-256:6D153ECA03C5A8EB2E0A86A7A7E5C59BBFB0C70C6346FBCCB5B9CAFC43D90394
                                    SHA-512:0F40A021A59847C1A6601CC993164B6CEB0F1490235FFF7766CF569AEBCF215F092E5C887D0E022F50358AF97677B0A8E7FA788D7D38B9F02764B88644E15EEC
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....[IDATH.c`fa.......j6....>..C-b...Bx.,....A4.-.$....F#.......`dF2.AK'....O4&+.h......."Z7[.....'.@....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):545
                                    Entropy (8bit):7.462798362030968
                                    Encrypted:false
                                    SSDEEP:12:6v/7uk3aZ7BMOFiSe2BCZ6hdxdIjbIqzuRJYSa16/LVqSWq6I:MaVBtS20YPb1IFGJW/I
                                    MD5:0F089C5C3D8F200201814E0EB4C3F459
                                    SHA1:63ABAC882C2DB38D101E23AF193F6D4F43473AEA
                                    SHA-256:353DA4B34D653159DF2EC1FC2D5CBC8CF7641FC7732927E6F5D7CA90A2053A8E
                                    SHA-512:90CE0E0F141C5A88F868913B11E1CDFA0FD23C7EE53F40CEBD7BC5F003E51665B0BA3C1B2346836187C0DD7A3CCF086B4757ADA23A02ECA573E87A7DAE50C0A0
                                    Malicious:false
                                    Preview:.PNG........IHDR.............V.W....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...+.Q......a..t....66$..;eXP..R.l..$Y.RRR...%J)C.k&b..y.......S...9...........e.j..W,#Q.........2.o.g.9...Ng....hH..1.........a.I_B.x&...z.ySR.....F..~6..p...@a;nXQ...Ah3CY...~<.Ej.0..d..)..5Z}.,....b.*.X.N.........(~:HNN<LJ..o (..@l...X..O....P...W..p..u.98.r'.?>......./.d.c..j.._.Z./{te.hh.%.0f1.....y....d.M..'^.P...Aq...^=:...or......6./..C|.8.5..JS..;(.......}q KM.."&..O'.t...~\.L^^..f.c|_>..7.7.A7A....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):307
                                    Entropy (8bit):6.663616187019764
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPXK+aWdKcRWGTNxsApmjrFStcKVqdDH2h5BKwlYXPDYQ/bp:6v/7maZRWGNxsAIjGcmC2hdYfDYQ1
                                    MD5:FCABE0FE5FB6AB4D1BC770E86AD12CF6
                                    SHA1:867239C44A4BBF506A46B03E8ABF757A7C037D5D
                                    SHA-256:3D5D9F419FA612706668AE59A2584F565C984DB6ADDB38BC7FE00C7DC62B59EE
                                    SHA-512:B8BFD5793B9EA21237A90951CE2964EFB76A0AF2B67B1D1DE101F32DD2C4533D4C0E3F58DBE74ACF2BD0CBD35973C9D6879828953B15A9D2014C8429C1D751CE
                                    Malicious:false
                                    Preview:.PNG........IHDR.............J~.s....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c`....!I............@9P....?C=q. ZP...C.X..x?.L/G.2...p..B..4./ .%>@...-%^9/.{..3.5......v...aL.L.w...p.W..X.-.(x...E....>...A...`..z..C....q.W....A..$...=.QK..!K.{.w`H.....v..,)......9.F......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1279
                                    Entropy (8bit):7.7728133290999475
                                    Encrypted:false
                                    SSDEEP:24:Hagth1pJkSNT3ozc6+HhciZMoKhHydxHKNJiQfMmUqvG3b8aMJthT+M/6tVP:60Rh30c62hlShHyxHaiQeqs8aS6b
                                    MD5:F4B99D3B08ABCE65385AF2311B6AF205
                                    SHA1:0BB77AA406DE198E1E7CCC244E2782C2A99636FC
                                    SHA-256:1DF75926F2E4805278B1182EDB75A121543EAED317E25F76A758EE4BE6A2CA6B
                                    SHA-512:4BE3CD59A4F807773ECBC8B2F7BDE70D5FBEE235189702BC26E2252B5E520AEC11D81EE6BFB6654A448CFEE8DBE7A1E5EF614984EFE8C4D75AF6C021F99A82B6
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UKo.E...}.z.&.u@.....$.. .R$...K!...8!"b......._ ...0......$..$.-..$...W.....!...vw..uUW}.....}...z*..|..*...<.]......^v.....6..N.`'T^.-...$.,.!.=H.!H....w...?.....`....MG....6C.B....$I!.F..CH.}...h.@z7...;.....`..E..._q.v.js.9.C....(U.$9...9Fp..{..K...n_n.............f..n...=..V.`...U.0S..4Z`..j3`U.\.*u...r..O.1'..^..V...7*...2K$.z..i..i..p.ctV......;u.v........K{.....Z.|.6...I..,<....].G..s..!h.A+f..4.....;....hf.l..x.P....C2..di2...8.N~...2....F...E....ywB.8........p...........[7.X..c...6..f......M....cJ.Q4i.tY.). ) ...`.O.g(G.......O?.Y.w.<....(AdI%..^.C?.a,s.?..)....<....6...ux...E.c...Oj....."$.3.F.$..(-...h_.J..'SxP".*.y!#...R.i......t.........$.."I..@..$.V.Q..q.S<..n.....2.....C..~`H...y.E.?..GD.&*.0.)..\&..i`..e.Js.2=;...Q...0...k=.&...#.0M.)*...#o.].4....9..n.j".4..(...-.....v..iM.......g....t.$...D...........$.....8EL..h.ipR.o'j.~..j..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):990
                                    Entropy (8bit):7.65551415416186
                                    Encrypted:false
                                    SSDEEP:24:HajFLtp3/M8CuDffgrBaaMOwBb8ZjYUPOA3e82:6jF/0mgrBfMO6bW3WAz2
                                    MD5:3E6D7FA4522E07F8192A81502ADD5A53
                                    SHA1:9884B12F9817BDB8336949275B83990E58902BF4
                                    SHA-256:C6B55C49D45991902846062F9E4F1E2C0D62FB94B1A561C64869DDE6795CF2E4
                                    SHA-512:A97D047F82592BC9EE66E9A96CEEB37601F730AFEDCB7F6E927B2A325435FBC0435A4B7F22CBE7DEA302828BC06693CC224B6CDC2B785C4D6F487AC21C29ED1B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....kIDATH..mH.Q..9.jj..2..Va/.........F.d"...t. ..^|.!..C.\.a....(...*....,..D.|A..9..%*{.....>....>../omm..b.....zz.^+o/.....f&`.ZI....&......r......................o.0..=.yz....noWW.TVVBNN.$&&.J...\.z....*JJJ.@YY...v..B.c.......B...n.YYY/x....L.......p...T*..@LL....@}}=ttt..........4Pa..fc.EEE$.pK...u... (..Mp\\.444......0...:.......:9F(............EX.....b...(.Jhoo..wb.}.9..a....ZV...n...wGKK.....=//....~`M.~...f..hnnf...t.x.>....."..}...&.......mmm....B....VVV...j6o0......8.4....~..h4..w.*...As....i...... .?...r.....d.r..M....fs...:G....w.y..b.pbC@..X.H$...ann.zzz.<"".\..P.u.....J......a:,......V..F#.}~..N.pS......N..=B...T..Z...8....,p....4_.....6.........R.<2N.^..)7.$.>33.f.'A...Q.p8...7..&....X..[..=..821..+........Q"[M.U..7%....A>#;.L.<Ah.;y[.... ........4...N........V..9...p...-....E.r..*..9(H..*..q.../....3\..?.E.{...a.._........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):361
                                    Entropy (8bit):7.136545221158386
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcNhk/eXTFt+0bT32NHeVrSNjPseqgdVp:6v/7saZzOeXpt+0brBVrSVp/
                                    MD5:E66957D87199382D40D1B3AC2030DD36
                                    SHA1:F325D0E8E6F917870C6347A23E00BD4790C57F21
                                    SHA-256:3EFA6A5D9F7B5F09B9FB0DB45EC34D615C80BF1D9F3AECE3BFFD79DDA460DDCE
                                    SHA-512:15BB2D84A28242A97CB427C85172BF95C105E02763F293F1805507FAD55447A6713BB7BAACB04D74D738D48749E7556DF15D7BAD1FDB04D2B8445EB6F2760931
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...M..0...A..Kt.S.....!A/..zSt.:.'.<..<mk..Iq.yx@.....Q.^..B .x6..t.R......4....=..0@.g.G...*......9.....&d.{y .[.Z.w:...X........!0.,.k..+.;.]...QL.(B..B.U....`m.O..Ef..6b..cM....'..).D..+\.A.w u<.........E.%$...&...sqk .C..UT.5.....}...0......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):306
                                    Entropy (8bit):6.779836965175441
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKclwiLM2sv05l2rJJsXFT0l4T3ZI1c3HIhLXHqb25XK5dp:6v/7saZlRl40FT0lw3eoQY254z
                                    MD5:8E64E50CCAC92FC093AA628D8112F8EE
                                    SHA1:10915949A8961D422913911BA06526558261753F
                                    SHA-256:E6B37820393C225CC6F6AFA6E1A219BC77AE141C3D7752504361E23396590513
                                    SHA-512:9DA167F55DE5CF1B13A689761CC1592DAE76B4DD63B22ED91BF8AAB4BEC55C9FDF7F289B5A7C4115B8CE67674EBCD100E93482964B1E3ECA6036309404C46B81
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```x...i.A..../_......^...C-...s.....'\.g.}...l.,l..p.c..m.m0.Y..Q.......<...P\E.@5...:8.f6.a.2..>.F...........-@.*...0..M..Y,.l.......W...[.e..`S......9.X...%..\...Bn...[@......x.(.f....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):316
                                    Entropy (8bit):6.818936178614701
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcTN30YmdwJb5Lg+F/M9Twluxdyh5NBGUfYup:6v/7saZFtVLgYixdyDNHfYc
                                    MD5:0ACCFBB75443E54C4878CD76EDFF0D15
                                    SHA1:937E5DBEA628B6E0D0B3E6C791C3EE915AF298E4
                                    SHA-256:A8023BFB133FA556C06693FFD28F06B34291D0DF793A93AF19624F42D78E13D9
                                    SHA-512:D19DC1E6816F18978A3B6C1F8032CA3A0327CC90A0F6B3348C2A203658BE6D9AC607024AF5F1EA9C31C6CE026351217A43CFF6D1A9CE00C211B11CD594C4FE6C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```...S...PR,...;.}L}.X..>c...8U|...n.Fg....P16ZYP..|@\J+....j[p..}....Z..."-`.b5 .'......K........l.../..g..{r-...7..'.Z...f..'2P6Hl...)2x.U+...P9.k4..2..`.R..B1,..R........W..*d.>y..K...9..]."...&.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):262
                                    Entropy (8bit):6.584171654438013
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcJAg7vsGDI1xhQxdskJ4VUyXKvgJBawDqp:6v/7saZJfs8rdr4VUeegnvDA
                                    MD5:413E95B3CAC7DB03B6E40323FBC18D98
                                    SHA1:876667A7EE4327D386AA64040532A1E6DCBDBCAE
                                    SHA-256:5AA196E1F2735BD69C4385AAE15D962D42338CD4AF33986D9EE2FE77875CEEF1
                                    SHA-512:42C341F2CC135AEC25A9C5F59FBD1BB151F0378557C9EA0F45662CE692364DA240E70E99A7CF84863CEFCEBC6A85EEEA2BC41606E1E9A883023B71628DA91D34
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..^...g.%... ..1P.(.....$.jw.....Qn..9.,.).........l..I...}@.....j.,.....d..Z.C}....\..r&"........w.AD-Cq...a..|@.C.Y...*M......P........N..VSZ......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):993
                                    Entropy (8bit):7.688663120600708
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZps37hqnMk2Rx4FKY9o1GF3S0a7S6Va13TRm1EaKzAmWP3PU0tTZcxX3cm:HaIW9IY9o1o/a7Szd2pbPU0t9cx8b+d
                                    MD5:391040BE857029A0BB882CB51DFFA521
                                    SHA1:AD3038BEBC151F7A7613835C41B4063B2F376EE9
                                    SHA-256:5A2E899C9786B7E9FA9F1E06BD49404A0B36FF29500D05FD0C55F990026A8319
                                    SHA-512:095683084D980049DBED2500B0C2FB7FCADB76DECB4D5202A67FB9F2B4363CCEB7CFB2CF3B69CC7E6235E6E1142C3AB9FA80FF69F2C14D6AF98ADF874A93893F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....nIDATH.VmHSQ.^z..^w.;..$%.5G..i~....B$..L..a...fF~e(...eZ....4E.S.v...V.a.0..c.F{;..]f..y..s......}.;...s...O..a. ..:.!...a.o......!...m~.9.e....,..%....V.8...........I =.x.)....E..;/..."1.)........G.J..'....r..a..0.T....... .8..8.a76..e.MJ.......N..K..AH...I.E...!.....S)....eQ9..M...{......P!.s....\`._./.}....WKX.xj:..).D..S.=..Z{.......c......h.O:.....A[.......[%.F *G}......M.&&..j.9ray..TQ..kg...wp...?.hz..P.v.?(:....a...f.e...A8.5....a...h.CAn....} .....F..N8NLW...J....T......u...6RE...$..x..UA1.v{.....n7........Gf...A...K.n.=.......6.g....".)B..'..\|iy......Gp...60....\.]n.a.b..$.H^b\.Db:.'.c../b..@ ..............T.~...b........X,@.............eI%../.6...r/r.$..^...[..o.{.&.0..._... I.|7.h.%.7....!Pt....f.B>..4.@.._..3..`g'....".$...8L|...&..S|>..Un..a.Jq%.![x........i...mw.w..*D......^L9vS...Q..B...K.......o.o._..s.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):411
                                    Entropy (8bit):7.242398236393612
                                    Encrypted:false
                                    SSDEEP:12:6v/7+aZTasVcx36DtL4a6g/dhwV7rDoRjuKblWw6N:FadasVum9ju2WNN
                                    MD5:FE0F7DF9971E48C19D8FEA372734E52D
                                    SHA1:E60F5AA29E2D442BF66A595DE9939570D0D9755E
                                    SHA-256:D2D12E525510C4F1F4E307925C7ECC406DD2F987945D936EBF59B088E807659E
                                    SHA-512:D60AFC0E757C906BB3549900042B068C11743AD5AADBE990DE9366DB3E4430D3612D3C04F39C82329CEAD2849339A15E29AA6C04D3C3AD0FEFEC1A5EC4982B47
                                    Malicious:false
                                    Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....(IDAT(....K......C.$"....!..Z\........"..p.]...%..A.."....."T....)....z.P.K.<.Jn.(""V<.I.#.?.4m..1M.E.:l...ni.T<.E1...EE......M.9c.:..I.DD./.}..0.bYDl...N.p.m...u.....5.h...eU.n].Q1.@..1e.;;.....o.E\2"...0...u..X...qA..X......y.f.'k...q.U.Q.......8..?..s\.]......n..es>.UW..7_Rx.W.5.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                    Category:dropped
                                    Size (bytes):407
                                    Entropy (8bit):7.178780035130412
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPUb+aWdKcEsFn+U/CrAP50JC4/N+FI3/l3Jmhe8tgO2dEJIobw/89y114OP:6v/7+aZBcmWBJZsIvlZmgUbw/sy118Y
                                    MD5:727803547B9D498B078729DBB656D2B5
                                    SHA1:1A542DD567C5804764C9A11F16557B7CA1AA9DEC
                                    SHA-256:FEF7AFF7C54E323D86718B4B1C66920E69D2B42E53F114FB1629161F840FED10
                                    SHA-512:DBC33E83F3932A5B9AA0FE4174E600E934C652633DB6EEADA0CE285B5E1AC8EDEFE363366669236C1BEE31243F382B009B50B212A42A0F99014A69110027CFA7
                                    Malicious:false
                                    Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....$IDAT(...?H........!.......Ehr....%H0.$...hp..1......[.%*...."B...#<._.y.|G..{Z*..........M.[...DlY..."........Q.Sz.v.=.......L..G]....f....i8..F.].s..cA.;...M.T.-.'}...i..8`...U<.2....f._.pS.G..4..3f...t4&..5.}.u..3J....qYI.k..Wu......"6.Z....6.].DCD...]}...Q.T.._I.u{...S....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):485
                                    Entropy (8bit):7.338671748313559
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZAt7iUNbC2AE9kqYfILAAdRi07YXuqlXFDq:NKa+tRNe2X9kq/LAAdRi+qlXJq
                                    MD5:0B139E6D98EA7664969D538AE9F30173
                                    SHA1:4AD439ADB97A2BF953662B19E8F15E2DC986D758
                                    SHA-256:AA926C6838263FFE0045CD7209D930DB09BE7822EAFA0C429C92FB8ABBCE4211
                                    SHA-512:824EB79F7B63F4C1690F32E66FE17174FE3E523BAAF60783E0FF94D0C920C19B12419027BC4A039D81CFAC470B18206E66833E6EA5EC2BC995888093B2763FB1
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....rIDAT8...M.1.D/ AB...%..*.(.>H.*H...H.@BH@p..`<..#AX..g.gwg.,.4.n5..z.}wq.}}.g'6..d.K....|;>.\..6.W.:.`B.......Zk.."......Y$....q....0..,l.,d.....$.....*..%...n.$/...Z".J.;.......,.'M.r...w...HBP\......&.Lg&..u$8.V(U........ls..e.\w.45....u../(..R..]n\.nQ(....(k.D..)..XPDA...3..T=w....3.....]...m..Q....N.2.q4j..*.qHF.m;#%2..;;.:.(k....%\.v...^{...?.....e....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1424
                                    Entropy (8bit):7.817369567859558
                                    Encrypted:false
                                    SSDEEP:24:NKaJbYqc0xTBTFi2TY7vVYFR+Y40kmhp7LwZZRY//NAl25MH:nuqc0xTVm7xL0kU7j//Nx5MH
                                    MD5:187C609F9439FEA205DD9BDDCABB7D71
                                    SHA1:CC07D2BEE876ABDE4FAFD2B2C27D28B68978A46E
                                    SHA-256:A873EF621E5A4466809EE2E8ABFDCB063DEF0FDD965A129FFAC83A57F817755D
                                    SHA-512:CFBEB4DEBFAF9494CDC971FDF51750A1D2C852AD2976E0A9587083DE21B79DD93AC5CE63905125D6970EE144FC1DD74344AA6BC86A27604039EC6AE7EF13C57E
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8....W.y..93H..Q.Zo.B..Pi.d7d-f...Rh.1e.a4d.I3.....n].J!.0...7.i.s~.....{.....}..y._...I.;x..Z.T.. .e.....os..I.R.n/..mI.."[nq'.H....l#Y....9.,.\.fw.D,.Y:b.n...P.4k.{K.z.r...%..H.m:.ua...\..3WZ...'..E_..z........y~e..Lo=.."..G.(....D..........+..t.0nX.Z..M..[&...v?.&s...,...........\..9.U.{..`E.......?.a..=.d%.v.......u.G......^=..xm....,.W=..'....PWCr..Y....#..C.O.qo.).H.r...A....SF.]d.p(+.QAU.....G.BZ.;...0.h.n>.`.%...fW.r|}q..<...E.+.Z..........h.8E..8..S3.......|.......o..M;.q.6..W.?..@.-.>;5SY..MUi..+#''...N....+.&W..Y}...VZ....P...]S.....cQ.F.._<.g5..H....(.#A...t.........L/.3Rq.*.....f.J....:..1.>).<!.U....d......\.*.'1.....\.G.0.A8.}..@m).nz..E.....5.k...g.j+EA.,......z...E...4....[v.....%..4..Crc..6..b..<..p.n./.2...I.......k......@......lE....ZS.'.....=Q..%...g...A.$;..:>..wJ...E....p}g..J1>.;.p....oR.Y._Y..o..x.sOk.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1352
                                    Entropy (8bit):7.808495374579655
                                    Encrypted:false
                                    SSDEEP:24:NKa8/xBij4z0AYjpTpZ6SLfI0TQn+8twOHe9auP3k0QaPwF2E8z5:nKxC+kVTjI0TQ1twOEPf9zDz5
                                    MD5:57353E3C3926BD8F1A7F0E7CFD99B59E
                                    SHA1:ABF39C3A16C8662712825D01F9859DAECC47BE17
                                    SHA-256:C1ACEBFD14631115E0B05904BDB8EDF3895684E75EAE41E68CAD60FA47E10AC6
                                    SHA-512:3087E0D4D3382259241ECE160E8DF4ADCB6EA608D41785D20732D73E2832E8205D1F51D2107289507F9D487D894DF74E07A9B004A0C8FA80A28A4AF61B08A845
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8O.Tko.E.....Y{..q..y8nh.Z*.".._...w>....P...*.R.....).Ij;.........t......{.9WQ..C.~W4LJ.....~.m..Hd.9...Z.h...(.-u.`.M..tTC...w.....f>.aO..(....f./....z.dYF.*....tUg.T,qjh,..x......j.F.r.D.P..X !..VV.(.B..K%...Ql.......f..Wl.1..-.w.3.F...9.8...1..r.`7.<.('.#.|..g.'.q......_.N..$&.P.&.1..Z+j..S.p...!..,r...k..t..R>.$.D.r.1...!2.....M..L.....3...u....T^%.Gb.e...P~....0z..3:..5...g%A....@+ FQ.".........*9...D0B@.W\...I..3...~........;.q:...L....4..a.f....O%...r....|[%...L4..aT.Q*.......@.~..1#.....#.f.qT.)eKY#H..t..3j.A....$........]&...F....F.nv.3..(..w....e.*$"M.8.|...H.-......]..F.B,......q..R.&gO/0.k.F..w.*.T].........B.9P....q.;.....z.%P.dZ*e....A9.0..'..v..^....7..j.;sAB.n..Jv9.|..":.;.^.2.g...5.E0e.Y.......V>Z.,}x6...u..l...4.y.Ar.....W~...A'....V.&.j.....0UM....twy....~..YK.l.......g..r....$S.s.<R....6...Z.._5...?,..Z...c......n,...:H.r.4}....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1414
                                    Entropy (8bit):7.804249307631032
                                    Encrypted:false
                                    SSDEEP:24:NKa/b6wxzZ+sZUT+kvUaRLfQfxyHz5EshfRnWKTOEDpzpFOZzwqCK3OqYRv:n/HKT+kv5JfQfIHzXhkKhpzpkZzw7uOX
                                    MD5:34A70EAABFC6A8BF981949C8BD860240
                                    SHA1:FBB6AC1B11169A365D871D99D6657A6347CF75FA
                                    SHA-256:20B2C5C9CF8EE17B25816897BA20A57A60571248ADBE38E71561C10E47A8E8E0
                                    SHA-512:6946500E625AC25059F389887ED34C5779C13B7B5DEAF92B5924A9245F8277D831D58450E3F699FE7F85D93562C249CEF0C1BBFF344278096778C780652AC89E
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...SSW..M^....-HX.l.I...R..:.HE.....A..qi.m-.c].S.E.J.V.(Z.T.....{eS.k._.........y..r.....}.&.....m..G>a.cO!.m....DeY.?.>....P..,.5#-ylW.0...d......'f.8...p.R.`E.......=..S..-.".U~D.y-G...b?(8.#5.Yf......r....@...g........uG4M....t..!.)..[f.&.)..a.c.`'b:...g2..XF.Mq.O..).j-.4.o....e.o.W..0R..`U...C.+..g.9L.......j..BMC.....P....w...BT....i9.,.....^.Du.......V ..?u.. j...[7.(....Z..,..N.....a.....{.Jc=.|.....t}w.^<...gzn..j.O.>.h...#..p.N..........W}=+.Q.;..".#..1....;.....4.1.,F..O..."a.]..ZhE4(.'..L...o..(gzn2.......5.)PT....B(P....cG..............._..Kj...m;.r.....!G.p\..`..yF.Q.-..........I...~..T>!..N..m;..c.rb,.....P....A..x... !..4.}bF.'.+.c.c.........D.5.5.|D.........aNEaSs..2..o.1...o..(..@Dhf..p.W.....-...l..;.Z.X..+g..j..rp..[l.[!%M9,...D.... P.$.#.w......+SD{..qW.x\[`}.N...B.F..T..4..F.p............,h.n-.."....b.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1166
                                    Entropy (8bit):7.797797851076832
                                    Encrypted:false
                                    SSDEEP:24:NKafiuEtcDXDP7WjWiLp05HZVF9YyWIJEJF1F1b0m8N:na1czj7uWUp05nLYyOJLF1QB
                                    MD5:046AEA9AB7057E55745762FAA010E10B
                                    SHA1:A91FA64199894B1CA4F292A9BB576BDF486C60F4
                                    SHA-256:CC403C513AC0AF447371E2F553FF3FF348C8BECFB99BE81A3FEFD996EB398EF3
                                    SHA-512:3D9C639003604D4C8AFD5523C5B3E272685FAA8073C415A69063B0F35AF4E4C400D8EF6C7BC9D9D2C90A902A1003D465409883B41C781A8F2B4F0C7489D364CB
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..{PTU....w..]vy.....$)........eWL........G..LZI*..........1..`.l..."B..pD............3g...9..{|.?.......4!.h..&.|:^).,..QYj..l.a.D9.=s.=..$.{..u......)......]{s...e......Y...>......77..Ws.B.q,........M ..X..6.....5.b.......#...O..H...e... ..1..0....:w...X..o.K....h.!'.....yv.".4S."......s.;.M...A..&....@k"...e.b.L.[.c...@....g.[+,I.sk.m..''[.6..<i(:..T...w_...2...s....%.|~..D.O..u/y:O:N.....p_/.Q"ldz4%\.'M.W..w.^Dz$Y....3T...p..,.d.......Y.%.....^...n.9.tKY:b...x...Q...Yb..z..vP..*.#}.t.....DN0..C.M.l.....;....g..O=..8~....R...[.K...dAM.n...=......k...}Wj.>.<...m..k.....[........m{u24.{VK.tW.....Q...>.oyD.?V..f.lW.GK.e[..O.!.....9+.KV2.L..'.u.......%..].v....4...h...`G....).N(M..P..X....2.baL<.P#[.._VN...FA.Y...U.LD.../.#.j..a&.l.V...."...<QF.@.u..(y.Fzy..rS,OiY.n....'f.{../.p]u6..{v..i].w<#....J..z~...<7..G.....y..i.....{...1..W#....44.<\
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):940
                                    Entropy (8bit):7.698059274671223
                                    Encrypted:false
                                    SSDEEP:24:NKayTTWBJJBYcqUXXBqCLpy4eoK/Y+wUfBYo3MaN+hYdhqxaZQtU:n5vJB5q6Xk/3wifBY9KdMcAU
                                    MD5:88456D52FA5CE2113ECA03F1E2CB7A97
                                    SHA1:AF86942112096F87D3572D3FC1B23A701BD685C6
                                    SHA-256:2DDB6497DB20C2FDEB867B42AF780058D976B22786099C77282D2D6916017423
                                    SHA-512:4C156B3AFB3DF5A2A5E339465ABABBD7BDE255AE9167898B748DCCC17B630BB4A632B4D7461572D4C0997D3755BECD38983FAF2947F98D15BB50C6ECBDB50F77
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....9IDAT8.c`."Xo,.......*.@.iMQ?nL.._.((.&D.p.6.A.Z.d..m5...g].B.A.LD.T.."...$ .%\..A@..XDWO....o..4...|........_K.(eg.~zc..[..F...D....d.`...G...:..\...T[..H.k\......E..qa6n.z*. k2..gx)m.W.n.f.Q3A..s..l.~.!....=...*....5..YKn....g..033...-...LE.15WO....S.U!.@..!M...b..m$.XIl....12<..._......5._..D.K......W....y~...A@.....1.b.";..V.7.B^o......sn..[...~.........z........y.A.E9..?o...lP....W.~=..A._.,H.....aK(0....X.c.-....\..|%..8.[.P..u.D6..n..'*..... . .&.S.$W. .."...."..vs....d....z|~......P......k.g.....,5....).}j.............O..\.../.j6:.gt*..N......jk...... .....~...t1...F...v..KyZHC..5...........`...^..<....:.r.q..........q...i..z.J.uz(..'l.....CU..Z.j..7.x..p..V#..8.P`"...5..R....WTZ...%.9.t..TW..a..]..n.....xS...+UOW....K|...g..o.0.,...@5..;[]..g`.....b\....^..........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1271
                                    Entropy (8bit):7.806469024341951
                                    Encrypted:false
                                    SSDEEP:24:NKaHXAnYeAJvDXw4NaxsqugTF5/Zd8nFE6xM1sjHjeRcSA7:nHg2JvDX7AsqR55rSF1XHSRcl7
                                    MD5:14920E906B09626149CEF38E4BCE82A6
                                    SHA1:9FC903C48025F9F9BDB3A0351AAF6B89196F2787
                                    SHA-256:AABB8ECB201696CE2DE4B71BD5A6ADC9DC87458D61A26B001388F1B924A6891C
                                    SHA-512:E9782A18827F09D62B7755F77982779701C025C64A5C018B6F5C4BF7A9D3BA22523F91DE69B21C1CBDDDE98CEF69762EDC0F5091008D266D7A91592D15BFBF7B
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8O.TklSe..iOo..:7V....[.s...@.:@A......Q.d&.@B.. .x!1H....A.-.?...,...tc..-.........~z..9.9-.../Mz..>..>..~..]|..A....R.W..s?.2..9j*SE.0.J.*.N.d...h.,... ...Nu F........(KH....c._....D(1..L.V....l:....^.Nvp..W.>.E'....T..B.2..d..H.x..+.J.....V.S.z...$.d.B.....n..l...u|./B.<),.7.>......R..Y./W..-.$..s...B.8>6.G...-.f..).....%. .F.u}>vr.........".....k:8C....c.?.N"8..&...^.-..w...I...s...b.~w.sfi..h......~.#..7....#O....x..@.@.....R>..7..k.1("YA....,....d>..).cD.[........|..........-5.......Ha......lO.V.2m.E..T.........Z.J.M...cb.o........D..r.wy..O.=...1JE...wU.NU.S..g..0.P..)[.PLjJ..A..7-.;....sb.?..]....$]...M....v.x.'.@...D....@...Ed.....m.....a2...3F..X...-.Z.C..c.......X.F/1....tg...G......?}."q.{.M!.N6..l...v.dq...<.[......([@.B...E..g..-.v/v}T-...M...8.5..Z.*\............[{n].4....><)..]ba...y...#..r.K;.....~w1.".........#.l..hQ:..H+.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1246
                                    Entropy (8bit):7.7774242762524946
                                    Encrypted:false
                                    SSDEEP:24:NKav6spIR70nXxKVBdJCYjREcHaPUWO12ajMKMvQu1+80CAC:nCPNsXxKVzJCeRZHaPA12sMPMCAC
                                    MD5:B6C4F1B8069156D45626FEB88F39735B
                                    SHA1:261D95B451131A13BBE7F1C3DB7E4D43B792F656
                                    SHA-256:F683C94984865C1D450DB960F5B0D329F228B9F2A16C8DE8C8B7518E757DCB90
                                    SHA-512:B4463288C0C76A320E8CA279FDABB8FB82CD490C0FC32EFD9F1F8BA9D7295E1A33413B8764FBB238F6A4B3A01F492DC3E07EB1FC4E5143024AE084039C1DBF64
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....kIDAT8.T{PTe....e.e..]X..1.Lyh....h.ZX3Y...fSS0..,.|. .i..,I.h..1|T#.X.%d5.P...1,.l........\...|......BBn.....&.Jt.L.+...Y.0eQ.*=....=N.0A}...XD.".".''o..b..L.4.....,.r...k.J...m.......LB.M.9r&#J.A.K.?C)".%#...(.}.z.....+/U.7.Fo..8.....Q..K$A._ncI/.."...."..._.+..yQGEj..Cq..]...R...A.I.@..g.H.K..s.sYCg...9........M..D...p..e..3..`..|..>...^...V..mv....\|fm...Q.0..p`g..#..24.d........C...........y.f.....u,.A...?.02.......8.o.I..t.hw.{.368.......=.l..}*..ix`..S.$z.E<Y`......'....q.......5.,E...S..[aH+.....k.2....?[=.5z..+{s..ru....C.....].]......+l..t...k{j.?J...c..2...1.&..FA.a.;....)CgK....-.].yg.B#...4...u.@.....Zj...*.=..ua..Z.4....u..s...........4..:).l0.R...JG%\_.....}'..(9]...,,.8L./b..Q.k.a,....Bu..~..........F`!J.Uff.{-@g.kC.LSGe.`..Uc....z.G.....V;v...L...k.H+K.\..4._...6.%.v.l>..F.....o.^.....YG..*t.......Dj..sNI..xV.sh..i..;.....W.....r
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1178
                                    Entropy (8bit):7.804844334364623
                                    Encrypted:false
                                    SSDEEP:24:NKayvtbsVHLp4VV8k9q2m/FtmZRKRZR1IzrmRoLxEimgqEY:ncbs4z8aPm9tu8LIzra4OlEY
                                    MD5:86D892E71AC4015A288433E03EC49AA9
                                    SHA1:B326E43693B4A716916C5D6B5DEC30699A1B72ED
                                    SHA-256:30774B36A38FBCF8BF0E51CBD9F569B52EC43534F0A8E218F2ADE6F01E3258FD
                                    SHA-512:B15F69930C0ACA543AC037E6423F71119A156E2EFEC80976B57616D641BCEEEA3A1D45D81B14EC7A90D3299D11AD33D58E3EDA98AA661D48DC4F9F19AF4F0FBD
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....'IDAT8..Tkl.U..........Z.>....%.(h.@..QyX...h(...(.`P.hP......5H....4E...JK+.R..R..i.m...;./..;..?9?&w.9.........<....N..L.C......c.g.....H...|..:..P..6~...[u..C..}.....n..=0%.....V.@..iJ..u..8f.C.........M.*.<..)F.zJ%n.]0P..@.S,.8,G..r....G2......H...n....9.....z8.j.i...n.}5WBE.27IdO.LF.wu.pD...[...5...&Z..=O.....#.P......].....u%3e.."Q..':.r...<..hCQ..yf}.%.S...g....U.a.+....YE...I:P..#...q..v>Q...1.3..r4..m..4.,!:z.!..zT..:.st...2...IE.....H[..1.....B;.LL'.....$u.........M..e...O..LL.*.i.%u.Cc.......h.F"..4.t.M.>p.4!.w..Xp.v..cb...Z5.-hb...K:..D@.~5....L.'...*..<+K.}]..s...M.CGk.P 0.fV....E.,`......skW.FS...g.........S.\....o..........=.}....E."3.5_.."....T...-.0M.._tY..N.y...P.d...J...]f.I;........-..0.B.U.....Z.@.....t?...r......0...M.......W.P$.........2.8......P..._..q....5&..E.&x^..b.....!OR,4.X..M...........C4.%{....T.....a..M.n...M_?.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1212
                                    Entropy (8bit):7.789728112228107
                                    Encrypted:false
                                    SSDEEP:24:NKatGDvzVjgvDNFp/N+SD6I5E7TmNMnkxZ5CV4OgaOZVXHVaEuwz58c:n4zVa7ptt5SBnoZdOZOE/I9
                                    MD5:7768E97229175F79AE6BDFF0EC911338
                                    SHA1:7D95E4851E50B5338FAFCA037BB1F6284A6E1D78
                                    SHA-256:99E5E32140E254CAD6365529E4D9E75A368E02A90BAA8F60E47D3E89CB92CCEF
                                    SHA-512:A72DA1002E0DE0F5B58CBDFD7A02B6BCD4BEF7F782C4B58EDEF745F77C5E7FC8E084AC81B152DEC2DE7C3AC29B4B023D130D272F26FA13EF77C7348DCD52B608
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....IIDAT8.T{LSg./..Z...R.f<...1E..8...S...&..!l.e.Y....L.i...:...**.'.@./..a,.R..@.......e...?n.......w.....f.....j..>...#.+S@cQ...4z^T.U..4....p...2...T.....C...#..I......]8`F..F..p..L..1..7.U...t.B.+...X.u)......B;>\.o.....I]..:..W...#.6.u..x..ak.u..E.^...Lj.3.../......j.*Y....g@....j...:S.}.^.@..S...t.|m3na.;......y.....){...........G....e.aa.7..K.n..[P..Me...7:....tu..5=...>.O^L.z.....<. ......2..s...F...%?%.R\..Uw.j.......].5VT...m...@..M>..x.H..@).5.Jv..*o.8.*..."..E.QT.2.......j&..CR....v.>~I.......+.e.;....DGJ_bB...2{.X...;....|.bPuq\T..E7..........)3.....?3&.....1....i...I.....x.K....e./...Tr........O.i.........(2Y.Ho.-1.l.nn}"......#S..iz....y....aS..{...b..v..s..._tn..J.....o.o.r...a...AcF......+].....n. /.....r.........>./.!.#....%$.Pk.?.t...7....'...&.@E..C.!"._O.....w...%9..N..3..8...'..K"....5f..!l.K'....An./3K..Hg......C....E0qZ
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):382
                                    Entropy (8bit):7.091139352072596
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKcudu2H9s7veHV4vP6bAP4bfzrn2zOhR6/N061gI1pgjRg5h0Ic:6v/7aKaZu/ds7FKb3vhR6FF1gI1+j+R8
                                    MD5:7D30802EDA70E31337CBF102445F62F0
                                    SHA1:F7FF0022BDEE8912BE1195CE9F6ECDDE9547747E
                                    SHA-256:C2489D049090A645DC8D78C4B5CADC39836B77819F1621C235A7F19EA9523521
                                    SHA-512:51383EAD561A7605E007A1E68391ACB89D5E43B5458ABE478E257886CDA0BEAF9B28BA6EC4A628863A4D1927EE54236AFF62BFF031E8A605BEB71774F1207130
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c`."...K.J.. .A.2\..b5>..j..kL.fS...j.Izhh.#.P.~.:F6...P..~.M..~m".};[..`..h..-W.#....1... av{~V... &...#. yv&.... "..#?+.A.{.U.....u".A."I.B.L.5.R.......DX..4.b.%2:....6X..DP.N..Q...}9.J!...x.7..j..p.vK...j...p.t./...F...I.D?.-'..\.Q,...w.c......5."....9.5.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1490
                                    Entropy (8bit):7.831566708508583
                                    Encrypted:false
                                    SSDEEP:24:NKagt3wgbZYBvARdxpiIkcqgzq1OiJq8pFsXhac5ZFoDwYZeBFjgFOKVMhppcS6N:nqwgbWBvAdpvkcrW19qE2XhaUmGBFjgn
                                    MD5:5A46B56F02FDA5D6623DDF636DE197C6
                                    SHA1:A5C99BEF8F42568CFC040C0A1D70F49C46DD10BE
                                    SHA-256:36E9DC2B2B868E8B2100CE3FA77816793F7DCF85963DE85226E0F15E0398398E
                                    SHA-512:16AB38152FBAB27EECE8E7AAC75307319500C7AF75D3EE0EC4EA718D56292F4BBA939FB84C538519D9B80411C1DB4716B142DAE95A29EF6A9E4AA6F89B7C0243
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<...._IDAT8O.U.W.u.......A..9.LEC...g.b...e^....T.}.&.....$.5.....A N.<`Q.......5.........}~.... ..c..x.F.rp.....|.... .c..[w.k9..........?..~n.ckf...."9..v.YC........Fo.(....)...>n..9......VC.`.t....4..2U{l/k,O..H......bz+...@......^^.}i..].....D.:7.]...k.<.u...\.a...1......k>....xg..|......H.....q-..w.Y_Tg.r..q.v.G...zj6xk&:.I...kW.0.t....X....=...dy|..k)..a0.....t.j7].e...c(....D.....Sc.ix.%<.Yq..h..e\.I.h......9c.o3..6.:..D..7..v.........:.N....y;oc...(.tt*].Z.....:........Syj.o.v.Y....Z..:'....J.$..\N.El...}..D..1.o}QU.4..^U.z.........O].tQ.....;*.1?a....../.._P3...@9a:...>>.qIb...sC.Z.G......K.r/..ip..0{.......[s...... d.*.3n@X..@r..tf.^.....>...41...+.....V".................OL?;.....c..Eay......E..m...skJ.t/%._./..!...-....rg.D..j.o.-.p.]...e...O...M.|..^\.6.|..`|..5..1'{....X...z..P.u1U...4....I..v.9o...a.......;)."..>qQ....7...$/.../....l..>2.^?...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):951
                                    Entropy (8bit):7.747218915734698
                                    Encrypted:false
                                    SSDEEP:24:NKabe3s0vsdfihBvaxZuf4Y+ctisn54L9:nysvfwixwf4+tis49
                                    MD5:1F74CB8E2355E6ACF43E44D28A138C7A
                                    SHA1:3DC1FACE31D2B1E47B16A39C7463526FA085C17F
                                    SHA-256:FAF1B5BC5867DC66F1AFAC3511B5D7A3DDA4CBBF64F432FD3CBB010A00E01336
                                    SHA-512:F31ACF993BA7BE655E4B4E87FFA31CBD2EA5E26EC1174A72C41C3FD57D6F42D56DBEFB5DFF5BCB05A6575DEC2176667F7E9B8DA4A0A6BC6A043336A12EABAF08
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....DIDAT8..iv.0..M..B)K...b.0....=..-;t.f..`3.....y.._b.....j?.h......v[...{C....K-.`.&.........`Y.u....+...`.{.pC..K..P..0.....!..$..&..dl.....zv.....HP.z..X..7:.1.....!.".....=V.h...5....5....SV0........V...........*.l..gH.'.>.{.KS9@....Z.h....EUi...V.E.....}D.....d."@...v.6..Y.k.HP.n.Z.!z.I.........I....3.6.....6+.d....=..~Q.....$...Z.f.."ZD.8...]....q.m....L.a........l.m....@."..Q....3O.....v.......kz0R..uR..%.8F..o.,ya).?,y.<}.#P.^.z.`.V...].L..2V d...JT.....&)...y.A.PzN._......d.@..=K..x.....E.2...l)..j...T.u\..[....).....~)?f[E..N...h..EV"k.]u.9...c.5G\&..4...*..@....8..U"X..d....5....~...-[..C......fR..v..Io......o.v`.K.3.%.r6...s./;#(.....*p.i...-c..S.u.E:..\...8.88..6........2..x..<.k.{.A.AWqQi....*M>M.....\. .....*...1|.Ja0......h.S.....CZS...J.S...>...} Fv..6....V.Z.v]..:../.........:..c....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1312
                                    Entropy (8bit):7.806633556387323
                                    Encrypted:false
                                    SSDEEP:24:NKaV3hhyuostgkZYNf9q9UVuS82GrfD3jrQpdtAr29iliH3UpICKop7bDztcJzYB:nV3h55tgW41qHL3rwdu6miXUh3pPftcg
                                    MD5:685023499522C0ACACC3650269C2E8D0
                                    SHA1:34A9CDF9EDAA4CC10EC7FACBED724179B7772E7F
                                    SHA-256:B5BD53878939DDB310F67ED7A49FDBD9577E29FB73F53136057AE6BF2DF022D5
                                    SHA-512:4D6D3CF2713F994E0ABE2B058043F54DC15263F915C2084A640BE5D128D2BFA30EAF4C37342E434044530EC707F362EE52603027E105EE17457DF8D7E8B61028
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..mPTe..].m..l..S..D...0M.8...#.R.6..a.0..c..."j..../...(......./....+........}.sznl.H...g...;....;g...$...3.}&..p...Y]1..A..p....[n...A.h.f,.;....7..y.J.S..'f)..4J2.........1c..w.b.`..P.z<.t.........y.6.^....tb}Y...x.X.;.b...9....7..f...!.xz0.*=.....g...l....I..oYm.C%6.N.{.".)./..N0....e.g.EzA. ._...73_}........ .......T>]UEF.O..`..l...+;R.Wd`.i..O]..//.n..h~........C...LE...........2Jsb"......TL....Y[..C$.@$.t.*3..ja. ..tJ..F...j;.a..i..j.:.%..9....z6.,...:xZe..}~...W......g..*...d...n....xz.v.'....Gk.%'......fYE.(8>J.#.n.U..+.r...w.:1g..-7.H..)..X"Qp...O.^0.Z....!{?f...yZ......o2.h5...|*t^HH..o.A.G.#*.. ..u...{.S.p\^.....-:"\/=.;5.8.v..3>M!..T..e..>.O.e...Z..........1........Z....%.......;_.dS.s..f..L^#........O..sq..%...2u..='..l..+%{yM.....v.....^.b.L.?..T7xt<..F....(J..V.....LW..Cu...S....c%'....7.....o&V.,.....^U.1$p^@>.c .r.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):613
                                    Entropy (8bit):7.427799481386969
                                    Encrypted:false
                                    SSDEEP:12:6v/7aKaZXl0BKkPTHHmhW8GCTadF3X+ngTge44neweuwqpiETv4pY:NKa1SB7nmhVsZugM3UcqpXTQpY
                                    MD5:7FFD376E74D922E67505ABCE95F6C685
                                    SHA1:C0F712C0EB1B606EFA57B80742545F1B710C53D2
                                    SHA-256:7453E8B9D33849D564B00FCDE2B998A1B8D85DF5A4522671E9753940E8721BD4
                                    SHA-512:71718825F556E608ACAD212E5C6BCA2C255E23AC9766DDFBDAE036ECA73CDAC8887FDC8E3DDE3BB7746BE8D6BC49940CBC74F54E9E26CF8007EA738A6D085528
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c`...v..?...`Qp........A.fy....qc*.?.......(....W..].S..xm...{...v....._....V..DP..)C.s....2...V.....Z.-.,...?.O.'.@..-6}.=......|.O.....\p....'......?nL..!.d..2u.F9.og*.)..(A......_.......w....`..?..J-..1.QVF {...\.........+8.k.3).c....#L.iH..l..i.0....C.S.4....3..8x...4V.._..*..R...w.=[.....MV.....~........A.....mu..gg...0....~g..;..g. ..b..?..}.............Y...p...;....2..(...L{.t.'.!....2....<.-..<..t..>.....fJrb.%0....Y.`..`.8.....,U.... `......LJ.......1........j.@.OLJ.........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):354
                                    Entropy (8bit):6.967704790210181
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKc1MS3tIUieMhVPXxtKPs//smt48o+baQDyG2q3eW4ebkXTp:6v/7aKaZ1d3SUNMhVXzKW0mt48CxGJev
                                    MD5:B9088083C16AF54A3EAF7A2B204CF399
                                    SHA1:FA74CEDD7BF4B3F791A83A38A2F068D5CAAE1B85
                                    SHA-256:BECAAA5A1B294B5602F9C24B40E28051A71074CB05249D31EB9CC54848078F2B
                                    SHA-512:745A07FAC46DB5E13994BA8C358A93F52CC5A8BDD1334E716DDE5AB86FC6BCAD1CE8C63331BB37D85D08B176BE6F2B836CBCA20E9B6E42821A694AE401B481D3
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.T...1.|..)..c.f..a.$.`.6...F.`.$D...#Y......../....nD....s?.c]...3N$7`..Z......E..r..+..Pa..}^..`....E....Nc_...y.....e@..x...G.j:.$../"*.0........E.z?.....c.MMg.I..h..`..8.d....@w6..}.E|...EB.r..$......I.T..;@..M.......Q..EP.......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1262
                                    Entropy (8bit):7.74984945189834
                                    Encrypted:false
                                    SSDEEP:24:NKa/wQT4f+Fa43ASC/5N+vM1fz1O0rje0jwr2iw9yZmqLRHzAdvX0YDTnWz3azXd:nl4fLEAv5N+vcL1rjB0r2V0z6rW+zX75
                                    MD5:A7963ABE71B89FF26D4972F6CC4A3C53
                                    SHA1:78F9CFB460B8D0FA87B91492B60B210D573FC9A7
                                    SHA-256:F26D903A567979894819BB5F10E5E91C17E5645D3500E63D431656D07857C97F
                                    SHA-512:62598B21C1BA2593CCF91381B4B86A437D2B297DE8DA4F77E46E5A9BB0B77C2BDE8D81E5231B098C1B00AD4C8C06336DEC9709D03251AF13638F9E15CE354A7F
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....{IDAT8..Kl.U..s..?f....g[...|%.;.....%..sibp.^7...&nL.....HLL4..A.........1.).:..?.=..LW.W|....w..<%..;..X.u...U..u..K...m^o6......l..z.@8........E...k.x..0.y...a..QP.x8..4......fKL...5.y.z". ^T..ld...,...1...,..(.ej_ub..W.=.K}...l..V..y.s.T.D&4.P.J.Z..a....dAL..k/.wh.K..%[...oB........Zd....@y....<R.j0....q.(..*S.\.(.:C.....7..Y.m....-.-.O...>.*YR.D..D.&.#/ri..+.$*.R....A9.`.kl.F.@..t..jem.PX........ .....*Pq.K[ii.4..*...Q...h?hw....dh.8.Q...*.T.......s.s.f.y.1:=..Z...8..Z_.[.<h.r.......)....p..W.."....N.n...o5..n.&2D..gnt..x..W.n.....r..E...*y...?..............Yw...-...n1....#;`J...Pt .D.3.8.....ZiU)]L.V.'.....kf...~g.....g_.f.@.>S.@.%V...^h.lr.a52..*aiU9og8W.......o...I.2 .L]..+H]g....7.-.@L......B..vn....ckT...P[}.@....sY;c..........'.#....,..K=(7.SM.v......X1Q.*!..L.....w.x......S{6...e..Y;O.n#...|.....16.[F*..ll..b"F.....[=..d.it.1...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):305
                                    Entropy (8bit):6.885611004494081
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPyJg+aWdKclRA+7MxYjs80uO3tpNt6EozkfuJ1egDBRV75p:6v/7aKaZnA+7wYjb4tftRuJsgDnJ3
                                    MD5:9E805445A938AE8B849051182375D425
                                    SHA1:7A44BDBC0148AE1B816F279B87EF58CF205AFF93
                                    SHA-256:41F08FCD57E266C4DB874ECC6C363DBA31F43C164B9A559FE4BEA8355286E1F6
                                    SHA-512:F5E92409C71CB973239B8FD95E28EC5DD0EB1B62305980235EEAC092BDA3464DE65EDA010B9AB043CE1AE494A45FFDE651AACE1C4B4FADD47318A99FF273BB64
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...A.. ..P....^...x..z.n.%.a....../.....4].>.....Sh.yn..wI..rgI.....m).F .fk....C...A.62.u.M......7P.Bj..!Z!...9....$....+....%.l..`..)qotQ..(..P.....BX#.....NMSO............U.t..!..........IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1379
                                    Entropy (8bit):7.851578122642154
                                    Encrypted:false
                                    SSDEEP:24:NKazZG9rCnBno2MtYpvqDHkeN9kw6Ixiux1GXUyPxB+JbJC9:nuCnXMaADEeNuwbxfx1GkymJlU
                                    MD5:6C19AC57A7B307C7B679DF83CA41D7AB
                                    SHA1:C80F53D9F776194EB7F84C4FA179AF0FFFAE12BD
                                    SHA-256:C1DCD18D5D3F947734425481D555C92C62EB6D0281DD9C907F877A62D6945781
                                    SHA-512:341E56C4E09BBAEB3492277DE744ED2C15F7104FB902C47702A1A33C85D186C508D31E2C3A9AA198EA9E64CE4467BF36942F487847298017FE903AC958625804
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8O.Tkk.V..9GwY.e;..;I.4i..XKW.V......}........`P......-.....$M.tn|......../.8.Y>z.....a>..>y.5...bJ.............N...Y..<...,...v.[w..Ro......<...M.~9V...UR.^0.B'0...#q...c/.nL...QJ{.n....1..<.....@..G5.....jA..B.f..SJ/h....9lX\.J*..+........e.zY .jF......9q.#'....../..clZ.#....*I..^....../~?.=.{..@..w.f..u1.n..9h...0.../..K...~MX..d..............(.....p.T.Y.O..U.+iA.^'tB)+..2W.M.[...v.v.O....&.K".PX.#@...%@..........,...y...X4h.R..$#.X*j..M.!a.V^.....j%@......\`..Sxu^%.*..nF..u{l......0UJmn......9...3j'...F...a..........._5.'.T........!...}%.\..F....u..'.F.6]N.....o......t..G..MDP.E..}5.Wu.g...../vD...........-.\......v.n...J.h...a@..~...|7"...'K. .z....*{..1I.2P......ZN.....U....Xg.'.........|.E...^..LIF.S|....H....=A..Q.~.]..P.b2!.J1....cN..Y....4..x3.M....m.P..iHY...+s........1....#P!S..G.....<...djW:hC."/......J~=./.g1.g@.._.:.p.`Vd9....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1454
                                    Entropy (8bit):7.841228180729992
                                    Encrypted:false
                                    SSDEEP:24:NKa1j3DsQHMOXA1ZRXdeSAHvEfMhZTLHMWKbp7QBaeaNGDgBntMMvi2:n1jQQsXLXt0Ef+xSl8aF6gF/
                                    MD5:90F436C4EB5EAA5DA54205F501C001F2
                                    SHA1:F857DDD43CE290CB497C319CB0CD5048ADB90AC0
                                    SHA-256:B355518DA68971D4682F2A7106792A9AFF066375D837D3484B349E36F4325E5B
                                    SHA-512:ED6CEA414EC1889DF688AF0E479C1C203FBEA514AF181FF499E5C1BD2A19D09585E5E58E285B4B5CD7E4B56E2B1B130CC96B40CE13EAE8E45B0B1F3013326D7C
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....;IDAT8.U.WTe..;w...a.E..L.%5M.D...W\.t.<.....[......IS..s...N.....".&.B 0!..3....=s.....8.}........,-_....}.!.l.x.0g..1}..JrcV.1....5..y.]..F;S..(..g..M.W.MW...h.....L-wc,MYBO.q.uL....-....Tk.e.k......KV...$..\.....8...>..Nr..C.'.....y._Q..T...vs' ,...4.....Y..^.)Y....y.Bo.....5ga...U...U.C4^.Q.g.._.u1a..b..I.1Q.j.+}+)T....zq..2\.k9.=l.n.........G...I.ai9g._..[........}~....!.7O....yK&).%:.tg...^.t....8.q...MT~<.n~.:#...@.W{...=..^]..;......E.c..zOV.....L..:...f.....t<...."..+.._..7...47........&k.....J@..*[G.......@kv.@;..ar.a.u.b~.c....tw....f.........d*M...br...X..B...@U C<>.;...V.&'..>...]...`.n.k.e....7.e...<-...Q...)_..^0...(3H=QI..*w...r.)..p9T....6..N....sB5..b.T..s..^.....*+.N............X.S|z....).JO..-$ h.u 0...!+....(W.'....5.X.?...N.U....|...R....(.m.V.......)Q.??r.0422rw....0.....H..C.h.}.-G...H.W...t:X.i[2..k..H.su......+...u|./.J...7
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):1259
                                    Entropy (8bit):7.803232996291471
                                    Encrypted:false
                                    SSDEEP:24:NKa9VJP+IHiJhJkMJtdGaIY+8b8tt5HkNmv5rktJNVh+RNJIyRR0hF0s3IS:nJziJz3dzIY+8YXHBkt/zMNJ/+WDS
                                    MD5:6B1FF56502F329CADC3CFEFBDF6C1067
                                    SHA1:7CDBE86E176E8003075A28EFE90580977B2B23A9
                                    SHA-256:BA6B20376D36647802093350DE8945DB55420A816A1E5AB1E70B1B5092B62345
                                    SHA-512:19E722E4CE2D1C6C78E7729C7147AB5B7DDE62CD467160F9189187F998B2FE3C69D5B025A0E921DA6436F950D49B573622AB4842BAF8DF5C8E9B7F277A9B79DE
                                    Malicious:false
                                    Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....xIDAT8O...oTe.....W(Zk..**A.@.@..../E.b\.!$".....5.CC.....l.L$4....E.(H.Jki...B............{.y...9U...X..vf.....px,.....#.?>......e..Q...<.q..5.....n..C.m..E..|.....t...Mz..k.c....2.Og.5_kY...^,..".(5!....5.e..jg.hI.5%....w.....gV..l]..l......Wn.H.K.x.7...<Z.......U..VvH.qMT.......).ue...}....__....s#.n./...gOm..?..Q..E]x.BuaoI@Mx=^.#..D./...f.....3k.N.6.c\.{w.7..K......%.../m.w..U.W.Bs.~.R..Kq.vq.}Q.?{^.....4,...C...y..."....o./..q...Z.o.3X.T.3.*.&.....(wy....hQ....:)$.n.!...$o..^A.;j..N...4..a....M..Z.....>.<RG1G.Z...>.86YX..Zo...._...4R.....2W..6...'{.......~.......`.v9V..YcWh..O.T....Z.G.....&.k.{*.W.B.O.'^./..9..L:...j=;{.zz..D^........<..p/.T7T.l...P.;.b:...c..3._..u.=.=}....1..........k...gqA....y..C.....<...s%L...R.3.<J...W.X?..G.. ..`...$Z.G."{..)].U..3d..m)D#.'W.li`.V..+.xU0..u..n...&..$....(7.#RH..2.:..s..l....Q...+.=L...r.3.<
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):761
                                    Entropy (8bit):7.518655013264083
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZms4A8a4Pd172GGemXR6EnQItP4B/SmLe19M0NkE5ht/avcQLJLfV23Yn6:HaArA8Jj1sRbREKd9MC15naECJDgQGR
                                    MD5:24F6C36BC9BC1971C1C0E66B60A9E014
                                    SHA1:712C61ED11A59D225CCC7D075B9B16CA3FA6DC49
                                    SHA-256:31E68A423731C0EF3DC3B43029DD6E1205FA7D041BAFE98A8FE04F83DAF19B16
                                    SHA-512:78A46FBC5D0F1714BDAF4F482BD9E60A3B0FC714EF9E8C2EC6CE1C1687EDFDF071793B0D1B7ACB8FEF5E0E37285D89AEA555002EC8256D663DDF600AC8019F59
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`aa.....Z.j......~......{......V<....o}...._..P..[.......|......0....~#l..?...<....m..y.......z......+...h..?y...M.`Xt........|.y...[...h...x.NlS.....p.x....3.8>..z....y...Nu.....f%+.'.:...........^...O<.b.fD...m..|...5m...W.ZR..........dx....i.....mY.h.K\.......E....}.q.sF&..z).P,!...'..8E..f&9.8.........M....R...p.u..6>.......nA..g...5(...4\P...f9.p..S...d.:.,\..o!0.d..8.KY..7)\.....G...../.".k/...Y...N.0....6.o.fN.....r3...[........s.K......s2.T...?.B).K.......-4^`.k..p...3.Z.>..'.~..y.......<..UO1.~K.. .......u..,..p....7^......E4.T...............................j.......o*...4...j.Ze...W}.?.e....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1488
                                    Entropy (8bit):7.830263223589129
                                    Encrypted:false
                                    SSDEEP:24:Ham60wnVUp1TLilSCYiLEGYU22RlV8k8m8t9PhKedWHAXNbcyxsRC/i31wo6bNex:6m60wnVUplsYiLEGvP/V8k8VtPKe9XNc
                                    MD5:AC9A1ED9E70F5B6A24646B0E78FF2286
                                    SHA1:3D2A81753ED276F1435FBF14349E860A33DE298F
                                    SHA-256:A7F481A0C1FD92E49AD223642F81B9BAA7F12552A576D03DEB45CC525890AC29
                                    SHA-512:E01619CD73B2B6D3B87153B6DAAC00AE518BC4575854187BF3D3D10091712603901ABD3260E945E9E659BA3BC6E6D38106AF7EAA47A547A20DDC11930D37B4EA
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....]IDATH..{L.e..?..9.8..?....d.5.%k2..d..j..6]....rM+..$.X......V.X"......L.{\..9.....o.t..r....?......~.<.?8..n....p...L..z..Vt.5...-..i.G.>.....k.X{\..i3|e...p."..)..]...d).V..b...S.k......[.;.xt.GU.xy...!.t.j@OW..w..*....$.h0.....%@...9.S...Gl......g.b(....Q..;D.'.C;......W.6............Z>.&..=A.30...n.C.u&.^.w....WW!U..W..)...t..Ph.ah;.K..w.7.m.9x...........'>..U)3X.f.....m.h.h.......k.....G#...... ._|.S1{....`.].dm2...LF...f..yA.../..7h..CX.(CA..7...V...y....~...e+.4y"qc.$..c.....}.L..0.....0........Z..7...ufs..'...M.$.&.G>.}<ddM....^?...8...x.r..z.;.?I\..K....W.....t]..,....k.4ez...^q<...MsS./.6c.6J_n.....`..6v....J..,=.>.c'.w..t.........z8.b$..M@E(....r*..p].....yI.I.Q_.MK.........c..u.U...KxvU.'.H....yp...|..j.j%p...a.`...at<.PN..2.27.a..>.%.....:.}.........+...........4......W...........&.Iiii..;..v<.~dY.D.......9...}...B^.o..\..'......@?...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):828
                                    Entropy (8bit):7.628531924625159
                                    Encrypted:false
                                    SSDEEP:24:HavvY8M1eY/ny0PmdFUp8Sl1L8Rnd4mgemq:6YZd/nyICK8+1AEeJ
                                    MD5:42F443CCBEADC1FAD879DEA1F75B182F
                                    SHA1:1BEE19280B64BA2609283B459E44DB3753CB925D
                                    SHA-256:09E0C987889193585DBAE4A0E1A2E7DBD2629548AA2B4D962E51EB08B52023A4
                                    SHA-512:4A22ACA03B3E84BC0DE63F76AFFC301FD58EEF2091C172551DB54C3111B847BCCEDDDA8CF5D31926A01D8EEECAC44EC4EC4BC4290D6509529E479648C6FAC26F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UmHSQ.>.C[...V?.#.........N(....(.h$..D..+S!A.>H..-..i..~4.id94..V&X`....v..n.....8..9...{.Z.l.....>f.....j:..u......................M2...0........IF....27k.a....%...@......:\..|...F.v...D.b...@...bmK?t.....Gx'....44........EQ.x...............7..........<...]"........L.Y.v..F=.`rz...........E..'.Z.0.\..|.....'g...8\....N..C%..AkD..R.....n.........D.}.Z..l.........q.@V.A...y\..:!..fyU.T.4.....'.i.No..S...@..-.."....[d.cV...[N.j.s.zj.d=..l......%LP..Ys.i.....`.3X."Bl...8..N..u...0....J....n......yy.TP...[M.Y..c>i.v..<)r..~.....?.k.U4....v.w.B..q.bx..H....UB^....@&.M..[.;.ee....X.=F..G-...9....+.lrH..z$.u..2G....Z.|........V...2G.5..w..".....R...G......X...}."fTAk.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):769
                                    Entropy (8bit):7.577082747595084
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZtiE+PrUxLRyd2ypMZahJx9M48VokmuL3X9+8NIAOwNIXyf00zcjCZ1:HaqlPrUTylMZl4/E3X9+8NywGX2X1
                                    MD5:F1B62A32CD22D12C712EC8971D448F1D
                                    SHA1:60712C1D8E6FB520FB0D40A145B7BCAB6C00CC3F
                                    SHA-256:A7846BFA398EC3C56A19C069955CAE92F70E31958EE9EEF729F04E50EDD3E857
                                    SHA-512:E7FAE5B8D24BF76CB33178B4A89DCB390A3F6A19DE5177C956490791E8D893644DA8E734A03D0983B61C0E461FBEAB2570589D795482E26BB9AA1AE29CE2BF6D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U]HSa...kmssS,.(.....u!.....HZ].Q....x....U.B.&..d....L........c.ZX.....y<o.w:..m...|..o.....m.{....X'..5.].y....o.B.@..=......K.p.BG.Y.....MV.........WJ...b...L.F.)+ ...a..c..t.!.o>.. x..@.p(....F.a..B...q..R...?.#..!8....`jv.z....{....0I,1....y>Yw..F_E ._...W.G?......M.....F.?...n.~......|......1......+..,.F.Z.q|.~..8.:..Ex........z.Tz..d...[.Wnx....g.-6...%:z.nR..|.......?.w|!.m./2....XR$T.f..uB[{_.....@.A..,..*....:.@..)..VH....'shF........"WT.G...4h.#...B...W...A....+.Q....3#r^q....i.4..s...j.(...ZM'k..../.{......r.y4we..t...8_...f)..U.G....e...I.mB&d...M.t$C.,^...|.....J..a...J.o.G...8...W......[q.3..f....94.....$...F.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):655
                                    Entropy (8bit):7.418398877686977
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZcT4lYTthdiGLYShgVLBCBf8eghIQoR+pDggP0Y69C43sSnN:HaJYTtGGL/6DIfR+PPw9nsSnN
                                    MD5:CEAE5E858757317F11698A82E51380F7
                                    SHA1:0DC85782DE0935BB34754720A34977498766612E
                                    SHA-256:0D8EAD3075AB89D7213641CD9E268F532730A616D69BECBFB9D698CDAE766E0D
                                    SHA-512:9B0BBAA229D58947F2F30DD41124A4926150D362DD81A483FEAB70EED6A07E8C8FB449A52B9602B3A8E773717764290D33F2AC86D9C7AD717C9AE860A8754197
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..#....FX..5.h.R......'.>.....;fo._.>..N.$8...fdb...#..\|B...E.....1?.../...O..9.x0,... V.b.(...W.2.Y.../...c...s7.......K.........FF.....S4...by.$33.zn^.?.V.........=.......n>.?{.>....N.......p.[p.........q...Py...._Aqy.w................... ...d.?...l.#.E........?...6v...V......w........W..[ ,&.......I.......(."........Sw._......7.OX....t.. ..k.$h....{.]........?..n.%`$o.....r.,b....5...^.W......K....cl.....3P.......O.F....M..7M\..Xob]?.j..>E@C.s.........c..K.....@...A.L.......H..@\Ej.j....F.9`/4.8...C.....&....#....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):741
                                    Entropy (8bit):7.401437975873439
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZQCyrOtEECaDehpQtHtOBX6DKx9p7P2+IQq4ze62JrlZ2:HafCOtEPaDpH6YWrP2/QNeDplA
                                    MD5:EA5C6F7675A52D74B00E369EB9437524
                                    SHA1:C11BD43C6F6A03F31E38D42E50DD20299456100D
                                    SHA-256:80EBE115FB30963AC8541DEB3B48168DF559EE5BB1DADA6994B3FE6684398ECD
                                    SHA-512:464AE83AE8F991E496F714FB76B9A29EA9C8F3EB368B82969E0C641242B830D77990191129C5FC2A1074507D5D938C8D8B45949A428F08A2ECBE60A4BD5AA781
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....rIDATH.c`...4.p..%k:.8.|....[.O^}...u..w.....}....Ip.a.!......G..............c~ .._.?....sr.`X@.(200....._.......n:...k..n?......?...;I.....y=7/..I+...y.............7....z............Z..H..,,,......>y...G..?z....;...Y..lAba....@........l.....:...g..>}...........@XL.......J.33.;c...{N........N..?a.....Y.H..^..B..t...[.......}.....?.+.......XXX..h..v...%....1.......(..@%........&..E.7...$.P.&...y........1$....T...b[.A\.... 1!...T.B.....b...>L.} ..X..UP6H..H.H-L.....s...|b.0.-....@r<...2&..1.R.ZG7.gfa.Y..dx H....UT....,.aM.hXP..b9 ...7 1..H..$[...z....... ...._..i.....?+..oXJa...m..U-Y....O.<).{e.TG....Q..b...#..U......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1340
                                    Entropy (8bit):7.79907189110833
                                    Encrypted:false
                                    SSDEEP:24:HaYOFaXCM4MwRYRpPLpJheTPixZLo2JLzkXXu4unxejz/KsXweh:6nax4sRRpLeTQZpJLeu4uurv
                                    MD5:3F41A37AA36ABD8A820D4CDDC1492D75
                                    SHA1:14E65385F76AA1C5B560A0A2E3670B975ED5D4DB
                                    SHA-256:D92F1A82CDA991A2A6887EC402A41D304E4D4F20C848C376074CFC0635E0E24A
                                    SHA-512:1DED3D6BC7310C05132F24DBCC84C57157728CFF17A1EAA31D160F4A10BE68D41C253D6C1DF9340B574A08CB8FC62D726EC26A4C0C389A66D799FE0684B1005C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.T.P.U.........<7X.p.A...0I.^.%.C1Q.D...I B.(b.......y$o...@.J:&9.D.icV3..."..u...........9.|.;.W$.P.D".f.,+...Z.t.f..ts.....^...#.<...K(i..gU].44#%..q[.bCZ.........e.../.Y..:.+.. :..)...Ss...Q.t...<....$g...|.CW.C.)..FZDj.OD...u.y~.Xg@...jFZ.1..CeG?......H.E....@..wAk.....I..0.Q...l..7..-.....(l.C...PP...6|.[...."?....l..X..$.I.Y...&X...cU.!$.....\D....W..m......a.s.gp4..z.[...f.(.x/G.....Q..H......Q..'......f.,...w... .S-d.....z.............Dm.5._(...!..g.A&.f`a.,<.cabf#...k.PXiaK.c.o.`.f...-...f........rp........p&j..^....(j<#.5.9<..E3....gw.pH9%q.q..wQJ.]o....|... ..+l.Y..dh..b.o##...E.F5...C.....k...&:..@...7....=.I..Xk..1~..M'......{..d+......Ah...[.}.....o.x.*..~..fFIX9..rT.....O.)R.T...../.6.B].U2|...Y===...V(..V.e....q~..OFF..L..%.8...|...q[~=...!+..rG'.=O..?.z...(xR........l>...s.5.qC4#......3..H.1.F..8.1....%.q..=........o..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):894
                                    Entropy (8bit):7.6708373779537435
                                    Encrypted:false
                                    SSDEEP:24:HaoN//yF0axmW7vLhADeuQadt5uLyBeGvZBVVqSDS912c:6a/KvvLhADerWt5yyBeGfVfSz
                                    MD5:DE1DDB8F45F2BB1CF36C2047B21E7FFF
                                    SHA1:FB1FE8851F84E8DEF21325E8284C818A1E039F42
                                    SHA-256:258D0E407DAAB8B1971DD21C2CE12202433938620629241816CDA4118D6B9F88
                                    SHA-512:6D5AF7D77EF35E145997C71FC8F777A490E9B1E472B32C6857FEF44BCF40EC41D30E70EAB36CAF28DC8373779C355D7ABF34C76544D864E9B05F4EB3E28AC68C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..TiHTQ.}...q|(ZQ.23....WQ...#...J.... .2sIp....erA..M&..df.c..ei...D..).%.....L..3!t.p......w.A..l....c...rH-n.mm...FHV.Bl.."W..s..o..9....3...D!..."c+@.Cq.E..q\.T....5.MR..4.}...&r..Qa.AY......N..y..n.U@bV1\L.{..r.)..LX..Kh....IyO!....sk .n3T..As.0t.....A......nHUi..N..).>`......q"....u-p.3@...e..Pm...1...hdK.kH...qY@..i..@...X|.......6....U.p:,..7uAO.........p#.......,IR:b...2f4(4...A....{.MS4=....g..h....'p5..NE\.......+..qr....C..9Zj....]..3..#...LM)...p.c.UV.a-.$.w.......4.c..Lul.....Pr..B..]$)..M..6....W........PT....!....a#..:HD...*.?rX.y5.........cY?^.[.B..z.D......v....{/..Zy...I..0D.I1......!.#..QXdL...S....;+.."W[..Y.)8.. ....(^...b.:.j..x.fG41..3q....._..x1.d..K.I..d......L...2....'.@wr...z.h....\.k..&.G...2.t.c.......L...f....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):600
                                    Entropy (8bit):7.484814395261773
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZAozix/gQc64jpVKLH2pufHgkv2S5eVypvpkaN1CiyZp:HaDWx/gH64jLKLH2cfHNuSVdN1dKp
                                    MD5:018BF653EC51BFAD946AC0213AAB0E68
                                    SHA1:17DBA0866A37E42733B2E15E82ABDFB02889E62B
                                    SHA-256:0E690C86DD547CA847C820BE499F1CA89CCC24821A4A5119BF5F5720E6847EA4
                                    SHA-512:C89598BCFFDEE06E581E16D8C2E96025D50CBA3CA428D217F3BF58046BC026E6CAFB5A6CAF89FF4AB997FE561FADAAD4C5C1A1B41FAE760FFB3F40E4F0722739
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...=O.A...wf.<>..DE....hbch,,....Z..(l.l.....Zb."....F....`..gD.........\..jBcx.....[,.C....W.WOW...}..8@.T..7...;7..$.[,.C.r.n.q......p..0...tv.q]...`....W..{(..G..o_..4.. ...Q..b..C=...2xp?.}]...m.;.u..qk4Ir.3._..&R)R....u..)(...VWJ .4M......f.(N).!I..e.*1X...?..T.N.$.%..(.;.We.Z'T).0.h..,-Q..e....$.*.|8..I.Z...#...%I...Z.NN(....G.$'....._..f.......&C%.m26--.... Uj.m...F'....j<{:n?.6..".a..wo&..{.N..@.m..w..........#.......4h.~.8..,.....g......gW..~..:..].....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):758
                                    Entropy (8bit):7.45404515221275
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZBCyrOtEECaDehpQtHtOBXxQHXrtwFZRFaReGZYzVb3oob/j2xebS2c:HaCCOtEPaDpH6BQbtwFZRFaRegYh3Pb+
                                    MD5:950CE2E49A1FFCB55F9067B4CCC46754
                                    SHA1:31EF1D8D60F5BBF75B833FD1C99998E209413B83
                                    SHA-256:1B2F928DACD0BE76A895CC6C0D04AF3490FC9E033D8CA6F1B38723B0B461C3B3
                                    SHA-512:4EA76D316F26DF2D861EEA9B16F97C4D2C05E948C7BF813BA996E10667A829746970FBABB8ABF66D2973BD7E52A06D2D6E5586EFB25557FE0123E1E5D45C9D1C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`...4.p..%k:.8.|....[.O^}...u..w.....}....Ip.a.!......G..............c~ .._.?....sr.`X@.(200....._.......n:...k..n?......?...;I.....y=7/..I+...y.............7....z............Z..H..,,,......>y...G..?z....;...Y..lAba....@........l.....:...g..>}...........@XL.......J.33.;c...{N........N..?a.....Y.H..^..B..t...[.......}.....?.+.......XXX..h..v...%....1.......(..@%........&..E.7.5.....<|...D@i......(.... [..F....H......Q.k.. .5..]n<.vy.d.....0..v?.A......a....Z.T......@.........o.Y....8....'..<^...9.A].V........P.O ....|...Z.Oj.....w..Pw.........@.Dl........)P..dspZp?....~C.<.w.}...h.# .A0..i.O.:6b...2................c7.x....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):657
                                    Entropy (8bit):7.461097732684278
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZB7Hu154ihMvs0AmHNx0eTbgotABVNUuWype/GjrMeitDOo49Q/BV9vSwt:Ha+dq4mHNe8IVHWype/FeOio4y/jZSwt
                                    MD5:D9205FE71E17944FB8364B3FF88155C2
                                    SHA1:44534B63336528AE79DC57DFC1812E9AFAC277BF
                                    SHA-256:87AAA33FC6C8A6397D8C566C9AABB39B23CBFBFC8D79FAE24D1BF62162A9EB31
                                    SHA-512:F69FD6447A34AA2767E948FA91300BD6190D11AAFB690F8A00A99F4C15E0D8F4FD192E73858261D62350F5E8C378E4DB79AABC5E9F9852E291CE0AC50F5AB2FB
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.VK/CQ.....6..X.......".;-%A.&....~...x.DJ.,.....D,.*"B"A....u{..h-..L;3_.;..$I.........(&.@...."N2.Pj...L.....':...A..q.9.E.j.H$.gYX..xf.'.MP.}.2'}..5....d....A.jP....}t.Ts....5./.E.\.N..'dX....{.x..9.E.j9....C.X.i.GlT.........E.j9..0.t.E|.....6.,..D........v.M....Xa...\)..,@......O.,by....Z;.......sL..p8`.c..X.Oa..j.5..U;.N .2 .I..T...D!..5..DM"M.%.H.'V..!P....,..<.}..8.X.(..=...M......g../.......k.hx~..n......4...|ce.9...7..ili[~'.7A.!..D/ZD%...lE..Z.jO.U!ZvX.XXj........D..dX.H..e.^.D.u....Ht....wl.2..z6D....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):623
                                    Entropy (8bit):7.530319267640003
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZeaU20tYJBYh5ObFRUG2yn/YEowBAXaAeNuEWrweh5:HagtrtYJuh5kRJ2yn/YRajUpP
                                    MD5:B10DCF9D0A2B17300087408AF6606682
                                    SHA1:8C561A755C943F55C3D14155C6DE0575FC84D5B8
                                    SHA-256:CA6A857B81EDE5A265769E7BFE71CFAAAC43B1C7C4337127C5A42D131C4045CF
                                    SHA-512:6DF3F942BAD5FAFE49393F67B9F3089C201CC0A5F023ECE14E6278412CFF3ABB184282E1D89025E177BD52E1036ACB5A0FD35C25AC0556B01233B9EF17D39089
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V=O.A..#.0...`LLD..'V6.....J.2"..J;........h...P........7{s.|..n......{o.e..bt:..z'8.d.....Xg....a.>...v..!x......Ep.A.b.6:6.EYAIp/..\.~h.....V..S.ew.`BM.w.....l...Z4._e.../..~,`u[....I.q..NiI.....V...-...p.f. .p............ P...9.d.G.@.....\.D+...B..x..dM....^@..qv./..h..7C.s..a.].,. ..X.......N..l....@..X{.D.DB.....d..]8.&.T|..$.9.....i3$......&.F..W }.x./&.Kr....b.t.[.n.h.h.X...G.$...........C?.h.2j4...C.j.4+....6...Ui..~..:...9...c..=.m..0..S....g/?.8...I.......S4.}........z....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):378
                                    Entropy (8bit):6.968222383042327
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcjih8knzlRWjzdCh/29wc+r993SVXI3/VK7XXNuHatTT6p:6v/7saZjihhnzQi1cM993wXI39K7HEau
                                    MD5:DDE84629A1D30F57CD5F3A1DF596318A
                                    SHA1:2067D09EB69E37ED2E35766EF678203936BD97FC
                                    SHA-256:ACBD63A47ADB67428015647C304E2F77EC6EC6681EFF9D813477305AF0E6AD13
                                    SHA-512:62220DC3E0EB9A8E20923270799A25A560A5A792375519617198F331BF68518AB706E8DB5AD88DEB01DE8018E28E36E6EA1761743DA1F2985D795ACA49425E44
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`aa..........3............g.&.C-.....<~{...kk..?5....-.'l...7.r.@.^wj.....pM0.....-.mC.. ..*...n..%8-.k....4aS..@3i....9X.Y.............u8..W|.m.!.u..B......b.4.-.....D.F..WWH.d..pz:.., 5."2Z9A.v^\L^F.Y..I.B7..@..r9.E.2~....C...-..N-.[s...h.3H-.u...!..W{..{....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1404
                                    Entropy (8bit):7.823759117422973
                                    Encrypted:false
                                    SSDEEP:24:Haqst6/WZfvkhgzOBfAoquXFWagbRI0kZpNeIEo1TRtU9CE3IksGqNMRkCwrtGHS:6vk/iHwBoiFWaSRIZ8pzC+IlGqOeueIk
                                    MD5:02691D1183327E11C039CE8AE1FF8A12
                                    SHA1:F4753709E5AFDC80B88E65D70B1EFAEC697F735C
                                    SHA-256:B57572C16F509FCC87C7AA0A702F4A76C56FF30859309DB3C3C7CC0D35F8B684
                                    SHA-512:EF32441396943B73F576EBBC87BE8A90D4509781D10EED809BCAE7AA229F5F30D66940C969D635743E0948BF7F83D042FF54D284AAE8767B380D2B96359E89EE
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kL.g.....mii.Ue.....dj..{.`....rG...M.#P.....e^7.....&.nlqsj6.if.,....,.VZ...<l.`.dnO...^~...<...._n.E.sv.]...........\...^p9.4.&U.7Y1..?...v!....W d...%?.c44q2..;.(..p2..J'.2_1".0/..Ib}.T....K.....l.@t./.,q.......eJq?F]..P.....#t./.e..G;).y..[...r^H....7..K......R..q$.$.vuG.k0.T...(x.Z....;.C....j..\nz..5`..-.ZJr..s...|.{aS....C|..^..!.5.'zvW.E.xk..0;.$E.K#.?.s.....M.F....U.....w. $..r.......N....wm..u.H.V......-. .?...X.....Sy.?...2...=.g.V.(]$.4~68...w.>..G){.w._..5pt.}..xb.8.{.m.=w.M..d~................|7....m.........-..@..x.P.t82...(.nZ.....z...;d...............=.....A'..Y..w..[...J6..]...,....5..x.. b.B..Y2..XN_n..l..I.Ie......N....&.J.....["...U'.....T{$o.}`....v.R.9.|.Z.ln...f.>Ko....l.h[`...9.w...+[..1U..5I..g.`..X.P. }....w%C....zA....;.6R.p.."h.Ph>w...ZA.k...d..5`T.?..:.....UR....Ws!.!...}F..ZAXUm4C=.5!...O......FKC.......LeG.-.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1186
                                    Entropy (8bit):7.717202739319088
                                    Encrypted:false
                                    SSDEEP:24:Ha9wvVmF83N/aTBZ9jM8C5VczDoBAGXzzbxBKepwwfPn33+n+:6mtmFw/+ZgrpBPXzzbbK4Pn3O+
                                    MD5:BB5A53B04BB6C089E8AC6E8DC531AB06
                                    SHA1:7D49CF14FCBA6EF45D3758A17A83A1570A6AF423
                                    SHA-256:4DC853AECCFA023576F97D5A15D3343C92E4FB9E673B80593F5BFB82E80B4EFF
                                    SHA-512:A465336C4C390D1961BBFCAC7B47EA92243E3CC5D61599E65894126D6630ADBFBF58F99685F1CD6FBF555D607601A23D12DE6B1396F0D47323C0AA714BA7D97F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<..../IDATH.c` ..1.2.s..]..a..#.....y.P<....5T...9.[..$...[.p.o.3...lw..>..g..?u...<......~.s1?$.tV6.3L..............v....[...*\./'..?.6..$Y...1+2.k....!!..7....UME~..../Y...9I./...?y=.7.K.....7I..q.......|qj=..<..l.ezTD..7..Rj|........?w..q6...$Y...T..f..f....T?5.!.);.._./......N..l.,.I..xkW.]0...l...{........Ysl..,.(.....T.|.....?3..vR.....o....M;....K..?.L.oi./:'....]"....5..@.?VN..9.`...Gr..dA.6...3..ydi.......|.T....Y.Z.i....7.fA.v70..........>...&...........3...}`.!........i6..c............;.v..@.. .CS+...z.....O.._P$.......;@9.d...\.....LNW.....?Pn....?m...`x.S7...,s@.....G.,...f........i!f.gg....:....z....z.O.n._^W..K..-xCR....^...>S;.#..<.@._.N.Od...PA.f%..G...u....l.;..,.p....Q.'...i..`.g..6.[.;....A...K..,..E)?fec>N..<.{.f.LF..5..v...>...7.p.6..{........ZB..j...3.ka...o....T...d..1......F...\..S......41.6.ANs..;2..M...'...%E..0.?..=.Le.... bcc.t....R...}u.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1106
                                    Entropy (8bit):7.689550690966777
                                    Encrypted:false
                                    SSDEEP:24:HaqITus7uL9OAJ+EsZF871L/urmq7zXYseQO9Ra1l6OZ5H:6VupL9OuKZFI/uK6bPOXMQOZ5H
                                    MD5:9966CBE16A57DCC1B82D20840C01F0C3
                                    SHA1:138B2C87B5710E6ECA9B239DF5ED5A3D333C1B9B
                                    SHA-256:5BA79AF9D6B9C99B8A2D375CA3197D1135A20B14A49F3FD8604E258A4C967742
                                    SHA-512:943450C22F1135453208886F8959B0965C6225D4C1E0BA953B0EC5B9A4295788EF3ADE188D2351E494A7E95E6DB4C9D088A74EAC246AFB3F56854E284E1058FF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`....-.....r003...r....|.e'.FD..%. .=>.......@5........l.x.._...O.b.v...Wnr...m..1A...+..:Aq.#..,.@.NHf%@14.xX.s.|3....<...PB8...?.7.?V..P....k.EXXY..K...`..a-.=..._.f..../...m'.[.....vn.@....*....`1n..../N._s..1$.u......A..2Z....t...s..\.....O`P.V1.=V.....X.....d8..g..f......m..^..w.-......?~Q..r.B..<e..../.+.>..tE...F...K..........o.8...8.x_G................?.28n..........Y.....Ojs...%...J`..J`<l.i.7...,.....-;.b0..==.?.0...G..x....U........Z~....{.R=^.7.|.......S0,Xq....(7...+".yg.}..U:....;.x8.f.F._.....'.XZy.....?W..[.d...Aq.....e..o.....`.}.u..Z......pp.5.....E......goN*...Y....=......n./,...vi......%z.`.l....hL.N......b.7LY[=3.2.eI.........)..qo...\.......j....p...n..=S.cD...5..=@c|pZ..I.6Z/..C..m.....k.D....._....+6...j6..+...h..>.,.y....E1X-.Y.._T.......yE8..q0oE2....b(.Z.].X.w.x..*f...S....R.......0x..L...1.ac..Z.S.R.O.D..%..K(..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):909
                                    Entropy (8bit):7.6669428564650755
                                    Encrypted:false
                                    SSDEEP:24:HarsdqHGLF7QeILl8qAkMnEqefWDDEXKk04uoZUmEHirXY:645+egR5XKU3ZrEHH
                                    MD5:79C741859126C7CC5F1AE10CE15B76D6
                                    SHA1:AA020244049C78C5ED1F18ED83A6B991BCB087DA
                                    SHA-256:20B0760ED8B786CB601E1D69FFDFC0D89A28FE43DA5D1D3C98F21B8BF5ACC5EE
                                    SHA-512:B0CE451DE395E741F2E41DF1D766420F4A0DCED2D15CA4B5B7A64CB70A3EEB31A11FF370E602B5EB32BA4E699458E58AE2BB3BF065E5EE2D3439155FA37646B3
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kHSa...v.....V...S(.f..+.\....m...L..f./)!.LTP..`YA.".CA.!...}.CE.y....Q*';ZB.._.y........CQk...Z...]z.V..~...'....`...by..G5v{.e-....q...A0M..,fG...Ar.y.4nVQx7.s..L..h9X.L..._.....T......DJ....e.......V..(..l.b...3.....<.....uU9.....[K3..;...+s.i.D....8..,...Oi.$7.h...$.4....i...3...v./NEe.~e...X.4.B(.yC_..S..!..[.8.-....};@.....m....q.....3...M.s.ke.."..'..'W{!6G..A...J.4..f..;..P.Qy".,...L..O.0..wU]w...h.=/..geh..B~S.B...ay.fZ(..$.+.m..:...7@.h.q...lj.(..".QI...w... .E.......yf.|u{.......}.,.\.R....H6.....`....s....O)..H...*..S.~.X.GQ.1.>..'W..%aH0........!.;.A[.%~&v.)K..Z..u.HZa.tq..c..0(.....x.4.%.`.B%..".q.B...C...WT...7...... ....+....x....6-.F(...V.E-.pu.q...# X......6w.X.yE...#jk..&K...".......z.......!....4.a..@.."..?....3.p..5?.0ST...b.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1630
                                    Entropy (8bit):7.811174047068751
                                    Encrypted:false
                                    SSDEEP:48:6pge4tcbGkLd+xHVVdaae+bmPYCoXHsgaYhCVh:ogBtcykL0jaV+bmwCEjs
                                    MD5:41D4C4CC18FCB528AE0B544808673A7E
                                    SHA1:4DC3EAFDD605699028F84CCDF3F5CE9C93CB8849
                                    SHA-256:0436EC91851F214D792B7EA1E9F392ADE98B904A3009354B5D1733BF3BF7429C
                                    SHA-512:83D66506DB5C9A630489FEC881F9E8598B5B2397EA62BC3F507D07E5BD861C65AD10D715088E30B2DDA1D2156206528E15C5CB8BF233FD57B2AD07AF8EE1154B
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...4Ti....{..4.):...Q..X.$..m.U..J..b..%j.P.I.0...'d.e.8.4.Fq.m.J.<kC.c.a.>....ck.s............3.R..HII...@ ....D*.>.q...j..%.......W.+.........A.M.f?`s..N.././.....e....Lib.3...|.G.K..5{..".^7.LNNf."""@...'...V.J..\.G..........8g.nA.`n7./.&)cs.......u,b..^.*JJJb."##AT.5.)u}'.}..Z..fZ..g.A.......%U.p.x....A..[Ph....g.h..#...a./^.O5H.L....f..R..-...N...-_....P|]..g.Vn3+.-w..o?S..1.P(,KMMe......p.=a......w....P....j...d...^..t.ug.(j....h.-..!.n,//....t. $$..G..>.O..}9.........WQ..g....1..'.>...|@............N_..4..%.Zm{...1=QQQ.t.........@h.hn.sh.@p......J.t..!#Qc:....ilX.l..MYp....}JI.Rhnn..H.999.......%XQQQ...c.........*......04,...r.......T1..*//.Z,??.tAA......z$.o.W<...&x!y.qqq`dd..c..`aa........AAA..'.....UZZ..~.zx....&NR..m-..W..s........3fUUU ..@.@.....ec..Yff&.......y..bf......w...x...o.g..B}..0..<==U`'''.....l..v.o...K`'.T`..u..L..8.z.\....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1056
                                    Entropy (8bit):7.701852613120881
                                    Encrypted:false
                                    SSDEEP:24:Hai5d/8cLOb9kzfUsXIQXRkdcYuaqawk8ldTN:6q6bIfU+IQXRkdcYuaWN
                                    MD5:00DE8537DF0EA8F77B9DD9CECB310B19
                                    SHA1:EDF8DAAE50686CE3B643867DD985C32F8E4D0172
                                    SHA-256:EA9EDEC7670BCA439D9B5DCA0A3B6DF0D44594CC3416F32EACBAA3B54B4892A9
                                    SHA-512:12CD91B8B35CC0C6BBE9FE683C4F1DC7DC1CFB2CE2EA8CDC8FB137583FDC220F2357E98AB631E3C0FAC708A54AF48AE48866CF394961CA925DF285F67D916CAA
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` .d....9xX.2.2}..c=......w.b^.2.033s<...iVv............r...n..6Z...G...8.Y..q0...I.bm f.e.(.g.q..bac..e'.).........;.b.\....n.....D.p.|c.`..-.......yv .....4.....K.6..4...i._\...#...ff..,..{.X...2.W1...P...t............B..5..2.0M``aa.w.7..1.p.....>!.P...S....`.=^.k........-..4...u....n.....S...j.G.../N...9[.:,....I..F.?~1...QJ.3gY#..............i.)..d0..h...... K.H.... <qe......q.~?=.l..J........-.....p..........N.U..]..-...>.4;.dA....Y....Llj...*.,.uFe.I.+.......!.311~.Y...%|.vR......M.?fmi.....A._|x..g....1x..p.M,..;og..`jZ.....6.6.^|....i...."h..ww._xp.....9s..Z ...........T..........S..`.`.y...y........j..0322.Y.vb.,..".~J...o....G6.Yn..*..0013}.....d....-e.....~UL...l.(X`..f..'........i........%..|.n..5ag...GrQ........|.8......vP........kS...0U,`ec.....?4....C98- .Dw_\...-.. .........|....cZ..../.i....#....}.CP..oJ...d...B.d.n8>.......u.o\.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1179
                                    Entropy (8bit):7.785914688983405
                                    Encrypted:false
                                    SSDEEP:24:HaNOoTvO3QH/8zi7WcTXz2b5wDJ5EQ3S7FhU45KTpx4t6s4NWji1:6ocWAH/8zmWO+5wdC7FhU40v4t/4Eu1
                                    MD5:4CA8A77CB603F65CAB0522BB395568C6
                                    SHA1:D43BF8E4FC9FCB19F192B8E00BCD0FFCB308C264
                                    SHA-256:1EBC65DAD53C3F74D9758CEB079CAC9318724B796670F27EAC691BCCA523E6F4
                                    SHA-512:567E31373AADBE434129C2D51DFA4D37F8C19C26FAC6EEC3AD95D560993C70911E387EC12144F2748AEEC5C6EAE5BDC8B9D9BD3675D75CE67385F8E5FE93D99D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....(IDATH..kLSg...s.R.J..r..-.....X\%."^.u..e.-..:...&#b..g6.../.3^P.}!d...q..D62......(...y....z......sz.......W".~."...I..O....}.......K..3.....2./W1..:...iA..*VQ+.....L......w...z/9.......#+....+Sf...i....G..Bu....RRPj9~...]'^.......&U.'.......,...k.FK+lc...K........R....~.......e._qvX>g...X".([m.=...........6f[.?.O..=$.*.h..'..d....A..*.Vn.:...X.:...ot.5^..Y......F......!p.JA.`.w..:.:.U..8.,3..)..N.b..ia2.w#...p$..-.].../{B|...Z./,.....t,..)F..6.?.v.f}G...*l.o..U!..MP.].w.[.g..cmW,.e...I..#.......gp..>...=.!....Gj..1/..k..8..9..>B....,J.....{>..].......\..|....:()/....T.*......rf]=.7t..m.... .a..[....o.(.O...e.3(..Re..N..GKn.?2".Z,....o.._.X.....)......TuZ...J..z2'..Kv.u..._...T*..;'cn1,./.....4....;$e.A..JX.4.xD.........1..A2.@....).).c...".b.....l..b,3i,k.....L....p..dBxw...I.i.:.....S...'MU............t...C..NI..`7r...9.V.....G.Za.W.........
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):988
                                    Entropy (8bit):7.631799691763389
                                    Encrypted:false
                                    SSDEEP:24:HaUN5N9Mbu3Rvtny2nQgzgn9nd+dQDwfdrykpl3k:6O58YRvE2Qsgn9dwQDwcu3k
                                    MD5:34727D6D70E85120139CD8C38D8E6FBE
                                    SHA1:1C452DC914392873D8E7AE4D7A6E6FBB9A4A0AD4
                                    SHA-256:8A66BB00445B1611B986A7C620A8F37D013C529CB34DE08B9306839A3C08E22B
                                    SHA-512:4258CC835CDA2B1F28B0789A2312C012DFCD49527B606A651B451A088F5530D1E2234881A6527FA5C7FD18C792EF250721F2A9373F9D71F2728403E5613408AD
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....iIDATH.c`...8....X..J@.........;7..}W...zB.Y..rp....d..T...:@.D...@Ck9xXo.s.|3.....m..f.....n`.bg...._.^.+.0.'fV..,lL......|....?.?.?.\..E+...c.Q-F..e........A.XY.....t68( ....4._.(..Ys...'M0./.....t..M..yfk.`.`>NL.5X....|qj..#=.E-q..,4~.K......!)......8...h..J.h9.f.[.}..J6v.-.X..c.r..#.D\....._..w..Z......].,..s..oY..?...w......:..w..V.cA.........w..F.....E...8....8.....?.F.u.X.+!-. .:.QBA...Y...A.. .*...87...m)..KL~zfi.P..<..[D...B"|.@q0kK.d.E.br|..5F......jY..!I...3..;'....68X..QR...Po<.9....hr.p>._^>?.$.]f}...Mi...&.O...o...O..o............tO.Jr^...&..).......Z.'.."..{......_....K.8.wMS...d .<.."V`.?.......)(...X....[........#3.j<fb..).;.U.V..f..z..B|.`._L....6..F.2..E._..T....\ `...z....c..?.0.P.._\../0X.....-I.m.b.`y.*.@.@.A..E...)(..eD.%..% ..b.|jo...G..X`........,.~B.E.$L(.X.. .*...I..Z....u|....d..U-.`......)...7...h~ .....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1074
                                    Entropy (8bit):7.681932689849198
                                    Encrypted:false
                                    SSDEEP:24:HaXh6HuBALuUMtm5YuPzPsssq3NCOgimuFDwsHZjFfj:6x6OyLq+zPssHAOgm+sHZjBj
                                    MD5:30C60B5220B323DDF9417A596E1F263B
                                    SHA1:208A8046C56E485360EBDA7FFC973D9405810608
                                    SHA-256:F0F6855C2DA350DD2F4F85FCB11302668C3BEA6F6B5820A99D0FB60DAC8DBA76
                                    SHA-512:19C839A20710D6F2B3A64CDE5CED376662A7341A73C04CBE63FEC56F50DAD00BD5C1D95D3D3094926B8B318D235567483FF30757626A35DDC56FBDFC387AE9EF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`........31P.....q2..s.l..a...".^L..$;..]vn.CB2.sx....Jy.......h.Z.a......Cj...lw./Xb..f.[...6..-].....in~..l.,W.E..h.K8b......>011..w..U..qm.J.. .a...p.....s.P..uJ`..l^a.kb.<....3.Z..ir.H.r0...c{.h ..!Nes.r.V......,.n3.-.-......P.a|.ic|..7^..M. Y..vZB.w.0.n*..}rIQ}.Vk8]B..<.;...3....A..M..z.mX..>c...8...].n@W..6...r5O.8J<.R.......T..h..I.|P...6.....7...Q,..2...1......p0...,.>.....69....V.m.&..B...Gr'..C.0...p...D..t..G....>K!...].=..X...].F@_...1M..306.A'...X...lul.."..&:@....1..a.iT..l.A4/...T.0$t...........,).a .....=&.bzM...:...|2....'.M...T.~.h6.F..]f.....DD..-S_.w6.._.6..O.3..T...G..nX..}....B..>=I..`....2..r..%...e..H.n..v....L...:..?0g.wM...W.....9EQ...=.. ...,P~..$..N..%....-.......?y........<.....G.y.|..&.W.t...[\...q.....nA....0..lu....,.../.(.3M{.@..@..0R.xE8^........f(.].t@D.._.A..@=....!.`@XAOh......*.?....W.,.a..r...mG..F^2'.u..9...(..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1198
                                    Entropy (8bit):7.679975891907876
                                    Encrypted:false
                                    SSDEEP:24:Ha/kd0JmWOez1Po9eVh0PAZExwaqi3C+I7VFs++qQtZHMTB:6ysTaimAowA3VmVFs++qQtMB
                                    MD5:FC889A3ABE091582FDF7FBD398B73E7E
                                    SHA1:8B0138DFA090C377FB6E1D4B867D87EE6E0785E4
                                    SHA-256:5A163EB5126F9872300339777411BED9D847945B141654D7D40B7040515A0A51
                                    SHA-512:86C906DFED708C9FBA8D84F1D73B38D54350324443828B3F2486C11108795B042D28D5AFD9626C480BA08998D705277D566A269FFCBE377055CDFD6E9B12B83A
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....;IDATH.c`..........X..._.c....c.P..Zv......s...b.....bv4}..`.f...g.q.."..m".>f.._......q...l.."H...*..A...|"..M.X...l._.8.........a06.>......a..@#b.Z .w>$.u.....~1...".....Wmq.08o...M[....\..35.i.o...n...y.,...]31.PVM......V...d...[H...3..=.....QY...!.?...>.V._...<..".f.....,.'..2.0...u5.7].....p.1.....~Q...N.g.....s.G.Z..P...4..d......f...:[;9swvM...Osw4..ta*.E.R|p.k.........i.QT..(..q...r..x~rC.....U.o..c~.5D.o.....v......&........@.el..&...s@C8....RrQ....?...6........aK..~...Q5.`K@...'..d..o.!p*b.o.......M1........J.l87..../<.&....Sg.5...". .y....p/l.[8q.....o2...6.....H.F..,....7.X.V....\.l..-@NAp>7/..t.'..._`.....'..q[..`...Al....N....g.oZ../...;...kb,......aj....zQ...o....O.....xx0.......g.<...Z...^.T...{Q.....%].....D.H..D..e......P.w.h.c....~.q.....js%.6.S....=[....D./..?oW..P..J..oY..?.....<....f?.cU>r."h..D..s..L..3.P...`<aG....1.......s
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1359
                                    Entropy (8bit):7.8377593343058045
                                    Encrypted:false
                                    SSDEEP:24:Ha0CcwBqThBareuZB2T5K/BIM5tJ+A+s32N3wUJHHjP7ALgfSOlpZ02+2:6bcwBEHaDQlKZIMfJV6351DP7yg/Zo2
                                    MD5:3D8FD81BDD5718D6E719B4783859552C
                                    SHA1:E80FE55A5AB4BEC4E2D8CCB953CE253DC2DFD229
                                    SHA-256:57FD10C279146711B42C45DA9A7C6A2DAC2729C860EF6709D07FEE5E38DB847E
                                    SHA-512:C256ADA511E08B1ABF5156474BD064A70A487A7ED652EAC1B9C1882C9BCE1A0C6ADCDCC21F55A0A064E3A8A6E22465DCC365659B3F6EF2DC7EEACEF3A593F3B4
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..{PTu..w.c..]v....(.O...!...H..L.....!....8.f.=..GtF.QK..........(..i.......WXv.... y.....s..~.....#.L.T.A..n.-.&.b9}.....<.%.<.F.d.DN_...AX..uY..P.l...HX..n..6VJ...d3~..*.%.....I.NJDXC...-....-....q......:...X7.J..]..s....D.\..."t..;.GZz:eB.T...i...qBB.$).".h.<#..)..u.....r|...Aa&.f.....J...."...E.,.;[}.....&WH..O..>o..{.p...m..Q..I=E.......hK+..y.cu^.K..)s..7>(s....zV.._+.dw...||..r.......|9=....z(z......2._F.z. /,Z}q......].1?v.4C....e..A!.A.+...3A5....b......cs......^..o....,......w.W\,.l..c1...W..>..\.E5.T``..W(..z.A.l..a......O.V...d'...B.^]../<c.7.......,..>....4j.W..D.....?...........qX4.n*.KI..4..L..g._..E..*>..|O....?XtZ.jx*.x4h..W....5..m2...lG....(.....s..w__...>..j..&2.%..!.r,.....[}.\Sp0.. ....A..B.g...]'......-...V<E`.j..Lhp./.n...G}t...u.V...I..=......VQ.._..Y....U.....t46....f...AO....eY8.......z.Y.A.l.EG.5...-...qc..Q?W.,.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1284
                                    Entropy (8bit):7.786659025253531
                                    Encrypted:false
                                    SSDEEP:24:HagCKQbywLcv9LKPL2+HfTDNwygg6vnRvztUOXEDvfmWZbMSo:6gwbjC9LQ19inRvz8DvzVo
                                    MD5:51F47D579CEE5735CFDEDD2197F8E56D
                                    SHA1:ADD0C8B4F0BEAFB130D473EC1AC3E888A0DA5086
                                    SHA-256:228FE9ACC3D899777AC7EEEFF13ED50FC258A52AC798B0FA055FEA82189B42F1
                                    SHA-512:3FFF99FECAA8E81AC7E647A3B6F701CA22C1DF5BCF6AA39A0CB78D1E5CA53B625357AC99E87AF382AE3343EFC2ED5703BB0D83D70ECC96642DAD6AC4AF5C75D7
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...L.g..K{.ki......B....-.H. .h2..ns... J....BB..N...2c.,.-Y\.F...&......_..XL..N#.w..G...x.'.{...>..<.S.%.5(.F.....U......<.5.(.C>.!Y...|..gg+0.........@|.\......V..A..6&....b.2.J.3.G}...q..k.{...<...<3...........Ulk.....Q...`>........^..GU5....yA.:B..:n.a..`..\...q...a.hp.hL...g..X...o.......Ff...>.b..}h.l....V.q.e.XG.U2....?..M1.9..k...1..].+/..&..}.....,tDx..].$/pT,..Q".kD<.>...x.]...%.......L.@.4.....rR.!SO|B ...N...Js.."a.vS..yEr...Ow.g.N......r$..'+ISG........z...*<.... ...idB.3........N..E..]m..r.l..5u....i$1I...../..wz.y.....HFz...0K.~.V.e43Sd....o...e.rz...`sC.V.P..w.....h...B.I....`..?@..'....4.....x.......iih...7.u.0C_Y'.j.....S..D..e..eXUWA..+.^..NJ.S..c._..{.tc...G.v......V...#/...o..l.2..7....j.."..R.n..d&.....]...k..'w.O.6D).....e.......x..]...Z....z..$.-....vN_Z...:.sV.R..J^=.<..4.$..sv...\.5@..N...Z.......%..Q.k.k..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1098
                                    Entropy (8bit):7.772443665706941
                                    Encrypted:false
                                    SSDEEP:24:HawtzF/OGdnbikPCI1+124fGECIsBADkdcl8jd1:6KmIbikPF1+g4fsbBklsd1
                                    MD5:D6B00FACABEFE77D2FE0FCA8A9226840
                                    SHA1:C852AC78C44992BF1CB42D10E3CF223ED5D51A52
                                    SHA-256:0EEB87EF373498763D9441590C44A8C6F8F27B930DE1306E98707933D569F71D
                                    SHA-512:A5DBAC5E653D8C4560B9B3A5BB0BF3237158D0411298987C15E422799910874893C6FF32E3BD79FB22A09C9DDDD86AF20906B323AA4DF24C1BA7DC38F64AE0D0
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UmL.W.~y?..hq.h]E..t..K...~P.q...EQ.e.,.(..LD@e...`..l.....).`...`..-[.~.g.~-q~%....f&,b.Nw.'99...9.....a........DY.j$...w........a.....Y$.'.D@.=.4,.-C..!.kQH..@.@.qi..O6b......SN....d*./C@|...........E.C.7G.:.]"yv......%.)!...4k@...A.M.........3...).| ...3..(.u.(.A.V.+i..4VA.:...V.i....>2f$.+....b..t9q.e..G.C...,....zi.e...X.cX.=..lP./....p.P1..w>..@.....I...QL......4.h.a.N.9o.B[z..........:$i..)S.. .3.o...K.....|.Y.q`..xG.....dIa2..5R.. ...0M..m....K......$n.Q`..B.u.......fKJH./.D5G.d.gZ.K.......S.."7.D.n..E..&..o?W....z.;.lCQH. .u.;-C%.<..)3.s.{D....2...L.w..~.CW...x...d...X?_K..V.iY.6....@FA.5zv...UI).?..>...].cC.+....:....\.[...Z.{.)9^Y.8P.....V.Mzv....x..n......}....j->z......M...!m.....E...."._2.~..+.X$...U-..].+...U......B....kk.8.!..o...../..t..&..%.....V{..q.:....3.h...|.A..r"....T{,.y..W.zD...I.....y....#B;..Q...T...'.....\..$...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1252
                                    Entropy (8bit):7.797631294703633
                                    Encrypted:false
                                    SSDEEP:24:Ha+41Hry8Df6RaR/VNZoOXRDqtsFDhBhFvX8bsR2djc:6+oHrN76aPDhDqiDvMQ8a
                                    MD5:7ED8090B348BC71066281C049A319B37
                                    SHA1:C9BF4BCA33330374B538A6306A558FE32C265036
                                    SHA-256:6275484907BD978EDD03A23844B0EDB6D5303F2CFF1C0C24836DFB04E7DB0A54
                                    SHA-512:228331AA94C9CAEBEBBD338E5A7A7596CA3BC630772D28A01962F0E5D623BB80DB24A637BFFB8FE8AF11E8F7F8AF4F8777A5E52C87955CFBCC16347F0849A9D7
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....qIDATH.UyL.g...fgwgYv...EnX.K..^Z....T..r.@...H5h9lZZ.5i.1^..=hK4.....c..5m...* {...M5....%.d2...}....F$z.<..:..])...H.c.n;B...V`].....|1V..x<..FR .&........,ua~........K_u8m..u^....O..r....H,....@...%kZ.. ....#].........|0t..On.*....A.R.5-].),.Rx.......#.......x..@t...;D9G.b..gzC..C..">...\.V2.N..t1.J{b.r(...7.A..+.oaH).k.>...S...VNxN-.T..j.N.....G."....H.E+H..7..D.<]......1nP~d.ZM~...j.R@...6._.d7_..^....!.e..B-I..-,...........S.B>%x....y......w.DN..E.0...(~.Lg)......Y.....9..+.Eu`L...q.#"...S.."S2......\....c....v.....;....|.Oo.r....Y+..a.'.O$.q0.<..vTm..W]g$...(u(.(i.....M.M!.7e...K...^`<...o&......o..f.0.P^]....+B.TWR....C]G.j+^.8Re>0......t..^a....gU.Z.[t....'S....=...=$2.ve[....f.....<D...p....o.`t..z....l.M..xJ..^?..r]g....N~bf.1....@..9..88^..6..Aq..1....\......N..W.:..:Pk...~'A...jo..{.%.3.c....N:.I...c...$(U..&..|.l....=.[mg.....;
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):803
                                    Entropy (8bit):7.541297801337646
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZt75gzLjhowZacw+swEvaTGzHv1GqBxh5wkRUlt3vqf8jHvMH0mHVpVX6l:HatQRowZacw+BEvyMHsofw33vxzmt6l
                                    MD5:BE99344A6E4022C2C02569EB3A9612E7
                                    SHA1:FB83938C60E503A943D936AD64B278FF8798C068
                                    SHA-256:E3E9DBF01E6BCCFFD8F49F1F32938DE5EA6AF40035FFF8BBB46704FAB4BCAA66
                                    SHA-512:E77E1CDA7870551E855200CA71ED6B0BA7B68C04E4E3FFC942194520C1B5F30515084326D5D357EA24E97D1EB1DB35A5F1EA8E4A8E9AD803A7997701C4052D7C
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..\..w.v....Z.......\.........M..G.9..n.{M./... ...~ }...8..A........n.O.}.C.(....zN...>.N....$...;[....O...js.~...; ...[.=....>H...Sn.CC......8.]<.v.\..;..b3oj.c..;] ..3.Ib..1..0xd`b..n[.5L..C....:...>..m...0.......UW....n/F..E..}C.... ...aq.. .I...f.!....<..3 V.q"...b!<....= ......../.bA....j<p...! ...~..@.K..*P...I....|..%.#....C*...1'....gh.M....../P...G(}...U....+.e.q.W..4... @L..G3\UR...gd.5..X...K.1...zz..ee.@..........1xaT....`...&..g..n..9.T[{.....AssUR.....T_....bX.ZU.......gg......e....5....BKu.>... .Xp..T....@....A.o....\[{.X.&....YQ1.#..feE.${...ab.8.....)1.........?......@^[..l.........]TTK..@....c...(..."..QcceP...f.!.AA.T....01._(..H.@.....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):243
                                    Entropy (8bit):6.422869898567927
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKchkVCpGQFHoshpMw7xRP2i0DslHJ1gbp:6v/7saZhkopGU/r7P+ig1
                                    MD5:059D91E46C3142D8E4C9271DE40CE144
                                    SHA1:3CBB3BF701A4A23378E91B8EB30A40080AF103B9
                                    SHA-256:561EE41BFE3339532A4B14BB1C0F4379B37051394ED246CDD504AC0ABA79408C
                                    SHA-512:E84780791E954CCF4C32E1BAE27CAF28FA537D5A09D13C32E680498A425F40EAA56727767ABE6B80EE577C91E16416F9DCDC1CC1218F565DB3F2651657F9289D
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf........C4....I.j..........~......J.5.}......i.}0.-..".-...#9Ir....n.n......j....>..F....V.Q.........F&f..2P=...dA...I.c....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):854
                                    Entropy (8bit):7.529945105993399
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZhJBp/xSl1hCH0l2XJJIpmGN4zjLfX+zQ3YhvzLDiCMDRiKNienICJj5vx:Hav2lrr2Z6ojLX+NVMQOJj1Lrd
                                    MD5:0D8C6D90A8ACF1655E213E7CDC31C25E
                                    SHA1:B475D9CBEE9264DEE63F3A8F72B595F3B537EF10
                                    SHA-256:66D789CF6D1CCE8AEA7E6FC1F35129995529C0F6EC4CAE9C6BB1D4B1560AABDA
                                    SHA-512:AE70E98C52DD7ACFF11AE2D8093F31D71AC92F2922E3592B1C04875B9C7653555D62E5DD9DC22264CE0792999AAA05A584A4F9AAA2DEA82D5C745E7999DDE0EF
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```x..... u.x.q.....p,.....p.d..-..?....{..s....y..x ,(......A9!...........c...p.'.....V..@....cA$..\....3s..fa.p..=..8..9y?6.Y88\.e...Y.g.......PX...../...'...G..MJ.... .pP........57.....s.HY..3)X._.<.-..W.P|&....UL,,...2..>......t.(>.XK.9.%...7.X..`....$..L..gb........':x.....M|....0......G.............q5q..-ffa;....I .GS....8MbffN.R*h.@\....&@.....H.qD.x*..P`da=.' .'..=.....j.#....%0.....p....MV>.XX>..|.bq....'...%".....7..&..s..^....K.|..\[T.S~.O.._.5..+.p.V.@....*.&.._DJ.&...u`.....v....._X...+;W6P<... .A.......e.gc.@X\..52...p.....B.......G.&.pP....|P.Ob...V.L{.2\.-.....%\qm...q...^...f6...q....".m..d..../V.nxP...es.._......8...@...`....&..$5...'8..f..q.2.a....M.8.$.....F........o.bM.dI....$.......nQ....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):461
                                    Entropy (8bit):7.037071167502854
                                    Encrypted:false
                                    SSDEEP:12:6v/7saZ++irj8c5pxpHiLep0N8Gdg7R2SCYbDsAq7:Haw+irj8c5pniLa0z+CaO7
                                    MD5:C48DBDD7111FC6370C99D9AF1DB5CA25
                                    SHA1:94134E54328EB50BE24BA53005D0608D47C4A324
                                    SHA-256:89267EFF928357F51A583A794AAFD9928D8E3B87376E0804ADF933CD1B794016
                                    SHA-512:69BDB9963CCC2CD3ED55079A39F40B40EA8555E1A32AF0DDAFECDB9903F1222B9396B6F5C5909CFA399E956B79509892E348F4645DF8D827B0F2496C9D404254
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....ZIDATH.c`........~...> .....8..].x*..4.P.Z.@......3.83....'@.M..JPW.." ...qX..._ n!.Lq ...j N...0\...&..3...@..p. >........h..-`..~./..q,.3..Y..i.1..n.....Y..?..'T.....e..7.H.$6..?.1;5,..F ....=@...{HIa.,.....IM.,...Z.....ld\O@o0.d.e2FR-!dx......@....I.I=.>.....k..W....@E|..]..?...)....K...T .!..Jh.x..mPv3...v...tW.u.e ^Hm.$.x......P>...~.F.S......IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):456
                                    Entropy (8bit):7.173747785075021
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKcwiOV4ZJp4EB4+ocdX4uwqowGUtnrNoZyrNlBpssBnDO5ckcM9s:6v/7saZwbiMC4oTwqJLNeknDO5cunpiB
                                    MD5:BCA6E8F983FDC2FB7B423CB3167DAD11
                                    SHA1:F240604385ACA89AD08B7CF9C5576C7708627E15
                                    SHA-256:7F51D062663848D2D1F8556481878CFE38A27452166589524CAFEB35D7CFECD3
                                    SHA-512:4CBC2535E117BC137264A90A30A683E2262BF99632ED35036BF799020E6FEAB942B91C5C209B75C99F91C20AE75A89E6ACEBD9B7DD71AE9527899982D9FE8E86
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....UIDATH.c`..0..+.s1...... ....8....e.......@<..oB-;I..9...._.b.$...%F.....[..;..4yA ...:8.....fA..-....@...m74o.@...1.....U.....%....h.N...h.'6o.C-h@..h.."..B-M...C1......DJ.Z@.....2,..J...4}.|..j...,..f.%@\...h..[@..Z...#.......C.>(s2Rj.....Bp9....BJ|R.E....A.3...9....../.b......L...P.V..\....:(.A.9..A..@...m>......x!.-...}...~(......... ....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):421
                                    Entropy (8bit):7.186986765554187
                                    Encrypted:false
                                    SSDEEP:6:6v/lhPZi+aWdKc5JE3T8oD5wFlJkUSQWp2EAQy18AHBNOU0Q2YTeGe1seKFAkp:6v/7saZo3ihkUSkEixBNOU0qS5seQn
                                    MD5:4F9496046D0CD092D3150913D3A170F8
                                    SHA1:E4FD54ED05E62A1961406965CD9FA2C7220399C4
                                    SHA-256:D2ABC6484210C8815F083EE84070EC040DB227D166984ECD3938B4B7AD6ABCB5
                                    SHA-512:73E98EC3C1D11A9FC1BD90CD097CA88E52F5A4F28471A573C7673F6A78DD6DC226E538E762B82D6DE3450FD151B34155CA1FE7055C2311640804BE235446FE32
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....2IDATH.....@..79K..i...]..@...@.....M..vZ_....`.3.\.De.b..Y......z..~.R0E\...?.'.....z_..p..w.s..b.4..8..(.f...X I.......k........i....y.Aq..i.!... .".t].@x...4MCk./... ..Q..a...,.s.,....... .!V=(....0...=...|lv...>...".m...y...^.......M.....0./.}r.....X.$>..H}b.0..@..+..'.=..HF...Kt.b.Zc....-....*..l*....IEND.B`.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1116
                                    Entropy (8bit):7.754627554128948
                                    Encrypted:false
                                    SSDEEP:24:Ha29ycw0TbJM+kWDJRM1YZdIHVH2+U6AmR5GtIF15cejUEsPtTR:62k0TS+koRoYZdIHVWS6I150EsPtR
                                    MD5:AF8F5AFB51E4EE017CB1C342DDC80F4B
                                    SHA1:D8166710C0D5D9AE23D35A7CD07A0B1CADE2A255
                                    SHA-256:42FE2B2847B16DD2F8DCC4DC4A69C77B7BCC13E004B1BF737FB5FED40DAE4EE7
                                    SHA-512:37673D0F4CC6C2CF3145B5108C2E9DFDA16703BEC022F05F5B897039F06DBE76753686BDA02DB986324D8AC7D6A982CEEBB254C71F61B1ECC1B24F0F0007639F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q...jS.....i]h...)bP&...mn...........e.2.n....eYVP~.*D4.Z_.bTP..........l.u[{...xx.s.s..s..9.+..eS*...."N.V.)//...G+((..R....}ii)........p.^~~....B.hO...P.Vk...G.n........O.vw/.;@....O..///.kkk...hPS......l...7.>.......P.G.!..R...'.x.v.:.X.^........8.x.I..r...&.V<''g.........Q..2Q.......j..h. h./...+%%%....N7..y.....r.1...y8...x.aW....bf.pQK.Y.J.c.-L.dG......8.d.jg5..wb_,.........]55>.s....y.w...x._...!.O....4....kpq..n.....0"`..l...x.....b.............[.....FO1b....q...*...!A...l..........;...7....s._..Bi.....M. ;O55.G...bW0...d#...c.........$....Xg..d......w.....x..9h.Z....S-!..?f....F..X,..e..|,X.~3Z.z.n....u...)m....J...h,:::.....i..04<.....R...).A.-@..g..{zV.Z].PH}}.|.<.+.?...A?..X.a.\r...ef.J.$..2.nCK.C...;...#.,.X..!n,.d.].\....=w.VW7.im.....n...W.Lv..&..-H....+/...I.=.I....%55../.w*...'...........D.sg......t....G.|)...4...Zv.?..?fXX..**.`ttt
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1105
                                    Entropy (8bit):7.709561833557226
                                    Encrypted:false
                                    SSDEEP:24:HaGRSu6+CJjcWzXg0eWdqh9kQZ3TQbzbveF58fz:6iNWJYWTgUEh7tQbneFOz
                                    MD5:B6E1E5D06089AACAE7AB12C6448E9731
                                    SHA1:7A81C81C63C0C06ABA0B08292326EFFD0EBA4B0D
                                    SHA-256:5D565B1058E38726209CC254C75A00EA7545008FC1EF6F2571038F82E1601A56
                                    SHA-512:1B462B02EF50F92D68004EAD43CEFB324BAFCE946836E32653173E2813ADB216F303139E6A4223BBE6A9DB94927BA1D69CC8875E05CCF4C7CEFAAD691E1558E7
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q..m...2E)BZ..E.].1(.T..67o}.Fv..>4......%A..e...........TP....M..|...;.zu..........;..y.YP....^....b.F.....?......l0....}qq1.......{q.Nnn........=.wkAq..h.j.....6x.......n....=....0.w999I..\YY.B;.1`{.N....py...0....^v|..;.....!.o.p....k.>..^./H.-.d..^7..=..*wvvv./...f#..8xH.1N..>.:t....,...d2=F..a.X.KEEEB....B...C.`V.9..s..<....P.*%%%.;.Uw..x....,"qG?....N.H....%@.....o.9......wm6.r....O..;F.....([...e@.:qnT..S3..........-R..<.;..8..U..zs+....(.x.1.e.x...........i..Ew.o....f....(.......-......".]..&...-.5...A..........cuu .@....I^d.o.la...6E..uzzz..3..p.Y.mS..6E....l6C\\.....*.2.mbGjk..A........*.n......t.6..]...x...j.....A................E..h.D.U'...h]..-Y@.........p....~.>.([)`.Z....L... ..8.j..nk[.Xo....$.0m.[...u.vWU...M..z.n4....g..l%.M...U.......C3Sp.......%...W........mx......?!dddt..._V..f\;IQ<fID..3..Q.c.DaJ.;.....30........QQQ5(....R..5.E.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1093
                                    Entropy (8bit):7.743931751177379
                                    Encrypted:false
                                    SSDEEP:24:HaRV0uZNXr+iyPuiie4Lz9BjfkTCDbOtGlA+gdR3hSY+vQ/GW3N08wE3IS:6RV0aN7+iFNe6zfoTCDbOtGlAHhGvQ/p
                                    MD5:AACA2345FBB42680C297C9D82E1564D9
                                    SHA1:13CE3194A9E4613F402C082AA19171CA0027A985
                                    SHA-256:7590CB06896645C94929873166C2F9E6B33C6F7ED6721B28AF13EA7CCBD9AB78
                                    SHA-512:1EB11C63BFD7E5873BCEDFAA5CEBACD3AAD2578047B3779E96C8836E20D7D01C2751658D9BE9774695B1FD5DF6542C484078B4A7D9DD278D2281A91C9E38F36F
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UkHSq._....)J".z.,2.R.LR....|.E...Y...=\e..(..(.aYB.!....k}.M.......N...{:g....kO....{..w.....d.i..&@.VG.t.9EEE~......YZ...^....@aa! 8....deem.......I....m:...=x.nw....p..S....{.......fff..1rUU...8..;.v..?.....W........e...i....M.~.B#...0..8.:..........Q*GFFF./.....!.....O.D.n.H..PF.*............h...+....W.......At.q.X.(...n..`..R%&&..d..O....cF@.[E.VQ5,.......<6..c.R./'.....K ...|.aEv..]TE.f@..0f.....'../_....U..t<.Q...h..<..7"....^..K .*~G ..zk.h.Z...z.....%2.....D.0....d..{.c1../.Z..H.DFF..&.......X..f..,6j.g..=.....'%%.%...))).x....db.2.j...!`...i7......2....._..L...:.L.f.....z..A......=...S2..=..Vq....Q.\.....#..j.}.k.p...WHN.....pz.}W.jXkL.".......$....u.>.+^.a.*.....I....2.z...Sg2.n%..x~yr..$q.q.....Z.........sP\...$....T*...x.C..1.Q.......|....,MHH..M.......KMM..nV(.......X.T..l...}.8nv..;4..v'=...........?$$..AKq..5..#..)a.i[.G.Y..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):1087
                                    Entropy (8bit):7.726447155721982
                                    Encrypted:false
                                    SSDEEP:24:HayqeZgfR3ldEeM+mN5/2RrWQO003w2+B+p9FTohkYBb:6vX1EeZi5/2RSQDQw2+sF0hrb
                                    MD5:0B7D9D952ABA12E25F7ABF2D5F744AE5
                                    SHA1:86FAE6CA765B86879591145A489DADEE8E461553
                                    SHA-256:6AB24D436C46A02C560C96280DD7292CC02754E7BEB1BC4E1F455C819AEBC92C
                                    SHA-512:1C1538A60FE63DC4155315A4B1818C9CCA9186B2A17C46AC673C9414401AEB382635645C63692558FF72E8188ECA59F7DCC7D6DF62F1D1E619C508021AEE5DA8
                                    Malicious:false
                                    Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UkHTA..6%.LQ....V#...(.I*.cw....mI....Gk....V.I.IE....BD#..OO.."{#=twu...s:.;.....8.3s...9W"..R...Je.F.YX\\./.....3_.V......B(**....;p.nvv........=...#8..h..c.p...O.......VW...:L....#z.........R....**..w.... `s..s..]{...*..x$r.C.?"....~.b.X..Fln..6...lh....'.Je.....<##c)...un/)..0#.2P..'.o.Q....V.....K.I.\PP...,??.2......d....]..Q.K.....5.n.;..C0...H..V.|.9.....Lx..I.O...3..!.@ ...LhC.{..H.#-.W...@.i>......z...<qEA?...g.Hp......y\.....zJ.....F.;.a..ov.J.v..Azz.K"...[&.@&3..du..9....J..$J...5..l?...<%.D.l.K....u..}J.{..$''.E.p.RSS{......L.%.,..G}.A..Att..b..Hq3.e"'...2...}'<Q..o..(...<~D.p.2.C.:.`.<.E[[.L.R...J008...T.V.....#ZAtD"..3+G.w......$..5.....2.....KJy.C.P4!.\.}.#..Wm:..f.I.......O.S..E.'.cr....^...p......%%..:...\..c.....$.......x.(6....AAA....z..~.`...........sE&....<Q....e[...].h.Z.......e...1....!!!GBCCk.t;...`gD.:m.b..]..a...R./_
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
                                    Category:dropped
                                    Size (bytes):2238
                                    Entropy (8bit):2.6372815917381076
                                    Encrypted:false
                                    SSDEEP:24:suFS+FEi9JJiebtmD1yBjyMiUgoKsDZ07A97uEM/ArhVL7KFuqd5+75myJdfyE/k:m+Kioebt81MJ7p97u1/YHeFldgbjk
                                    MD5:9AA3B592D6B0B33DADF80E8EDC7A3CE1
                                    SHA1:16783BB3C7FCAAA86341C87527431E91CCE01023
                                    SHA-256:4BEBB406645096C3B6EA129F6234C6D4B3B590ED0626C9D56742CE1132618ED4
                                    SHA-512:D74130AE644EBC4599F460B1F8AA5385693F2B1F873B037E82171C3A43BD18B9B9F949BC60254808A66A63FC104F3899FC437A88A109E04E54D2BBFFACCB51E2
                                    Malicious:false
                                    Preview:...... ..............(... ...@.................................f.3....3..33......3f...3..33......3f...f..3....3...f..3.......33...........3f.....3...3.f.3....f........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PNG image data, 450 x 240, 8-bit/color RGBA, non-interlaced
                                    Category:dropped
                                    Size (bytes):87939
                                    Entropy (8bit):7.990756543245148
                                    Encrypted:true
                                    SSDEEP:1536:ts2l5YP6E32hEXBTl2AD+9v070pXZ55mSW8HPYDf4E7vpzONQkrSZ8k0Ah6GfAh9:ts2sPYOdl2Dv070PrZYDfnzOzSZ/0AkD
                                    MD5:B5A476E63CA7C607BCC975181ACAD3F7
                                    SHA1:5E1D6AC9973D67C55F92881A0FFFD957F5FFA614
                                    SHA-256:D625A953C7B79C59D139BBED4BFA9B341EC6C24C9DC55D58AD05987735A1F9C9
                                    SHA-512:8E7B0BD0365CC9C9A215D274A27031777CA8963243F3A23C62D310ACF11DB9F1C867240002EDFF6E7A5C923FDFF4B1DEF3FC11DDC9903235DDC585A1CC79D479
                                    Malicious:false
                                    Preview:.PNG........IHDR...............dW....sBIT....|.d.....pHYs..........+......tEXtSoftware.www.inkscape.org..<... .IDATx..y..eu?....]sso..I...] l.....J.h...W.....Z.m.j..E-.m..Z.......b .AvA.....Mr.....s..|.......zA....>.Y..|>3.E3{)......B.$r........,.W.o,.......v....q_.u.....8....cUEp.,.^<u0~-.2?u..xj;.G<...4V....p1.."...g.).g...s..}...:J...S..e.Y..y..TO.&_.....\..<(.#.c..AP..11.....1.p,._....v....k.@...A4....'/.Sw.d.u..R.N_.LJ];..........d.0.(..W.9N.c.\Pp.J...R?..T...;#.........k...N...N.q......y'.k.:x..\.*..5'..kN..8...p..p .4..R....... a&[g.-.G*.1..h...ao.8.WV...X....C..}...c.).....M...A.md.T.]q...se..b....7.a...5..p3.A..ie6N...0....t|sqxp;..8.8<.....u..<...8B.i...d.v.T..1...Kqxp7A.."A.8<x...w..|c...v..\s~{~.dcb.y8..".f.o.c.....b....>.~5..]kjL!.~.."c.II.j...7.N*+bK...YXg.!.....-..Q..U!I|\.Bh.Z.Z....n'H...A#\...\.O.1..k.gV.z...[..IO.d,Z..V.B.)H.m...Z.K.:...xk.M.....I.cZ.....gq.X.0C_;.z...N(...._UhV..*g.e...*..Q.....v2..uB..F'......R...UP[.....
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:XML 1.0 document, ASCII text
                                    Category:dropped
                                    Size (bytes):2552
                                    Entropy (8bit):4.639660685199659
                                    Encrypted:false
                                    SSDEEP:24:2d6RzXXSs4E0xZXgie0eKeVegevXgD5v0rl3r2FrrQ9ppssWJ/lB+Rg4FpEp00rQ:cozXXpJaZXsv90DvXG1M2TU6+
                                    MD5:5BB26A0E36CA2126C373A0A106369AE0
                                    SHA1:8BEC490C77FCE71D9785417E10E80B2C6042CD26
                                    SHA-256:9368E5566516F00A49FD62B4159FC431226503F4B178A1A0DC10C5DCCC52DA77
                                    SHA-512:66C0F1C897467CC2D7065E489F8F0F43B7DBDE8738DD6BFE8DDB9B9D1AD0CE6F2182E44EBAACEB3934CC3AC243C4FAABC0D869AA784DB0EB055E3A73A0D0D0A9
                                    Malicious:false
                                    Preview:<?xml version="1.0" encoding="utf-8"?>.<toolbox width='5'>. <group id='view' title='View' translatable='true'>. <item type='builtin' function='zoom_in'/>. <item type='builtin' function='zoom_1_1'/>. <item type='builtin' function='zoom_out'/>. <item type='builtin' function='display_3d'/>. </group>. <group id='proc' title='Data Process' translatable='true'>. <item type='proc' function='fix_zero'/>. <item type='proc' function='scale'/>. <item type='proc' function='calibrate'/>. <item type='proc' function='arithmetic'/>. <item type='proc' function='level'/>. <item type='proc' function='facet-level'/>. <item type='proc' function='align_rows'/>. <item type='proc' function='scars_remove'/>. <item type='proc' function='grain_mark'/>. <item type='proc' function='grain_wshed'/>. <item type='proc' function='grain_filter'/>. <item type='proc' function='grain_dist'/>. <item type='proc' function='shade'/>. <item type='proc' function='polylevel
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):13988
                                    Entropy (8bit):4.470050759523897
                                    Encrypted:false
                                    SSDEEP:192:amKqRIbyUjLD5YwPpYfge9Y+JWv0p+mAdYnnXuYFIHtcB4:amKqaj/CwiYxv02
                                    MD5:5A0F02767724BCC01946D99DA9EAB646
                                    SHA1:A3BDCC4DB28F4FCA0F435559167BBDE18AF20361
                                    SHA-256:38ED976B0425B62DAD0C82A8C8DFAB2A582F29070ADF93FA8338AA3F537C92A5
                                    SHA-512:1C3618BE569FE3A626B40CC277273E27D1380CEC8BD9E4F1BDFB5F5C6C52149A66FC51A51F41E040140EF1FFC67EC9D336CBF2DE5CC1EFF5B38B62D6628A1A09
                                    Malicious:false
                                    Preview:# vim: set ts=30 :.accurexii-txt.managing-files.acf2d.statistical-analysis.acf2d.afmw-spec.managing-files.aistfile.managing-files.alicona.managing-files.ambfile.managing-files.ambprofile.managing-files.anasys_xml.managing-files.andorsif.managing-files.anfatec.managing-files.angle_dist.statistical-analysis.angle-distribution.anneal_synth.synthetic.annealing-synthesis.apedaxfile.managing-files.apefile.managing-files.arc-revolve.leveling-and-background.revolve-arc.ardf.managing-files.arithmetic.multidata.data-arithmetic.asciiexport.managing-files.asdfile.managing-files.assing-afm.managing-files.attocube.managing-files.axis.selections.basicops.basic-operations.bcrfile.managing-files.bdep_synth.synthetic.ballistic-synthesis.binning.basic-operations.binning.blockstep.scan-line-defects.line-correction-block.burleigh_bii.managing-files.burleigh_exp.managing-files.burleigh.managing-files.calcoefs_load.caldata.calcoefs_new.caldata.calcoefs_simple.caldata.calcoefs_view.caldata.calibrate.basic-ope
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Zp\305\231\303\255stupn\304\233n\303\275 popis'
                                    Category:dropped
                                    Size (bytes):10628
                                    Entropy (8bit):5.1324791193575825
                                    Encrypted:false
                                    SSDEEP:192:S5ewTiwExfniJqBURCySjGHzKYDYwlzPsqAky+RwybKz92sjSpw:SYwWhxfnigBURCzj8hpKZR+w
                                    MD5:2C6B374EC95CC962BB39DC1545BA8426
                                    SHA1:4168E6BEFCEE4ECCB5EC7AD3C765C21E68F5FC62
                                    SHA-256:4CE0C6D761953B04122024716D02C7B00885012CBCDBF8A084C835F8E3FE83D2
                                    SHA-512:B15C4BCCB451590218185CC36FCB2B5D2B65C3EB3A24A739F111CC159EAC17AF86AAA784807E0044DC194631BD436B2751CA597B86D62083D351C5BB0E7C4765
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf 'Ukazatel na pixelov\303\241 data obr\303\241zku pixbuf'
                                    Category:dropped
                                    Size (bytes):23987
                                    Entropy (8bit):5.377577782299227
                                    Encrypted:false
                                    SSDEEP:384:yapCPnVIL/jFtcWDx8c0MYAqvch8Y0uOxWhY4tWfOGgKm5VBhH+:yapCPu/cWDx8JpgBWgy4gfdkBg
                                    MD5:0FED09B38B369C55651BB895CC3A351C
                                    SHA1:38D163D1F0745AA15F9AA88A5094A90218F5DFB8
                                    SHA-256:F77427FE1F4474DC79728D8DA3F001F41AA74A75A94E51092B627E8AAE608C84
                                    SHA-512:9AFEC2B667DE55D5880E43BAE6D9F53570D7712A0497012B6D3318631C941AB3CF95B80EE3D4225C11DFE4F1F27B1A4B91BFD31AA8742A9A82413FB59558AABC
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 29 messages, Project-Id-Version: gettext-runtime 0.19.4.73 ' -V, --version vypsat informace o verzi a skon\304\215it'
                                    Category:dropped
                                    Size (bytes):5814
                                    Entropy (8bit):5.556195007588839
                                    Encrypted:false
                                    SSDEEP:96:qU1+HPMJ3Hlivn7vn8CJ6vOXt4Akhb2gZRmYM+qLYM+q2wttm4uIHJ9zkpeM0c:qw+PMJ3Hli/7/avOdFkgkPM+rM+qfHDs
                                    MD5:DAFB13FD043ED5F0EA6927404456317F
                                    SHA1:D3BDC902CF01068DD7FD5453C4E39EF2BA2ED8FF
                                    SHA-256:E8B370809C930C64B4AC2BAD96CC10D59F2EBE82AF9BB370B6EA7400C6230B75
                                    SHA-512:9FB759681486DBC2F3C8981B3A700A0804565F4626BF2C66E674B766C0CFC1091F58881549AA918A49CA02EEA9B2ED0AB2708FAB26F9AFCA3597390A2ADC6E8D
                                    Malicious:false
                                    Preview:....................)...............B.......9.......M...........\...(...x...........e.......:...........O.......i.......H...................1.......&...3.......Z.......i..."...~...9.......I...........%.......................................................1.......=...B.......B...b...T.......&......./...!.......Q...^...^...8...............................................*.......7...........J.......Y.......u...V.......k...........g.......).......5.......Q.......e.......v........................................................................................................................................................................................ -V, --version output version information and exit.. -h, --help display this help and exit.. -v, --variables output the variables occurring in SHELL-FORMAT..%s: invalid option -- '%c'..%s: option requires an argument -- '%c'..Bruno Haible.Display native language translation of a textual message w
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 56 messages, Project-Id-Version: GNU gettext 0.10.38 ' dokon\350eno.'
                                    Category:dropped
                                    Size (bytes):6377
                                    Entropy (8bit):5.225263173206567
                                    Encrypted:false
                                    SSDEEP:96:eCnC6P5EIGfjJBHa0//xDZ+Lzr3ftK3cSXaonzpjlEDEhztJD4G5:eoPbGfjJBHaWJDZ+DPtKZaozVp82
                                    MD5:9B83CA58A6C1142363A9AFE916414E9A
                                    SHA1:DC0FCE7954412BC7D85863DBC99F7E54AC56C76A
                                    SHA-256:ED7D2BC6269EB185D68AA6CD215CA50A12523A24D3D8F380A2F1BCD63B7775F5
                                    SHA-512:55C12A9F70631F1A47D0D0E26F8559D6F91A6B0FD14A63CD03C6B93D16514E5B02F4F887BD94386332BEA01FAC29B1E9093EC2BBABE29CFC92CA36E8C139A263
                                    Malicious:false
                                    Preview:........8...........O.......................,....... .......3.../.../...c...+.......T...............4...C...?...x...!...............c.......X...F...].......O.......'...M.......u...R.......................$...........%...*...D...;...o...........................$.......$...!.......F......._.......}...........".......#.......*.......5...=.......s...............................................................).......8...+...H...*...t...'.......................!.......1...........H.......@...<...M...........8......./...............c...?...B.......H.......C.../.......s...........v.......V.......d...t..._.......(...9.......b...X...m...................).......#.......0...7...L...h...........................*.......*...:.......e... ...z...(.......4.......".......$.......N...A.../.........................................../.......?.......Y.......w...................0.......2.......0...........L.......c...$...}...F...........5.../...................,...........$... ...&...*...............".......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' P\305\230\303\215KAZ (Voliteln\303\275) p\305\231\303\255kaz, kter\303\275 m\303\241 b\303\275t pops\303\241n'
                                    Category:dropped
                                    Size (bytes):123325
                                    Entropy (8bit):5.52459012162757
                                    Encrypted:false
                                    SSDEEP:1536:NZwErmJ8XIO6JnLQwF5kg7cRU17DipGQ4B1m1V6SMgOTVROhZCS/oXBwgMxG6tQP:NvW8F2LFF5kg7L17DDJurST62bMfCcc
                                    MD5:F547A2921A74FA0255ABB1006839D972
                                    SHA1:1252F6782F92A496A54DA0B671F57EEE45EA5D32
                                    SHA-256:D393C41609B98B1DAC3D3CFB2D32B81BA0EFEA0FD88D6590AAEA5BFA5FE2F6E3
                                    SHA-512:E991D14014350EBDB3BCE2EF79BFF7510FBE2A3C60925382BF302B12016AC46ED611C0B02EC8C3532FFEA9800E497953F3C2058BA066348E9AC9111590A00072
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+-properties 'GdkImage, kter\303\275 zobrazovat'
                                    Category:dropped
                                    Size (bytes):161754
                                    Entropy (8bit):5.385381014680175
                                    Encrypted:false
                                    SSDEEP:3072:em1YvN/CkL47yS3RH49ljUYPw7sXK7BxaBcxMa/9xWThE:n1WBCkLMysy9ljUYPwI+BxaBcxMa/9xp
                                    MD5:BBE17FBF39F832DC93ACDEE04959277B
                                    SHA1:12D8320CA7B8616247EFAF8E5DE9A4EE1C55A9C5
                                    SHA-256:51BAF6D145362DE46E38DA989154DCF7527178DDEA802AD1BAFCB6A54A28C377
                                    SHA-512:1D640FCED357E6F0794A399B858BA3240FC2B839F1B75A0914C28732304095E67E239F29B864DEB46C54A75C371F9769E359FDAA915D2D5EEF0AC0E32A231C78
                                    Malicious:false
                                    Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 868 messages, Project-Id-Version: gtk+ '"%s" nemohlo b\303\275t p\305\231evedeno na hodnotu typu "%s" atributu "%s"'
                                    Category:dropped
                                    Size (bytes):57280
                                    Entropy (8bit):5.421875086873875
                                    Encrypted:false
                                    SSDEEP:768:gKJHhOe1KPEBjSQ8zCtWG9+06llQ4c4FY834OeSZpqPpEl:gKJHYeYEizC49G4caSUQPpEl
                                    MD5:87D0B5EDC1561695F781A92F210EBD2A
                                    SHA1:961EF34B859060FB4A860CCE54A7368CC1311F2F
                                    SHA-256:AF02CFE1A150A66016EA945190B5A1F5CF1FC8D55AD2FDC0A104DDE4777FCBA0
                                    SHA-512:160D4932617169C6428E003D1DBBDA35E5E97F75BC9F682E2C7E10B3D5EF3FB675126AD036998DA32779198BABBBC5FBA9011029952BB997918A13A41420A23C
                                    Malicious:false
                                    Preview:........d.......<.......\6.......H..F....H.."....H.."....H..,....I......CI......\I......iI......oI......zI.......I.......I.......I.. ....I..7....I..)....I..4...(J..=...]J.......J.......J.......J.......J.......J..'....J..$....K..(....K..)...WK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...%L......VL......bL......nL..9...yL..6....L.......L.. ....L..0....M..5...KM..9....M..8....M..:....M..7.../N..2...gN..4....N..1....N..?....O..1...AO..?...sO.......O.......O.......O.......O.......O.......O..3....P......5P......CP......`P......}P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q.."...=Q..>...`Q.......Q.......Q.......Q.......Q.......Q..V....Q......8R.......R.......R.......R.......R.......R.......S.......S......,S......:S......GS......\S......nS.......S.......S.......S.......S.......S.......S.......S.......S.......T..+....T.......T..!....T..)....T.......U......(U..$...>U......cU..1....U..-....U.......U..!....U.......V.."....V......QV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 550 messages, Project-Id-Version: gtksourceview '.desktop'
                                    Category:dropped
                                    Size (bytes):33875
                                    Entropy (8bit):5.288425965571156
                                    Encrypted:false
                                    SSDEEP:768:siKv2O9y0uEF2KQQCMovYtTmatdpa//xDKf3/7v7NzZvm1yW5BhfhQvH:Z30pF2KQ2ovYtCatraxWfzp5m5BhfhQP
                                    MD5:C8EA11F5EE3DB1083E133CB627834C0C
                                    SHA1:D4C95F9488814F800EB41E096B75445A02C27E9F
                                    SHA-256:534A0D20F71D7940E6B20ACC2B4E0C1D855FC3E68BA904EB163A07FB4F870D99
                                    SHA-512:17ED90C8A977CFCEB6B7B1C2275E87A393FABA55EBB6D6B91578D2B1896836577B5D3700475B8F707215F28662D01B4CBBC1DD10CB2E767B5C4CDF0505D386E5
                                    Malicious:false
                                    Preview:........&.......L.......|".......-.......-.......-.......-..............................&.......*.......5.......I.......O.......S.......Z.......a.......w................................................................/......./......"/......6/......G/......V/......b/......m/......~/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0.......0......%0......30......A0......H0......\0......d0......t0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1.......1......#1......,1..{...51.......1.......1.......1.......1.......1.......1.......1.......1.......2..)....2..&...72......^2......f2......t2......|2.......2.......2.......2.......2..1....2.......2.......3.......3......%3......23......:3......J3......L3......T3......[3../..._3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4....../4......@4......E4......O4......_4......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 4878 messages, Project-Id-Version: Gwyddion ' je svobodn\303\275 software uvoln\304\233n\303\275 pod GNU GPL.'
                                    Category:dropped
                                    Size (bytes):366436
                                    Entropy (8bit):5.632927240863713
                                    Encrypted:false
                                    SSDEEP:6144:CZHUlsFv7BKgBGVvrLDbNu7fdkMBUSTBBSZd6JbGhEkN1u8U9NXAlUj7e:MRJ10vNulNSKahEkN1u8U92lJ
                                    MD5:1B225D190B7C5B17FDFAA2C77AE33D0F
                                    SHA1:385C9DA8B55A3E80E08E84FC54065789FF55F21B
                                    SHA-256:44EBBF7E6C353F05558031188D65FF110F12C6E0B105010A2E81EFEAD6BBDBBD
                                    SHA-512:60E7CF32328593469631F9F0DBDC54A605C7B40F5308C1A2C0C814D9BEC79E621FE21E21B7E719C2CBC03FEA22F41D6841673F7E9B4B864E735E88B009DD7A3D
                                    Malicious:false
                                    Preview:....................y....0..........)..........................,.......H...&...Q...-...x...(..............,............... ...........?...%...X...D...~................. ...... .......$...,...$...Q.......v.......~...........................&......%...........&.......;.......P.......d.......}..........................................$......"...........&...'...B.......j...................!..................................).......F... ...].......~...%.......(.......!......)....... ...4... ...U...#...v... ..........................................).......7.......H.......[.......j...!...|................... ......6.......4.../...4...d...4.......5...... ......."...%.../...H.......x...,.......-......*.......3...-...7...a...'.......%......."..................(...+...G.......s...........%.......$......%......!......."...6...#...Y...%...}...#.......$......#...... ...........1.......I...!...i...................0......*.......*...$...+...O.......{...............................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 1.5.4 'Barrierefreie Beschreibung'
                                    Category:dropped
                                    Size (bytes):10520
                                    Entropy (8bit):4.955538150211772
                                    Encrypted:false
                                    SSDEEP:192:S5ew1rbZBIg5vqBURCySfGIy2VF8mY5RxAxP:SYwNbZWOSBURCzfWqFASxP
                                    MD5:D2FD4CBCDA8036A4525E7217D6A1871B
                                    SHA1:C712CBEAB8390EC36567D434303114CD58029027
                                    SHA-256:D30DF7D8F0B6896A79E65E376F5180530D57CDC89B2BA3F98649D5BD96A9AC55
                                    SHA-512:64DCEC8E43F02A91AC9E061FEE179E40613D3375FC33235CD6EC579F3C8CA488F39C0A65BC7F79A0E894354B919EB5BEAE270C880843DF369EBD1760E7B4828C
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf master 'Zeiger auf die Pixel-Daten eines Pixbuf'
                                    Category:dropped
                                    Size (bytes):23921
                                    Entropy (8bit):5.17443570210766
                                    Encrypted:false
                                    SSDEEP:384:yapCAoFB7jFtcWDx8c0MYAqvch8Y0PoZ0mVgE+p6tLwapDNfl3wvAsihu/KQK7Hq:yapCzlcWDx8JpgBtZkpeLwalN2DGcKbq
                                    MD5:0D2C5D6A6B2C83B3E01267D84A6D4857
                                    SHA1:8FD93A8F660B026EAC1A9897BFA6618A2AFE6038
                                    SHA-256:669BA31E4CB585F5C69E3EBA17A02D4529AFC17AB70A03818EFB49A0430A68A1
                                    SHA-512:C650E404CD23F4BF936C17207887BE9F1DEE461E9CA4EA6813D8425C96FA297A044361649CB1EE4F2F9B539C2353FFCC89290013C96FF21FD6ACC3BD0741B6E9
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (zwecks Kompatibilit\303\244t; wird ignoriert)'
                                    Category:dropped
                                    Size (bytes):9188
                                    Entropy (8bit):5.211599968885511
                                    Encrypted:false
                                    SSDEEP:192:T08zxxlurx9lHli/7/avO1inVFWo8TNBWjzYr:TjABFADWO1inLNe/
                                    MD5:24E429512E04C6C5F52B64D3EDBDC2EB
                                    SHA1:8907F58FEE79047EC5F10BCC286C74ECFD5112F0
                                    SHA-256:518E2F317976094EC0A0BF8DFBBF2CDFE7697C74FB2B1C9C7E7DEC8DE3641859
                                    SHA-512:4D3131E8EBFABE4174C5966E0D119B3F721ED17F52DE78DDA0D0ED74C8E2285535135E49A93A34BA1E2BF0B1F2332052D71D1C68BF012C2390DED3DB93846DE3
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................E.......C...F...@.......<.......E.......G...N...J.......@.......=..."...E...`...Q.......q...........j...E...........G... .......+.......%.......3...:...*...n...+...............................{.......I...X...@.......'.................... ....... ..e.... ..,...K!..*...x!.......!.......!..#....!..D....!..V...4"......."......Q#......f#.......#.......#.......#.......#.......#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: GNU gettext-tools 0.20.2 ' (nur XML-basierte Sprachen)'
                                    Category:dropped
                                    Size (bytes):121783
                                    Entropy (8bit):5.086282383142756
                                    Encrypted:false
                                    SSDEEP:3072:8lOPBqQwP6xA4PnTOJ6mfyVTf+ZLrQjU/HU3Twp8MAM7I:8yNwPJPyV+/Vp8e7I
                                    MD5:DFAE5A395D467CF2577E231EA67D8F67
                                    SHA1:FD4B54E480D865A33EF9BE003652266AB49C2BB5
                                    SHA-256:EE47380EB8EBE33B6BEFAC5290F1D65AC6560DEDFDC303EFB2EA2A6A9468333B
                                    SHA-512:E200653DD3F0362CEB55600AB9F4FACC9C3006A469E4E106BC3AD756A28F517FEBC14C4341B183733696209B5FC970E53544F8096D87A46C4102B5A59C8BF589
                                    Malicious:false
                                    Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib master ' BEFEHL Der (optionale) zu erkl\303\244rende Befehl'
                                    Category:dropped
                                    Size (bytes):126996
                                    Entropy (8bit):5.310048143107935
                                    Encrypted:false
                                    SSDEEP:3072:Nv7B1/C2LFF5kg7L17DcipVftvBTq3ChUiFAZ9FHD/XTA0w3:Nvf/CqlD1hBTqQAnFHD/TA0e
                                    MD5:0561BFCCE12682622549355A19E9142D
                                    SHA1:6E6709DED793B324A9A76F1742688AC28C5DA4DF
                                    SHA-256:630D636B56A345331505CB9A93163F7C7EAA014AD621B2279D8B552BD3A39521
                                    SHA-512:38B56170C1D96CA3CF4A4CAC799B03BEF9D8A04F702C1FE9161F728ACE7F12A9217418123C2D4EF3BC5A14E28AB2B0D24B81D3E503843547893B7BEC59C30169
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1912 messages, Project-Id-Version: GTK+ master 'Ein anzuzeigender GdkPixbuf'
                                    Category:dropped
                                    Size (bytes):181624
                                    Entropy (8bit):5.194449993225638
                                    Encrypted:false
                                    SSDEEP:3072:IeyLeOBOs4sLyy4XZGjUYPfb1xA4LZ8EYbanl:j00sDWzJGjUYPfBxAVEYA
                                    MD5:A44B4EF9237E50BA38C73BCE4FBE29DB
                                    SHA1:D03CC52ACF8597684D7DFDF6948CE873BEF33CF8
                                    SHA-256:A69EB1CD8B9161AD2D9FE9237DA3637EA81AD58B63D4723898342FD0A04ABD8F
                                    SHA-512:3376803263D4D2F9482902653D065CC1AD31B8E9119BD5201367C7CB3EEE06FA93E03F5E209764457852055D9DA91410EFB3320BFC6574BBDBF178F8608CC70D
                                    Malicious:false
                                    Preview:........x........;.......w......p.......q...g.......e......C...V...5.......N......Q.......9...q...0.......*......<.......?...D..._..............2.......+...4...4...`...,.......Y......N.......N...k..................8......5...,.../...b............................................................................#.......9.......F.......U.......a.......t..........................................................................................................!.......+.......7.......C...'...O.......w...........$..............D......A..."... ...d...G..............5.......)...2...&...\...G..............#..................................'...5...V........................... ......0..............=...D......................................................................../...........@.......M.......[...#...c...0.............../..................................&.......=.......E.......T.......\.......t.............................................................4.......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 869 messages, Project-Id-Version: GTK+ 2-24 '\302\273%s\302\253 konnte f\303\274r das Attribut \302\273%s\302\253 nicht in einen Wert vom Typ \302\273%s\302\253 konvertiert werden'
                                    Category:dropped
                                    Size (bytes):58669
                                    Entropy (8bit):5.289399969078758
                                    Encrypted:false
                                    SSDEEP:768:hH3d9ro9tlZq/HjLs/4B4SQ8zC/FwG9+0VBVwbtk/8AoIyEzqqZx2bxn3/:Z3dNaq/UQtzCNwkBHid/
                                    MD5:37A80D9D20C3B3E7272C57553AD00BFD
                                    SHA1:748C2483590DC2503248BC9B434E9FBBA1FAE726
                                    SHA-256:6EDBD5D88BB0A5916A7F3B8615062A0EA6AD94A3A7DD59F8B886171BF20B06AC
                                    SHA-512:4E2EEB0CD234C26EBB96D25C0EB92CA426780DFEEDC4F2D3EC87DB8EC95E9C4C0E036FEFB51C4BDEFFCEDA99E625199B559640F91DEBD07B12A0B94B52134532
                                    Malicious:false
                                    Preview:........e.......D.......l6.......H..F....H.."....H.."....I..,...&I......SI......lI......yI.......I.......I.......I.......I.......I.. ....I..7....I..)....J..4...8J..=...mJ.......J.......J.......J.......J.......J..'....J..$....K..(...>K..)...gK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...5L......fL......rL......~L..9....L..6....L.......L.. ....M..0...*M..5...[M..9....M..8....M..:....N..7...?N..2...wN..4....N..1....N..?....O..1...QO..?....O.......O.......O.......O.......O.......O.......O..3....P......EP......SP......pP.......P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q..3...MQ.."....Q..>....Q.......Q.......Q.......R.......R.......R..V...%R......|R.......S.......S......!S......1S......=S......JS......WS......pS......~S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......2T......GT..+....T.......T..!....U..)...(U......RU......lU..$....U.......U..1....U..-....U......&V..!...<V......^V.."...rV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 550 messages, Project-Id-Version: GtkSourceView master '.desktop'
                                    Category:dropped
                                    Size (bytes):33792
                                    Entropy (8bit):5.102855731704914
                                    Encrypted:false
                                    SSDEEP:768:siKvbFfVwPMHOx2KQQCMovYtTmatdpa/+bVzeooLdziTLO:Z5S22KQ2ovYtCatrpbVzeooViTK
                                    MD5:61AD58B2A8FCA56B1F00D77577D006D4
                                    SHA1:FBE8E0C6317E87E120B3C95F309F743411F8A5AC
                                    SHA-256:536CA6EE2E3E17A1E931EADB55FF6AF9F98C3C45E567F15D8F2FDF19B2D2BBA5
                                    SHA-512:27D775E20437E4CE3303EA8660CA5EA934D005C7CFF1BE28F233C29A1EE7E6EBA335495DAC73D349C4ACA136D850E7577C49A2061063A011F239E128A5200356
                                    Malicious:false
                                    Preview:........&.......L.......|".......-.......-.......-.......-..............................&.......*.......5.......I.......O.......S.......Z.......a.......w................................................................/......./......"/......6/......G/......V/......b/......m/......~/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0.......0......%0......30......A0......H0......\0......d0......t0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1.......1......#1......,1..{...51.......1.......1.......1.......1.......1.......1.......1.......1.......2..)....2..&...72......^2......f2......t2......|2.......2.......2.......2.......2..1....2.......2.......3.......3......%3......23......:3......J3......L3......T3......[3../..._3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4....../4......@4......E4......O4......_4......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1211 messages, Project-Id-Version: gwyddion ' ist freie Software, ver\303\266ffentlicht unter der GNU GPL.'
                                    Category:dropped
                                    Size (bytes):84393
                                    Entropy (8bit):5.35612439382429
                                    Encrypted:false
                                    SSDEEP:1536:jWhMCvxyNrh/aqHWx6IZTK4dDu2fdn8nGUASDB9qzwYldwttddGk89IEpzHzAoI9:jA5eK6IZTK4dFdnAGUASDB9MwvtjGkUw
                                    MD5:EABDB20BB328463C996DC9F7C74F246A
                                    SHA1:B1DE0125EE605DC4560B79B2C0592D9231FC81D7
                                    SHA-256:E7F8258733E3ECDC4546BE64209813EAAD8E2E88276296C48A4EC3ECB11AF651
                                    SHA-512:413984F5083393432167CF8016EFF8000C0FAE81009E07DD6696C053836C300F031251C46D8DBC9DB92E2D299C450CF7DCFD1521969357FAA542DA97599859B7
                                    Malicious:false
                                    Preview:.................%..S....K.......e..)....e......Ce..,...Te.......f.......f.......f.......f..&....f..%....g......3g......Hg......`g......kg..'...}g.......g.......g..!....g.......g.......h......0h......Kh......\h......jh......{h.......h..6....h..4....h..4....i..4...Ai..5...vi.......i..,....i..-....j..*...6j..3...aj..7....j..%....j.......j.......k..%...(k..$...Nk..%...sk.."....k..#....k..%....k..#....l.. ...*l......Kl......cl......{l.......l.......l.......l.......l.......l..#....l.......m..%...5m..#...[m..$....m..+....m..&....m.......m.......n..+...2n.. ...^n.. ....n.......n.......n.......n.......n.."....n..'..."o.. ...Jo......ko..$....o.......o.......o.......o..!....p..'...#p......Kp.. ...gp.......p.......p..#....p.......p.......p.......q......!q......<q......Uq......tq.. ....q.. ....q.. ....q..,....q..(...#r......Lr..%...lr.......r.......r.......r.......r.......r.......r.......s......1s......Fs......bs..!...{s.......s.......s.......s.......s.......s.......t.......t.......t......At......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Accessible Description'
                                    Category:dropped
                                    Size (bytes):9907
                                    Entropy (8bit):4.839428044426715
                                    Encrypted:false
                                    SSDEEP:96:TFoi84hrwVl7kQMxbaK2LTJrBSaPGgqBc8CySOaI5RCGuDMPKgqBcPC1SOaI5d:S5ewUQwF2LTJgqBURCySjGuDM9UwC1SG
                                    MD5:8D357A4F22FF1CB6656B8C0B9D0739FF
                                    SHA1:C85821F279BFF41B5938929DB0F86ED6B6638DAA
                                    SHA-256:FB63EF5C40CF1E332DAD4E296A86B822CA2EF9785244FC818391AD55ACD0590C
                                    SHA-512:42BB97A28AB60D9A40F648A1E1B2B1D513F0B4348B01D14CCE6BF8F02553BD4F220BC4D73604DE3695B5EE07781941923BFC3902FB6B4ECAD5A63A83A2F2A4F2
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 212 messages, Project-Id-Version: gtk+ 'A pointer to the pixel data of the pixbuf'
                                    Category:dropped
                                    Size (bytes):21706
                                    Entropy (8bit):5.0821426689270846
                                    Encrypted:false
                                    SSDEEP:384:RzuoVbZUaFtcWx8O0MYAqvch8YkFjFEzWx8ciMYst2ch9chrB:RLVJcWx8vpgBY2zWx8Lp0aj
                                    MD5:B94703CA58C0B70998BFA10D87EC8558
                                    SHA1:51E670C8ED5E63CE69047E9344E840A40261FFEC
                                    SHA-256:5C4139C7514838AD331898AD7484FB760C4DC222C580FD8CFE65B3A1E8296A69
                                    SHA-512:1B2C07D4D63EE299FB334C9EC1F354A80E5A415A4CA9CE0F86563F722767B9B94D2C405258A80F39288D074438D700706B4C6A8C0020602A24667922EAC96034
                                    Malicious:false
                                    Preview:........................\...........).......&...................:.......Y...%...y...........................).......-.......!...6.......X...-...q...,.......,....................... ...-...$...N...*...s..........."...............................*...!...)...L.......v...........,.......0...............%...<.../...b...........................<...................'.......D.......b...".......'...................................%...`...C...*.......R.......(..."..."...K...&...n...........V.......!.......N...(.......w... ...............'..............."...........6...Z...P...........8.......8...........7...!...O..."...q...&.......%.......%.......B.......N...J...0...............&........... .......*...&...1...$...X.......}...........!...............".......".......$...(...q...M...;...............$.... ......? ..$...n ..*.... ..O.... ..*....!..%...9!../..._!..-....!..e....!..%...#"..x...I".......".......".......".......#.......#..N...5#..S....#..N....#..N...'$..2...v$..H....$.......$.......$..$...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1043 messages, Project-Id-Version: glib ' COMMAND The (optional) command to explain'
                                    Category:dropped
                                    Size (bytes):108822
                                    Entropy (8bit):5.159169751548222
                                    Encrypted:false
                                    SSDEEP:1536:a4MIHc4YNy4AZ5LvtxJghMsJGp/UwxJHrh+JGpW+Y:vNPYNyzx6hMBp/HxFrhPpWP
                                    MD5:CA9DA959377FF2838BFF334CE165D344
                                    SHA1:8CA5AB76F333F514BFF6B1837828C1A275E3BDD5
                                    SHA-256:CDA3FB9BF1449D68CDA26FD2EEF72858D25D889E3F9DC113D873F301B349476B
                                    SHA-512:3181AD7E69EC2547E4B7823C29FC048A9BB3BBE10572F7BCB26468B123349BE45CFA8907E3BC929557419027ECAE56621DAB3602C444E713D42DEB345A8A69EA
                                    Malicious:false
                                    Preview:................. ..w...LA......(W......)W..7...XW.._....W..1....W..&..."X......IX..9...fX..Q....X..9....X..+...,Y......XY......vY..&....Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Z.......Z.......Z.......Z..:...0Z......kZ......wZ.......Z.......Z..Y....Z.._....Z..a..._[.......[.......[.......[.......\......0\......N\..)...e\..<....\..*....\.......\..!....].."...-]......P]......o]..#....]..!....]..[....]..&...1^..4...X^..a....^.."....^..5...._..J...H_..8...._..&...._..$...._.......`.......`......%`......>`......N`......X`......c`..B....`..!....`.......`.......`..K....a..1...]a..)....a.......a..U....a..8...$b......]b......sb..?....b..+....b.......b..(....c......)c.. ...Ac..!...bc.......c.......c..4....c.......c..)....c..#....d..#...@d......dd......~d..2....d..9....d..!....e..4...%e../...Ze..6....e..+....e..1....e..-....f../...Mf..#...}f.. ....f..*....f.......f..(....g..=...2g..,...pg..,....g..&....g.......g..^....h..a...mh..B....h.......i..+...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1722 messages, Project-Id-Version: gtk+ 'A GdkImage to display'
                                    Category:dropped
                                    Size (bytes):155232
                                    Entropy (8bit):5.073310288287369
                                    Encrypted:false
                                    SSDEEP:3072:nT9sJGyw1S3RH4oYjUYPApufqFDlj6YxV:Zmw1sqoYjUYPA4+Dlj6YxV
                                    MD5:FD1C51B71DB5655FC8317986C5FEB23B
                                    SHA1:61552D97EB10E69C72DA8198F44CB04F3EA28F06
                                    SHA-256:C07FDA44AE310EEFA2FA8074A0E874D5A69ED156B6A36E3F326D4AC04C756D65
                                    SHA-512:00B1C80A4232DE86CD08C691A2D175EA701152346DC28D46030EE06CECA531C78A9BBC2AF79BCFC918E4C1685D9DCF0C2FCC5649F922DFB029FE7F64A8189EB2
                                    Malicious:false
                                    Preview:.................5.......k.................................e......C...K...5.......N......Q.......9...f...0.......*......<.......?...9..._...y..........2.......+...)...4...U...,.......Y.......N.......N...`..................8......5...!.../...W....................................................................................).......8.......D.......W.......c.......j.......w....................................................................................................(.......3.......?...'...L.......t...................$.....................D.......A...A... .......G..............5.......)...Q...&...{...G..............#..........................1.......M.......l...5.....................0...........(...=...W................................................................/...........N.......[.......i...#...q...0................................................................-...5...>.......t.............................................................6.......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 868 messages, Project-Id-Version: gtk+ '"%s" could not be converted to a value of type "%s" for attribute "%s"'
                                    Category:dropped
                                    Size (bytes):54764
                                    Entropy (8bit):5.213343358885846
                                    Encrypted:false
                                    SSDEEP:768:gKJHhOgPKkJ3JwzJPEBjSQ8zCtWG9+0yo1hQtzCWCnjvgE:gKJHYEKkJ3e1EizC4LzCtgE
                                    MD5:E3E29D0F964571BA3D375438C228E63A
                                    SHA1:B3FD7813D87B4D11C2DBD502E5794A8B287778E7
                                    SHA-256:828358174B83A54A0463561215BD9BFED710CE3C79999194E6851A88C8D2E8E5
                                    SHA-512:81385CE796E14967F5413BE89C0C978F66E0C2E7658CDEE4B9FE3660956B6386F1749A45E5471D788624B66FA5ACDCD2D484EBBD94387C5CAD1048059E6D5A3D
                                    Malicious:false
                                    Preview:........d.......<.......\6.......H..F....H.."....H.."....H..,....I......CI......\I......iI......oI......zI.......I.......I.......I.. ....I..7....I..)....I..4...(J..=...]J.......J.......J.......J.......J.......J..'....J..$....K..(....K..)...WK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...%L......VL......bL......nL..9...yL..6....L.......L.. ....L..0....M..5...KM..9....M..8....M..:....M..7.../N..2...gN..4....N..1....N..?....O..1...AO..?...sO.......O.......O.......O.......O.......O.......O..3....P......5P......CP......`P......}P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q.."...=Q..>...`Q.......Q.......Q.......Q.......Q.......Q..V....Q......8R.......R.......R.......R.......R.......R.......S.......S......,S......:S......GS......\S......nS.......S.......S.......S.......S.......S.......S.......S.......S.......T..+....T.......T..!....T..)....T.......U......(U..$...>U......cU..1....U..-....U.......U..!....U.......V.."....V......QV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview '.desktop'
                                    Category:dropped
                                    Size (bytes):30947
                                    Entropy (8bit):4.9987576750073375
                                    Encrypted:false
                                    SSDEEP:768:T6XjjsHGA/0TpywALjQCqofYtUmatdn1/2ms8ofqPWzat439/3:T6Tju0poIofYtratJsoofqP6atKV
                                    MD5:1DA36B276ECDF3DCEB0F4BF5EAC24D66
                                    SHA1:D5044689462823AFB080F64282B188168208B675
                                    SHA-256:A855D12A1C6E3C0E2E63267951D4E27291D09CF88B8E3752CB08A6CB338A1693
                                    SHA-512:FD500CA3DEE3A5D30F11505F16EEC09B13EAF0E259785FC5274CF957C0321C1FEE20A18C50B1CD449E74E78FAC8621C6CC894A6AC166034F69A2B376296E7544
                                    Malicious:false
                                    Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 4878 messages, Project-Id-Version: Gwyddion ' is free software released under GNU GPL.'
                                    Category:dropped
                                    Size (bytes):346220
                                    Entropy (8bit):5.385309862061066
                                    Encrypted:false
                                    SSDEEP:6144:CZHUlsF9ffzyVvrLDbNu7fdkMBUSTjFQaEN7uHx4H00dAd:MRL7ivNuld+7uB0K
                                    MD5:183EB7FD4392ABBDF482B080C408E992
                                    SHA1:3316D49EA5A6057B8862E42D6D8C0207F31CBEA1
                                    SHA-256:D11A65C76E909E3425E1B36036DEE8C354BEB5411DF9DAC70DC15B30C9B2C492
                                    SHA-512:24353E605B928D85C733674A1AA55578AF3AD1DDACE07354C54224BB6E59F302174AE4BE83EF2198B56083522F400233606ED76B5F7EFD6997E619288E4D1CA8
                                    Malicious:false
                                    Preview:....................y....0..........)..........................,.......H...&...Q...-...x...(..............,............... ...........?...%...X...D...~................. ...... .......$...,...$...Q.......v.......~...........................&......%...........&.......;.......P.......d.......}..........................................$......"...........&...'...B.......j...................!..................................).......F... ...].......~...%.......(.......!......)....... ...4... ...U...#...v... ..........................................).......7.......H.......[.......j...!...|................... ......6.......4.../...4...d...4.......5...... ......."...%.../...H.......x...,.......-......*.......3...-...7...a...'.......%......."..................(...+...G.......s...........%.......$......%......!......."...6...#...Y...%...}...#.......$......#...... ...........1.......I...!...i...................0......*.......*...$...+...O.......{...............................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk.HEAD 'Descripci\303\263n accesible'
                                    Category:dropped
                                    Size (bytes):10733
                                    Entropy (8bit):4.865953628025581
                                    Encrypted:false
                                    SSDEEP:192:S5ew7BTE5u9qBURCySPGDSWbnnsVDnDKIn:SYwFYu8BURCzP/anO
                                    MD5:63643CB196115CA92116677936AB503B
                                    SHA1:DC5745FF0F867B90987D7AD07BF55A1DFE810532
                                    SHA-256:B40118A505E04E3F29802658D87956ECF182B1504EEFFA693BFD72295F6CE437
                                    SHA-512:4BDC0DB5976CF5FB144E5E3D70EA644F5734146266CB49A7766E535EEEE823F143CBAEA80733C92176BF30757F47B13DF581E11B6017E7E4CF396E9FCE6DBF71
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf.master.es 'Un puntero a los datos del p\303\255xel del b\303\272fer de p\303\255xeles'
                                    Category:dropped
                                    Size (bytes):24268
                                    Entropy (8bit):5.048306540654722
                                    Encrypted:false
                                    SSDEEP:384:yapC+UabIsjFtcWDx8c0MYAqvch8YyPlIaCqEo0vPonl118aaw72AqRh:yapCYIscWDx8JpgBc+aCqx04lMAO
                                    MD5:BA94634DD9E0D57807C05383CDFED141
                                    SHA1:D7B2CE9C451C0A9C7BF7BDB7629CDB97F8469A7E
                                    SHA-256:600E9840267E2A4352EBAB50B1187B300F251FAB3C1555E962A839A9D7A8CA8A
                                    SHA-512:AAC131CFF9E5792C8D079361F9C31B1DA857984D1682A0B353D346CAAF0E5E5E664FE18FE1AB741F9F19F293818E76D28D1627B2D6D9A8D8DE6D8A43A854DD73
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: GNU gettext-runtime 0.20.2 ' -E (desestimado por compatibilidad)'
                                    Category:dropped
                                    Size (bytes):9164
                                    Entropy (8bit):5.148091276523689
                                    Encrypted:false
                                    SSDEEP:192:Ts0xxlurx9lHli/7/avO1izP3WZdZbqxRMnmygW:TDABFADWO1izvWZjwJyF
                                    MD5:C2A0106D8BCBF804879AFE34094BF321
                                    SHA1:EBE4E4BDBDAAC07754C6329DE6971F0261892C6A
                                    SHA-256:B14C6780F4E66FEAF077C305BE69E4A290EAC9E54D18F203897D8BF84EA30D13
                                    SHA-512:EF7FBE7FF6A6E2C401E0AF57A8C31467B35DF491920777F84BBE47D8784ABEFA8383D2939B0035EB9DC4E5F7A1102C1B128433C48E390FC3CEFD0AFC8C8EEFB0
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................=.......=.......;...<...>...x...I.......L.......S...N...E.......C.......7...,.......d...q.......M...k...J.......}...............2.......!.......0.......,...(...-...U...!.......................l.......>......."...J...$...m................ ....... ..].... ..3....!..+...@!......l!..$...{!..C....!..F....!.._...+"......."......C#......T#......o#.......#.......#.......#.......#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 699 messages, Project-Id-Version: GNU gettext-tools 0.20.2 ' (solo lenguajes basados en XML)'
                                    Category:dropped
                                    Size (bytes):123220
                                    Entropy (8bit):4.9811759708787715
                                    Encrypted:false
                                    SSDEEP:1536:+u70DsyeAeMIbMICqQwPDa0xuu21pcSTOyjOF3v4RwxRhotnyQI:p70CFbcqQwP1xuuInTOy6F/4RwxR+fI
                                    MD5:3FD4BA4330530C7417144CD55829FF85
                                    SHA1:149DB719BBCC6E0A6E383F50CDD1828BBFC8C434
                                    SHA-256:1F81E923489C3F8D0FF45F9C3B54746192FC58CD310657183A8B15EBEDCAD2F5
                                    SHA-512:5340BB39FE95A2CDDD1623CEC5C43DDAE98187D8F2EA27F0ABA46F6BCFC881785199B041BC971D4EA85288C59B8894E38F7D74B56B8D3C9C882277E7FE1BFCDA
                                    Malicious:false
                                    Preview:.........................+......p:..;...q:..4....:..D....:......';..&...E<......l=..6....>..=....>..z....>......x?..F....@..O...I@.......@..;...\A..<....A..L....A......"B..@....C..A...JC..A....C..Q....C..Q... D..L...rD..K....D..K....E......WE..I....E......>F..L....F..:....G..L...NG..v....G..E....H..L...XH..4....H..8....H..9....I..P...MI..=....I..L....I..G...)J..L...qJ..G....J..=....K..J...DK..D....K..@....K..:....L..L...PL.......L..K...1M..G...}M..H....M..;....N..8...JN..9....N..?....N..J....N......HO..@....O..>....P..:...HP.......P..7...>Q..8...vQ..;....Q..5....Q..M...!R..B...oR..:....R..;....R..L...)S..:...vS..P....S..p....T..I...sT..F....T..?....U..H...DU..H....U..L....U..L...#V......pV..5....W..<...6W..:...sW.......W..>...:X..A...yX..=....X.......X.......Y.......Z..;....Z..O....Z......-[..K....[..I....\..;...L\..C....\..u....\..8...B]..G...{]..I....]..D....^..s...R^..B....^..J...._..2...T_......._..D....`......\`..M...ka..F....a..:....b..L...;b..N....b..4....b..H....c..G...Uc..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib.master ' COMANDO El comando (opcional) que explicar'
                                    Category:dropped
                                    Size (bytes):125714
                                    Entropy (8bit):5.227110849063442
                                    Encrypted:false
                                    SSDEEP:1536:NZwEM85NY4c9O6JnLQwF5kg7cRU17Di/sbVVpNd6SLl/1guzyEvmqTjw3KytACvF:Nv75NjcM2LFF5kg7L17Dh5sQ0uqL
                                    MD5:76F6A007B8DCF321459A15A2BCE0BAC1
                                    SHA1:F63BFADB284B3620745C46062F975DD67A7F4FC2
                                    SHA-256:D98A665B6FFCB52AD9C0B31548BBECA87B1FA9C9708D71F4919E639B918880C6
                                    SHA-512:214D63B7F1F0EDA4CB429A63808AAB9861D41ECDBAC10D5A393A7AEEBE6420C8230D3E139C861C8BB1B4C8FD3FD61122E74C569BA09EBED13D3D0FC5C165E110
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+-properties.gtk-2-22 'Un GdkImage para mostrar'
                                    Category:dropped
                                    Size (bytes):169606
                                    Entropy (8bit):5.0689044915654495
                                    Encrypted:false
                                    SSDEEP:3072:em1YvN/COXoyS3RH49ljUYPAJ2nVYJ5abFfraO0RR76B:n1WBCOXoysy9ljUYPNO7A
                                    MD5:7F0C5E406FA7B02E8E2078F3F0B1EB00
                                    SHA1:80E2DD3EFEE95FDB92265E324E5139A6AC161AB2
                                    SHA-256:4C8868F15655C88FDEF1BAAF5DF71B2A46F8DF2E621F8E4AF91A08A55B9679AE
                                    SHA-512:EB0F7856A00DF7D1080344B5525B2E166185EC8AD4F4771F436AB81F82655C841EA1A226C8D81A0F7F77A45070C755AAB282BDA4980DDED85D3202BFFF035BB9
                                    Malicious:false
                                    Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 1.1, 868 messages, 1 sysdep message, Project-Id-Version: gtk+.gtk-2-22 '"%s" no se pudo convertir a un valor de tipo "%s"para el atributo "%s"'
                                    Category:dropped
                                    Size (bytes):58800
                                    Entropy (8bit):5.236057716366569
                                    Encrypted:false
                                    SSDEEP:768:To5DBFSkMCniPoKrb2f/oRbFmsa/4SQ8zC/FwG9+07KXXK+jCHEEEe9/3bFAy:ESrCHKrKopF3+zCNwQKHykJIfbFAy
                                    MD5:3233D03B617FB99B7EB5426185D3FE76
                                    SHA1:2F18EFCE576D0E063E4984CDCB81E07E98A79314
                                    SHA-256:602D7D97A724A89A83DBBBFCB75F518DAD5200F9EB00A933A43BCB6FF824058F
                                    SHA-512:B696F3960A8D92EC6E88536B0AF8E6D5F6763E330895487AAAB34AD38F9BC9A6F4AB4A2C3111D701793393BB0C0D281F5AED88740E2E9ECF3144FEFF19350314
                                    Malicious:false
                                    Preview:........d...0...P.......p6.......H.......H...H.......H..F....H.."....I.."...7I..,...ZI.......I.......I.......I.......I.......I.......I.......I.......I.. ....I..7....J..)...BJ..4...lJ..=....J.......J.......J.......J.......K.......K..'...%K..$...MK..(...rK..)....K.......K.......K.......K.......K.......K.."....L..#...#L..!...GL..0...iL.......L.......L.......L..9....L..6....L.......M.. ...=M..0...^M..5....M..9....M..8....M..:...8N..7...sN..2....N..4....N..1....O..?...EO..1....O..?....O.......O.......P.......P.......P.......P......%P..3...EP......yP.......P.......P.......P.......P.......P.......P.......Q.......Q.......Q.......Q......!Q..!.../Q../...QQ..3....Q.."....Q..>....Q.......R....../R......?R......GR......NR..V...YR.......R......FS......OS......US......eS......qS......~S.......S.......S.......S.......S.......S.......S.......S.......T.......T......"T......+T......>T......MT......fT......{T..+....T......'U..!...:U..)...\U.......U.......U..$....U.......U..1....U..-...,V......ZV..!...pV..
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 550 messages, Project-Id-Version: gtksourceview.HEAD '.desktop'
                                    Category:dropped
                                    Size (bytes):33988
                                    Entropy (8bit):5.039000051452868
                                    Encrypted:false
                                    SSDEEP:768:siKv03j2KQQCMovYtTmatdpa/O2wbyoVis1hcGg/BJ/:ZfT2KQ2ovYtCatrfh2oT1hcGg/B5
                                    MD5:D662DFDDCCA56A4E3399A5EFBF09725C
                                    SHA1:57ACABD8970F59EAB27235F7FA4348602F4A4A3C
                                    SHA-256:E2EC9A36F16EC1412073EF606AA32221A669126774CCD2B84D6F628CAB90BEC4
                                    SHA-512:4FE633E241164A272E420F1A5C9128EE5B1CA97B981113008E8E57E040C2CAC1B7CF044B42C2B3F9FD157B9CEB4C7B685C68B92F163D442D022CC7E63D309336
                                    Malicious:false
                                    Preview:........&.......L.......|".......-.......-.......-.......-..............................&.......*.......5.......I.......O.......S.......Z.......a.......w................................................................/......./......"/......6/......G/......V/......b/......m/......~/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0.......0......%0......30......A0......H0......\0......d0......t0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1.......1......#1......,1..{...51.......1.......1.......1.......1.......1.......1.......1.......1.......2..)....2..&...72......^2......f2......t2......|2.......2.......2.......2.......2..1....2.......2.......3.......3......%3......23......:3......J3......L3......T3......[3../..._3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4....../4......@4......E4......O4......_4......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 840 messages, Project-Id-Version: Gwyddion '%s es software libre; puedes redistribuirlo y/o modificarlo bajo los t\303\251rminos de el GNU General Public Licence como est\303\241 publ'
                                    Category:dropped
                                    Size (bytes):52030
                                    Entropy (8bit):5.241671459882161
                                    Encrypted:false
                                    SSDEEP:768:Tau+SCojInYWEmr6For9hicOvgdD13TrdXVcw57HxL5ZXwe+jdv7AxIUr:2u+Sx15FgOodD1fdXOw57HVge+xv7Ns
                                    MD5:9F4CD9D07C9DC5E87AE089B482E4D01F
                                    SHA1:FD4AFF8B4B3DA429572209F8E191FBC9FA621D6F
                                    SHA-256:084BCF0FC2797112A021C072BBA31EF980CF49C8071C8DBF07888A2F333A6446
                                    SHA-512:12AEBA0496F04B362D4DB30764AAA9E07AFC43E9208D08A0ECF1135A0064D6A29761F9E50E28D734BAEE1893311C585231AE1B8C16C212D6F6581A26008F86B4
                                    Malicious:false
                                    Preview:........H.......\...c....4......(F..,...)F......VG......hG......~G.......G.......G.......G.......G.......G.......G.......G.......G.......G..t....G......aH......pH.......H.......H.......H.......H.......H.......H.......I.."...$I......GI......TI......ZI......rI..,...|I.......I.......I.......I.......I.......I.......I.......I.......J.......J......-J......6J......RJ......YJ......bJ......yJ.......J.......J.......J.......J.......J.......J.......J..9....J......%K......:K......?K......GK......LK......UK......[K.."...uK..#....K.......K..a....K..!...)L......KL......ZL......jL......|L.......L.......L.......L.......L.......L.......L.......L..h....L......<M......GM......WM..!...`M.......M.......M.......M.......M.......M.......M.......M.......M.......M.......M.......M.......M..'....N......5N......JN......RN......WN......]N......gN......sN.......N.......N.......N.......N.......N.......N.......N..[....O......]O......gO......qO.......O.......O.......O.......O.......O.......O.......O.......O.......P......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk HEAD 'Description accessible'
                                    Category:dropped
                                    Size (bytes):10673
                                    Entropy (8bit):4.885148337883671
                                    Encrypted:false
                                    SSDEEP:192:S5ewLIetaxZqBURCyShGNKCVLcaCZR7Shcl9wPu1RRKRY5Evl/Q:SYwUNxQBURCzhsVLcaCZR72eKw8lY
                                    MD5:930C9F509B7F1CF4E97F646C55A67F67
                                    SHA1:0B67573CC6394530A3237935D752118CA977CA61
                                    SHA-256:D55071A2344138778923B00B794F3F78D4D384AA58C95DE001302F4E215074AA
                                    SHA-512:F58E8DB008FFA789CA10C340D8799465C54773478341C7C6A8BDF5AB29D4EA2F80841F2A06ECCB488F290787674E8F9E97C4573EAFE766DBC326450F95A1DE8D
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf master 'Un pointeur vers les donn\303\251es de pixels du tampon de pixels'
                                    Category:dropped
                                    Size (bytes):25316
                                    Entropy (8bit):5.155472250184355
                                    Encrypted:false
                                    SSDEEP:768:yapCSa20XlcWDx8JpgBRFHWhwWguzz8+yry:BpCSWQpgDFHWhw7ry
                                    MD5:ED7BD86F974D416FBE1585A7D8872C87
                                    SHA1:BAFCB36FFEE9F5D67AA4C79F03B55272017BE48C
                                    SHA-256:70D3D27FEE678FB501BF27C9F9D507A081880C4EBC5CE9A686FC311E282C921B
                                    SHA-512:A161EFD7C0FB95803F7DA499B83FE2D2FAE1E908E85360A440CF811A8D9256D76B4993A068573FEBA989DF1AE774B03CEC6CF12D4454FC618468F7B0A84F0961
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (ignor\303\251 pour la compatibilit\303\251)'
                                    Category:dropped
                                    Size (bytes):8909
                                    Entropy (8bit):5.151174521158977
                                    Encrypted:false
                                    SSDEEP:192:T1Kxxlurx9lHli/7/avO1inbfQmNl/uH0ZgaG1/4fd:T1gABFADWO1inbomNM+fG5Wd
                                    MD5:09708D4B994E6FA7A59FA19CCB78A82C
                                    SHA1:C03322E2D9AB57AA27EB6A3580E397C9F10D3E26
                                    SHA-256:16F90AB0EC7B2C0F05BB53F0FA2DA3BE8F136D7D94ECE68E5AFA590E14EEE526
                                    SHA-512:93A1391A1D67623FC834B93DA1AE19388FD81A784D7BA4E70A3671E11791F38F4347F48515AEEB18EF78C8BA78B291172ED3B4DA514C3E95DC7C4F38E283E9E6
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................=.......G.......E...>...<.......K.......I.......W...W...6.......9.......A... ...T...b...c.......P.......K...l...y....... ...2...3...S...&.......9.......+.......(.......*...=.......h.......u...l...h...>................... .......$...................Z.......6...N ..2.... ....... ....... ..#.... ..9....!..G...E!.......!......;"..%...K"......q".......".......".......".......".............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: gettext-tools 0.20.2 ' (seulement les langages de la famille XML)'
                                    Category:dropped
                                    Size (bytes):124508
                                    Entropy (8bit):5.100469941426852
                                    Encrypted:false
                                    SSDEEP:3072:8HTbBqQwP6xA4PnTOJ6bBfKkVpJkJgvc71H4phmW96Cz:8z9NwPJ6fKkHWYc71H4pr6W
                                    MD5:DE8D4310BF6D87A881F986C52F16ECA5
                                    SHA1:1F6C95D54DB345D3DB54F29DEE2C187BF4E5251E
                                    SHA-256:CE14C56766E8F0C2278B4856CE64AC39B59DAB10ABEC9A5761980D0D35C39323
                                    SHA-512:D4107A62FF116505E787944A3D4362EDCE0FE008260704529AF8721392FA99165493846405C57F9A21C9000A255CC0D9AF96FF510A713411EC76301D0A20164A
                                    Malicious:false
                                    Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib master ' COMMANDE La commande (facultative) \303\240 expliquer'
                                    Category:dropped
                                    Size (bytes):132447
                                    Entropy (8bit):5.313444916910655
                                    Encrypted:false
                                    SSDEEP:3072:NvAPgrH1T2LFF5kg7L17D7bsek0oUl5vRdSamfLCQ:NvtH1TqlD7bsek0HTSapQ
                                    MD5:7BB56EA22755D17EE656D4BE32FEA4BC
                                    SHA1:102BEF41819531D788E472ECA304C946019794D9
                                    SHA-256:A0895FFEB432967810274C36205E2DA4D7B31F980ACECC87F50930430740D0AD
                                    SHA-512:49F74AD636E7840D8F3002111FF34700D723776F2ABAAB74FC909E0EA25A02065F706990CF50124814BADD1BBABB2AB47B83347C9AFA34E74741E9D3A0B29347
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+_properties HEAD 'Un GdkImage \303\240 afficher'
                                    Category:dropped
                                    Size (bytes):172038
                                    Entropy (8bit):5.127969048470811
                                    Encrypted:false
                                    SSDEEP:3072:em1YvN/CTnUyS3RH49ljUYPKPFgZVrOgrX:n1WBCoysy9ljUYPKdfuX
                                    MD5:5DA9D6D5D743F975B7A3F7A9CD5AA01C
                                    SHA1:CC8AE1CB2CB96BF2337D4799289A380596E1162A
                                    SHA-256:A02C51B49C9EC2757C816058DB32A3E04566D054C22A5864788DC006F9B03DF7
                                    SHA-512:799FFED0209DCC6A806ADFC0EC3E24EEEB3E2FBD933D8755E2BA2D9D7616E086DE1F0200155DDCC35FF4BF6AF684E680AE2A8B647585808B02C8C7539ABA6E9A
                                    Malicious:false
                                    Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 867 messages, Project-Id-Version: gtk+ HEAD '\302\253\302\240%s\302\240\302\273 ne peut pas \303\252tre converti en une valeur de type \302\253\302\240%s\302\240\302\273 pour l'attribut \302\253\302\240%s\302\240\302\273'
                                    Category:dropped
                                    Size (bytes):59666
                                    Entropy (8bit):5.298531752944225
                                    Encrypted:false
                                    SSDEEP:1536:5mX5pwmVe/fkzizC4I9KLxeKErWbUzFN2V2t:50EmeH2izCF9YeKESbUzD20
                                    MD5:8698415DE61C5A421E701C500B798C32
                                    SHA1:D295B4294F09BCA45185B04D8978F5A7AB65C4A7
                                    SHA-256:69F1E659F15C1F2FC154F37FE126673E0ED56BE9E42060E2A760E2665B6D5C06
                                    SHA-512:2915C4BFD7069F6BA781340E1FD6E9D8E269BD14F3F90FFEDAF3106A2C9273C09FDC921D65466B6601CFF1BA34A8670314F8B27E367DA90220081C10BBB31D26
                                    Malicious:false
                                    Preview:........c.......4.......L6......xH..F...yH.."....H.."....H..,....I......3I......LI......YI......_I......jI......qI......|I.......I.. ....I..7....I..)....I..4....J..=...MJ.......J.......J.......J.......J.......J..'....J..$....J..(....K..)...GK......qK.......K.......K.......K.......K.."....K..#....K..!....K..0....L......FL......RL......^L..9...iL..6....L.......L.. ....L..0....M..5...;M..9...qM..8....M..:....M..7....N..2...WN..4....N..1....N..?....N..1...1O..?...cO.......O.......O.......O.......O.......O.......O..3....O......%P......3P......PP......mP.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....P.."...-Q..>...PQ.......Q.......Q.......Q.......Q.......Q..V....Q......(R.......R.......R.......R.......R.......R.......R.......S.......S......*S......7S......LS......^S......tS.......S.......S.......S.......S.......S.......S.......S.......S..+...sT.......T..!....T..)....T.......T.......U..$....U......SU..1...rU..-....U.......U..!....U.......V.."....V......AV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview HEAD '.desktop'
                                    Category:dropped
                                    Size (bytes):34078
                                    Entropy (8bit):5.090096811849565
                                    Encrypted:false
                                    SSDEEP:768:T6XjjsHBgYBK/I4xjQCqofYtUmatdn1/OVXOJiYJCUKDv:T6TjuBJ4VIofYtratJ6XOJiYJ6v
                                    MD5:6FB94218B155E58CDACADA6306FFF57D
                                    SHA1:D258275A8B3E89E71B93E2E9AD42D0E9366292C9
                                    SHA-256:E546EA7312D817A4C20C0C1247B571D6C0E868E4AD6A275C9E68460452D523F0
                                    SHA-512:6198F98254BEE7341EB0A9AC7BC4B0E7388B56FBF80993C6F86B4ADB6B48270CD04A666A1CA144352D4775D0BE2DB580FEE0BDCFA6B6A3057FA0BFD1A614F935
                                    Malicious:false
                                    Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 4378 messages, Project-Id-Version: French localization ' est un logiciel libre d\303\251velopp\303\251 sous la licence GNU GPL.'
                                    Category:dropped
                                    Size (bytes):339057
                                    Entropy (8bit):5.390770170899853
                                    Encrypted:false
                                    SSDEEP:6144:EuiITy2MqOklcL/RbQu2fQQTX51WIpxYfiumRqyFSwyCfEZ:EuzM/USQuufxYfoRqyFSwy7
                                    MD5:E6DD4E63FA00B0AF9794AD15586DFE33
                                    SHA1:8FEA8887A4E2751A6341EEE5D73BF19F4328DEAE
                                    SHA-256:060422F70D7E356904B91176B81AE2DD0A2E8754F9394A03FEDBEDFFE0F064F2
                                    SHA-512:EA0297CA4A51AB2F10133229DC35ACC3020D378CB00B9D540871D314464D9A7BE3FC64ABBBA6DAFFA63977D39DDC8645D6DB7525282768F876A0B5593F5DAD12
                                    Malicious:false
                                    Preview:................................l..)....l......#m......0m......Dm......`m..&...im..-....m..(....m.......m..,....m.. ...%o......Fo..%..._o..D....o.......o.......o.. ....o.. ....p..$...3p..$...Xp......}p.......p.......p.......p.......p..&....p..%....q......-q......Bq......Kq......cq......vq.......q..$....q.."....q.......q..'....q.......r......:r......Sr..!...lr.......r.......r.......r.......r.......r.. ....s......3s..%...Ns..(...ts.. ....s.. ....s.......s.......s.......t....../t......=t......Nt......at......pt..!....t.......t..6....t..4....t..4...,u..4...au..5....u.......u..,....u..-...(v..*...Vv..3....v..7....v..%....v.."....w......6w......Tw..+...sw.......w..%....w..$....w..%....x.."...&x..#...Ix..%...mx..#....x.. ....x.......x.......x.......y.......y......6y......Cy......Wy......iy......zy.......y.."....y..#....y.......y..%....z..#....z.."...Rz..#...uz..$....z..+....z..&....z.."....{.. ...4{......U{..%...q{..(....{..!....{.......{.......|.......|..+...5|......a|......z|.. ....|.. ...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Descrizione accessibile'
                                    Category:dropped
                                    Size (bytes):10825
                                    Entropy (8bit):4.824338692034769
                                    Encrypted:false
                                    SSDEEP:192:S5ewfslOvk0gqBURCySjGRuHQvVMd3pgZxhp9HZDlu5O:SYwUc80bBURCzjj/kHpxtf
                                    MD5:667FFE0CBC33462AC5813A5CC5AE46AF
                                    SHA1:5F86783C4F362753387A8B304B92B69883358E9C
                                    SHA-256:21850C4817C6A7D24B9BE092161156F8D50B099993D34FF99DF550487E05F2B1
                                    SHA-512:F20779A5FC550AB608B04778B74401787519C80E2DA45D61D78645B1759CC00C1E57753F44F5B9AEBB55D85CB8670F63325C3CF739378357D3C585B243579348
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf 'Un puntatore ai dati pixel del pixbuf'
                                    Category:dropped
                                    Size (bytes):24095
                                    Entropy (8bit):5.046749425997171
                                    Encrypted:false
                                    SSDEEP:384:yapC6chYqyZjFtcWDx8c0MYAqvch8Y0kjf099h+XTu0Vww0x65ycKLm256:yapC6cOzdcWDx8JpgBpsv6nH
                                    MD5:30977C0A3D9C5C1E01AC177FBDAAEEED
                                    SHA1:68C90E8228B97A0B8148BA457F18503088050304
                                    SHA-256:2B04B5F34FF7A910CED3B34C5517E8E83E4F75BC7F3D7965A8765D4768E1B55C
                                    SHA-512:68F96049C62EB6B096D3B54672EB729FD081D66ADC12383B7AD0929033634CCE045370BD718304027E1695E7D76263780958454CEF8B314A14A9EC2CB9B80699
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 29 messages, Project-Id-Version: gettext-runtime 0.19.4.73 ' -V, --version mostra le informazioni sulla versione ed esce'
                                    Category:dropped
                                    Size (bytes):5672
                                    Entropy (8bit):5.158511300750996
                                    Encrypted:false
                                    SSDEEP:96:qU1+tgQPMJ3Hlivn7vn8CJ6vOXt4AuvVjR6MJFngiFLngi777UYdICtAA4:qwOgQPMJ3Hli/7/avOdFGL6ibFb7XOCC
                                    MD5:D8ED72CFD78D89846E17EC6AEA5F2CED
                                    SHA1:BC898EAE36D71EF57DF13D8B317E93755691022D
                                    SHA-256:8D3D87343D0581B7791E717D3F7721E11205455BCAF51869AF2F24B0682BEDAE
                                    SHA-512:6ECB47B176705C7FADF1E7DC4A93A85B04C614C156D8F216FA54DCCE38156AF8BC03F570117638663C00F93EA7350C3D833EC4777C57E5BD043FA81FFB5EF482
                                    Malicious:false
                                    Preview:....................)...............B.......9.......M...........\...(...x...........e.......:...........O.......i.......H...................1.......&...3.......Z.......i..."...~...9.......I...........%.......................................................1.......=...L.......:.......P...M...........,...............u.......D...n...(.......................................1.......-...........%.......4..."...R...;...u...I.......................!.................................................................................................................................................................................................................... -V, --version output version information and exit.. -h, --help display this help and exit.. -v, --variables output the variables occurring in SHELL-FORMAT..%s: invalid option -- '%c'..%s: option requires an argument -- '%c'..Bruno Haible.Display native language translation of a textual message w
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 602 messages, Project-Id-Version: gettext-tools 0.19.4.73 ' (solo linguaggio C++)'
                                    Category:dropped
                                    Size (bytes):105947
                                    Entropy (8bit):4.9293611820453345
                                    Encrypted:false
                                    SSDEEP:1536:GRrZIgvB5IJ60wPDazRAN1pULTOfi4LLAUzIoryejZ7sOX8v4FB:OZG60wPmRAV6TOfiKUUzSal8v4FB
                                    MD5:CC270EC0907FB47A303A488BED25D238
                                    SHA1:C15DFF1EEE7465ABE853FFBFA477CB6D7C9F9903
                                    SHA-256:F60430BB4DEDE9F6B5DDFCA0E0ACBBC7997AE4F72705C8AFA86353A3FE4004C2
                                    SHA-512:83EA8DDAB7C7B34800F13D71CE744530804C68EB949D4CD21BC553B2E70727AC4BC9608DB7D3237D3FCB9761C80181B1C0B774709CB6821820000BD71375B01D
                                    Malicious:false
                                    Preview:........Z...........)....%......`2..4...a2..D....2.......2..&....3...... 5..6...<6..=...s6..z....6......,7..F....7..O....7..;...M8..<....8..L....8.......9..@....9..A...;:..A...}:..Q....:..Q....;..L...c;..K....;.......;..I....<.......<..:...k=..L....=..v....=..E...j>..L....>..4....>..P...2?..=....?..L....?..G....@..L...V@..G....@..=....@..J...)A..D...tA..@....A..:....A..L...5B.......B..K....C..G...bC..H....C..;....C..8.../D..9...hD..?....D..J....D......-E..@....E..>....E..:...-F..7...hF..8....F..;....F..5....G..M...KG..B....G..:....G..;....H..L...SH..:....H..P....H..p...,I..I....I..F....I..?....J..H...nJ..H....J..L....K..L...MK.......K..5...*L..<...`L.......L..>...)M..A...hM.......M......<N.......N..;...RO..O....O.......O..K...gP..I....P..;....P..u...9Q..8....Q..G....Q..I...0R..D...zR..s....R..B...3S..J...vS..2....S.......S.......T..M....U..F....U..:...(V..L...cV..N....V..4....V..H...4W..G...}W..|....W..@...BX.......X..:....Y..9...?Y..4...yY..:....Y..F....Y..,...0Z..-...]Z..9....Z..N...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' COMANDO Il comando (opzionale) da spiegare'
                                    Category:dropped
                                    Size (bytes):124440
                                    Entropy (8bit):5.2114813099255075
                                    Encrypted:false
                                    SSDEEP:1536:NZwEhPqhYOI5OhyO6JnLQwF5kg7cRU17DizPuOcgOZN3:NvVcYOI5Ot2LFF5kg7L17D0uOgN3
                                    MD5:437B8E189A094820267E940FE6E6478B
                                    SHA1:70101C8463379BA40F2A1910B3CB04D3CB178957
                                    SHA-256:13B9BCE2EF000CD55DEE5B80409276ABBE3D85C04574DAEE44CA3BAAF16FCD9D
                                    SHA-512:481F2D61AAC32E8F388AB129E42CD99FBF249914D1B8FBB9D81F0C7C0BEDFB1874BEAEF64C5CE4EF6E38E2C8028226BBA812E287699F28B2EEE314A0DBA5DA77
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1724 messages, Project-Id-Version: gtk+-properties 'Un GdkImage da visualizzare'
                                    Category:dropped
                                    Size (bytes):170013
                                    Entropy (8bit):5.041453396288932
                                    Encrypted:false
                                    SSDEEP:3072:uAahoAbPvS3RHsoljUYPGHPn1XtIlXwc4+b:rahPbPvsGoljUYPGPRSlAc4+b
                                    MD5:092C35E75E4A88E1531CAB71642A97CD
                                    SHA1:B393E202AE61381DF6858A974846303AF5FF8896
                                    SHA-256:2D4406C29ACF7E639FF32D7F2241F23DD1596864C89419C52075382FC636588E
                                    SHA-512:611C5063685B0741A0B89DCD9AE85E52795B12E15C0AB21DD8C74260F67E2F1345DB63A2BD0C63354A0CC194E277DE76EB9538E1BAE9A42A18E17828361A127A
                                    Malicious:false
                                    Preview:.................5.......k.................................e...5...C.......5......N.......Q...d...9.......0......*...!...<...L...?......._..........)...2...F...+...y...4.......,......Y.......N...a...N.......................8...8...5...q.../........................................................2.......B.......V.......l.......y....................................................................................................).......7.......M.......X.......b.......l.......x...................'............................$...........%.......:...D...L...A....... ......G...........<...5...k...).......&......G..........:...#...@.......d.......n...........................5..........!.......1...0...G.......x...=..........................................&.......;.......P.......`.../...n...........................#.......0..................$......./.......F.......N.......].......e.......}...5.........................................-.......H.......W.......o...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 868 messages, Project-Id-Version: gtk+ 2.24.x 'Non \303\250 possibile convertire \302\253%s\302\273 in un valore di tipo \302\253%s\302\273 per l'attributo \302\253%s\302\273'
                                    Category:dropped
                                    Size (bytes):57923
                                    Entropy (8bit):5.210724408876679
                                    Encrypted:false
                                    SSDEEP:768:gKJHhOHo1cNmqsiPEBjSQ8zCtWG9+0LzlWP9s/RDW5s6qPKPVPXFQMkgg:gKJHYHLNZsOEizC48WP9s/uq24gg
                                    MD5:44927F0087E80505F9FD0DF2B4A9AEE9
                                    SHA1:55434936DA9D404F5485C3B607F5B3C766C207A4
                                    SHA-256:B976386D20D12DAB558F1BFE73387A504729EB9970200EB393F466CD97C5270D
                                    SHA-512:DBF071609482226AEDFA90C513423D25B6CB7B22D452874797A32B96D18A9668A17CE5AE64463652B19F1816F5A56F24F50FA95D3E926D7E7B12F583310D0032
                                    Malicious:false
                                    Preview:........d.......<.......\6.......H..F....H.."....H.."....H..,....I......CI......\I......iI......oI......zI.......I.......I.......I.. ....I..7....I..)....I..4...(J..=...]J.......J.......J.......J.......J.......J..'....J..$....K..(....K..)...WK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...%L......VL......bL......nL..9...yL..6....L.......L.. ....L..0....M..5...KM..9....M..8....M..:....M..7.../N..2...gN..4....N..1....N..?....O..1...AO..?...sO.......O.......O.......O.......O.......O.......O..3....P......5P......CP......`P......}P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q.."...=Q..>...`Q.......Q.......Q.......Q.......Q.......Q..V....Q......8R.......R.......R.......R.......R.......R.......S.......S......,S......:S......GS......\S......nS.......S.......S.......S.......S.......S.......S.......S.......S.......T..+....T.......T..!....T..)....T.......U......(U..$...>U......cU..1....U..-....U.......U..!....U.......V.."....V......QV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview '.desktop'
                                    Category:dropped
                                    Size (bytes):32945
                                    Entropy (8bit):4.9863910962423015
                                    Encrypted:false
                                    SSDEEP:768:T6XjjsHi3hxg22+sEYkKjQCqofYtUmatdn1/6LCRzP7/oefA+/Lp+:T6Tjui3bckMIofYtratJIYXoK+
                                    MD5:ED1D6D04D3052A5D7AD9C6812ADA6104
                                    SHA1:32A7E07CDB7044E8CED7A5898E875B5077F122E7
                                    SHA-256:E66E11AD65F1F562B91CBE02984A53A4865BC60BF3E183DFD7C7E5DA56223311
                                    SHA-512:65C89F3FB8C83ACA41EC832ECC3E08F3473843850E83AE05AECD3B1165C6055884B6B3C8FA8E7218E5DC02A86DDFBC97BBF33208231B847F207123D7F8A2E16A
                                    Malicious:false
                                    Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 2828 messages, Project-Id-Version: it ' \303\250 un software libero rilasciato sotto GNU GPL.'
                                    Category:dropped
                                    Size (bytes):217671
                                    Entropy (8bit):5.302786594082807
                                    Encrypted:false
                                    SSDEEP:6144:xNHQM5TIIwb3qd4QjReOgqy5j1hleGzTtA+:tTg3q36leGzBA+
                                    MD5:C1379C0E484678E1876E1554DDC79325
                                    SHA1:D5766B69E06A4739D5E1093FA970C0641EF3A2B2
                                    SHA-256:D13981BAE49E00C29ACF0A48413B7FAD2C81F11CEE67A83A8EC4B2426481AAA7
                                    SHA-512:80E038E456155C77A89A9EF3B8A87C7705D9EFBB7311EFF43E2C0C889CE80E02BA1CAF33EB0A6AD13AF205BF1239B96EE670D770D8ED8CF2FAFDC602EB8697C1
                                    Malicious:false
                                    Preview:................|X.................)................... .......4.......P...,...a...........%.......D...................%.......E...&...^...%.......................................$...............'...6.......^...!...y................... ...................................!.......4.......C.......U.......m...........................................................%.......#...A...$...e...+.......&.......".......%.......+...&... ...R... ...s...........................#...............'....... ...?.......`...$...}...#.......(.......".......................!...H...'...j........................... .......#...................9...&...Q... ...x...................................!...................:... ...Y... ...z... .......,.......(.......!...........4.......T.......i.......{...................................................!...........=.......O.......m...................................................................$.......!...'...&...I...2...p...(.......%.......-.......+... ...+...L...5...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 140 messages, Project-Id-Version: atk master '\343\202\242\343\202\257\343\202\273\343\202\271\345\217\257\350\203\275\343\201\252\350\252\254\346\230\216'
                                    Category:dropped
                                    Size (bytes):9964
                                    Entropy (8bit):5.518032919494422
                                    Encrypted:false
                                    SSDEEP:192:oWtewPH61vNqFKxrsC+/GXvR2Too4/tqsJ2og:or4WXrsCCERs6Uskog
                                    MD5:912393130B94993B26D2D9D0A9392751
                                    SHA1:34E373ED93B53AF2FF4798C0E543756FEF908EDD
                                    SHA-256:B0423565F5583DEA6A0804BBBA6917D1C0C0619DF371A678F7D096C0FECF092B
                                    SHA-512:204F9178810C6DDB738E8025EFCF473DC2F4EEB6A7897063CA05ADC46CFE4C9F8D4FA7FB4CED82ED670DF53139B2E37F0FE2316ECF11FBD45DD95C95DE5CA5B2
                                    Malicious:false
                                    Preview:................|.......................................................&.......8.......H.......a...#............... ...............................C...+.......o...-...y...4...............?...k...:.......<.......7...#...4...[...,.......$...............B...........7...5...E.......{...'.......#.......".......(.......=.......6...]...*...................................................................................................(.......8.......F.......T.......^.......f.......q.......................................................................................................!.......4.......:.......G.......N.......Z.......a.......f.......l.......w.......................................................................................................................................................%......./.......<.......H.......M.......V.......d.......j.......t...............................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 203 messages, Project-Id-Version: gdk-pixbuf master 'BMP \347\224\273\345\203\217\343\201\256\343\203\230\343\203\203\343\203\200\343\203\274\343\201\256\343\203\207\343\203\274\343\202\277\343\201\214\344\270\215\346\255\243\343\201\247\343\201\231'
                                    Category:dropped
                                    Size (bytes):25288
                                    Entropy (8bit):5.791552083597433
                                    Encrypted:false
                                    SSDEEP:384:po3P6gzufduW02j8cAxmXmX6BBA0PEY2ZD+BEY98U:p06YuKSEY2ZU
                                    MD5:760D49D3F26E252356B2FAA9F71391CA
                                    SHA1:3DDCDC88B975F5D0894F9D3D5877DCDE091DB449
                                    SHA-256:86F709BD79369E52F11B0DD4101B6CA6C482DD5DCD3B8AD198EAE493DF5E1582
                                    SHA-512:F07908460723CCA62B438C387DAE4448BD02685F7D31A157FFB7E53966F6FC181D737CFD2F7D4780C3832BD85BD0181D3A7AC526DDF423DF91BFB4733CC9984B
                                    Malicious:false
                                    Preview:................t...........................%...).......O...)...d...-.......!....... .......".......(..."...*...K...-...v...,.......,...............'...........A.......Z... ...w...$.......&......."...................%.......A...*...\...).......................&.......*.......+...<...#...h...&...............,.......#.......-...3.......a.......|...................6...................................5.......Q...!...n...".......'...................................6...`...J...*.......N.......(...%..."...N...&...q...........R...............J...#...#...n..................................."...........%...Z...?...........8.......8...........&...!...>..."...`...&.......%.......%.......B.......N...9...0...............&...................$... ...8.......Y...%...n...........-...........................................<..."...U... ...x...".......o.......7..., ......d ..$.... ....... ..$.... ..*.... ..O...'!..*...w!..%....!../....!..-....!..e...&"..%...."..r...."......%#......6#......I#......e#..J...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: GNU gettext-runtime 0.20.2 ' -E (\270\337\264\271\300\255\244\316\244\277\244\341\244\313\314\265\273\353)'
                                    Category:dropped
                                    Size (bytes):8529
                                    Entropy (8bit):5.966358131691811
                                    Encrypted:false
                                    SSDEEP:96:TDHD9cdxxwKTurZb9lHlivn7vn8CJ6vO1At4g+SbGm0pwMfiV+5eTgR5Ukt/8:TDCxxlurx9lHli/7/avO1izXkUx
                                    MD5:BF38A296ACA2860708F16B653ABA313A
                                    SHA1:B23DCA3BC4AAA1399A2C3005EC9C9B41FEADBA4E
                                    SHA-256:07E6C9677BD281B34E506DD7901B7E58AAAEA405C3887F6485CE5C6C0FF56DD3
                                    SHA-512:962C23CF7376EDE8D3BE8C4E52869BC9E5769AB14CAF3D2D16A942CFD681FDA8DC6494431F6BE403BC6F54228203FFBEABAF1FA81BA47BEC6307BF1071D9DA9C
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................1.......;.......9...?...=...y...J.......J.......I...M...7.......5.......-.......;...3...E...o...J.......J.......x...K...........).......!.......-.......)...\...#...............................F...k...$.......................*.......................E...........>...=...S...................%.......>.......S.... ..m...n ....... ....... ....... .......!......(!......1!......B!.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: GNU gettext-tools 0.20.2 ' (XML\245\331\241\274\245\271\244\316\270\300\270\354\244\316\244\337)'
                                    Category:dropped
                                    Size (bytes):109793
                                    Entropy (8bit):5.853754584632392
                                    Encrypted:false
                                    SSDEEP:1536:wAIeeoeIhzICqQwPDaHxA421GcSTOJjO/5Sc6uT24ADdMQ3i:8eVBqQwP6xA4PnTOJ6/Ec6Y24auQ3i
                                    MD5:A71F1DBB3C90F31D254AB51F9980703B
                                    SHA1:5C65EC12A7DCB95A195D97108E04E954558180D5
                                    SHA-256:9B6A81BC68888754A901B910EE8A338FC8D6D8FBDB0C27D140B9342975A80784
                                    SHA-512:8C61F2617CD939ED32C9BD8DCE5B701D3F5BC0AF616AA0D2CE95AC1C398F144A99268680592A907E3160DC95E15A1F612C3FB7FCDE50A59B77B8446B28AEF3C0
                                    Malicious:false
                                    Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 648 messages, Project-Id-Version: glib glib-2-28 ' COMMAND \345\257\276\350\261\241\343\201\256\343\202\263\343\203\236\343\203\263\343\203\211 (\344\273\273\346\204\217)'
                                    Category:dropped
                                    Size (bytes):82470
                                    Entropy (8bit):5.866943687121482
                                    Encrypted:false
                                    SSDEEP:1536:LPfNBpGHOAAXQ4w3eGTT379GcU8H/3aUv:L5GcXLcxTT379I8faUv
                                    MD5:222DF600434C42BA72FAE2ED5C1C628D
                                    SHA1:E70609F76AE3E5715210A982BE29EFF91C274DFB
                                    SHA-256:D8E6956938F1B4BC964A0183B73178D55F643D375264056EA9F16479A2CE370E
                                    SHA-512:662F83F4F46B774A284767C5E6C84889A73E0317A7609577CBCBC090677699E6ABE4B40724B72B3AA90279FC59BFC8BC495A5F9E8F73090FC44C81161C5934DE
                                    Malicious:false
                                    Preview:................\...m....(......P6......Q6..1....6..&....6..Q....6..9...+7......e7.......7..&....7.......7.......7.......7.......7.......7.......7.......7.......7.......8..Y....8.._...m8..a....8..).../9..<...Y9.......9..!....9.."....9.......9.......:..#....:..!...R:..[...t:..&....:..4....:..a...,;.."....;..J....;..&....;..$...#<......H<..!...g<.......<..K....<..U....<..8...B=......{=.......=..+....=..(....=.. ....=.......>.......>..)...6>..#...`>..#....>.......>.......>..2....>..9....?..!...G?..4...i?../....?.......?..+....?..1....@..-...C@../...q@..#....@.......@.. ....@.......@..(....A..=...@A..,...~A.......A..^....A..a...'B..B....B.......B..+..._C..%....C..&....C.......C.."....C..1....D..0...HD.."...yD..)....D..!....D.. ....D..A....E......KE.......E.......F.......F.......F.......F.......F.......G......1G..;...QG..#....G..*....G.......G.......H..*...$H......OH..&...YH.......H..$....H.......H..4....H..$....I..&...:I..a...aI..F....I..4....J..2...?J..:...rJ..A....J..@....J..;...0K..W...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1714 messages, Project-Id-Version: gtk+-properties gtk-2-22 '\350\241\250\347\244\272\343\201\231\343\202\213 GdkImage \343\201\247\343\201\231'
                                    Category:dropped
                                    Size (bytes):180122
                                    Entropy (8bit):5.869888259674955
                                    Encrypted:false
                                    SSDEEP:3072:XqR0lZnREfN9qS3RX49XjUYPTt25o7EeqmCro1vmmlso9uOuTiLNvF:XE0lZnRENUsy9XjUYP4kCro1viw
                                    MD5:7D31107FE2363C922BBD7EFC66956485
                                    SHA1:496092E2E1D782AB36124EEE38EF877D605D9891
                                    SHA-256:949A73A630256FD2F665119847296F05C2CF5E8BCD773076D34490730BCB7BB8
                                    SHA-512:E12DE79EF8E9CAA3C655D66D15E730B682444E95ADEB88BA2AB9D267843F5A047240E3EAF51F75B21CC7EC9150219BD423CEFB94FD3516C5A50F394B3A666249
                                    Malicious:false
                                    Preview:.................5......<k..............................&...e...=...C.......5......N.......Q...l...9.......0.......*...)...<...T...?......._..........1...2...N...+.......4.......,......Y.......N...i...N..................."...8...@...5...y.../.................................................'.......:.......J.......^.......t...................................................................................................#.......1.......?.......U.......`.......j.......t...........................'............................$...........-.......B...D...T...A....... ......G...........D...5...s...).......&......G...........B...#...H.......l.......v..........................5..........).......9...0...O...........=..................................#...............C.......X.......h.../...v...........................#......0..................,.......7.......N.......V.......e.......m...........5.........................................5.......P......._.......w...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 862 messages, Project-Id-Version: gtk+ gtk-2-24 '"%s" \343\202\222 "%s" (\345\261\236\346\200\247\343\201\257 "%s") \343\201\250\343\201\204\343\201\206\347\250\256\351\241\236\343\201\256\345\200\244\343\201\253\345\244\211\346\217\233\343\201\247\343\201\215\343\201\276\343\201\233\343\202\223\343\201\247\343\201\227\343\201\237'
                                    Category:dropped
                                    Size (bytes):61803
                                    Entropy (8bit):5.887837117731422
                                    Encrypted:false
                                    SSDEEP:768:A4j11v5tjTngKfWJ4vyaY55oEKKKBjSQ8zCLlG9+0HWzXxIJIgdAT0Ed:ApKfWJ4vyaY5SNizCZeWrxmAIEd
                                    MD5:A088DA5F8386E1D741284432A93795C7
                                    SHA1:4CBC9AD610A29E6DBB9E67AE178642D7324ADE27
                                    SHA-256:79E4962387F1735A7FCBA9380B26407DA6F1A00C475F130D44AE9C454A100DE9
                                    SHA-512:823D1914AAF7EE9936662C3BC90ED0E4D8B2BEDAA30EBBF09B0979CE8F1474EAA4C43C27E35BD1B969753A9CE78B41C7BC5859590347FBCBC4646A6D16F8AFB1
                                    Malicious:false
                                    Preview:........^................5.......G..F....G.."...@H.."...cH..,....H.......H.......H.......H.......H.......H.......H.......H.......I.. ....I..7...6I..)...nI..4....I..=....I.......J.......J.......J.......J......BJ..'...QJ..$...yJ..(....J..)....J.......J.......K.......K.......K.......K.."...,K..#...OK..!...sK..0....K.......K.......K.......K..9....K..6...#L......ZL.. ...iL..0....L..5....L..9....L..8...+M..:...dM..7....M..2....M..4....N..1...?N..?...qN..1....N..?....N......#O....../O......4O......=O......DO......QO..3...qO.......O.......O.......O.......O.......P.......P......&P......,P......3P......<P......DP......MP..!...[P../...}P.."....P..>....P.......Q......'Q......7Q......?Q......FQ..V...QQ.......Q......>R......GR......MR......]R......iR......vR.......R.......R.......R.......R.......R.......R.......R.......S.......S.......S......#S......6S......ES......^S......sS..+....S.......T..!...2T..)...TT......~T.......T..$....T.......T..1....T..-...$U......RU..!...hU.......U.."....U.......U......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 439 messages, Project-Id-Version: gtksourceview trunk '.desktop'
                                    Category:dropped
                                    Size (bytes):27375
                                    Entropy (8bit):5.688906548954756
                                    Encrypted:false
                                    SSDEEP:384:s662m34TILtXi44V80/WVLDhH56wMgzhLnod93eIlj+K/OJ0ZsMdRBqVzYNgEIxZ:f2i4EWLYHMboXOIBf/fndRB2mrXzgn
                                    MD5:568AA478F69A09BA9DB0F0DACC9002C1
                                    SHA1:8594AF2EC3379537995050027D30645AD1DFA5CF
                                    SHA-256:D35C2087BBBAF768B87CD5C3E930104973DADA9859825C5E56385E4BE7737177
                                    SHA-512:BCF106304B7B89B1D9FA8F25D125DD0D4463C1340139208641A41CFB45534B06007DE8F38DF5A760D14A4B1A61BC042F6FD0DCFB0CE5650AC86FCB6BEA07579C
                                    Malicious:false
                                    Preview:....................K............$.......$.......$.......$.......$.......$.......$.......$.......$.......%.......%......&%......:%......U%......Z%......o%......~%.......%.......%.......%.......%.......%.......%.......%.......%.......&.......&......!&....../&......G&......V&......[&......d&......h&......p&......~&.......&.......&.......&.......&.......&.......&.......&.......&.......'.......'.......'.......'......#'......5'......E'......K'......O'......X'..{...a'.......'.......'.......'.......'.......(.......(......$(......+(......6(..)...<(..&...f(.......(.......(.......(.......(.......(.......(.......(.......(.......(.......).......).......)......,).......)......6)......=)../...A)......q)......{).......).......).......).......).......).......).......).......).......).......).......).......).......).......*.......*...... *......0*......8*......N*......l*......v*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 3820 messages, Project-Id-Version: Gwyddion ' is free software released under GNU GPL.'
                                    Category:dropped
                                    Size (bytes):310410
                                    Entropy (8bit):6.055057784662882
                                    Encrypted:false
                                    SSDEEP:6144:lkBmi27w1Yib77Wy5HB7NJWkX1CUBMmzN7pOoItXs:lY2w77/rgUSmzN7pOoItc
                                    MD5:3A978042A287194BB75A8F1DA8860BFC
                                    SHA1:275A9B896794D399D96B839888E4B3F405B93360
                                    SHA-256:9FDBF20DC50EFB2AE8869E30F0E656D49922C5D23102FCDDD7B46FB7FE569E88
                                    SHA-512:DB0B850F39609D1A966D5D67BF1B8A5C711F28D39838078C4DB10119DE6735E4F835B5EBF8660D12FC0831F0E8451666678AE1E44706C15FB7BA5DFC261029A7
                                    Malicious:false
                                    Preview:................|w...............>..)....>.......>.......>.......>.......>..,....?.......@..%...G@..D...m@.......@.......@.. ....@.. ....@..$....A..$...@A......eA......mA.......A.......A..&....A..%....A.......B.......B......3B......>B..$...PB.."...uB.......B..'....B.......B.......B.......C..!...)C......KC......fC.......C.......C.......C.. ....C.......C..%....D..(...1D.. ...ZD.. ...{D.......D.......D.......D.......D.......D.......E.......E......-E..6...?E..4...vE..4....E..4....E..5....F......KF..,...zF..-....F..*....F..3....G..7...4G..%...lG.."....G.......G.......G..+....G.......H..%...4H..$...ZH..%....H.."....H..#....H..%....H..#....I.. ...6I......WI......oI.......I.......I.......I.......I.......I.......I..#....I......#J..%...AJ..#...gJ.."....J..$....J..+....J..&....J.."...&K......IK..%...eK..(....K.......K..+....K.. ....K.. ... L......AL......aL......~L..!....L.......L..#....L.......L.."....M..'...)M.. ...QM......rM..$....M..#....M.......M..(....M.."....N..$...BN..+...gN.......N..$...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk '\354\240\221\352\267\274\354\204\261 \354\204\244\353\252\205'
                                    Category:dropped
                                    Size (bytes):10235
                                    Entropy (8bit):5.523398594530372
                                    Encrypted:false
                                    SSDEEP:192:S5ew9r6EvAlowxwqBURCySjGDwzZaEhpP8GM3LsU+6Yvq:SYwRJvAltBURCzj73pPqLUi
                                    MD5:6565CD8D6F957893C3314F34FD9E60B8
                                    SHA1:1DC9E1EDA4A4931234FBA6C71D6C2598D00F517C
                                    SHA-256:E4EDB2A8CFD93F97899B9B51CABEAB7B7F005A1BFA044EDC0300B531D8CA6787
                                    SHA-512:F5BB3B9CD79B6094DB53D32AF2872572CE23EE793A176418CA47A1B9017B6CB4982F75069D673CCAD09A6033AFDEB1524039E0B3CD4F77B163FD0D1ADF5D036F
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf '\355\224\275\354\205\200\353\262\204\355\215\274\354\235\230 \355\224\275\354\205\200 \353\215\260\354\235\264\355\204\260\354\227\220 \353\214\200\355\225\234 \355\217\254\354\235\270\355\204\260'
                                    Category:dropped
                                    Size (bytes):25118
                                    Entropy (8bit):5.8827262911764855
                                    Encrypted:false
                                    SSDEEP:384:yapCWIj37nH0jFtcWDx8c0MYAqvch8Y03xiT2Iu1Owt6fU:yapCWIjrkcWDx8JpgB2xicR
                                    MD5:CA6769DF81A20C89FCCCB8F0E4CEB8B9
                                    SHA1:306BBA9C872FA2CA06877689E8B4FC419579EAF3
                                    SHA-256:32181FDAB6C1E0ADA6C7023AE307BC8C329FD7260C43F39AA3FBC956C2137EB9
                                    SHA-512:5348680EFCAFA1FAF45F779CF1B912A7995D2F40116C58AC947922BFCD1ED3B209C57E22FED6D5843AED1543FC4CBD362BC38B197CA81BE3701BE906F0DDF508
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: GNU gettext-runtime 0.20.2 ' -E (\354\225\204\353\254\264 \355\232\250\352\263\274 \354\227\206\354\235\214, \355\230\270\355\231\230\354\204\261 \354\230\265\354\205\230)'
                                    Category:dropped
                                    Size (bytes):9059
                                    Entropy (8bit):5.897092934389264
                                    Encrypted:false
                                    SSDEEP:192:T7dxxlurx9lHli/7/avO1izEvf2XyJtCmfHierk4ygwg:TvABFADWO1izEWiJUmfHierk4ygwg
                                    MD5:2EB43DE2274B52D789416364A850BD1F
                                    SHA1:151F00BCA0277F73F8941C192311DC4781554721
                                    SHA-256:79EEE949883F5FF651AC9A3B6E73D9754B863262A225817DBBE441E6FF9D3A59
                                    SHA-512:882748793EBEC77D3898A18A993727C928D841577FDC3069848636E1EC14C17247CD6D809BAB396B3DCD776F19D55AF87D80AF390EB42CEC168B467AE5520482
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................E.......I.......G...Y...J.......S.......S...@...P.......I.......G.../...E...w...R.......W.......Z...h...R.......................9......./.......D...&.../...k...4.......'.......................o.......F...O...!...........................A ......Q ..^...a ..&.... ..9.... ......!!......0!..(...P!..H...y!..Z....!......."......."..(....".......".......#....../#......=#......U#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: gettext-tools 0.20.2 ' (XML \352\270\260\353\260\230 \354\226\270\354\226\264\353\247\214 \354\247\200\354\233\220)'
                                    Category:dropped
                                    Size (bytes):122891
                                    Entropy (8bit):5.832110677535913
                                    Encrypted:false
                                    SSDEEP:1536:wAIAiydRhzICqQwPDaHxA421GcSTOJjOUHXstDM+8+pYRNZIXpk0JA8962/KXnpI:8AiytBqQwP6xA4PnTOJ6UWDM7g/P
                                    MD5:8D6DE35F8C27D2F524FE22C809EFEF0B
                                    SHA1:1991C5F02CD6770972318B80A851D2E411049994
                                    SHA-256:475AE09E2BFED1420D891E0A3594A98B37DE4DAFFEE5C27535AC483E2F769047
                                    SHA-512:B427918BFF0C5F74E78A0B71C1272A0094E30ABAE0567875D603DA81C02C78A0F69D3911A5419FC5CBC871862A68A33113248DD520E0C89EAF8B6B6F4C69C412
                                    Malicious:false
                                    Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' <\353\252\205\353\240\271> \354\204\244\353\252\205\355\225\240 \353\252\205\353\240\271\354\226\264(\354\230\265\354\205\230)'
                                    Category:dropped
                                    Size (bytes):131376
                                    Entropy (8bit):6.004169772817626
                                    Encrypted:false
                                    SSDEEP:1536:NZwE4AXZVsvw2O6JnLQwF5kg7cRU17Di7J6Wez+VGrKN60xyVPf1421tPf2E/Ykk:NvFKIr2LFF5kg7L17DYJ6n+gKN62b
                                    MD5:C0AB2DE931B2774E058F985765EFC42D
                                    SHA1:C43C2122C4A22191F161F6101CF03EB9343D1983
                                    SHA-256:953575AB179038132062F2A60BA8E0340B43F512E32258C56CFA51A0939F1F22
                                    SHA-512:A3920E1FFD8732BE0F1EE5F4FA860823991B919E4DCE2C592A2ABD0E1BDF58E73016A5FD35DA4B0A4A2EFDFCD9E3AC1558FEAF23920893290D5D745F518D50DE
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+-properties.HEAD '\355\221\234\354\213\234\355\225\240 GdkImage'
                                    Category:dropped
                                    Size (bytes):162384
                                    Entropy (8bit):5.9156735973544174
                                    Encrypted:false
                                    SSDEEP:3072:em1YvN/CFT9zIyS3RH49ljUYP1nHtAVh7cC9:n1WBCFTBIysy9ljUYP1nKhQg
                                    MD5:2FB3BD761F9E0EC26B7C27918FECEECA
                                    SHA1:E093A043FBD09C859617BD1558D756D122B7590B
                                    SHA-256:A42C05EE3AD3D2F35ECD62CEACC21D126119E1BF7F803FE6D9091A723B1E88BA
                                    SHA-512:D8BACABE2FDDD44B7C1A2E480EB6B49AC8CB37CE99883F7E05A8B9D3E9BC108E2D0609266BD91E81C238AC4E2C47571D7251245635B73E83947FED91C721848E
                                    Malicious:false
                                    Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 867 messages, Project-Id-Version: gtk+ '"%1$s"\354\235\200(\353\212\224) "%3$s" \354\225\240\355\212\270\353\246\254\353\267\260\355\212\270\354\235\230 "%2$s" \355\203\200\354\236\205\354\235\230 \352\260\222\354\234\274\353\241\234 \353\263\200\355\231\230\355\225\240 \354\210\230 \354\227\206\354\212\265\353\213\210\353\213\244'
                                    Category:dropped
                                    Size (bytes):59727
                                    Entropy (8bit):5.879539153893844
                                    Encrypted:false
                                    SSDEEP:768:5m5vRUx/B4SMcVbvkHLHBjSQ8zCtWG9+0nR7kaGNAhPjGpFODZj:5mXUvBMcV7kzizC44kaGNAhbSij
                                    MD5:BC85A9421177EF7B8239F7D9A7C589DA
                                    SHA1:5179F7FED24BD2DB14CBEFAD8C81DA258E43C184
                                    SHA-256:93FC45E2385A4899E902811BB4274BBA41D420A43062786F038FD0A084824910
                                    SHA-512:D5301DEDC5F76FC405EC5DE4C37AABAFC7928EC6DE862514CB5654392D98430E9F736966B48AAD8761187BECEB95D68A9BC12B15436DC7F4084B8711101D9DE3
                                    Malicious:false
                                    Preview:........c.......4.......L6......xH..F...yH.."....H.."....H..,....I......3I......LI......YI......_I......jI......qI......|I.......I.. ....I..7....I..)....I..4....J..=...MJ.......J.......J.......J.......J.......J..'....J..$....J..(....K..)...GK......qK.......K.......K.......K.......K.."....K..#....K..!....K..0....L......FL......RL......^L..9...iL..6....L.......L.. ....L..0....M..5...;M..9...qM..8....M..:....M..7....N..2...WN..4....N..1....N..?....N..1...1O..?...cO.......O.......O.......O.......O.......O.......O..3....O......%P......3P......PP......mP.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....P.."...-Q..>...PQ.......Q.......Q.......Q.......Q.......Q..V....Q......(R.......R.......R.......R.......R.......R.......R.......S.......S......*S......7S......LS......^S......tS.......S.......S.......S.......S.......S.......S.......S.......S..+...sT.......T..!....T..)....T.......T.......U..$....U......SU..1...rU..-....U.......U..!....U.......V.."....V......AV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 449 messages, Project-Id-Version: gtksourceview '.desktop'
                                    Category:dropped
                                    Size (bytes):25802
                                    Entropy (8bit):5.626747785647055
                                    Encrypted:false
                                    SSDEEP:384:yXRUsq8b5Uxw2BBXMA3BKgzhLnod95HeBlQ+2/K/qvDINb0AIDC2XCwSo/E5d:Ib5UremKMboX5+Bi+2i/WINerSwdEL
                                    MD5:B3ECBEF13ECEFAB04A27890F2D5894E4
                                    SHA1:B2A9F9CAA844828E6B0ACA759A33D683528E0082
                                    SHA-256:A6B30DF7EAE0024DE09BE09EDF969B77D49A7F92C971EFF158B493660A06044F
                                    SHA-512:0099AE77451E95A8A50E2BE998EA7C96F1BD1DAB748E5D7F08B6878ACC672ECB1111369569B1F367F5354129AD40D8ABD31C745E1F44196DF185B81A5A4CE22D
                                    Malicious:false
                                    Preview:................$...W...,........%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......&......%&......*&......?&......N&......^&......m&......}&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......'......&'......5'......:'......C'......G'......O'......]'......k'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......(.......(......$(......*(.......(......7(..{...@(.......(.......(.......(.......(.......(.......(.......).......).......)..)....)..&...E)......l)......t).......).......).......).......).......).......).......).......).......).......).......*.......*.......*.......*../... *......P*......Z*......d*......i*......o*......z*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+.......+......-+......K+......U+......a+......p+......w+.......+.......+.......+.......+.......+.......+.......+.......+.......+.......+.......+......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 583 messages, Project-Id-Version: gwyddion '\354\235\200 GNU GPL\352\270\260\353\260\230 \353\254\264\353\243\214 \355\224\204\353\241\234\352\267\270\353\236\251\354\236\205\353\213\210\353\213\244.'
                                    Category:dropped
                                    Size (bytes):35057
                                    Entropy (8bit):5.750768121478152
                                    Encrypted:false
                                    SSDEEP:768:JQSg1GH/tZQcZlZL7cbxqPSG8pXL5MjbYODh:JlmGHFacZ/cbYiXWJh
                                    MD5:A0A57F1B6D87B4D85309A83F7C2167A8
                                    SHA1:1C29E1C07FAB980BA39B1035FEADFDA265B8235C
                                    SHA-256:4EF33D66268119C7E7CCFF5F26F964C8092DEE4234707079CE28424F496E2500
                                    SHA-512:46A8F697E78F01184E20DC28E5065D18DBFAC85CACC8F61F204C36074B1911C9938774B55C3EDD1B2AF313831FD7FC216AF8D02A0E24BC8D5CAC0281CBBC1A76
                                    Malicious:false
                                    Preview:........G.......T........$.......0..)....0.......1.......1......!1......A1..&...Z1..%....1.......1.......1.......1.......1.......2.......2...... 2......22......?2......S2......d2.......2..%....2..#....2..$....2..+....3..&...;3.."...b3..%....3..+....3.. ....3.. ....3.......4......64..#...R4..#...v4.......4.......4.......4.......4.......4.......5.......5......75......L5..!...e5.......5.......5.......5.......5.......5.......5.......5..#....5.......5.......6.......6.......6......,6......=6......K6..'...\6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......7.......7.......7.......7......37......J7......R7......b7..9...w7.......7.......7.......7..+....7.......8..-....8......J8......h8..!....8..!....8.......8.......8.......8.......9.......9......)9......;9......M9......g9......y9.......9.......9.......9.......9.......9.......9.......9.......9.......9.......9.......:...... :......+:......;:......A:......P:......f:......z:.......:.......:.......:.......:......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Descri\303\247\303\243o acess\303\255vel'
                                    Category:dropped
                                    Size (bytes):10583
                                    Entropy (8bit):4.919373241321581
                                    Encrypted:false
                                    SSDEEP:192:S5ew6jg4VG3ooGltk3qBURCySjGAoAeReRyGX0OUg70PyVN:SYw33oomkaBURCzjThX6i
                                    MD5:68E2977FB423665D3D064FD16F6E3C51
                                    SHA1:A214793EBDCCD515CC190972AA385241CE830120
                                    SHA-256:74DC425DA17BF9A6092842147EABE694836DDF58BC72F5AE060D8EF4512C476C
                                    SHA-512:D35A94C38AB7CA157AB7A2BD802EEA0C2BB2A556C9C9950D7A1825519B2FF9FEC4F8D69905B6CBABA5FADD600ED6984330E58E6B834242DF24EF1C558B079438
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf 'Um ponteiro para os dados de pixel do pixbuf'
                                    Category:dropped
                                    Size (bytes):23881
                                    Entropy (8bit):5.119815589307243
                                    Encrypted:false
                                    SSDEEP:384:yapCHxjFtcWDx8c0MYAqvch8Y0fLoHu+7SemeyBkqJDo6:yapCHFcWDx8JpgBOoH6gaD/
                                    MD5:3574A52E5E1D20D5A12D2394D2928931
                                    SHA1:9204325BE6250C3153201E6F6C7D27A654B206EA
                                    SHA-256:8715B7D44F80083437AEBDC0CCC0B0BA20DD7CEC6AC8E1F7EDE7711F36661437
                                    SHA-512:EC8C6D7A90D58607DEFE8F1976E41A11576CDD716A4A642B0A3815F4F2A4B0B0412126639D252737E82852F2C67954EA6AA8AB23DEED69770F2FCAB18AE9A582
                                    Malicious:false
                                    Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (ignorado por quest\303\243o de compatibilidade)'
                                    Category:dropped
                                    Size (bytes):8983
                                    Entropy (8bit):5.229725788115492
                                    Encrypted:false
                                    SSDEEP:192:TF0xxlurx9lHli/7/avO1in5eDwuaFiwGwb/G1q4sM0TF:TFeABFADWO1in5ezvsMIF
                                    MD5:BF505D1B3EE9270C7957D0966B46E80D
                                    SHA1:31480A14A1D15ACF98039925B7ACE7E5BAA55FCA
                                    SHA-256:B8A6FEBCE5B924E6C1DED8AA98B4BC538823AE61565693032AED094747C60669
                                    SHA-512:88C6AA73B8B73E89178BA56E2FDECC9D94CFBF5D2267182A281323CABCDACDB08855FD0D190F05F74D5F3251C66A752A291B6E4F7E170B1366ADD28206073276
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................G.......D...N...B.......;.......H.......J...[...P.......5.......3...-...8...a...M.......P.......M...9...H.......{...........L.../...k...!.......1.......(.......)....... ...B.......c.......p...g...e...;.......6...........@.......>........ ....... ......+ ..1.... ..+.... .......!......&!.."...C!..=...f!..J....!.......!.......".......".......".......".......".......".......#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 699 messages, Project-Id-Version: gettext-tools 0.20.2 ' (apenas linguagens baseadas em XML)'
                                    Category:dropped
                                    Size (bytes):121234
                                    Entropy (8bit):5.039990419882178
                                    Encrypted:false
                                    SSDEEP:3072:p70QgbcqQwP1xuuInTOy6Gm5RUAKttLnnMnJiYFcKa5rHsuBQ0KbcJEHmLQ8v:pgkNwPAq5RTH6Xv
                                    MD5:8C4CC15F94739A8F51FE91D0C52D24E8
                                    SHA1:9329048FAE51EA473CF2BAD39A5BDF3155C88B45
                                    SHA-256:2235AAD8CA2D418973613527D39166F20679FECCBFC574FFDB9ECDF2182DC94A
                                    SHA-512:762AF8603458F85B966EDDBC48B2940109A4BA12092DB29A727A532453EF9D76F2086BBB17FE04B27C4D3E69AF8E1531C6BD516011C68A4E8A5E894B41FAB371
                                    Malicious:false
                                    Preview:.........................+......p:..;...q:..4....:..D....:......';..&...E<......l=..6....>..=....>..z....>......x?..F....@..O...I@.......@..;...\A..<....A..L....A......"B..@....C..A...JC..A....C..Q....C..Q... D..L...rD..K....D..K....E......WE..I....E......>F..L....F..:....G..L...NG..v....G..E....H..L...XH..4....H..8....H..9....I..P...MI..=....I..L....I..G...)J..L...qJ..G....J..=....K..J...DK..D....K..@....K..:....L..L...PL.......L..K...1M..G...}M..H....M..;....N..8...JN..9....N..?....N..J....N......HO..@....O..>....P..:...HP.......P..7...>Q..8...vQ..;....Q..5....Q..M...!R..B...oR..:....R..;....R..L...)S..:...vS..P....S..p....T..I...sT..F....T..?....U..H...DU..H....U..L....U..L...#V......pV..5....W..<...6W..:...sW.......W..>...:X..A...yX..=....X.......X.......Y.......Z..;....Z..O....Z......-[..K....[..I....\..;...L\..C....\..u....\..8...B]..G...{]..I....]..D....^..s...R^..B....^..J...._..2...T_......._..D....`......\`..M...ka..F....a..:....b..L...;b..N....b..4....b..H....c..G...Uc..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' COMANDO O comando a ser explicado (opcional)'
                                    Category:dropped
                                    Size (bytes):124031
                                    Entropy (8bit):5.290274987230353
                                    Encrypted:false
                                    SSDEEP:1536:NZwE1sAUgfFfO6JnLQwF5kg7cRU17DiBOQ9ADVIClXO52iifkRkfC89:Nvxc2LFF5kg7L17D7QylXO5BM
                                    MD5:A22D63AAF558C85358C4D25F0DA3A843
                                    SHA1:2238B6AE1AE3773E29C96C5E9266F866C803BF5E
                                    SHA-256:12D9EE4F2BD4671A02D30A4866F13559A3ECAEC5CC7CBEDA475043E7AECDCD59
                                    SHA-512:EC445AF3485643AB55482F00C302B22FFE0CBBF0A8E2ECF5AC40DE29C2156CF89AD1E77EC3884D831ED5ACC2A97570879E55E2048DC89B96225A63242015459B
                                    Malicious:false
                                    Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+ 'Uma GdkImage a ser exibida'
                                    Category:dropped
                                    Size (bytes):163995
                                    Entropy (8bit):5.128043244037343
                                    Encrypted:false
                                    SSDEEP:3072:em1YvN/CLwl7xByS3RH49ljUYPq+79jMRHHF:n1WBCLAnysy9ljUYPK
                                    MD5:8C4A1B982E39F179A3978EA45D03D8B6
                                    SHA1:378711959062C3988D1975EF86C94D24A987BD88
                                    SHA-256:4ABE61CF09946662B78A1895EBA4568E1BEDD6A45456ADB92907289CDAF0BE43
                                    SHA-512:FF358D7480647EED7C9CF2C6A4C9960ECF7F35F67CE3CCB8EA62A36D73ABC71292AE4DBAAFC920F0BD02B25F1B79738C694F62FB0FC01A317B782C587EA171D3
                                    Malicious:false
                                    Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 867 messages, Project-Id-Version: gtk+ 'N\303\243o foi poss\303\255vel converter "%s" para um valor do tipo "%s" para o atributo "%s"'
                                    Category:dropped
                                    Size (bytes):57577
                                    Entropy (8bit):5.2526229700977165
                                    Encrypted:false
                                    SSDEEP:768:5m5vR//TlE/+JrOOrDJvkHLHBjSQ8zCtWG9+0FqGfveRIR4xbRKAnCZv0sGxQsAd:5mXHTlNSOrDdkzizC4+XiD03t/mu
                                    MD5:57E39BED2231FF1B0E187ACD3C68D1B2
                                    SHA1:D76471FDB3B06D9189B93B675CAA3C38F5581AA0
                                    SHA-256:4147DBD7BA0D698FB1C2980E3770F0E23C70B8D2FC9036B8908EE1520C827582
                                    SHA-512:96810533A955EF08BAFBD010C5C86A4BF3B078550A1DC2E32F7A5D3DE8AE45A206616B93B5E5F00F783674E5B5E6556BB355EA236C9774E85E30C5EC54985352
                                    Malicious:false
                                    Preview:........c.......4.......L6......xH..F...yH.."....H.."....H..,....I......3I......LI......YI......_I......jI......qI......|I.......I.. ....I..7....I..)....I..4....J..=...MJ.......J.......J.......J.......J.......J..'....J..$....J..(....K..)...GK......qK.......K.......K.......K.......K.."....K..#....K..!....K..0....L......FL......RL......^L..9...iL..6....L.......L.. ....L..0....M..5...;M..9...qM..8....M..:....M..7....N..2...WN..4....N..1....N..?....N..1...1O..?...cO.......O.......O.......O.......O.......O.......O..3....O......%P......3P......PP......mP.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....P.."...-Q..>...PQ.......Q.......Q.......Q.......Q.......Q..V....Q......(R.......R.......R.......R.......R.......R.......R.......S.......S......*S......7S......LS......^S......tS.......S.......S.......S.......S.......S.......S.......S.......S..+...sT.......T..!....T..)....T.......T.......U..$....U......SU..1...rU..-....U.......U..!....U.......V.."....V......AV......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview '.desktop'
                                    Category:dropped
                                    Size (bytes):33445
                                    Entropy (8bit):5.0680221462784125
                                    Encrypted:false
                                    SSDEEP:768:T6XjjsHyf+9DjmZYocRjQCqofYtUmatdn1//tqyvp1nQ:T6Tju9oKIofYtratJPqyv8
                                    MD5:27301ABECBE6F7BF28BD0718842CE3F0
                                    SHA1:ECF9DACD17B86FD9D41E5883F4D5E079594310D5
                                    SHA-256:5E27B09D6CB45FDBD0E9D503FAFD83C6EA5092A2642DC2263EF6D4EBFB7C5ED9
                                    SHA-512:AEC2673F32699C0EAB840DF172312A248C90E650992E322B9589DFD3A1072AFB26DCA4F156E0AB8223F9A7C4006A7E2BBBAB1D9E8FAB2713DC810C1EA0A7927D
                                    Malicious:false
                                    Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 3288 messages, Project-Id-Version: Gwyddion 2.46 ' \303\251 software atualizado sob a licen\303\247a GNU GPL.'
                                    Category:dropped
                                    Size (bytes):257716
                                    Entropy (8bit):5.398457864788208
                                    Encrypted:false
                                    SSDEEP:6144:JJmKE+i99gHXPbbwddGSmb3qzJEE5Ug1O4kXTMw1fftC:rjbwRuqzJ3XO4kXTMgffg
                                    MD5:0A69B688B0A0AC7E184B40BF3E024569
                                    SHA1:A28C52AA7754E9A1CA8275B4943E35766759A97D
                                    SHA-256:5C24A49862F5B9CC9C573F8E20415CF8F943AEC5A2A71B0BCB05B595671B74BD
                                    SHA-512:7DD84777BAFCF38B502C321F4FF4840BBAF6E47F79ED99CB54BDA2F48DB1555071ABE6F4AAA88810296020AC3CE52922E8D3502922E09D842FB47028E23A1D5B
                                    Malicious:false
                                    Preview:.................f..'...........8...)...9.......c.......p...................,...............%.......D...........b... ...v... .......$.......$...................................=...&...V...%...}...................................$......."...........5...'...Q.......y...........!............................... ...........<.......W.......h.......v...........................%.......$.......%......."...,...#...O...%...s...#....... ...................................$.......1.......E.......W.......h...........%.......#.......".......$.......+...6...&...b..."...............%...............+....... ...9... ...Z.......{...................#...............'....... ...&.......G...$...d...#...............(......."...................3...!...M...'...o........... ....................... .......#...........@......._.......w...&....... ...........................................4...!...M.......o........... ....... ....... .......,.... ..(...= ..!...f ....... ....... ....... ....... ....... ....... ......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk trunk '\320\236\320\261\320\273\320\265\320\263\321\207\321\221\320\275\320\275\320\276\320\265 \320\276\320\277\320\270\321\201\320\260\320\275\320\270\320\265'
                                    Category:dropped
                                    Size (bytes):13625
                                    Entropy (8bit):5.216037224042169
                                    Encrypted:false
                                    SSDEEP:192:S5ewFqbSiyK1qBURCySFGGpdLYPJPkQVSkRp:SYwFqbSiyNBURCzFPU8kRp
                                    MD5:77D67B2E3DBE2D46F0F0555A81F55DE0
                                    SHA1:C340E9008DDBDC96E9C43483A2CF28BB1A311304
                                    SHA-256:A5C5B5EEED3BCD3EF518984B22F2C71C21F502047DC88FA4D4D1E9381F2A6C2C
                                    SHA-512:BF9CD52A5247FB3E27E265678E4B2077BF7231061C619506F31D189B8CC20F1E8E17761D0B3C52D1F5F57DEE2F30924FA73FC96B57630A1437AC4F745D894B2F
                                    Malicious:false
                                    Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 209 messages, Project-Id-Version: gtk+.master '\320\243\320\272\320\260\320\267\320\260\321\202\320\265\320\273\321\214 \320\275\320\260 \320\277\320\270\320\272\321\201\320\265\320\273\321\214\320\275\321\213\320\265 \320\264\320\260\320\275\320\275\321\213\320\265 pixbuf'
                                    Category:dropped
                                    Size (bytes):32397
                                    Entropy (8bit):5.291577124714546
                                    Encrypted:false
                                    SSDEEP:384:uTx8EKfQLF3QfnAivchincd80gwvAqSABHmuEYJpVTuZPSdK:+cfZ/ond80gwvAqSAxmuEYJpNuZ6E
                                    MD5:A28307EEDACECB51B88CCD888EAEFBB0
                                    SHA1:6D1ADEFD0576D3746C984E40F3E1D45469F1530E
                                    SHA-256:6B18378BEEB98C84502C4F627EA7619DD5A069FF0E0AE9F3CB46F0DE445ECFBD
                                    SHA-512:9DE6F668EC6D55F1074FB77179FFBDF73BBE980B176C2CF89A13C86D75A9F015068990959693367110A78B97B58358E81BEA217E99B39DA233CC63E44ED9320C
                                    Malicious:false
                                    Preview:........................,...........).......&...........................!...%...A.......g...................).......-.......!........... ...-...9...,...g...,....................... .......$.......&...;.......b..."...m...........................*.......)...........:.......Y...*...s...........,.......#.......-...........L.......b.......w...6......................................."...'...'...J.......r...........................`.......*...L...N...w...(.......".......&...........9...R...S...........J.......#...........3.......M.......j..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&....................... .......................!..............."...G... ...j...".......o.......7...........V...$...u...........$.......*.......O.... ..*...i ..%.... ../.... ..-.... ..e....!..%...~!..r....!......."......("......;"......W"..J...s"..O...."..J....#..J...Y#..2....#..H....#...... $......%$..$...B$..,...g$......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (\320\270\320\263\320\275\320\276\321\200\320\270\321\200\321\203\320\265\321\202\321\201\321\217 \320\264\320\273\321\217 \321\201\320\276\320\262\320\274\320\265\321\201\321\202\320\270\320\274\320\276\321\201\321\202\320\270)'
                                    Category:dropped
                                    Size (bytes):11509
                                    Entropy (8bit):5.483885548289898
                                    Encrypted:false
                                    SSDEEP:192:T2ypxxlurx9lHli/7/avO1indiyh5BUhtQhQzW9qBCygElH0wN:TzABFADWO1indTHShtQhQzW99ElH0s
                                    MD5:EC113491493A417C39C80174E539A3ED
                                    SHA1:96134CE7B26072767B075353C7828FC915D6713C
                                    SHA-256:72002E6570003A411ED50A1A9A3714048C5090A90BEAE17D52DE664B47F8886B
                                    SHA-512:84AD4887BB9EE6D7E8FEF5FCE57B9C082B9786C96A1F2FDA57384E2A6A3363F043BF07009CDE05ECF5ABDDEE65E4FEB5D2F3C491813AB95AF9529BBB8D7D729E
                                    Malicious:false
                                    Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................[.......f...q...j.......J...C...v.......v...........|...W...2...W.......j.......y...M...................v...V...........9.......^.......9...!...^...[...K.......M.......;...T...$.......G...............M............ .......!.......$..)....'.......'..t....'..Q...o(..q....(..,...3)..6...`)..R....)..]....)..}...H*..(....*..&....+.. ....,......7,..4...W,.......,.......,.......,.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 699 messages, Project-Id-Version: gettext-tools 0.20.2 ' (\321\202\320\276\320\273\321\214\320\272\320\276 \320\264\320\273\321\217 \321\217\320\267\321\213\320\272\320\276\320\262 \320\275\320\260 \320\276\321\201\320\275\320\276\320\262\320\265 XML)'
                                    Category:dropped
                                    Size (bytes):152383
                                    Entropy (8bit):5.365909676313479
                                    Encrypted:false
                                    SSDEEP:3072:p70VCbcqQwP1xuuInTOy6+y+lJmmnMn9Vuikz9iTsmiMsmbxi7jbnZbGb2Gxyr0i:pg3NwPA7lJmmnMn9Vuikz9iTsmiMsmbg
                                    MD5:3069B4404783DBE06054BBA6C0CDACA3
                                    SHA1:E8C9F9DB98D19A2450B4D7884824353EC682C396
                                    SHA-256:AFD2DCB2B69A3F046A2E7215ECA03738F4EB29F5A277D6E6E731ED1F6E77BC9D
                                    SHA-512:A45F4C8C88F51F129F0423C1745BFF2574959F6585FCAE591524AE5046085B7086D4D4D8E4BB15EF3DAA56D03AD1F5558A07F2B21C885CFD3E98EDA982220B38
                                    Malicious:false
                                    Preview:.........................+......p:..;...q:..4....:..D....:......';..&...E<......l=..6....>..=....>..z....>......x?..F....@..O...I@.......@..;...\A..<....A..L....A......"B..@....C..A...JC..A....C..Q....C..Q... D..L...rD..K....D..K....E......WE..I....E......>F..L....F..:....G..L...NG..v....G..E....H..L...XH..4....H..8....H..9....I..P...MI..=....I..L....I..G...)J..L...qJ..G....J..=....K..J...DK..D....K..@....K..:....L..L...PL.......L..K...1M..G...}M..H....M..;....N..8...JN..9....N..?....N..J....N......HO..@....O..>....P..:...HP.......P..7...>Q..8...vQ..;....Q..5....Q..M...!R..B...oR..:....R..;....R..L...)S..:...vS..P....S..p....T..I...sT..F....T..?....U..H...DU..H....U..L....U..L...#V......pV..5....W..<...6W..:...sW.......W..>...:X..A...yX..=....X.......X.......Y.......Z..;....Z..O....Z......-[..K....[..I....\..;...L\..C....\..u....\..8...B]..G...{]..I....]..D....^..s...R^..B....^..J...._..2...T_......._..D....`......\`..M...ka..F....a..:....b..L...;b..N....b..4....b..H....c..G...Uc..|...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1046 messages, Project-Id-Version: ru ' \320\232\320\236\320\234\320\220\320\235\320\224\320\220 \320\232\320\276\320\274\320\260\320\275\320\264\320\260 \320\264\320\273\321\217 \320\277\320\276\321\217\321\201\320\275\320\265\320\275\320\270\321\217 (\320\275\320\265\320\276\320\261\321\217\320\267\320\260\321\202\320\265\320\273\321\214\320\275\321\213\320\271)'
                                    Category:dropped
                                    Size (bytes):154573
                                    Entropy (8bit):5.472591587333734
                                    Encrypted:false
                                    SSDEEP:3072:bnEbNMNLFsWuYtBSrFn4od69AVNu+eevGzx+/Fu+dqN3qHqW1:bngMJVBS5569UeIGzx+Nu+dqN3qH51
                                    MD5:EA1697575BF7FF7931AEDE45871787D2
                                    SHA1:8B39713CD6557DC6649EA1C7342E83D68648B12C
                                    SHA-256:C6844EE5B90B1E4960294643E88AE80D743E38C9975026CAC915E7EC08F0CA57
                                    SHA-512:4838124A0C816E7BCEB9696E6E8F7976CDD3043D25AF1E4C4C7D8E78CF2CF531B5DFF6CC52A676C632052E3AFB708F6E0122401A4F24B2C206E8C039AB34BCD7
                                    Malicious:false
                                    Preview:................. ..w...|A......XW......YW..7....W.._....W..1... X..&...RX......yX..9....X..Q....X..9..."Y..+...\Y.......Y.......Y..&....Y.......Y.......Y.......Y.......Y.......Z.......Z.......Z.......Z......%Z......-Z......6Z......>Z......GZ......OZ..:...`Z.......Z.......Z.......Z.......Z..Y....Z.._...3[..a....[.......[.......\......-\......K\..)...b\..@....\..*....\.......\..!....].."....]......Q]......p]..#....]..!....]..[....]..&...2^..4...Y^..a....^.."....^..5...._..J...I_..8...._..*...._..$...._.......`......$`......*`......C`......S`......]`......h`..B....`..!....`.......`.......`..5....a..)...La......va..O....a..U....a..8...1b......jb.......b..?....b..+....b.......c.......c.. ...%c..0...Fc..!...wc.......c.......c..4....c.......c..)....d..#...1d..(...Ud..=...~d..,....d..4....d..&....e......Ee..^...be..a....e..g...#f..B....f.......f../...ag..)....g..*....g.......g.."....h..&...$h..1...Kh..0...}h..$....h.."....h..8....h..>.../i..%...ni.......i.......i..4....i..;....i..#...;j..6...
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1719 messages, Project-Id-Version: ru '\320\236\321\202\320\276\320\261\321\200\320\260\320\266\320\260\320\265\320\274\320\276\320\265 \320\270\320\267\320\276\320\261\321\200\320\260\320\266\320\265\320\275\320\270\320\265 (GdkImage)'
                                    Category:dropped
                                    Size (bytes):217914
                                    Entropy (8bit):5.324923633586286
                                    Encrypted:false
                                    SSDEEP:6144:f86XfpjUYP3QKVJPQLUHwCWv+iJP96Bq9h8/Vi64UKIhz8ADj4LBVwDLNImJth:E6XJfgJ9h894UNhz8ij4L7wfymJth
                                    MD5:DA52FFF084804539D2C4E347EE686070
                                    SHA1:8DA5A33F5F9868818B5086E7F7B1E882B6A5C2AF
                                    SHA-256:51592251430540410920E7832D85AB556891F393F19D122A78D1BC48DBA49C9F
                                    SHA-512:54F83BA9E692741979E103F29787FE5BBE70772A69C7F29722ECCDED1AACA7245FF040A87A4F4924F61C3D6C0BB20D623C5130486191F0413BE8C3E860A94B23
                                    Malicious:false
                                    Preview:.................5.......k......`.......a.......w...........e.......C.......5...O...N.......Q......9...&...0...`...*.......<.......?......._...9...........2.......+......).......4...?...,...t...Y.......N.......N...J...................8......5......./...A.......q.......}............................................................................"...............A.......M.......T.......a.......t...........................................................................................................)...'...6.......^.......j...........$......................D......A...+... ...m...G..............5.......)...;...&...e...G..............#..................................7.......V...5......................0..............=...A................................................................./...........8.......E.......S...#...[...0.....................................................................5...(.......^.......}....................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 1064 messages, Project-Id-Version: gtk+.master '\302\253%s\302\273 \320\275\320\265 \320\274\320\276\320\266\320\265\321\202 \320\261\321\213\321\202\321\214 \320\277\321\200\320\265\320\276\320\261\321\200\320\260\320\267\320\276\320\262\320\260\320\275\320\276 \320\272 \320\267\320\275\320\260\321\207\320\265\320\275\320\270\321\216 \321\202\320\270\320\277\320\260 \302\253%s\302\273 \320\264\320\273\321\217 \320\260\321\202\321\200\320\270\320\261\321\203\321\202\320\260 \302\253%s\302\273'
                                    Category:dropped
                                    Size (bytes):98356
                                    Entropy (8bit):5.5337280228207995
                                    Encrypted:false
                                    SSDEEP:1536:6XmQDQrxzyk1NZVtX1juTNiEzS75uDGOnXvcx0O6:6HQ+kvFFuTdzS75uqOnXU6
                                    MD5:A3EB9B3918614E9D23BC9880726C0804
                                    SHA1:AF8D910D8BBB0C5D21432EEC24F6D4BEB4B500C9
                                    SHA-256:649B0483869D47EE15C83D4BD097E6DEFDB0E9AB3DF95122487A201746BB41B1
                                    SHA-512:FD8DD0E9213016AE4E761882FB8304436303BE7885063D0FED4311E7DC87EE6320BA9FE37035966B4F3AE4A4AFAEE73DDF8A6BB0AC28E3FE1E455695748A8F87
                                    Malicious:false
                                    Preview:........(.......\!.......B.......X..F....X.."... Y.."...CY..,...fY.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.. ....Y..7....Z..)...NZ..4...xZ..=....Z.......Z.......Z.......Z.......[......"[..'...1[..$...Y[..(...~[..)....[.......[.......[.......[.......[.......[.."....\..#.../\..!...S\..0...u\.......\.......\.......\..9....\..6....]......:].. ...I]..0...j]..5....]..9....]..8....^..:...D^..7....^..2....^..4....^..1...._..?...Q_..1...._..?...._.......`.......`.......`..%...4`......Z`......o`......x`.......`..)....`..-....`.......`..3....a......8a......Fa......ca.......a.......a.......a.......a.......a.......a.......a.......a.......a..!....a..!....b.. ...2b.."...Sb..(...vb..*....b..-....b..,....b..,...%c......Rc..'...mc../....c.."....c..>....c......'d......?d......Xd......ud.......d.. ....d.......d.......d..V....d.......e.......e.......e.......e.......e.......e..$....e.......f.......f......0f.."...>f......af......nf.......f.......f.......f.......f.......f.......f......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: ru '.desktop'
                                    Category:dropped
                                    Size (bytes):41712
                                    Entropy (8bit):5.343842538573471
                                    Encrypted:false
                                    SSDEEP:768:T6XjjsHoxQe/rdtjQCqofYtUmatdn1/TqcYX3kSVlP:T6TjuoLrTIofYtratJ5qtX3kSVlP
                                    MD5:D5AFE120BE7DDBC9BE85E62787CD967D
                                    SHA1:8E7A27ABADFEDD8254A1D07E74165ACD51C4512C
                                    SHA-256:89C9AA7DF27E05D4305B12696CCA6590F36287AA3DF7CECB0E45511FDDBEBFA5
                                    SHA-512:77B21192AC473225754BEFF24AC24FFC7B95A4959D3E99996079DDBDA5B501E7E47B8846159662B7267721C6549A27974661B1B80624EE1C1E22D4264D99C1C3
                                    Malicious:false
                                    Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:GNU message catalog (little endian), revision 0.0, 4878 messages, Project-Id-Version: gwyddion ' \342\200\223 \321\201\320\262\320\276\320\261\320\276\320\264\320\275\320\276\320\265 \320\237\320\236 \320\277\320\276\320\264 \320\273\320\270\321\206\320\265\320\275\320\267\320\270\320\265\320\271 GNU GPL.'
                                    Category:dropped
                                    Size (bytes):479977
                                    Entropy (8bit):5.572529183579759
                                    Encrypted:false
                                    SSDEEP:12288:MREnpvNul+y3X+xDJ5xUqZr09qjV1//ETE5C+CI79VtoFWJKxPhHWuhCsZL6emyu:2epvMKT33oY
                                    MD5:23F3632B56012CE1C3CCB93D6799722D
                                    SHA1:B970C80E6D9A2B900B602C70219B4F8E8ECDCA8E
                                    SHA-256:B009837B5FD8562177754E08089E664CE2E76DF3075DA8DD32B47474CD9676D2
                                    SHA-512:5E4BBE1F5DD7994D7D240FB380CEEED4B7035EB1CAF4F38C7FD4850B8428D103BC0CF0C4E470122777FC32A93696E789E14111D7571300EC47107F40BCED57E9
                                    Malicious:false
                                    Preview:....................y....0..........)..........................,.......H...&...Q...-...x...(..............,............... ...........?...%...X...D...~................. ...... .......$...,...$...Q.......v.......~...........................&......%...........&.......;.......P.......d.......}..........................................$......"...........&...'...B.......j...................!..................................).......F... ...].......~...%.......(.......!......)....... ...4... ...U...#...v... ..........................................).......7.......H.......[.......j...!...|................... ......6.......4.../...4...d...4.......5...... ......."...%.../...H.......x...,.......-......*.......3...-...7...a...'.......%......."..................(...+...G.......s...........%.......$......%......!......."...6...#...Y...%...}...#.......$......#...... ...........1.......I...!...i...................0......*.......*...$...+...O.......{...............................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):82
                                    Entropy (8bit):4.179232823699804
                                    Encrypted:false
                                    SSDEEP:3:LFhmEr0NaIVR0D5lo2oJYRAgpFab4:LK7VRElrALb4
                                    MD5:4AE0697CE8CE144E285609DD83AD53F3
                                    SHA1:F4886997FDB05B998F3510EE4BFC62257E15DD30
                                    SHA-256:DCDBB5A775EB9DBF659D80B6694D381A822AF3665706C3ED7488B84D95EB8F8A
                                    SHA-512:C9E8BA2431BD469D7AC212FD7E548CC1FD8285E216A1BF0FCBF9EA9AFF16D7E2B9B31CF0D1A2BE5233A9E0EC0B27313FA094DE5208204C3DAD4E8DD41B332ADF
                                    Malicious:false
                                    Preview:#.# Default keybinding set. Empty because it is implemented inline in the code..#.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):3818
                                    Entropy (8bit):5.004948993395511
                                    Encrypted:false
                                    SSDEEP:48:d+cwyUjHSuyPAho/ThvyS4XE7XE5dz4vw5Y2Tr9x:F4pyf/ThvyS4XuX4kvw5/Trf
                                    MD5:4B600A3C3C2AC37F7D0C13C4D86AC752
                                    SHA1:D1DA549C070D74AA9F9456C4C1E0CCBDDE5256C8
                                    SHA-256:4214BEE389645EDCC7C9971BA35DC4D96E8C135EBC92C51C05B0C7DD36ABD8E5
                                    SHA-512:D4ECE8E39A80073BEC016B375A75BB5FF5C697AFF560E5D4AAFC6031F26451F8D3EF32FAF1A0B2BE3470450EB2EA3AE8978CC444EE0E2D2EF374EF43340E64BA
                                    Malicious:false
                                    Preview:# GTK - The GIMP Toolkit.# Copyright (C) 2002 Owen Taylor.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to the.# Free Software Foundation, Inc., 59 Temple Place - Suite 330,.# Boston, MA 02111-1307, USA....# Modified by the GTK+ Team and others 1997-2000. See the AUTHORS.# file for a list of people on the GTK+ Team. See the ChangeLog.# files for a list of changes. These files are distributed with.# GTK+ at ftp://f
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):1825
                                    Entropy (8bit):5.031325379211077
                                    Encrypted:false
                                    SSDEEP:48:ScqeT1e9fw22war0FG+V9NHBunH4tc8s69so:ScqucwXwarCbOH4qbG
                                    MD5:94D104680CEC5F3D8BBEC56258D0C926
                                    SHA1:72EDE372FCB34B29754F20AD44F49BC8605CF22C
                                    SHA-256:E9DD3015F76E05F185EBE7564D364AEF8B8168B05E62421C99875E14E4597977
                                    SHA-512:CF7D04304FA58E2DD9A8492B31B065C03C1F7EA96AB71D7D3D212EB17436C7C181470C23296FA3F599F1EF56C6B243921ED7F0A92AD3E0A6CD40A5FE857955A9
                                    Malicious:false
                                    Preview:gtk-icon-sizes = "gtk-menu=13,13:gtk-small-toolbar=16,16:gtk-large-toolbar=24,24:gtk-dnd=32,32".gtk-toolbar-icon-size = small-toolbar..# disable images in buttons. i've only seen ugly delphi apps use this feature..gtk-button-images = 0..# enable/disable images in menus. most "stock" microsoft apps don't use these, except sparingly..# the office apps use them heavily, though..gtk-menu-images = 1..# use the win32 button ordering instead of the GNOME HIG one, where applicable.gtk-alternative-button-order = 1..# use the win32 sort indicators direction, as in Explorer.gtk-alternative-sort-arrows = 1..# Windows users don't expect the PC Speaker beeping at them when they backspace in an empty textview and stuff like that.gtk-error-bell = 0..style "msw-default".{. GtkWidget::interior-focus = 1. GtkOptionMenu::indicator-size = { 9, 5 }. GtkOptionMenu::indicator-spacing = { 7, 5, 2, 2 }. GtkSpinButton::shadow-type = in.. # Owen and I disagree that these should be themable. #GtkUIManager::a
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:ASCII text
                                    Category:dropped
                                    Size (bytes):69
                                    Entropy (8bit):3.7974371816690633
                                    Encrypted:false
                                    SSDEEP:3:LFxLyVLfr7g7F3+9FVpAGCevn:LfIja5ltev
                                    MD5:5FC9003DDC2C64B110B1161259F61923
                                    SHA1:4ECDDBCCEDDBD90A3A654D3788EC3AEF8C197A8A
                                    SHA-256:6D9BEAF039092AEC5C1FBC23A62402BCD0704C45C430189A6AC69AE8AA797A67
                                    SHA-512:5C90F3F1037FFF9F10AA2030BED2C670EDD528482532E617549DB2133E26CF801BDEC56D4543FEB024CDEC1C0026909CA9A21B378EC3B89489C18C395660C9FC
                                    Malicious:false
                                    Preview:#.# This theme is the default theme if no other theme is selected..#.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                                    Category:dropped
                                    Size (bytes):46107
                                    Entropy (8bit):6.500694252312658
                                    Encrypted:false
                                    SSDEEP:768:4XWsAYF0UQj0TU9a+IWNu9B1MxlthhMLWI027zpiUGtuzoOmEj7V0oghm:4msAYBdTU9fEAIS2PEtucOmEf6Nhm
                                    MD5:D46C24B67CCFFF870F8466905DD1DDB4
                                    SHA1:46EC09788F0AED78A34DD610C1764F3E2376E60F
                                    SHA-256:B39E563CBBA2B25145D1C62C0D5760D2716EFE6F92CB72DD3F0479A956705010
                                    SHA-512:30A20FBA32EBFF83A4B7EF7D427251C8B35738191AE16DFB837C75FD4C87F48B448CF156523E9A6B4414FA45A1F5FD1DE4601528A94AB2C03D09551938DF1014
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf.sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*......@6............@.......................................@.............................................x............................................................................................................text...vf.......h.................. ..`.rdata...............l..............@..@.data...x...........................@....ndata... ...............................rsrc...x...........................@..@................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Mon Nov 11 13:33:30 2024, mtime=Wed Nov 20 19:21:21 2024, atime=Mon Nov 11 13:33:30 2024, length=678139, window=hide
                                    Category:dropped
                                    Size (bytes):1977
                                    Entropy (8bit):3.4366479501324054
                                    Encrypted:false
                                    SSDEEP:48:81dsfsUecdx6gdxj1qdxMxwIkCmdxMxwIM:87Uedw19xwMBxw
                                    MD5:CAF5A8BD057ED3B75BECA9D951E2713D
                                    SHA1:330D2CE5F80CD6721FB0BFE32D8562CB387C3B79
                                    SHA-256:C24CC83B45A82C52200F34F14BBF550141890AF5DC685075B2B5FE15E2D25FCC
                                    SHA-512:D12056090A82D8763C024005E500C38E8601AEDA0B81830A1C2772925E17EDE397E7BF55524135519E5E865E572BCE6EC3D8CD3627329636D3F7DA77FAFFABC7
                                    Malicious:false
                                    Preview:L..................F.@.. ....Yt.F4....S.;...Yt.F4...X...........................P.O. .:i.....+00.../C:\.....................1.....tY....PROGRA~1..t......O.ItY......B...............J.....jb..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....Z.1.....tY....Gwyddion..B......tY..tY.............................I..G.w.y.d.d.i.o.n.....J.1.....tY....bin.8......tY..tY......r:......................}.b.i.n.....f.2..X..kY/t .gwyddion.exe..J......kY/ttY......~:........................g.w.y.d.d.i.o.n...e.x.e.......Y...............-.......X...........Z........C:\Program Files\Gwyddion\bin\gwyddion.exe....G.w.y.d.d.i.o.n. .-. .S.P.M. .d.a.t.a. .a.n.a.l.y.s.i.s.6.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.w.y.d.d.i.o.n.\.b.i.n.\.g.w.y.d.d.i.o.n...e.x.e.5.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.w.y.d.d.i.o.n.\.s.h.a.r.e.\.l.o.c.a.l.e.\.e.s.\.L.C._.M.E.S.S.A.G.E.S.=.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.w.y.d.d.i.o.n.\.s.h.a.r.e.\.g.w.y.d.d.i.o.n.\.p.i.x.m.a.p.s.\.g.w.
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:data
                                    Category:dropped
                                    Size (bytes):115948649
                                    Entropy (8bit):5.996872196524083
                                    Encrypted:false
                                    SSDEEP:1572864:VhKL4OQ38PaIhHkh8l9GHIh/nnTkhu0XJJ1WQhHYMA4S:2nTkhuD
                                    MD5:1B1648BA261FF602290CB1C1431A0F8E
                                    SHA1:D14EB0FB29112CADACF315912FD3167F65151E59
                                    SHA-256:80A24A026D9F0ECCED3EF1D6F3E1ACEFC8B8C81D5BFCDF617E60F8B62794F48F
                                    SHA-512:4F451EA89D080E3B7E4DAD75BA1925C654424658488AB84B45B54882156456B7C67ECF1589693C5507826B1AE2DD99AFC41620E491176DFA1D82D156EBC74F1A
                                    Malicious:false
                                    Preview:&.......,.......l...............`...........................................S...i...............................?...........<...'...........................................................................................................................................................G...J............=..f.......................t.......................v...............g.......................t...............................................T.......................................................j.......................t...........................................................................................................................Z...................................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):9728
                                    Entropy (8bit):5.158136237602734
                                    Encrypted:false
                                    SSDEEP:96:o0svUu3Uy+sytcS8176b+XR8pCHFcMcxSgB5PKtAtgt+Nt+rnt3DVEB3YcNqkzfS:o0svWyNO81b8pCHFcM0PuAgkOyuIFc
                                    MD5:6C3F8C94D0727894D706940A8A980543
                                    SHA1:0D1BCAD901BE377F38D579AAFC0C41C0EF8DCEFD
                                    SHA-256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2
                                    SHA-512:2094F0E4BB7C806A5FF27F83A1D572A5512D979EEFDA3345BAFF27D2C89E828F68466D08C3CA250DA11B01FC0407A21743037C25E94FBE688566DD7DEAEBD355
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|..c8O`08O`08O`08Oa0.O`0.@=05O`0llP0=O`0.If09O`0.od09O`0Rich8O`0........PE..L.....Oa...........!.........0......g........0............................................@..........................6..k....0.......p...............................................................................0...............................text............................... ..`.rdata..{....0......................@..@.data...h!...@......................@....rsrc........p....... ..............@..@.reloc..~............"..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                                    Entropy (8bit):7.999962811655682
                                    TrID:
                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                    • DOS Executable Generic (2002/1) 0.02%
                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                    File name:Gwyddion-2.67.win64.exe
                                    File size:25'684'878 bytes
                                    MD5:05c65dd3bf712228edad0dee5aaccc78
                                    SHA1:7d1ca96f10c3cf1e18cfa5a7459f9e892ad0db9c
                                    SHA256:4cea4b3b1ff1979e01f7da89802d4b864b29d05cb75b05690b180a1a008b946c
                                    SHA512:71ec189326f9180dac622bf3d9821bcf8138ba098cafd1a800522040ceb16b6ae043b058ed1e0f1645565b5ab7ea31d2cb83fc44cba7ed42f0d1b7655bb9c92a
                                    SSDEEP:786432:gXUji40lRULVlM1OejW3J3Vxtdddv6wEF1UF1Z8UF:gXg03ClM1OoWvxtddYwEHUXp
                                    TLSH:F14733E02EFEA313DA699F76FD288701A375ECACC12B942E8035B756525454E9F0BC70
                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf..sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*.....
                                    Icon Hash:c2e8d89cccc8e6e6
                                    Entrypoint:0x403640
                                    Entrypoint Section:.text
                                    Digitally signed:false
                                    Imagebase:0x400000
                                    Subsystem:windows gui
                                    Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                    Time Stamp:0x614F9B1F [Sat Sep 25 21:56:47 2021 UTC]
                                    TLS Callbacks:
                                    CLR (.Net) Version:
                                    OS Version Major:4
                                    OS Version Minor:0
                                    File Version Major:4
                                    File Version Minor:0
                                    Subsystem Version Major:4
                                    Subsystem Version Minor:0
                                    Import Hash:61259b55b8912888e90f516ca08dc514
                                    Instruction
                                    push ebp
                                    mov ebp, esp
                                    sub esp, 000003F4h
                                    push ebx
                                    push esi
                                    push edi
                                    push 00000020h
                                    pop edi
                                    xor ebx, ebx
                                    push 00008001h
                                    mov dword ptr [ebp-14h], ebx
                                    mov dword ptr [ebp-04h], 0040A230h
                                    mov dword ptr [ebp-10h], ebx
                                    call dword ptr [004080C8h]
                                    mov esi, dword ptr [004080CCh]
                                    lea eax, dword ptr [ebp-00000140h]
                                    push eax
                                    mov dword ptr [ebp-0000012Ch], ebx
                                    mov dword ptr [ebp-2Ch], ebx
                                    mov dword ptr [ebp-28h], ebx
                                    mov dword ptr [ebp-00000140h], 0000011Ch
                                    call esi
                                    test eax, eax
                                    jne 00007F8404F93F6Ah
                                    lea eax, dword ptr [ebp-00000140h]
                                    mov dword ptr [ebp-00000140h], 00000114h
                                    push eax
                                    call esi
                                    mov ax, word ptr [ebp-0000012Ch]
                                    mov ecx, dword ptr [ebp-00000112h]
                                    sub ax, 00000053h
                                    add ecx, FFFFFFD0h
                                    neg ax
                                    sbb eax, eax
                                    mov byte ptr [ebp-26h], 00000004h
                                    not eax
                                    and eax, ecx
                                    mov word ptr [ebp-2Ch], ax
                                    cmp dword ptr [ebp-0000013Ch], 0Ah
                                    jnc 00007F8404F93F3Ah
                                    and word ptr [ebp-00000132h], 0000h
                                    mov eax, dword ptr [ebp-00000134h]
                                    movzx ecx, byte ptr [ebp-00000138h]
                                    mov dword ptr [0042A318h], eax
                                    xor eax, eax
                                    mov ah, byte ptr [ebp-0000013Ch]
                                    movzx eax, ax
                                    or eax, ecx
                                    xor ecx, ecx
                                    mov ch, byte ptr [ebp-2Ch]
                                    movzx ecx, cx
                                    shl eax, 10h
                                    or eax, ecx
                                    Programming Language:
                                    • [EXP] VC++ 6.0 SP5 build 8804
                                    NameVirtual AddressVirtual Size Is in Section
                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x85040xa0.rdata
                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x4d0000x1578.rsrc
                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IAT0x80000x2b0.rdata
                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                    .text0x10000x66760x68006f5abe9eeda26ee84b3c1ed1a6c82001False0.6568134014423077data6.4174599871908855IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                    .rdata0x80000x139a0x14008c5edfd8ff9cc0135e197611be38ca18False0.4498046875data5.141066817170598IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .data0xa0000x203780x6004b2421975c21b032f7ea000f5e7f9fbfFalse0.509765625data4.110582127654237IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .ndata0x2b0000x220000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .rsrc0x4d0000x15780x16008ad9f7797086a24df973506488db409dFalse0.3552911931818182data3.9438390822746894IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                    RT_ICON0x4d2200x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishUnited States0.2666967509025271
                                    RT_DIALOG0x4dac80xb4dataEnglishUnited States0.6111111111111112
                                    RT_DIALOG0x4db800x120dataEnglishUnited States0.5138888888888888
                                    RT_DIALOG0x4dca00x202dataEnglishUnited States0.4085603112840467
                                    RT_DIALOG0x4dea80xf8dataEnglishUnited States0.6290322580645161
                                    RT_DIALOG0x4dfa00xa0dataEnglishUnited States0.60625
                                    RT_DIALOG0x4e0400xeedataEnglishUnited States0.6302521008403361
                                    RT_GROUP_ICON0x4e1300x14dataEnglishUnited States1.15
                                    RT_MANIFEST0x4e1480x42eXML 1.0 document, ASCII text, with very long lines (1070), with no line terminatorsEnglishUnited States0.5130841121495328
                                    DLLImport
                                    ADVAPI32.dllRegCreateKeyExW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetFileSecurityW, RegOpenKeyExW, RegEnumValueW
                                    SHELL32.dllSHGetSpecialFolderLocation, SHFileOperationW, SHBrowseForFolderW, SHGetPathFromIDListW, ShellExecuteExW, SHGetFileInfoW
                                    ole32.dllOleInitialize, OleUninitialize, CoCreateInstance, IIDFromString, CoTaskMemFree
                                    COMCTL32.dllImageList_Create, ImageList_Destroy, ImageList_AddMasked
                                    USER32.dllGetClientRect, EndPaint, DrawTextW, IsWindowEnabled, DispatchMessageW, wsprintfA, CharNextA, CharPrevW, MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, GetSystemMetrics, FillRect, AppendMenuW, TrackPopupMenu, OpenClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcW, GetMessagePos, CheckDlgButton, LoadCursorW, SetCursor, GetSysColor, SetWindowPos, GetWindowLongW, PeekMessageW, SetClassLongW, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, FindWindowExW, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, EmptyClipboard, CreatePopupMenu
                                    GDI32.dllSetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectW, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject
                                    KERNEL32.dllGetExitCodeProcess, WaitForSingleObject, GetModuleHandleA, GetProcAddress, GetSystemDirectoryW, lstrcatW, Sleep, lstrcpyA, WriteFile, GetTempFileNameW, lstrcmpiA, RemoveDirectoryW, CreateProcessW, CreateDirectoryW, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceW, WideCharToMultiByte, lstrcpynW, lstrlenW, SetErrorMode, GetVersionExW, GetCommandLineW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, CopyFileW, ExitProcess, GetCurrentProcess, GetModuleFileNameW, GetFileSize, CreateFileW, GetTickCount, MulDiv, SetFileAttributesW, GetFileAttributesW, SetCurrentDirectoryW, MoveFileW, GetFullPathNameW, GetShortPathNameW, SearchPathW, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalFree, GlobalAlloc, GetModuleHandleW, LoadLibraryExW, MoveFileExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, lstrlenA, MultiByteToWideChar, ReadFile, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW
                                    Language of compilation systemCountry where language is spokenMap
                                    EnglishUnited States
                                    No network behavior found

                                    Click to jump to process

                                    Click to jump to process

                                    Click to dive into process behavior distribution

                                    Target ID:0
                                    Start time:15:21:09
                                    Start date:20/11/2024
                                    Path:C:\Users\user\Desktop\Gwyddion-2.67.win64.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe"
                                    Imagebase:0x400000
                                    File size:25'684'878 bytes
                                    MD5 hash:05C65DD3BF712228EDAD0DEE5AACCC78
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low
                                    Has exited:false

                                    Reset < >

                                      Execution Graph

                                      Execution Coverage:27.1%
                                      Dynamic/Decrypted Code Coverage:0%
                                      Signature Coverage:15%
                                      Total number of Nodes:1608
                                      Total number of Limit Nodes:50
                                      execution_graph 3675 403640 SetErrorMode GetVersionExW 3676 403692 GetVersionExW 3675->3676 3677 4036ca 3675->3677 3676->3677 3678 403723 3677->3678 3679 406a35 5 API calls 3677->3679 3766 4069c5 GetSystemDirectoryW 3678->3766 3679->3678 3681 403739 lstrlenA 3681->3678 3682 403749 3681->3682 3769 406a35 GetModuleHandleA 3682->3769 3685 406a35 5 API calls 3686 403757 3685->3686 3687 406a35 5 API calls 3686->3687 3688 403763 #17 OleInitialize SHGetFileInfoW 3687->3688 3775 406668 lstrcpynW 3688->3775 3691 4037b0 GetCommandLineW 3776 406668 lstrcpynW 3691->3776 3693 4037c2 3777 405f64 3693->3777 3696 4038f7 3697 40390b GetTempPathW 3696->3697 3781 40360f 3697->3781 3699 403923 3701 403927 GetWindowsDirectoryW lstrcatW 3699->3701 3702 40397d DeleteFileW 3699->3702 3700 405f64 CharNextW 3704 4037f9 3700->3704 3705 40360f 12 API calls 3701->3705 3791 4030d0 GetTickCount GetModuleFileNameW 3702->3791 3704->3696 3704->3700 3709 4038f9 3704->3709 3707 403943 3705->3707 3706 403990 3710 403a54 3706->3710 3712 403a45 3706->3712 3716 405f64 CharNextW 3706->3716 3707->3702 3708 403947 GetTempPathW lstrcatW SetEnvironmentVariableW SetEnvironmentVariableW 3707->3708 3711 40360f 12 API calls 3708->3711 3877 406668 lstrcpynW 3709->3877 3931 403c25 3710->3931 3715 403975 3711->3715 3821 403d17 3712->3821 3715->3702 3715->3710 3733 4039b2 3716->3733 3719 403b91 3722 403b99 GetCurrentProcess OpenProcessToken 3719->3722 3723 403c0f ExitProcess 3719->3723 3720 403b7c 3940 405cc8 3720->3940 3727 403bb0 LookupPrivilegeValueW AdjustTokenPrivileges 3722->3727 3728 403bdf 3722->3728 3724 403a1b 3878 40603f 3724->3878 3725 403a5c 3894 405c33 3725->3894 3727->3728 3731 406a35 5 API calls 3728->3731 3735 403be6 3731->3735 3733->3724 3733->3725 3737 403bfb ExitWindowsEx 3735->3737 3742 403c08 3735->3742 3737->3723 3737->3742 3738 403a72 lstrcatW 3739 403a7d lstrcatW lstrcmpiW 3738->3739 3739->3710 3740 403a9d 3739->3740 3743 403aa2 3740->3743 3744 403aa9 3740->3744 3944 40140b 3742->3944 3897 405b99 CreateDirectoryW 3743->3897 3902 405c16 CreateDirectoryW 3744->3902 3745 403a3a 3893 406668 lstrcpynW 3745->3893 3751 403aae SetCurrentDirectoryW 3752 403ac0 3751->3752 3753 403acb 3751->3753 3905 406668 lstrcpynW 3752->3905 3906 406668 lstrcpynW 3753->3906 3758 403b19 CopyFileW 3763 403ad8 3758->3763 3759 403b63 3761 406428 36 API calls 3759->3761 3761->3710 3762 4066a5 17 API calls 3762->3763 3763->3759 3763->3762 3765 403b4d CloseHandle 3763->3765 3907 4066a5 3763->3907 3924 406428 MoveFileExW 3763->3924 3928 405c4b CreateProcessW 3763->3928 3765->3763 3767 4069e7 wsprintfW LoadLibraryExW 3766->3767 3767->3681 3770 406a51 3769->3770 3771 406a5b GetProcAddress 3769->3771 3772 4069c5 3 API calls 3770->3772 3773 403750 3771->3773 3774 406a57 3772->3774 3773->3685 3774->3771 3774->3773 3775->3691 3776->3693 3778 405f6a 3777->3778 3779 4037e8 CharNextW 3778->3779 3780 405f71 CharNextW 3778->3780 3779->3704 3780->3778 3947 4068ef 3781->3947 3783 403625 3783->3699 3784 40361b 3784->3783 3956 405f37 lstrlenW CharPrevW 3784->3956 3787 405c16 2 API calls 3788 403633 3787->3788 3959 406187 3788->3959 3963 406158 GetFileAttributesW CreateFileW 3791->3963 3793 403113 3820 403120 3793->3820 3964 406668 lstrcpynW 3793->3964 3795 403136 3965 405f83 lstrlenW 3795->3965 3799 403147 GetFileSize 3800 403241 3799->3800 3819 40315e 3799->3819 3970 40302e 3800->3970 3804 403286 GlobalAlloc 3806 40329d 3804->3806 3805 4032de 3809 40302e 32 API calls 3805->3809 3811 406187 2 API calls 3806->3811 3808 403267 3810 4035e2 ReadFile 3808->3810 3809->3820 3812 403272 3810->3812 3814 4032ae CreateFileW 3811->3814 3812->3804 3812->3820 3813 40302e 32 API calls 3813->3819 3815 4032e8 3814->3815 3814->3820 3984 4035f8 SetFilePointer 3815->3984 3817 4032f6 3985 403371 3817->3985 3819->3800 3819->3805 3819->3813 3819->3820 4000 4035e2 3819->4000 3820->3706 3822 406a35 5 API calls 3821->3822 3823 403d2b 3822->3823 3824 403d31 3823->3824 3825 403d43 3823->3825 4067 4065af wsprintfW 3824->4067 3826 406536 3 API calls 3825->3826 3827 403d73 3826->3827 3829 403d92 lstrcatW 3827->3829 3831 406536 3 API calls 3827->3831 3830 403d41 3829->3830 4047 403fed 3830->4047 3831->3829 3834 40603f 18 API calls 3835 403dc4 3834->3835 3836 403e58 3835->3836 4055 406536 3835->4055 3837 40603f 18 API calls 3836->3837 3839 403e5e 3837->3839 3841 403e6e LoadImageW 3839->3841 3842 4066a5 17 API calls 3839->3842 3843 403f14 3841->3843 3844 403e95 RegisterClassW 3841->3844 3842->3841 3845 40140b 2 API calls 3843->3845 3847 403f1e 3844->3847 3848 403ecb SystemParametersInfoW CreateWindowExW 3844->3848 3849 403f1a 3845->3849 3846 403e17 lstrlenW 3851 403e25 lstrcmpiW 3846->3851 3852 403e4b 3846->3852 3847->3710 3848->3843 3849->3847 3857 403fed 18 API calls 3849->3857 3850 405f64 CharNextW 3854 403e14 3850->3854 3851->3852 3855 403e35 GetFileAttributesW 3851->3855 3853 405f37 3 API calls 3852->3853 3858 403e51 3853->3858 3854->3846 3856 403e41 3855->3856 3856->3852 3859 405f83 2 API calls 3856->3859 3860 403f2b 3857->3860 4068 406668 lstrcpynW 3858->4068 3859->3852 3862 403f37 ShowWindow 3860->3862 3863 403fba 3860->3863 3865 4069c5 3 API calls 3862->3865 4060 40579d OleInitialize 3863->4060 3867 403f4f 3865->3867 3866 403fc0 3868 403fc4 3866->3868 3869 403fdc 3866->3869 3870 403f5d GetClassInfoW 3867->3870 3872 4069c5 3 API calls 3867->3872 3868->3847 3875 40140b 2 API calls 3868->3875 3871 40140b 2 API calls 3869->3871 3873 403f71 GetClassInfoW RegisterClassW 3870->3873 3874 403f87 DialogBoxParamW 3870->3874 3871->3847 3872->3870 3873->3874 3876 40140b 2 API calls 3874->3876 3875->3847 3876->3847 3877->3697 4084 406668 lstrcpynW 3878->4084 3880 406050 4085 405fe2 CharNextW CharNextW 3880->4085 3883 403a27 3883->3710 3892 406668 lstrcpynW 3883->3892 3884 4068ef 5 API calls 3887 406066 3884->3887 3885 406097 lstrlenW 3886 4060a2 3885->3886 3885->3887 3889 405f37 3 API calls 3886->3889 3887->3883 3887->3885 3891 405f83 2 API calls 3887->3891 4091 40699e FindFirstFileW 3887->4091 3890 4060a7 GetFileAttributesW 3889->3890 3890->3883 3891->3885 3892->3745 3893->3712 3895 406a35 5 API calls 3894->3895 3896 403a61 lstrcatW 3895->3896 3896->3738 3896->3739 3898 403aa7 3897->3898 3899 405bea GetLastError 3897->3899 3898->3751 3899->3898 3900 405bf9 SetFileSecurityW 3899->3900 3900->3898 3901 405c0f GetLastError 3900->3901 3901->3898 3903 405c26 3902->3903 3904 405c2a GetLastError 3902->3904 3903->3751 3904->3903 3905->3753 3906->3763 3912 4066b2 3907->3912 3908 4068d5 3909 403b0d DeleteFileW 3908->3909 4096 406668 lstrcpynW 3908->4096 3909->3758 3909->3763 3911 4068a3 lstrlenW 3911->3912 3912->3908 3912->3911 3913 4066a5 10 API calls 3912->3913 3914 4067ba GetSystemDirectoryW 3912->3914 3917 406536 3 API calls 3912->3917 3918 4067cd GetWindowsDirectoryW 3912->3918 3919 4066a5 10 API calls 3912->3919 3920 406844 lstrcatW 3912->3920 3921 4068ef 5 API calls 3912->3921 3922 4067fc SHGetSpecialFolderLocation 3912->3922 4094 4065af wsprintfW 3912->4094 4095 406668 lstrcpynW 3912->4095 3913->3911 3914->3912 3917->3912 3918->3912 3919->3912 3920->3912 3921->3912 3922->3912 3923 406814 SHGetPathFromIDListW CoTaskMemFree 3922->3923 3923->3912 3925 406449 3924->3925 3926 40643c 3924->3926 3925->3763 4097 4062ae 3926->4097 3929 405c8a 3928->3929 3930 405c7e CloseHandle 3928->3930 3929->3763 3930->3929 3932 403c40 3931->3932 3933 403c36 CloseHandle 3931->3933 3934 403c54 3932->3934 3935 403c4a CloseHandle 3932->3935 3933->3932 4131 403c82 3934->4131 3935->3934 3941 405cdd 3940->3941 3942 403b89 ExitProcess 3941->3942 3943 405cf1 MessageBoxIndirectW 3941->3943 3943->3942 3945 401389 2 API calls 3944->3945 3946 401420 3945->3946 3946->3723 3954 4068fc 3947->3954 3948 406977 CharPrevW 3951 406972 3948->3951 3949 406965 CharNextW 3949->3951 3949->3954 3950 405f64 CharNextW 3950->3954 3951->3948 3952 406998 3951->3952 3952->3784 3953 406951 CharNextW 3953->3954 3954->3949 3954->3950 3954->3951 3954->3953 3955 406960 CharNextW 3954->3955 3955->3949 3957 405f53 lstrcatW 3956->3957 3958 40362d 3956->3958 3957->3958 3958->3787 3960 406194 GetTickCount GetTempFileNameW 3959->3960 3961 4061ca 3960->3961 3962 40363e 3960->3962 3961->3960 3961->3962 3962->3699 3963->3793 3964->3795 3966 405f91 3965->3966 3967 40313c 3966->3967 3968 405f97 CharPrevW 3966->3968 3969 406668 lstrcpynW 3967->3969 3968->3966 3968->3967 3969->3799 3971 403057 3970->3971 3972 40303f 3970->3972 3974 403067 GetTickCount 3971->3974 3975 40305f 3971->3975 3973 403048 DestroyWindow 3972->3973 3976 40304f 3972->3976 3973->3976 3974->3976 3978 403075 3974->3978 4018 406a71 3975->4018 3976->3804 3976->3820 4003 4035f8 SetFilePointer 3976->4003 3979 4030aa CreateDialogParamW ShowWindow 3978->3979 3980 40307d 3978->3980 3979->3976 3980->3976 4004 403012 3980->4004 3982 40308b wsprintfW 4007 4056ca 3982->4007 3984->3817 3986 403380 SetFilePointer 3985->3986 3987 40339c 3985->3987 3986->3987 4022 403479 GetTickCount 3987->4022 3990 403439 3990->3820 3993 403479 42 API calls 3994 4033d3 3993->3994 3994->3990 3995 40343f ReadFile 3994->3995 3997 4033e2 3994->3997 3995->3990 3997->3990 3998 4061db ReadFile 3997->3998 4037 40620a WriteFile 3997->4037 3998->3997 4001 4061db ReadFile 4000->4001 4002 4035f5 4001->4002 4002->3819 4003->3808 4005 403021 4004->4005 4006 403023 MulDiv 4004->4006 4005->4006 4006->3982 4009 4056e5 4007->4009 4017 405787 4007->4017 4008 405701 lstrlenW 4011 40572a 4008->4011 4012 40570f lstrlenW 4008->4012 4009->4008 4010 4066a5 17 API calls 4009->4010 4010->4008 4014 405730 SetWindowTextW 4011->4014 4015 40573d 4011->4015 4013 405721 lstrcatW 4012->4013 4012->4017 4013->4011 4014->4015 4016 405743 SendMessageW SendMessageW SendMessageW 4015->4016 4015->4017 4016->4017 4017->3976 4019 406a8e PeekMessageW 4018->4019 4020 406a84 DispatchMessageW 4019->4020 4021 406a9e 4019->4021 4020->4019 4021->3976 4023 4035d1 4022->4023 4024 4034a7 4022->4024 4025 40302e 32 API calls 4023->4025 4039 4035f8 SetFilePointer 4024->4039 4032 4033a3 4025->4032 4027 4034b2 SetFilePointer 4031 4034d7 4027->4031 4028 4035e2 ReadFile 4028->4031 4030 40302e 32 API calls 4030->4031 4031->4028 4031->4030 4031->4032 4033 40620a WriteFile 4031->4033 4034 4035b2 SetFilePointer 4031->4034 4040 406bb0 4031->4040 4032->3990 4035 4061db ReadFile 4032->4035 4033->4031 4034->4023 4036 4033bc 4035->4036 4036->3990 4036->3993 4038 406228 4037->4038 4038->3997 4039->4027 4041 406bd5 4040->4041 4042 406bdd 4040->4042 4041->4031 4042->4041 4043 406c64 GlobalFree 4042->4043 4044 406c6d GlobalAlloc 4042->4044 4045 406ce4 GlobalAlloc 4042->4045 4046 406cdb GlobalFree 4042->4046 4043->4044 4044->4041 4044->4042 4045->4041 4045->4042 4046->4045 4048 404001 4047->4048 4069 4065af wsprintfW 4048->4069 4050 404072 4070 4040a6 4050->4070 4052 403da2 4052->3834 4053 404077 4053->4052 4054 4066a5 17 API calls 4053->4054 4054->4053 4073 4064d5 4055->4073 4058 40656a RegQueryValueExW RegCloseKey 4059 403df6 4058->4059 4059->3836 4059->3846 4059->3850 4077 404610 4060->4077 4062 4057e7 4063 404610 SendMessageW 4062->4063 4065 4057f9 CoUninitialize 4063->4065 4064 4057c0 4064->4062 4080 401389 4064->4080 4065->3866 4067->3830 4068->3836 4069->4050 4071 4066a5 17 API calls 4070->4071 4072 4040b4 SetWindowTextW 4071->4072 4072->4053 4074 4064e4 4073->4074 4075 4064ed RegOpenKeyExW 4074->4075 4076 4064e8 4074->4076 4075->4076 4076->4058 4076->4059 4078 404628 4077->4078 4079 404619 SendMessageW 4077->4079 4078->4064 4079->4078 4082 401390 4080->4082 4081 4013fe 4081->4064 4082->4081 4083 4013cb MulDiv SendMessageW 4082->4083 4083->4082 4084->3880 4086 405fff 4085->4086 4088 406011 4085->4088 4087 40600c CharNextW 4086->4087 4086->4088 4090 406035 4087->4090 4089 405f64 CharNextW 4088->4089 4088->4090 4089->4088 4090->3883 4090->3884 4092 4069b4 FindClose 4091->4092 4093 4069bf 4091->4093 4092->4093 4093->3887 4094->3912 4095->3912 4096->3909 4098 406304 GetShortPathNameW 4097->4098 4099 4062de 4097->4099 4100 406423 4098->4100 4101 406319 4098->4101 4124 406158 GetFileAttributesW CreateFileW 4099->4124 4100->3925 4101->4100 4103 406321 wsprintfA 4101->4103 4106 4066a5 17 API calls 4103->4106 4104 4062e8 CloseHandle GetShortPathNameW 4104->4100 4105 4062fc 4104->4105 4105->4098 4105->4100 4107 406349 4106->4107 4125 406158 GetFileAttributesW CreateFileW 4107->4125 4109 406356 4109->4100 4110 406365 GetFileSize GlobalAlloc 4109->4110 4111 406387 4110->4111 4112 40641c CloseHandle 4110->4112 4113 4061db ReadFile 4111->4113 4112->4100 4114 40638f 4113->4114 4114->4112 4126 4060bd lstrlenA 4114->4126 4117 4063a6 lstrcpyA 4120 4063c8 4117->4120 4118 4063ba 4119 4060bd 4 API calls 4118->4119 4119->4120 4121 4063ff SetFilePointer 4120->4121 4122 40620a WriteFile 4121->4122 4123 406415 GlobalFree 4122->4123 4123->4112 4124->4104 4125->4109 4127 4060fe lstrlenA 4126->4127 4128 406106 4127->4128 4129 4060d7 lstrcmpiA 4127->4129 4128->4117 4128->4118 4129->4128 4130 4060f5 CharNextA 4129->4130 4130->4127 4132 403c90 4131->4132 4133 403c59 4132->4133 4134 403c95 FreeLibrary GlobalFree 4132->4134 4135 405d74 4133->4135 4134->4133 4134->4134 4136 40603f 18 API calls 4135->4136 4137 405d94 4136->4137 4138 405db3 4137->4138 4139 405d9c DeleteFileW 4137->4139 4141 405ede 4138->4141 4175 406668 lstrcpynW 4138->4175 4140 403b71 OleUninitialize 4139->4140 4140->3719 4140->3720 4141->4140 4148 40699e 2 API calls 4141->4148 4143 405dd9 4144 405dec 4143->4144 4145 405ddf lstrcatW 4143->4145 4147 405f83 2 API calls 4144->4147 4146 405df2 4145->4146 4150 405e02 lstrcatW 4146->4150 4151 405df8 4146->4151 4147->4146 4149 405ef8 4148->4149 4149->4140 4152 405efc 4149->4152 4153 405e0d lstrlenW FindFirstFileW 4150->4153 4151->4150 4151->4153 4155 405f37 3 API calls 4152->4155 4154 405ed3 4153->4154 4173 405e2f 4153->4173 4154->4141 4156 405f02 4155->4156 4158 405d2c 5 API calls 4156->4158 4157 405eb6 FindNextFileW 4161 405ecc FindClose 4157->4161 4157->4173 4160 405f0e 4158->4160 4162 405f12 4160->4162 4163 405f28 4160->4163 4161->4154 4162->4140 4166 4056ca 24 API calls 4162->4166 4165 4056ca 24 API calls 4163->4165 4165->4140 4168 405f1f 4166->4168 4167 405d74 60 API calls 4167->4173 4170 406428 36 API calls 4168->4170 4169 4056ca 24 API calls 4169->4157 4172 405f26 4170->4172 4171 4056ca 24 API calls 4171->4173 4172->4140 4173->4157 4173->4167 4173->4169 4173->4171 4174 406428 36 API calls 4173->4174 4176 406668 lstrcpynW 4173->4176 4177 405d2c 4173->4177 4174->4173 4175->4143 4176->4173 4185 406133 GetFileAttributesW 4177->4185 4180 405d59 4180->4173 4181 405d47 RemoveDirectoryW 4183 405d55 4181->4183 4182 405d4f DeleteFileW 4182->4183 4183->4180 4184 405d65 SetFileAttributesW 4183->4184 4184->4180 4186 405d38 4185->4186 4187 406145 SetFileAttributesW 4185->4187 4186->4180 4186->4181 4186->4182 4187->4186 4188 401941 4189 401943 4188->4189 4194 402da6 4189->4194 4192 405d74 67 API calls 4193 401951 4192->4193 4195 402db2 4194->4195 4196 4066a5 17 API calls 4195->4196 4197 402dd3 4196->4197 4198 401948 4197->4198 4199 4068ef 5 API calls 4197->4199 4198->4192 4199->4198 4223 401c43 4245 402d84 4223->4245 4225 401c4a 4226 402d84 17 API calls 4225->4226 4227 401c57 4226->4227 4228 401c6c 4227->4228 4229 402da6 17 API calls 4227->4229 4230 401c7c 4228->4230 4231 402da6 17 API calls 4228->4231 4229->4228 4232 401cd3 4230->4232 4233 401c87 4230->4233 4231->4230 4234 402da6 17 API calls 4232->4234 4235 402d84 17 API calls 4233->4235 4237 401cd8 4234->4237 4236 401c8c 4235->4236 4238 402d84 17 API calls 4236->4238 4239 402da6 17 API calls 4237->4239 4240 401c98 4238->4240 4241 401ce1 FindWindowExW 4239->4241 4242 401cc3 SendMessageW 4240->4242 4243 401ca5 SendMessageTimeoutW 4240->4243 4244 401d03 4241->4244 4242->4244 4243->4244 4246 4066a5 17 API calls 4245->4246 4247 402d99 4246->4247 4247->4225 4306 6fbb17be 4307 6fbb17f1 4306->4307 4317 6fbb2053 4307->4317 4309 6fbb1811 GetDlgItem GetWindowRect MapWindowPoints CreateDialogParamW 4310 6fbb185e SetWindowPos SetWindowLongW GetProcessHeap 4309->4310 4311 6fbb1852 4309->4311 4314 6fbb18ab 4310->4314 4320 6fbb1e9c 4311->4320 4323 6fbb20b3 wsprintfW 4314->4323 4315 6fbb18c1 4326 6fbb1e4e 4317->4326 4319 6fbb206d 4319->4309 4321 6fbb185c 4320->4321 4322 6fbb1ea5 GlobalAlloc lstrcpynW 4320->4322 4321->4315 4322->4321 4324 6fbb1e9c 2 API calls 4323->4324 4325 6fbb20d7 4324->4325 4325->4315 4327 6fbb1e95 4326->4327 4329 6fbb1e58 4326->4329 4327->4319 4328 6fbb1e86 GlobalFree 4328->4327 4329->4327 4329->4328 4330 6fbb1e72 lstrcpynW 4329->4330 4330->4328 4814 6fbb1cbe 4817 6fbb1c66 4814->4817 4818 6fbb2053 2 API calls 4817->4818 4819 6fbb1c6d 4818->4819 4820 6fbb2053 2 API calls 4819->4820 4821 6fbb1c74 IsWindow 4820->4821 4822 6fbb1c81 4821->4822 4823 6fbb1c87 4821->4823 4825 6fbb13d2 GetPropW 4822->4825 4826 6fbb13e5 4825->4826 4826->4823 4844 401e4e GetDC 4845 402d84 17 API calls 4844->4845 4846 401e60 GetDeviceCaps MulDiv ReleaseDC 4845->4846 4847 402d84 17 API calls 4846->4847 4848 401e91 4847->4848 4849 4066a5 17 API calls 4848->4849 4850 401ece CreateFontIndirectW 4849->4850 4851 402638 4850->4851 4852 6fbb1bb4 4853 6fbb2053 2 API calls 4852->4853 4854 6fbb1bba IsWindow 4853->4854 4855 6fbb1bc7 4854->4855 4856 6fbb13d2 GetPropW 4855->4856 4857 6fbb1bd3 4856->4857 4858 6fbb1be5 4857->4858 4859 6fbb1e4e 2 API calls 4857->4859 4859->4858 4556 402950 4557 402da6 17 API calls 4556->4557 4558 40295c 4557->4558 4559 402972 4558->4559 4560 402da6 17 API calls 4558->4560 4561 406133 2 API calls 4559->4561 4560->4559 4562 402978 4561->4562 4584 406158 GetFileAttributesW CreateFileW 4562->4584 4564 402985 4565 402a3b 4564->4565 4566 4029a0 GlobalAlloc 4564->4566 4567 402a23 4564->4567 4568 402a42 DeleteFileW 4565->4568 4569 402a55 4565->4569 4566->4567 4570 4029b9 4566->4570 4571 403371 44 API calls 4567->4571 4568->4569 4585 4035f8 SetFilePointer 4570->4585 4573 402a30 CloseHandle 4571->4573 4573->4565 4574 4029bf 4575 4035e2 ReadFile 4574->4575 4576 4029c8 GlobalAlloc 4575->4576 4577 4029d8 4576->4577 4578 402a0c 4576->4578 4579 403371 44 API calls 4577->4579 4580 40620a WriteFile 4578->4580 4583 4029e5 4579->4583 4581 402a18 GlobalFree 4580->4581 4581->4567 4582 402a03 GlobalFree 4582->4578 4583->4582 4584->4564 4585->4574 4874 6fbb1cae 4875 6fbb1c66 4 API calls 4874->4875 4876 6fbb1cb5 4875->4876 4881 401956 4882 402da6 17 API calls 4881->4882 4883 40195d lstrlenW 4882->4883 4884 402638 4883->4884 4890 402b59 4891 402b60 4890->4891 4892 402bab 4890->4892 4895 402d84 17 API calls 4891->4895 4896 402ba9 4891->4896 4893 406a35 5 API calls 4892->4893 4894 402bb2 4893->4894 4897 402da6 17 API calls 4894->4897 4898 402b6e 4895->4898 4899 402bbb 4897->4899 4900 402d84 17 API calls 4898->4900 4899->4896 4901 402bbf IIDFromString 4899->4901 4903 402b7a 4900->4903 4901->4896 4902 402bce 4901->4902 4902->4896 4908 406668 lstrcpynW 4902->4908 4907 4065af wsprintfW 4903->4907 4906 402beb CoTaskMemFree 4906->4896 4907->4896 4908->4906 4921 402a5b 4922 402d84 17 API calls 4921->4922 4923 402a61 4922->4923 4924 402aa4 4923->4924 4925 402a88 4923->4925 4933 40292e 4923->4933 4926 402abe 4924->4926 4927 402aae 4924->4927 4928 402a8d 4925->4928 4929 402a9e 4925->4929 4931 4066a5 17 API calls 4926->4931 4930 402d84 17 API calls 4927->4930 4935 406668 lstrcpynW 4928->4935 4936 4065af wsprintfW 4929->4936 4930->4933 4931->4933 4935->4933 4936->4933 4791 40175c 4792 402da6 17 API calls 4791->4792 4793 401763 4792->4793 4794 406187 2 API calls 4793->4794 4795 40176a 4794->4795 4796 406187 2 API calls 4795->4796 4796->4795 4937 401d5d 4938 402d84 17 API calls 4937->4938 4939 401d6e SetWindowLongW 4938->4939 4940 402c2a 4939->4940 4948 406d5f 4950 406be3 4948->4950 4949 40754e 4950->4949 4951 406c64 GlobalFree 4950->4951 4952 406c6d GlobalAlloc 4950->4952 4953 406ce4 GlobalAlloc 4950->4953 4954 406cdb GlobalFree 4950->4954 4951->4952 4952->4949 4952->4950 4953->4949 4953->4950 4954->4953 4955 6fbb1b98 CreateControl 4956 401563 4957 402ba4 4956->4957 4960 4065af wsprintfW 4957->4960 4959 402ba9 4960->4959 4968 401968 4969 402d84 17 API calls 4968->4969 4970 40196f 4969->4970 4971 402d84 17 API calls 4970->4971 4972 40197c 4971->4972 4973 402da6 17 API calls 4972->4973 4974 401993 lstrlenW 4973->4974 4976 4019a4 4974->4976 4975 4019e5 4976->4975 4980 406668 lstrcpynW 4976->4980 4978 4019d5 4978->4975 4979 4019da lstrlenW 4978->4979 4979->4975 4980->4978 4981 40166a 4982 402da6 17 API calls 4981->4982 4983 401670 4982->4983 4984 40699e 2 API calls 4983->4984 4985 401676 4984->4985 5014 404a6e 5015 404aa4 5014->5015 5016 404a7e 5014->5016 5018 40462b 8 API calls 5015->5018 5017 4045c4 18 API calls 5016->5017 5020 404a8b SetDlgItemTextW 5017->5020 5019 404ab0 5018->5019 5020->5015 4515 40176f 4516 402da6 17 API calls 4515->4516 4517 401776 4516->4517 4518 401796 4517->4518 4519 40179e 4517->4519 4554 406668 lstrcpynW 4518->4554 4555 406668 lstrcpynW 4519->4555 4522 40179c 4526 4068ef 5 API calls 4522->4526 4523 4017a9 4524 405f37 3 API calls 4523->4524 4525 4017af lstrcatW 4524->4525 4525->4522 4543 4017bb 4526->4543 4527 40699e 2 API calls 4527->4543 4528 406133 2 API calls 4528->4543 4530 4017cd CompareFileTime 4530->4543 4531 40188d 4533 4056ca 24 API calls 4531->4533 4532 401864 4534 4056ca 24 API calls 4532->4534 4541 401879 4532->4541 4535 401897 4533->4535 4534->4541 4536 403371 44 API calls 4535->4536 4537 4018aa 4536->4537 4538 4018be SetFileTime 4537->4538 4539 4018d0 CloseHandle 4537->4539 4538->4539 4539->4541 4542 4018e1 4539->4542 4540 4066a5 17 API calls 4540->4543 4544 4018e6 4542->4544 4545 4018f9 4542->4545 4543->4527 4543->4528 4543->4530 4543->4531 4543->4532 4543->4540 4546 406668 lstrcpynW 4543->4546 4551 405cc8 MessageBoxIndirectW 4543->4551 4553 406158 GetFileAttributesW CreateFileW 4543->4553 4547 4066a5 17 API calls 4544->4547 4548 4066a5 17 API calls 4545->4548 4546->4543 4549 4018ee lstrcatW 4547->4549 4550 401901 4548->4550 4549->4550 4550->4541 4552 405cc8 MessageBoxIndirectW 4550->4552 4551->4543 4552->4541 4553->4543 4554->4522 4555->4523 5021 401a72 5022 402d84 17 API calls 5021->5022 5023 401a7b 5022->5023 5024 402d84 17 API calls 5023->5024 5025 401a20 5024->5025 5026 401573 5027 401583 ShowWindow 5026->5027 5028 40158c 5026->5028 5027->5028 5029 402c2a 5028->5029 5030 40159a ShowWindow 5028->5030 5030->5029 5048 401b77 5049 402da6 17 API calls 5048->5049 5050 401b7e 5049->5050 5051 402d84 17 API calls 5050->5051 5052 401b87 wsprintfW 5051->5052 5053 402c2a 5052->5053 5054 6fbb148c 5055 6fbb13d2 GetPropW 5054->5055 5056 6fbb1497 5055->5056 5057 6fbb14d2 5056->5057 5058 6fbb14ba CallWindowProcW 5056->5058 5059 6fbb14a1 LoadCursorW SetCursor 5056->5059 5058->5057 5059->5057 5061 40167b 5062 402da6 17 API calls 5061->5062 5063 401682 5062->5063 5064 402da6 17 API calls 5063->5064 5065 40168b 5064->5065 5066 402da6 17 API calls 5065->5066 5067 401694 MoveFileW 5066->5067 5068 4016a0 5067->5068 5069 4016a7 5067->5069 5071 401423 24 API calls 5068->5071 5070 40699e 2 API calls 5069->5070 5073 4022f6 5069->5073 5072 4016b6 5070->5072 5071->5073 5072->5073 5074 406428 36 API calls 5072->5074 5074->5068 5108 401000 5109 401037 BeginPaint GetClientRect 5108->5109 5110 40100c DefWindowProcW 5108->5110 5112 4010f3 5109->5112 5113 401179 5110->5113 5114 401073 CreateBrushIndirect FillRect DeleteObject 5112->5114 5115 4010fc 5112->5115 5114->5112 5116 401102 CreateFontIndirectW 5115->5116 5117 401167 EndPaint 5115->5117 5116->5117 5118 401112 6 API calls 5116->5118 5117->5113 5118->5117 5130 401503 5131 40150b 5130->5131 5133 40151e 5130->5133 5132 402d84 17 API calls 5131->5132 5132->5133 5140 402c05 SendMessageW 5141 402c2a 5140->5141 5142 402c1f InvalidateRect 5140->5142 5142->5141 4408 405809 4409 4059b3 4408->4409 4410 40582a GetDlgItem GetDlgItem GetDlgItem 4408->4410 4412 4059e4 4409->4412 4413 4059bc GetDlgItem CreateThread CloseHandle 4409->4413 4453 4045f9 SendMessageW 4410->4453 4415 405a0f 4412->4415 4416 405a34 4412->4416 4417 4059fb ShowWindow ShowWindow 4412->4417 4413->4412 4456 40579d 5 API calls 4413->4456 4414 40589a 4420 4058a1 GetClientRect GetSystemMetrics SendMessageW SendMessageW 4414->4420 4418 405a6f 4415->4418 4422 405a23 4415->4422 4423 405a49 ShowWindow 4415->4423 4419 40462b 8 API calls 4416->4419 4455 4045f9 SendMessageW 4417->4455 4418->4416 4429 405a7d SendMessageW 4418->4429 4424 405a42 4419->4424 4427 4058f3 SendMessageW SendMessageW 4420->4427 4428 40590f 4420->4428 4430 40459d SendMessageW 4422->4430 4425 405a69 4423->4425 4426 405a5b 4423->4426 4432 40459d SendMessageW 4425->4432 4431 4056ca 24 API calls 4426->4431 4427->4428 4433 405922 4428->4433 4434 405914 SendMessageW 4428->4434 4429->4424 4435 405a96 CreatePopupMenu 4429->4435 4430->4416 4431->4425 4432->4418 4437 4045c4 18 API calls 4433->4437 4434->4433 4436 4066a5 17 API calls 4435->4436 4438 405aa6 AppendMenuW 4436->4438 4439 405932 4437->4439 4440 405ac3 GetWindowRect 4438->4440 4441 405ad6 TrackPopupMenu 4438->4441 4442 40593b ShowWindow 4439->4442 4443 40596f GetDlgItem SendMessageW 4439->4443 4440->4441 4441->4424 4444 405af1 4441->4444 4445 405951 ShowWindow 4442->4445 4446 40595e 4442->4446 4443->4424 4447 405996 SendMessageW SendMessageW 4443->4447 4448 405b0d SendMessageW 4444->4448 4445->4446 4454 4045f9 SendMessageW 4446->4454 4447->4424 4448->4448 4449 405b2a OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 4448->4449 4451 405b4f SendMessageW 4449->4451 4451->4451 4452 405b78 GlobalUnlock SetClipboardData CloseClipboard 4451->4452 4452->4424 4453->4414 4454->4443 4455->4415 5143 404e0b 5144 404e37 5143->5144 5145 404e1b 5143->5145 5147 404e6a 5144->5147 5148 404e3d SHGetPathFromIDListW 5144->5148 5154 405cac GetDlgItemTextW 5145->5154 5150 404e4d 5148->5150 5153 404e54 SendMessageW 5148->5153 5149 404e28 SendMessageW 5149->5144 5151 40140b 2 API calls 5150->5151 5151->5153 5153->5147 5154->5149 5155 40290b 5156 402da6 17 API calls 5155->5156 5157 402912 FindFirstFileW 5156->5157 5158 40293a 5157->5158 5162 402925 5157->5162 5159 402943 5158->5159 5163 4065af wsprintfW 5158->5163 5164 406668 lstrcpynW 5159->5164 5163->5159 5164->5162 5165 40190c 5166 401943 5165->5166 5167 402da6 17 API calls 5166->5167 5168 401948 5167->5168 5169 405d74 67 API calls 5168->5169 5170 401951 5169->5170 5174 40190f 5175 402da6 17 API calls 5174->5175 5176 401916 5175->5176 5177 405cc8 MessageBoxIndirectW 5176->5177 5178 40191f 5177->5178 5191 401f12 5192 402da6 17 API calls 5191->5192 5193 401f18 5192->5193 5194 402da6 17 API calls 5193->5194 5195 401f21 5194->5195 5196 402da6 17 API calls 5195->5196 5197 401f2a 5196->5197 5198 402da6 17 API calls 5197->5198 5199 401f33 5198->5199 5200 401423 24 API calls 5199->5200 5201 401f3a 5200->5201 5208 405c8e ShellExecuteExW 5201->5208 5203 401f82 5204 40292e 5203->5204 5209 406ae0 WaitForSingleObject 5203->5209 5206 401f9f CloseHandle 5206->5204 5208->5203 5210 406afa 5209->5210 5211 406b0c GetExitCodeProcess 5210->5211 5212 406a71 2 API calls 5210->5212 5211->5206 5213 406b01 WaitForSingleObject 5212->5213 5213->5210 5221 6fbb10ef 5222 6fbb1e4e 2 API calls 5221->5222 5223 6fbb1151 5222->5223 5224 6fbb1e4e 2 API calls 5223->5224 5225 6fbb1158 5224->5225 5226 6fbb1e4e 2 API calls 5225->5226 5227 6fbb115f lstrcmpiW GetFileAttributesW 5226->5227 5228 6fbb11a8 5227->5228 5229 6fbb1185 5227->5229 5231 6fbb11be 5228->5231 5232 6fbb11b2 lstrcpyW 5228->5232 5229->5228 5230 6fbb1189 lstrcpyW 5229->5230 5230->5228 5233 6fbb11e5 GetCurrentDirectoryW 5231->5233 5234 6fbb11d8 CharNextW 5231->5234 5232->5231 5235 6fbb120d GetOpenFileNameW 5233->5235 5236 6fbb1205 GetSaveFileNameW 5233->5236 5234->5231 5237 6fbb120f 5235->5237 5236->5237 5238 6fbb1213 CommDlgExtendedError 5237->5238 5240 6fbb123a 5237->5240 5239 6fbb1220 5238->5239 5238->5240 5242 6fbb1238 GetOpenFileNameW 5239->5242 5243 6fbb1230 GetSaveFileNameW 5239->5243 5241 6fbb1e9c 2 API calls 5240->5241 5244 6fbb124f SetCurrentDirectoryW 5241->5244 5242->5240 5243->5240 5259 401d17 5260 402d84 17 API calls 5259->5260 5261 401d1d IsWindow 5260->5261 5262 401a20 5261->5262 5263 40261c 5264 402da6 17 API calls 5263->5264 5265 402623 5264->5265 5268 406158 GetFileAttributesW CreateFileW 5265->5268 5267 40262f 5268->5267 5269 6fbb1be7 5270 6fbb2053 2 API calls 5269->5270 5271 6fbb1bed IsWindow 5270->5271 5272 6fbb1bfa 5271->5272 5274 6fbb1c00 5271->5274 5273 6fbb13d2 GetPropW 5272->5273 5273->5274 5275 6fbb1e9c 2 API calls 5274->5275 5276 6fbb1c14 5275->5276 4457 40252a 4468 402de6 4457->4468 4460 402da6 17 API calls 4461 40253d 4460->4461 4462 402548 RegQueryValueExW 4461->4462 4466 40292e 4461->4466 4463 402568 4462->4463 4464 40256e RegCloseKey 4462->4464 4463->4464 4473 4065af wsprintfW 4463->4473 4464->4466 4469 402da6 17 API calls 4468->4469 4470 402dfd 4469->4470 4471 4064d5 RegOpenKeyExW 4470->4471 4472 402534 4471->4472 4472->4460 4473->4464 5318 40202a 5319 402da6 17 API calls 5318->5319 5320 402031 5319->5320 5321 406a35 5 API calls 5320->5321 5322 402040 5321->5322 5323 4020cc 5322->5323 5324 40205c GlobalAlloc 5322->5324 5324->5323 5325 402070 5324->5325 5326 406a35 5 API calls 5325->5326 5327 402077 5326->5327 5328 406a35 5 API calls 5327->5328 5329 402081 5328->5329 5329->5323 5333 4065af wsprintfW 5329->5333 5331 4020ba 5334 4065af wsprintfW 5331->5334 5333->5331 5334->5323 5342 6fbb14d6 5343 6fbb14ee 5342->5343 5344 6fbb1775 5342->5344 5346 6fbb14f7 5343->5346 5347 6fbb1666 5343->5347 5345 6fbb15b3 5344->5345 5350 6fbb1781 RemovePropW 5344->5350 5348 6fbb15e0 5346->5348 5349 6fbb1500 5346->5349 5351 6fbb13d2 GetPropW 5347->5351 5354 6fbb13d2 GetPropW 5348->5354 5352 6fbb153c GetDlgItem 5349->5352 5353 6fbb1507 5349->5353 5350->5345 5350->5350 5355 6fbb1687 5351->5355 5356 6fbb13d2 GetPropW 5352->5356 5353->5345 5359 6fbb1524 SendMessageW 5353->5359 5357 6fbb15ea 5354->5357 5355->5345 5358 6fbb168f GetWindowTextW DrawTextW 5355->5358 5368 6fbb1552 5356->5368 5357->5345 5360 6fbb20b3 3 API calls 5357->5360 5362 6fbb16e3 5358->5362 5359->5345 5363 6fbb1618 5360->5363 5361 6fbb174b 5361->5345 5371 6fbb1763 DrawFocusRect 5361->5371 5362->5361 5364 6fbb1717 GetWindowLongW 5362->5364 5365 6fbb20b3 3 API calls 5363->5365 5366 6fbb1726 5364->5366 5367 6fbb1735 DrawTextW 5364->5367 5369 6fbb1620 5365->5369 5377 6fbb17ac GetSysColor 5366->5377 5367->5361 5368->5345 5373 6fbb20b3 3 API calls 5368->5373 5372 6fbb20b3 3 API calls 5369->5372 5371->5345 5375 6fbb1627 5372->5375 5373->5345 5375->5345 5376 6fbb1653 SetWindowLongW 5375->5376 5376->5345 5378 6fbb172b SetTextColor 5377->5378 5378->5367 5379 401a30 5380 402da6 17 API calls 5379->5380 5381 401a39 ExpandEnvironmentStringsW 5380->5381 5382 401a4d 5381->5382 5384 401a60 5381->5384 5383 401a52 lstrcmpW 5382->5383 5382->5384 5383->5384 5385 405031 GetDlgItem GetDlgItem 5386 405083 7 API calls 5385->5386 5394 4052a8 5385->5394 5387 40512a DeleteObject 5386->5387 5388 40511d SendMessageW 5386->5388 5389 405133 5387->5389 5388->5387 5390 40516a 5389->5390 5395 4066a5 17 API calls 5389->5395 5392 4045c4 18 API calls 5390->5392 5391 40538a 5393 405436 5391->5393 5398 40529b 5391->5398 5404 4053e3 SendMessageW 5391->5404 5397 40517e 5392->5397 5399 405440 SendMessageW 5393->5399 5400 405448 5393->5400 5394->5391 5419 405317 5394->5419 5439 404f7f SendMessageW 5394->5439 5396 40514c SendMessageW SendMessageW 5395->5396 5396->5389 5403 4045c4 18 API calls 5397->5403 5401 40462b 8 API calls 5398->5401 5399->5400 5407 405461 5400->5407 5408 40545a ImageList_Destroy 5400->5408 5415 405471 5400->5415 5406 405637 5401->5406 5420 40518f 5403->5420 5404->5398 5410 4053f8 SendMessageW 5404->5410 5405 40537c SendMessageW 5405->5391 5411 40546a GlobalFree 5407->5411 5407->5415 5408->5407 5409 4055eb 5409->5398 5416 4055fd ShowWindow GetDlgItem ShowWindow 5409->5416 5413 40540b 5410->5413 5411->5415 5412 40526a GetWindowLongW SetWindowLongW 5414 405283 5412->5414 5424 40541c SendMessageW 5413->5424 5417 4052a0 5414->5417 5418 405288 ShowWindow 5414->5418 5415->5409 5432 4054ac 5415->5432 5444 404fff 5415->5444 5416->5398 5438 4045f9 SendMessageW 5417->5438 5437 4045f9 SendMessageW 5418->5437 5419->5391 5419->5405 5420->5412 5423 4051e2 SendMessageW 5420->5423 5425 405265 5420->5425 5426 405220 SendMessageW 5420->5426 5427 405234 SendMessageW 5420->5427 5423->5420 5424->5393 5425->5412 5425->5414 5426->5420 5427->5420 5429 4055b6 5430 4055c1 InvalidateRect 5429->5430 5433 4055cd 5429->5433 5430->5433 5431 4054da SendMessageW 5435 4054f0 5431->5435 5432->5431 5432->5435 5433->5409 5436 404f3a 20 API calls 5433->5436 5434 405564 SendMessageW SendMessageW 5434->5435 5435->5429 5435->5434 5436->5409 5437->5398 5438->5394 5440 404fa2 GetMessagePos ScreenToClient SendMessageW 5439->5440 5441 404fde SendMessageW 5439->5441 5442 404fd6 5440->5442 5443 404fdb 5440->5443 5441->5442 5442->5419 5443->5441 5453 406668 lstrcpynW 5444->5453 5446 405012 5454 4065af wsprintfW 5446->5454 5448 40501c 5449 40140b 2 API calls 5448->5449 5450 405025 5449->5450 5455 406668 lstrcpynW 5450->5455 5452 40502c 5452->5432 5453->5446 5454->5448 5455->5452 4586 6fbb18c9 GetProcessHeap 4587 6fbb18ec 4586->4587 4588 6fbb190f 4587->4588 4589 6fbb1900 4587->4589 4591 6fbb1e4e 2 API calls 4588->4591 4590 6fbb1e9c 2 API calls 4589->4590 4592 6fbb190a 4590->4592 4593 6fbb1917 4591->4593 4594 6fbb1b93 4592->4594 4595 6fbb194c 4593->4595 4623 6fbb2083 4593->4623 4597 6fbb1e9c 2 API calls 4595->4597 4599 6fbb1956 GetProcessHeap 4597->4599 4598 6fbb1920 4600 6fbb2083 2 API calls 4598->4600 4601 6fbb1b8c HeapFree 4599->4601 4602 6fbb1928 4600->4602 4601->4594 4626 6fbb125b GetClientRect 4602->4626 4604 6fbb1940 4605 6fbb1e4e 2 API calls 4604->4605 4606 6fbb1948 4605->4606 4606->4595 4607 6fbb1960 GetProcessHeap HeapReAlloc lstrcmpiW 4606->4607 4608 6fbb19bb lstrcmpiW 4607->4608 4621 6fbb19a0 4607->4621 4609 6fbb19e2 lstrcmpiW 4608->4609 4608->4621 4610 6fbb1a09 lstrcmpiW 4609->4610 4609->4621 4611 6fbb1a30 lstrcmpiW 4610->4611 4610->4621 4613 6fbb1a54 lstrcmpiW 4611->4613 4611->4621 4612 6fbb1adb lstrcmpiW 4614 6fbb1aec CreateWindowExW SetPropW SendMessageW SendMessageW 4612->4614 4615 6fbb1ae7 4612->4615 4618 6fbb1a78 lstrcmpiW 4613->4618 4613->4621 4616 6fbb1b7b 4614->4616 4617 6fbb1b60 SetWindowLongW 4614->4617 4615->4614 4619 6fbb20b3 3 API calls 4616->4619 4617->4616 4620 6fbb1a9c lstrcmpiW 4618->4620 4618->4621 4622 6fbb1b81 GetProcessHeap 4619->4622 4620->4621 4621->4612 4622->4601 4624 6fbb1e4e 2 API calls 4623->4624 4625 6fbb209d 4624->4625 4625->4598 4627 6fbb1e4e 2 API calls 4626->4627 4628 6fbb1292 4627->4628 4642 6fbb1303 4628->4642 4643 6fbb1332 lstrlenW CharPrevW 4628->4643 4631 6fbb1e4e 2 API calls 4632 6fbb12b6 4631->4632 4633 6fbb1332 4 API calls 4632->4633 4632->4642 4634 6fbb12c9 4633->4634 4635 6fbb1e4e 2 API calls 4634->4635 4636 6fbb12db 4635->4636 4637 6fbb1332 4 API calls 4636->4637 4636->4642 4638 6fbb12ed 4637->4638 4639 6fbb1e4e 2 API calls 4638->4639 4640 6fbb12ff 4639->4640 4641 6fbb1332 4 API calls 4640->4641 4640->4642 4641->4642 4642->4604 4644 6fbb1358 4643->4644 4645 6fbb1375 4644->4645 4647 6fbb1360 MulDiv 4644->4647 4648 6fbb137b MapDialogRect 4645->4648 4649 6fbb12a4 4645->4649 4647->4649 4648->4649 4649->4631 5471 402434 5472 402467 5471->5472 5473 40243c 5471->5473 5475 402da6 17 API calls 5472->5475 5474 402de6 17 API calls 5473->5474 5476 402443 5474->5476 5477 40246e 5475->5477 5479 402da6 17 API calls 5476->5479 5481 40247b 5476->5481 5482 402e64 5477->5482 5480 402454 RegDeleteValueW RegCloseKey 5479->5480 5480->5481 5483 402e71 5482->5483 5484 402e78 5482->5484 5483->5481 5484->5483 5486 402ea9 5484->5486 5487 4064d5 RegOpenKeyExW 5486->5487 5488 402ed7 5487->5488 5489 402ee7 RegEnumValueW 5488->5489 5490 402f0a 5488->5490 5497 402f81 5488->5497 5489->5490 5491 402f71 RegCloseKey 5489->5491 5490->5491 5492 402f46 RegEnumKeyW 5490->5492 5493 402f4f RegCloseKey 5490->5493 5495 402ea9 6 API calls 5490->5495 5491->5497 5492->5490 5492->5493 5494 406a35 5 API calls 5493->5494 5496 402f5f 5494->5496 5495->5490 5496->5497 5498 402f63 RegDeleteKeyW 5496->5498 5497->5483 5498->5497 5499 404734 lstrlenW 5500 404753 5499->5500 5501 404755 WideCharToMultiByte 5499->5501 5500->5501 4650 6fbb1cce SendMessageW ShowWindow 4651 6fbb1d53 SetWindowLongW 4650->4651 4652 6fbb1d02 4650->4652 4653 6fbb1d09 KiUserCallbackDispatcher IsDialogMessageW 4652->4653 4656 6fbb1d52 4652->4656 4653->4652 4654 6fbb1d26 IsDialogMessageW 4653->4654 4654->4652 4655 6fbb1d36 TranslateMessage DispatchMessageW 4654->4655 4655->4652 4656->4651 5502 401735 5503 402da6 17 API calls 5502->5503 5504 40173c SearchPathW 5503->5504 5505 401757 5504->5505 5506 401d38 5507 402d84 17 API calls 5506->5507 5508 401d3f 5507->5508 5509 402d84 17 API calls 5508->5509 5510 401d4b GetDlgItem 5509->5510 5511 402638 5510->5511 5516 6fbb1cc6 5519 6fbb1c9b 5516->5519 5520 6fbb2053 2 API calls 5519->5520 5521 6fbb1ca0 5520->5521 5522 40563e 5523 405662 5522->5523 5524 40564e 5522->5524 5527 40566a IsWindowVisible 5523->5527 5533 405681 5523->5533 5525 405654 5524->5525 5526 4056ab 5524->5526 5529 404610 SendMessageW 5525->5529 5528 4056b0 CallWindowProcW 5526->5528 5527->5526 5530 405677 5527->5530 5532 40565e 5528->5532 5529->5532 5531 404f7f 5 API calls 5530->5531 5531->5533 5533->5528 5534 404fff 4 API calls 5533->5534 5534->5526 5535 40263e 5536 402652 5535->5536 5537 40266d 5535->5537 5540 402d84 17 API calls 5536->5540 5538 402672 5537->5538 5539 40269d 5537->5539 5541 402da6 17 API calls 5538->5541 5542 402da6 17 API calls 5539->5542 5543 402659 5540->5543 5544 402679 5541->5544 5545 4026a4 lstrlenW 5542->5545 5548 4026e7 5543->5548 5549 4026d1 5543->5549 5551 406239 5 API calls 5543->5551 5552 40668a WideCharToMultiByte 5544->5552 5545->5543 5547 40268d lstrlenA 5547->5543 5549->5548 5550 40620a WriteFile 5549->5550 5550->5548 5551->5549 5552->5547 4200 4015c1 4201 402da6 17 API calls 4200->4201 4202 4015c8 4201->4202 4203 405fe2 4 API calls 4202->4203 4217 4015d1 4203->4217 4204 401631 4206 401663 4204->4206 4207 401636 4204->4207 4205 405f64 CharNextW 4205->4217 4210 401423 24 API calls 4206->4210 4219 401423 4207->4219 4215 40165b 4210->4215 4211 405c16 2 API calls 4211->4217 4213 405c33 5 API calls 4213->4217 4214 40164a SetCurrentDirectoryW 4214->4215 4216 401617 GetFileAttributesW 4216->4217 4217->4204 4217->4205 4217->4211 4217->4213 4217->4216 4218 405b99 4 API calls 4217->4218 4218->4217 4220 4056ca 24 API calls 4219->4220 4221 401431 4220->4221 4222 406668 lstrcpynW 4221->4222 4222->4214 4810 4028c4 4811 4028ca 4810->4811 4812 4028d2 FindClose 4811->4812 4813 402c2a 4811->4813 4812->4813 4331 4040c5 4332 4040dd 4331->4332 4333 40423e 4331->4333 4332->4333 4334 4040e9 4332->4334 4335 40428f 4333->4335 4336 40424f GetDlgItem GetDlgItem 4333->4336 4337 4040f4 SetWindowPos 4334->4337 4338 404107 4334->4338 4340 4042e9 4335->4340 4351 401389 2 API calls 4335->4351 4339 4045c4 18 API calls 4336->4339 4337->4338 4342 404110 ShowWindow 4338->4342 4343 404152 4338->4343 4344 404279 KiUserCallbackDispatcher 4339->4344 4341 404610 SendMessageW 4340->4341 4345 404239 4340->4345 4373 4042fb 4341->4373 4346 404130 GetWindowLongW 4342->4346 4347 4041fc 4342->4347 4348 404171 4343->4348 4349 40415a DestroyWindow 4343->4349 4350 40140b 2 API calls 4344->4350 4346->4347 4353 404149 ShowWindow 4346->4353 4352 40462b 8 API calls 4347->4352 4355 404176 SetWindowLongW 4348->4355 4356 404187 4348->4356 4354 40454d 4349->4354 4350->4335 4357 4042c1 4351->4357 4352->4345 4353->4343 4354->4345 4362 40457e ShowWindow 4354->4362 4355->4345 4356->4347 4360 404193 GetDlgItem 4356->4360 4357->4340 4361 4042c5 SendMessageW 4357->4361 4358 40140b 2 API calls 4358->4373 4359 40454f DestroyWindow EndDialog 4359->4354 4363 4041c1 4360->4363 4364 4041a4 SendMessageW IsWindowEnabled 4360->4364 4361->4345 4362->4345 4366 4041ce 4363->4366 4367 404215 SendMessageW 4363->4367 4368 4041e1 4363->4368 4376 4041c6 4363->4376 4364->4345 4364->4363 4365 4066a5 17 API calls 4365->4373 4366->4367 4366->4376 4367->4347 4371 4041e9 4368->4371 4372 4041fe 4368->4372 4370 4045c4 18 API calls 4370->4373 4374 40140b 2 API calls 4371->4374 4375 40140b 2 API calls 4372->4375 4373->4345 4373->4358 4373->4359 4373->4365 4373->4370 4377 4045c4 18 API calls 4373->4377 4393 40448f DestroyWindow 4373->4393 4374->4376 4375->4376 4376->4347 4405 40459d 4376->4405 4378 404376 GetDlgItem 4377->4378 4379 404393 ShowWindow KiUserCallbackDispatcher 4378->4379 4380 40438b 4378->4380 4402 4045e6 KiUserCallbackDispatcher 4379->4402 4380->4379 4382 4043bd KiUserCallbackDispatcher 4387 4043d1 4382->4387 4383 4043d6 GetSystemMenu EnableMenuItem SendMessageW 4384 404406 SendMessageW 4383->4384 4383->4387 4384->4387 4386 4040a6 18 API calls 4386->4387 4387->4383 4387->4386 4403 4045f9 SendMessageW 4387->4403 4404 406668 lstrcpynW 4387->4404 4389 404435 lstrlenW 4390 4066a5 17 API calls 4389->4390 4391 40444b SetWindowTextW 4390->4391 4392 401389 2 API calls 4391->4392 4392->4373 4393->4354 4394 4044a9 CreateDialogParamW 4393->4394 4394->4354 4395 4044dc 4394->4395 4396 4045c4 18 API calls 4395->4396 4397 4044e7 GetDlgItem GetWindowRect ScreenToClient SetWindowPos 4396->4397 4398 401389 2 API calls 4397->4398 4399 40452d 4398->4399 4399->4345 4400 404535 ShowWindow 4399->4400 4401 404610 SendMessageW 4400->4401 4401->4354 4402->4382 4403->4387 4404->4389 4406 4045a4 4405->4406 4407 4045aa SendMessageW 4405->4407 4406->4407 4407->4347 4830 4016cc 4831 402da6 17 API calls 4830->4831 4832 4016d2 GetFullPathNameW 4831->4832 4833 4016ec 4832->4833 4839 40170e 4832->4839 4836 40699e 2 API calls 4833->4836 4833->4839 4834 401723 GetShortPathNameW 4835 402c2a 4834->4835 4837 4016fe 4836->4837 4837->4839 4840 406668 lstrcpynW 4837->4840 4839->4834 4839->4835 4840->4839 4867 6fbb1c29 4868 6fbb2053 2 API calls 4867->4868 4869 6fbb1c2f 4868->4869 4870 6fbb2053 2 API calls 4869->4870 4871 6fbb1c36 4870->4871 4872 6fbb1c51 4871->4872 4873 6fbb1c3e SetTimer 4871->4873 4873->4872 4877 403cd5 4878 403ce0 4877->4878 4879 403ce4 4878->4879 4880 403ce7 GlobalAlloc 4878->4880 4880->4879 4885 4014d7 4886 402d84 17 API calls 4885->4886 4887 4014dd Sleep 4886->4887 4889 402c2a 4887->4889 4740 4020d8 4741 4020ea 4740->4741 4751 40219c 4740->4751 4742 402da6 17 API calls 4741->4742 4743 4020f1 4742->4743 4745 402da6 17 API calls 4743->4745 4744 401423 24 API calls 4746 4022f6 4744->4746 4747 4020fa 4745->4747 4748 402110 LoadLibraryExW 4747->4748 4749 402102 GetModuleHandleW 4747->4749 4750 402121 4748->4750 4748->4751 4749->4748 4749->4750 4762 406aa4 4750->4762 4751->4744 4754 402132 4757 402151 KiUserCallbackDispatcher 4754->4757 4758 40213a 4754->4758 4755 40216b 4756 4056ca 24 API calls 4755->4756 4759 402142 4756->4759 4757->4759 4760 401423 24 API calls 4758->4760 4759->4746 4761 40218e FreeLibrary 4759->4761 4760->4759 4761->4746 4767 40668a WideCharToMultiByte 4762->4767 4764 406ac1 4765 406ac8 GetProcAddress 4764->4765 4766 40212c 4764->4766 4765->4766 4766->4754 4766->4755 4767->4764 4909 6fbb1021 4910 6fbb1e4e 2 API calls 4909->4910 4911 6fbb1054 4910->4911 4912 6fbb10b4 4911->4912 4913 6fbb1e4e 2 API calls 4911->4913 4914 6fbb1e9c 2 API calls 4912->4914 4916 6fbb1069 4913->4916 4915 6fbb10be 4914->4915 4916->4912 4917 6fbb106d SHBrowseForFolderW 4916->4917 4917->4912 4918 6fbb10c0 4917->4918 4919 6fbb1e9c 2 API calls 4918->4919 4920 6fbb10e5 CoTaskMemFree 4919->4920 4920->4915 4941 4028de 4942 4028e6 4941->4942 4943 4028ea FindNextFileW 4942->4943 4945 4028fc 4942->4945 4944 402943 4943->4944 4943->4945 4947 406668 lstrcpynW 4944->4947 4947->4945 4986 402aeb 4987 402d84 17 API calls 4986->4987 4988 402af1 4987->4988 4989 40292e 4988->4989 4990 4066a5 17 API calls 4988->4990 4990->4989 4991 4026ec 4992 402d84 17 API calls 4991->4992 4993 4026fb 4992->4993 4994 402745 ReadFile 4993->4994 4995 4061db ReadFile 4993->4995 4996 402785 MultiByteToWideChar 4993->4996 4997 40283a 4993->4997 5000 4027ab SetFilePointer MultiByteToWideChar 4993->5000 5001 40284b 4993->5001 5003 402838 4993->5003 5004 406239 SetFilePointer 4993->5004 4994->4993 4994->5003 4995->4993 4996->4993 5013 4065af wsprintfW 4997->5013 5000->4993 5002 40286c SetFilePointer 5001->5002 5001->5003 5002->5003 5005 406255 5004->5005 5006 40626d 5004->5006 5007 4061db ReadFile 5005->5007 5006->4993 5008 406261 5007->5008 5008->5006 5009 406276 SetFilePointer 5008->5009 5010 40629e SetFilePointer 5008->5010 5009->5010 5011 406281 5009->5011 5010->5006 5012 40620a WriteFile 5011->5012 5012->5006 5013->5003 5031 4023f4 5032 402da6 17 API calls 5031->5032 5033 402403 5032->5033 5034 402da6 17 API calls 5033->5034 5035 40240c 5034->5035 5036 402da6 17 API calls 5035->5036 5037 402416 GetPrivateProfileStringW 5036->5037 5038 4014f5 SetForegroundWindow 5039 402c2a 5038->5039 5040 401ff6 5041 402da6 17 API calls 5040->5041 5042 401ffd 5041->5042 5043 40699e 2 API calls 5042->5043 5044 402003 5043->5044 5046 402014 5044->5046 5047 4065af wsprintfW 5044->5047 5047->5046 5060 4046fa lstrcpynW lstrlenW 5075 6fbb1000 5076 6fbb101c 5075->5076 5077 6fbb1007 SendMessageW 5075->5077 5077->5076 4797 6fbb1407 4798 6fbb1415 4797->4798 4799 6fbb1434 CallWindowProcW 4797->4799 4798->4799 4800 6fbb1430 4798->4800 4799->4800 4801 6fbb1454 4799->4801 4801->4800 4802 6fbb1458 DestroyWindow GetProcessHeap RtlFreeHeap 4801->4802 4802->4800 5085 4022ff 5086 402da6 17 API calls 5085->5086 5087 402305 5086->5087 5088 402da6 17 API calls 5087->5088 5089 40230e 5088->5089 5090 402da6 17 API calls 5089->5090 5091 402317 5090->5091 5092 40699e 2 API calls 5091->5092 5093 402320 5092->5093 5094 402331 lstrlenW lstrlenW 5093->5094 5098 402324 5093->5098 5096 4056ca 24 API calls 5094->5096 5095 4056ca 24 API calls 5099 40232c 5095->5099 5097 40236f SHFileOperationW 5096->5097 5097->5098 5097->5099 5098->5095 5098->5099 5100 4019ff 5101 402da6 17 API calls 5100->5101 5102 401a06 5101->5102 5103 402da6 17 API calls 5102->5103 5104 401a0f 5103->5104 5105 401a16 lstrcmpiW 5104->5105 5106 401a28 lstrcmpW 5104->5106 5107 401a1c 5105->5107 5106->5107 5119 401d81 5120 401d94 GetDlgItem 5119->5120 5121 401d87 5119->5121 5122 401d8e 5120->5122 5123 402d84 17 API calls 5121->5123 5124 401dd5 GetClientRect LoadImageW SendMessageW 5122->5124 5125 402da6 17 API calls 5122->5125 5123->5122 5127 401e33 5124->5127 5129 401e3f 5124->5129 5125->5124 5128 401e38 DeleteObject 5127->5128 5127->5129 5128->5129 4248 404783 4250 40479b 4248->4250 4253 4048b5 4248->4253 4249 40491f 4251 4049e9 4249->4251 4252 404929 GetDlgItem 4249->4252 4279 4045c4 4250->4279 4291 40462b 4251->4291 4255 404943 4252->4255 4256 4049aa 4252->4256 4253->4249 4253->4251 4257 4048f0 GetDlgItem SendMessageW 4253->4257 4255->4256 4263 404969 SendMessageW LoadCursorW SetCursor 4255->4263 4256->4251 4264 4049bc 4256->4264 4284 4045e6 KiUserCallbackDispatcher 4257->4284 4258 404802 4261 4045c4 18 API calls 4258->4261 4266 40480f CheckDlgButton 4261->4266 4262 4049e4 4288 404a32 4263->4288 4268 4049d2 4264->4268 4269 4049c2 SendMessageW 4264->4269 4265 40491a 4285 404a0e 4265->4285 4282 4045e6 KiUserCallbackDispatcher 4266->4282 4268->4262 4270 4049d8 SendMessageW 4268->4270 4269->4268 4270->4262 4274 40482d GetDlgItem 4283 4045f9 SendMessageW 4274->4283 4276 404843 SendMessageW 4277 404860 GetSysColor 4276->4277 4278 404869 SendMessageW SendMessageW lstrlenW SendMessageW SendMessageW 4276->4278 4277->4278 4278->4262 4280 4066a5 17 API calls 4279->4280 4281 4045cf SetDlgItemTextW 4280->4281 4281->4258 4282->4274 4283->4276 4284->4265 4286 404a21 SendMessageW 4285->4286 4287 404a1c 4285->4287 4286->4249 4287->4286 4305 405c8e ShellExecuteExW 4288->4305 4290 404998 LoadCursorW SetCursor 4290->4256 4292 4046ee 4291->4292 4293 404643 GetWindowLongW 4291->4293 4292->4262 4293->4292 4294 404658 4293->4294 4294->4292 4295 404685 GetSysColor 4294->4295 4296 404688 4294->4296 4295->4296 4297 404698 SetBkMode 4296->4297 4298 40468e SetTextColor 4296->4298 4299 4046b0 GetSysColor 4297->4299 4300 4046b6 4297->4300 4298->4297 4299->4300 4301 4046c7 4300->4301 4302 4046bd SetBkColor 4300->4302 4301->4292 4303 4046e1 CreateBrushIndirect 4301->4303 4304 4046da DeleteObject 4301->4304 4302->4301 4303->4292 4304->4303 4305->4290 5134 402383 5135 40238a 5134->5135 5137 40239d 5134->5137 5136 4066a5 17 API calls 5135->5136 5138 402397 5136->5138 5138->5137 5139 405cc8 MessageBoxIndirectW 5138->5139 5139->5137 4474 40248a 4475 402da6 17 API calls 4474->4475 4476 40249c 4475->4476 4477 402da6 17 API calls 4476->4477 4478 4024a6 4477->4478 4491 402e36 4478->4491 4481 402c2a 4482 4024de 4484 402d84 17 API calls 4482->4484 4486 4024ea 4482->4486 4483 402da6 17 API calls 4487 4024d4 lstrlenW 4483->4487 4484->4486 4485 402509 RegSetValueExW 4489 40251f RegCloseKey 4485->4489 4486->4485 4488 403371 44 API calls 4486->4488 4487->4482 4488->4485 4489->4481 4492 402e51 4491->4492 4495 406503 4492->4495 4496 406512 4495->4496 4497 4024b6 4496->4497 4498 40651d RegCreateKeyExW 4496->4498 4497->4481 4497->4482 4497->4483 4498->4497 5171 6fbb1d76 5172 6fbb2053 2 API calls 5171->5172 5173 6fbb1d7b 5172->5173 5179 401491 5180 4056ca 24 API calls 5179->5180 5181 401498 5180->5181 5182 402891 5183 402898 5182->5183 5185 402ba9 5182->5185 5184 402d84 17 API calls 5183->5184 5186 40289f 5184->5186 5187 4028ae SetFilePointer 5186->5187 5187->5185 5188 4028be 5187->5188 5190 4065af wsprintfW 5188->5190 5190->5185 5214 402f93 5215 402fa5 SetTimer 5214->5215 5216 402fbe 5214->5216 5215->5216 5217 40300c 5216->5217 5218 403012 MulDiv 5216->5218 5219 402fcc wsprintfW SetWindowTextW SetDlgItemTextW 5218->5219 5219->5217 4768 401b9b 4769 401ba8 4768->4769 4770 401bec 4768->4770 4775 401bbf 4769->4775 4777 401c31 4769->4777 4771 401bf1 4770->4771 4772 401c16 GlobalAlloc 4770->4772 4781 40239d 4771->4781 4789 406668 lstrcpynW 4771->4789 4774 4066a5 17 API calls 4772->4774 4773 4066a5 17 API calls 4778 402397 4773->4778 4774->4777 4787 406668 lstrcpynW 4775->4787 4777->4773 4777->4781 4778->4781 4783 405cc8 MessageBoxIndirectW 4778->4783 4780 401c03 GlobalFree 4780->4781 4782 401bce 4788 406668 lstrcpynW 4782->4788 4783->4781 4785 401bdd 4790 406668 lstrcpynW 4785->4790 4787->4782 4788->4785 4789->4780 4790->4781 5284 40149e 5285 4014ac PostQuitMessage 5284->5285 5286 40239d 5284->5286 5285->5286 5287 40259e 5288 402de6 17 API calls 5287->5288 5289 4025a8 5288->5289 5290 402d84 17 API calls 5289->5290 5291 4025b1 5290->5291 5292 4025d9 RegEnumValueW 5291->5292 5293 4025cd RegEnumKeyW 5291->5293 5295 40292e 5291->5295 5294 4025ee RegCloseKey 5292->5294 5293->5294 5294->5295 5297 4015a3 5298 402da6 17 API calls 5297->5298 5299 4015aa SetFileAttributesW 5298->5299 5300 4015bc 5299->5300 5301 401fa4 5302 402da6 17 API calls 5301->5302 5303 401faa 5302->5303 5304 4056ca 24 API calls 5303->5304 5305 401fb4 5304->5305 5306 405c4b 2 API calls 5305->5306 5307 401fba 5306->5307 5308 401fdd CloseHandle 5307->5308 5309 406ae0 5 API calls 5307->5309 5311 40292e 5307->5311 5308->5311 5312 401fcf 5309->5312 5312->5308 5314 4065af wsprintfW 5312->5314 5314->5308 5315 6fbb1c53 5316 6fbb2053 2 API calls 5315->5316 5317 6fbb1c58 KillTimer 5316->5317 4499 4021aa 4500 402da6 17 API calls 4499->4500 4501 4021b1 4500->4501 4502 402da6 17 API calls 4501->4502 4503 4021bb 4502->4503 4504 402da6 17 API calls 4503->4504 4505 4021c5 4504->4505 4506 402da6 17 API calls 4505->4506 4507 4021cf 4506->4507 4508 402da6 17 API calls 4507->4508 4509 4021d9 4508->4509 4510 402218 CoCreateInstance 4509->4510 4511 402da6 17 API calls 4509->4511 4514 402237 4510->4514 4511->4510 4512 401423 24 API calls 4513 4022f6 4512->4513 4514->4512 4514->4513 5461 4023b2 5462 4023c0 5461->5462 5463 4023ba 5461->5463 5465 4023ce 5462->5465 5466 402da6 17 API calls 5462->5466 5464 402da6 17 API calls 5463->5464 5464->5462 5467 402da6 17 API calls 5465->5467 5469 4023dc 5465->5469 5466->5465 5467->5469 5468 402da6 17 API calls 5470 4023e5 WritePrivateProfileStringW 5468->5470 5469->5468 4657 404ab5 4658 404ae1 4657->4658 4659 404af2 4657->4659 4737 405cac GetDlgItemTextW 4658->4737 4661 404afe GetDlgItem 4659->4661 4667 404b6a 4659->4667 4663 404b12 4661->4663 4662 404aec 4665 4068ef 5 API calls 4662->4665 4666 404b26 SetWindowTextW 4663->4666 4670 405fe2 4 API calls 4663->4670 4664 404c41 4720 404df0 4664->4720 4724 405cac GetDlgItemTextW 4664->4724 4665->4659 4673 4045c4 18 API calls 4666->4673 4667->4664 4671 4066a5 17 API calls 4667->4671 4667->4720 4669 40462b 8 API calls 4675 404e04 4669->4675 4681 404b1c 4670->4681 4676 404bd1 SHBrowseForFolderW 4671->4676 4672 404c71 4677 40603f 18 API calls 4672->4677 4674 404b42 4673->4674 4680 4045c4 18 API calls 4674->4680 4676->4664 4678 404be9 CoTaskMemFree 4676->4678 4679 404c77 4677->4679 4682 405f37 3 API calls 4678->4682 4725 406668 lstrcpynW 4679->4725 4683 404b50 4680->4683 4681->4666 4684 405f37 3 API calls 4681->4684 4685 404bf6 4682->4685 4723 4045f9 SendMessageW 4683->4723 4684->4666 4688 404c2d SetDlgItemTextW 4685->4688 4693 4066a5 17 API calls 4685->4693 4688->4664 4689 404c8e 4691 406a35 5 API calls 4689->4691 4690 404b56 4692 406a35 5 API calls 4690->4692 4702 404c95 4691->4702 4694 404b5d 4692->4694 4695 404c15 lstrcmpiW 4693->4695 4697 404b65 SHAutoComplete 4694->4697 4694->4720 4695->4688 4698 404c26 lstrcatW 4695->4698 4696 404cd6 4738 406668 lstrcpynW 4696->4738 4697->4667 4698->4688 4699 404ca4 GetDiskFreeSpaceExW 4699->4702 4710 404d2e 4699->4710 4701 404cdd 4703 405fe2 4 API calls 4701->4703 4702->4696 4702->4699 4705 405f83 2 API calls 4702->4705 4704 404ce3 4703->4704 4706 404ce9 4704->4706 4707 404cec GetDiskFreeSpaceW 4704->4707 4705->4702 4706->4707 4708 404d07 MulDiv 4707->4708 4707->4710 4708->4710 4709 404d9f 4712 404dc2 4709->4712 4714 40140b 2 API calls 4709->4714 4710->4709 4726 404f3a 4710->4726 4739 4045e6 KiUserCallbackDispatcher 4712->4739 4714->4712 4715 404da1 SetDlgItemTextW 4715->4709 4716 404d91 4729 404e71 4716->4729 4719 404dde 4719->4720 4721 404deb 4719->4721 4720->4669 4722 404a0e SendMessageW 4721->4722 4722->4720 4723->4690 4724->4672 4725->4689 4727 404e71 20 API calls 4726->4727 4728 404d8c 4727->4728 4728->4715 4728->4716 4730 404e8a 4729->4730 4731 4066a5 17 API calls 4730->4731 4732 404eee 4731->4732 4733 4066a5 17 API calls 4732->4733 4734 404ef9 4733->4734 4735 4066a5 17 API calls 4734->4735 4736 404f0f lstrlenW wsprintfW SetDlgItemTextW 4735->4736 4736->4709 4737->4662 4738->4701 4739->4719 5512 4014b8 5513 4014be 5512->5513 5514 401389 2 API calls 5513->5514 5515 4014c6 5514->5515

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 0 403640-403690 SetErrorMode GetVersionExW 1 403692-4036c6 GetVersionExW 0->1 2 4036ca-4036d1 0->2 1->2 3 4036d3 2->3 4 4036db-40371b 2->4 3->4 5 40371d-403725 call 406a35 4->5 6 40372e 4->6 5->6 11 403727 5->11 8 403733-403747 call 4069c5 lstrlenA 6->8 13 403749-403765 call 406a35 * 3 8->13 11->6 20 403776-4037d8 #17 OleInitialize SHGetFileInfoW call 406668 GetCommandLineW call 406668 13->20 21 403767-40376d 13->21 28 4037e1-4037f4 call 405f64 CharNextW 20->28 29 4037da-4037dc 20->29 21->20 25 40376f 21->25 25->20 32 4038eb-4038f1 28->32 29->28 33 4038f7 32->33 34 4037f9-4037ff 32->34 37 40390b-403925 GetTempPathW call 40360f 33->37 35 403801-403806 34->35 36 403808-40380e 34->36 35->35 35->36 38 403810-403814 36->38 39 403815-403819 36->39 47 403927-403945 GetWindowsDirectoryW lstrcatW call 40360f 37->47 48 40397d-403995 DeleteFileW call 4030d0 37->48 38->39 41 4038d9-4038e7 call 405f64 39->41 42 40381f-403825 39->42 41->32 58 4038e9-4038ea 41->58 45 403827-40382e 42->45 46 40383f-403878 42->46 51 403830-403833 45->51 52 403835 45->52 53 403894-4038ce 46->53 54 40387a-40387f 46->54 47->48 62 403947-403977 GetTempPathW lstrcatW SetEnvironmentVariableW * 2 call 40360f 47->62 64 40399b-4039a1 48->64 65 403b6c-403b7a call 403c25 OleUninitialize 48->65 51->46 51->52 52->46 56 4038d0-4038d4 53->56 57 4038d6-4038d8 53->57 54->53 60 403881-403889 54->60 56->57 63 4038f9-403906 call 406668 56->63 57->41 58->32 66 403890 60->66 67 40388b-40388e 60->67 62->48 62->65 63->37 69 4039a7-4039ba call 405f64 64->69 70 403a48-403a4f call 403d17 64->70 79 403b91-403b97 65->79 80 403b7c-403b8b call 405cc8 ExitProcess 65->80 66->53 67->53 67->66 84 403a0c-403a19 69->84 85 4039bc-4039f1 69->85 78 403a54-403a57 70->78 78->65 82 403b99-403bae GetCurrentProcess OpenProcessToken 79->82 83 403c0f-403c17 79->83 89 403bb0-403bd9 LookupPrivilegeValueW AdjustTokenPrivileges 82->89 90 403bdf-403bed call 406a35 82->90 92 403c19 83->92 93 403c1c-403c1f ExitProcess 83->93 86 403a1b-403a29 call 40603f 84->86 87 403a5c-403a70 call 405c33 lstrcatW 84->87 91 4039f3-4039f7 85->91 86->65 103 403a2f-403a45 call 406668 * 2 86->103 106 403a72-403a78 lstrcatW 87->106 107 403a7d-403a97 lstrcatW lstrcmpiW 87->107 89->90 104 403bfb-403c06 ExitWindowsEx 90->104 105 403bef-403bf9 90->105 97 403a00-403a08 91->97 98 4039f9-4039fe 91->98 92->93 97->91 102 403a0a 97->102 98->97 98->102 102->84 103->70 104->83 111 403c08-403c0a call 40140b 104->111 105->104 105->111 106->107 108 403b6a 107->108 109 403a9d-403aa0 107->109 108->65 112 403aa2-403aa7 call 405b99 109->112 113 403aa9 call 405c16 109->113 111->83 121 403aae-403abe SetCurrentDirectoryW 112->121 113->121 123 403ac0-403ac6 call 406668 121->123 124 403acb-403af7 call 406668 121->124 123->124 128 403afc-403b17 call 4066a5 DeleteFileW 124->128 131 403b57-403b61 128->131 132 403b19-403b29 CopyFileW 128->132 131->128 134 403b63-403b65 call 406428 131->134 132->131 133 403b2b-403b4b call 406428 call 4066a5 call 405c4b 132->133 133->131 142 403b4d-403b54 CloseHandle 133->142 134->108 142->131
                                      APIs
                                      • SetErrorMode.KERNELBASE(00008001), ref: 00403663
                                      • GetVersionExW.KERNEL32(?), ref: 0040368C
                                      • GetVersionExW.KERNEL32(0000011C), ref: 004036A3
                                      • lstrlenA.KERNEL32(UXTHEME,UXTHEME), ref: 0040373A
                                      • #17.COMCTL32(00000007,00000009,0000000B), ref: 00403776
                                      • OleInitialize.OLE32(00000000), ref: 0040377D
                                      • SHGetFileInfoW.SHELL32(00421708,00000000,?,000002B4,00000000), ref: 0040379B
                                      • GetCommandLineW.KERNEL32(00429260,NSIS Error), ref: 004037B0
                                      • CharNextW.USER32(00000000,"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe",00000020,"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe",00000000), ref: 004037E9
                                      • GetTempPathW.KERNEL32(00000400,C:\Users\user\AppData\Local\Temp\,00000000,?), ref: 0040391C
                                      • GetWindowsDirectoryW.KERNEL32(C:\Users\user\AppData\Local\Temp\,000003FB), ref: 0040392D
                                      • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,\Temp), ref: 00403939
                                      • GetTempPathW.KERNEL32(000003FC,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,\Temp), ref: 0040394D
                                      • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,Low), ref: 00403955
                                      • SetEnvironmentVariableW.KERNEL32(TEMP,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,Low), ref: 00403966
                                      • SetEnvironmentVariableW.KERNEL32(TMP,C:\Users\user\AppData\Local\Temp\), ref: 0040396E
                                      • DeleteFileW.KERNELBASE(1033), ref: 00403982
                                      • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,~nsu,"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe",00000000,?), ref: 00403A69
                                      • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,0040A328,C:\Users\user\AppData\Local\Temp\,~nsu,"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe",00000000,?), ref: 00403A78
                                        • Part of subcall function 00405C16: CreateDirectoryW.KERNELBASE(?,00000000,00403633,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405C1C
                                      • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,.tmp,C:\Users\user\AppData\Local\Temp\,~nsu,"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe",00000000,?), ref: 00403A83
                                      • lstrcmpiW.KERNEL32(C:\Users\user\AppData\Local\Temp\,C:\Users\user\Desktop,C:\Users\user\AppData\Local\Temp\,.tmp,C:\Users\user\AppData\Local\Temp\,~nsu,"C:\Users\user\Desktop\Gwyddion-2.67.win64.exe",00000000,?), ref: 00403A8F
                                      • SetCurrentDirectoryW.KERNEL32(C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\), ref: 00403AAF
                                      • DeleteFileW.KERNEL32(00420F08,00420F08,?,0042B000,?), ref: 00403B0E
                                      • CopyFileW.KERNEL32(C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,00420F08,00000001), ref: 00403B21
                                      • CloseHandle.KERNEL32(00000000,00420F08,00420F08,?,00420F08,00000000), ref: 00403B4E
                                      • OleUninitialize.OLE32(?), ref: 00403B71
                                      • ExitProcess.KERNEL32 ref: 00403B8B
                                      • GetCurrentProcess.KERNEL32(00000028,?), ref: 00403B9F
                                      • OpenProcessToken.ADVAPI32(00000000), ref: 00403BA6
                                      • LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 00403BBA
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000), ref: 00403BD9
                                      • ExitWindowsEx.USER32(00000002,80040002), ref: 00403BFE
                                      • ExitProcess.KERNEL32 ref: 00403C1F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: lstrcat$FileProcess$DirectoryExit$CurrentDeleteEnvironmentPathTempTokenVariableVersionWindows$AdjustCharCloseCommandCopyCreateErrorHandleInfoInitializeLineLookupModeNextOpenPrivilegePrivilegesUninitializeValuelstrcmpilstrlen
                                      • String ID: "C:\Users\user\Desktop\Gwyddion-2.67.win64.exe"$.tmp$1033$C:\Program Files\Gwyddion$C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES$C:\Users\user\AppData\Local\Temp\$C:\Users\user\Desktop$C:\Users\user\Desktop\Gwyddion-2.67.win64.exe$Error launching installer$Error writing temporary file. Make sure your temp folder is valid.$Low$NSIS Error$SeShutdownPrivilege$TEMP$TMP$UXTHEME$\Temp$~nsu
                                      • API String ID: 3859024572-1283787814
                                      • Opcode ID: ed5248a912319d130effd7f05a4d843c659f0a5d51aace41cf0d3086d1e01474
                                      • Instruction ID: d56582c8b11bee4b9d4e83ad1f604629a9588d533935b381636b20c84fba3529
                                      • Opcode Fuzzy Hash: ed5248a912319d130effd7f05a4d843c659f0a5d51aace41cf0d3086d1e01474
                                      • Instruction Fuzzy Hash: D4E1F471A00214AADB20AFB58D45A6E3EB8EB05709F50847FF945B32D1DB7C8A41CB6D

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 143 405809-405824 144 4059b3-4059ba 143->144 145 40582a-4058f1 GetDlgItem * 3 call 4045f9 call 404f52 GetClientRect GetSystemMetrics SendMessageW * 2 143->145 147 4059e4-4059f1 144->147 148 4059bc-4059de GetDlgItem CreateThread CloseHandle 144->148 166 4058f3-40590d SendMessageW * 2 145->166 167 40590f-405912 145->167 150 4059f3-4059f9 147->150 151 405a0f-405a19 147->151 148->147 153 405a34-405a3d call 40462b 150->153 154 4059fb-405a0a ShowWindow * 2 call 4045f9 150->154 155 405a1b-405a21 151->155 156 405a6f-405a73 151->156 163 405a42-405a46 153->163 154->151 161 405a23-405a2f call 40459d 155->161 162 405a49-405a59 ShowWindow 155->162 156->153 159 405a75-405a7b 156->159 159->153 168 405a7d-405a90 SendMessageW 159->168 161->153 164 405a69-405a6a call 40459d 162->164 165 405a5b-405a64 call 4056ca 162->165 164->156 165->164 166->167 172 405922-405939 call 4045c4 167->172 173 405914-405920 SendMessageW 167->173 174 405b92-405b94 168->174 175 405a96-405ac1 CreatePopupMenu call 4066a5 AppendMenuW 168->175 182 40593b-40594f ShowWindow 172->182 183 40596f-405990 GetDlgItem SendMessageW 172->183 173->172 174->163 180 405ac3-405ad3 GetWindowRect 175->180 181 405ad6-405aeb TrackPopupMenu 175->181 180->181 181->174 184 405af1-405b08 181->184 185 405951-40595c ShowWindow 182->185 186 40595e 182->186 183->174 187 405996-4059ae SendMessageW * 2 183->187 188 405b0d-405b28 SendMessageW 184->188 189 405964-40596a call 4045f9 185->189 186->189 187->174 188->188 190 405b2a-405b4d OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 188->190 189->183 192 405b4f-405b76 SendMessageW 190->192 192->192 193 405b78-405b8c GlobalUnlock SetClipboardData CloseClipboard 192->193 193->174
                                      APIs
                                      • GetDlgItem.USER32(?,00000403), ref: 00405867
                                      • GetDlgItem.USER32(?,000003EE), ref: 00405876
                                      • GetClientRect.USER32(?,?), ref: 004058B3
                                      • GetSystemMetrics.USER32(00000002), ref: 004058BA
                                      • SendMessageW.USER32(?,00001061,00000000,?), ref: 004058DB
                                      • SendMessageW.USER32(?,00001036,00004000,00004000), ref: 004058EC
                                      • SendMessageW.USER32(?,00001001,00000000,00000110), ref: 004058FF
                                      • SendMessageW.USER32(?,00001026,00000000,00000110), ref: 0040590D
                                      • SendMessageW.USER32(?,00001024,00000000,?), ref: 00405920
                                      • ShowWindow.USER32(00000000,?,0000001B,000000FF), ref: 00405942
                                      • ShowWindow.USER32(?,00000008), ref: 00405956
                                      • GetDlgItem.USER32(?,000003EC), ref: 00405977
                                      • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 00405987
                                      • SendMessageW.USER32(00000000,00000409,00000000,?), ref: 004059A0
                                      • SendMessageW.USER32(00000000,00002001,00000000,00000110), ref: 004059AC
                                      • GetDlgItem.USER32(?,000003F8), ref: 00405885
                                        • Part of subcall function 004045F9: SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                      • GetDlgItem.USER32(?,000003EC), ref: 004059C9
                                      • CreateThread.KERNELBASE(00000000,00000000,Function_0000579D,00000000), ref: 004059D7
                                      • CloseHandle.KERNELBASE(00000000), ref: 004059DE
                                      • ShowWindow.USER32(00000000), ref: 00405A02
                                      • ShowWindow.USER32(?,00000008), ref: 00405A07
                                      • ShowWindow.USER32(00000008), ref: 00405A51
                                      • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405A85
                                      • CreatePopupMenu.USER32 ref: 00405A96
                                      • AppendMenuW.USER32(00000000,00000000,00000001,00000000), ref: 00405AAA
                                      • GetWindowRect.USER32(?,?), ref: 00405ACA
                                      • TrackPopupMenu.USER32(00000000,00000180,?,?,00000000,?,00000000), ref: 00405AE3
                                      • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405B1B
                                      • OpenClipboard.USER32(00000000), ref: 00405B2B
                                      • EmptyClipboard.USER32 ref: 00405B31
                                      • GlobalAlloc.KERNEL32(00000042,00000000), ref: 00405B3D
                                      • GlobalLock.KERNEL32(00000000), ref: 00405B47
                                      • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405B5B
                                      • GlobalUnlock.KERNEL32(00000000), ref: 00405B7B
                                      • SetClipboardData.USER32(0000000D,00000000), ref: 00405B86
                                      • CloseClipboard.USER32 ref: 00405B8C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend$Window$ItemShow$Clipboard$GlobalMenu$CloseCreatePopupRect$AllocAppendClientDataEmptyHandleLockMetricsOpenSystemThreadTrackUnlock
                                      • String ID: $*K$H7B${
                                      • API String ID: 590372296-3419216912
                                      • Opcode ID: 0185fb71cb0ebac8bb253ddb79263eb6e3c4c27c477fa06c1930d1494c9be16a
                                      • Instruction ID: d0bbb34d81c2c7a38b5cdb5171fa906e4f4201ee6cbe22cb0b3272b57562556b
                                      • Opcode Fuzzy Hash: 0185fb71cb0ebac8bb253ddb79263eb6e3c4c27c477fa06c1930d1494c9be16a
                                      • Instruction Fuzzy Hash: D8B137B0900608FFDF119FA0DD89AAE7B79FB08354F00417AFA45A61A0CB755E52DF68

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 467 404ab5-404adf 468 404ae1-404aed call 405cac call 4068ef 467->468 469 404af2-404afc 467->469 468->469 471 404b6a-404b71 469->471 472 404afe-404b14 GetDlgItem call 405fae 469->472 475 404b77-404b80 471->475 476 404c48-404c4f 471->476 483 404b26-404b5f SetWindowTextW call 4045c4 * 2 call 4045f9 call 406a35 472->483 484 404b16-404b1e call 405fe2 472->484 479 404b82-404b8d 475->479 480 404b9a-404b9f 475->480 481 404c51-404c58 476->481 482 404c5e-404c79 call 405cac call 40603f 476->482 485 404b93 479->485 486 404df6-404e08 call 40462b 479->486 480->476 487 404ba5-404be7 call 4066a5 SHBrowseForFolderW 480->487 481->482 481->486 505 404c82-404c9a call 406668 call 406a35 482->505 506 404c7b 482->506 483->486 525 404b65-404b68 SHAutoComplete 483->525 484->483 503 404b20-404b21 call 405f37 484->503 485->480 499 404c41 487->499 500 404be9-404c03 CoTaskMemFree call 405f37 487->500 499->476 512 404c05-404c0b 500->512 513 404c2d-404c3f SetDlgItemTextW 500->513 503->483 523 404cd6-404ce7 call 406668 call 405fe2 505->523 524 404c9c-404ca2 505->524 506->505 512->513 516 404c0d-404c24 call 4066a5 lstrcmpiW 512->516 513->476 516->513 526 404c26-404c28 lstrcatW 516->526 539 404ce9 523->539 540 404cec-404d05 GetDiskFreeSpaceW 523->540 524->523 527 404ca4-404cb6 GetDiskFreeSpaceExW 524->527 525->471 526->513 530 404cb8-404cba 527->530 531 404d2e-404d48 527->531 534 404cbc 530->534 535 404cbf-404cd4 call 405f83 530->535 533 404d4a 531->533 537 404d4f-404d59 call 404f52 533->537 534->535 535->523 535->527 545 404d74-404d7d 537->545 546 404d5b-404d62 537->546 539->540 540->533 543 404d07-404d2c MulDiv 540->543 543->537 547 404daf-404db9 545->547 548 404d7f-404d8f call 404f3a 545->548 546->545 549 404d64 546->549 551 404dc5-404dcb 547->551 552 404dbb-404dc2 call 40140b 547->552 559 404da1-404daa SetDlgItemTextW 548->559 560 404d91-404d9a call 404e71 548->560 553 404d66-404d6b 549->553 554 404d6d 549->554 557 404dd0-404de1 call 4045e6 551->557 558 404dcd 551->558 552->551 553->545 553->554 554->545 565 404df0 557->565 566 404de3-404de9 557->566 558->557 559->547 567 404d9f 560->567 565->486 566->565 568 404deb call 404a0e 566->568 567->547 568->565
                                      APIs
                                      • GetDlgItem.USER32(?,000003FB), ref: 00404B04
                                      • SetWindowTextW.USER32(00000000,?), ref: 00404B2E
                                      • SHAutoComplete.SHLWAPI(00000000,00000001,00000008,00000000,?,00000014,?,?,00000001,?), ref: 00404B68
                                      • SHBrowseForFolderW.SHELL32(?), ref: 00404BDF
                                      • CoTaskMemFree.OLE32(00000000), ref: 00404BEA
                                      • lstrcmpiW.KERNEL32(00428200,00423748,00000000,?,?), ref: 00404C1C
                                      • lstrcatW.KERNEL32(?,00428200), ref: 00404C28
                                      • SetDlgItemTextW.USER32(?,000003FB,?), ref: 00404C3A
                                        • Part of subcall function 00405CAC: GetDlgItemTextW.USER32(?,?,00000400,00404C71), ref: 00405CBF
                                        • Part of subcall function 004068EF: CharNextW.USER32(?,*?|<>/":,00000000,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406952
                                        • Part of subcall function 004068EF: CharNextW.USER32(?,?,?,00000000,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406961
                                        • Part of subcall function 004068EF: CharNextW.USER32(?,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406966
                                        • Part of subcall function 004068EF: CharPrevW.USER32(?,?,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406979
                                      • GetDiskFreeSpaceExW.KERNELBASE(00421718,?,?,?,00000001,00421718,?,?,000003FB,?), ref: 00404CB1
                                      • GetDiskFreeSpaceW.KERNEL32(00421718,?,?,0000040F,?,00421718,00421718,?,00000001,00421718,?,?,000003FB,?), ref: 00404CFD
                                      • MulDiv.KERNEL32(?,0000040F,00000400), ref: 00404D18
                                        • Part of subcall function 00404E71: lstrlenW.KERNEL32(00423748,00423748,?,%u.%u%s%s,00000005,00000000,00000000,?,000000DC,00000000,?,000000DF,00000000,00000400,?), ref: 00404F12
                                        • Part of subcall function 00404E71: wsprintfW.USER32 ref: 00404F1B
                                        • Part of subcall function 00404E71: SetDlgItemTextW.USER32(?,00423748), ref: 00404F2E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CharItemText$FreeNext$DiskSpace$AutoBrowseCompleteFolderPrevTaskWindowlstrcatlstrcmpilstrlenwsprintf
                                      • String ID: $*K$A$C:\Program Files\Gwyddion$H7B
                                      • API String ID: 4039761011-2311555617
                                      • Opcode ID: 8fe5d6185855569599b0147f93014e69bfe7dcd8b72b59fe1028842fc76bdad0
                                      • Instruction ID: 9155a42c54a3203d4d9709c494e168d8d926bd307d67cbb08bf4d9f42020e7e3
                                      • Opcode Fuzzy Hash: 8fe5d6185855569599b0147f93014e69bfe7dcd8b72b59fe1028842fc76bdad0
                                      • Instruction Fuzzy Hash: 94A171F1900219ABDB11EFA5CD41AAFB7B8EF84315F11843BF601B62D1D77C8A418B69

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 643 405d74-405d9a call 40603f 646 405db3-405dba 643->646 647 405d9c-405dae DeleteFileW 643->647 649 405dbc-405dbe 646->649 650 405dcd-405ddd call 406668 646->650 648 405f30-405f34 647->648 651 405dc4-405dc7 649->651 652 405ede-405ee3 649->652 656 405dec-405ded call 405f83 650->656 657 405ddf-405dea lstrcatW 650->657 651->650 651->652 652->648 655 405ee5-405ee8 652->655 658 405ef2-405efa call 40699e 655->658 659 405eea-405ef0 655->659 660 405df2-405df6 656->660 657->660 658->648 666 405efc-405f10 call 405f37 call 405d2c 658->666 659->648 664 405e02-405e08 lstrcatW 660->664 665 405df8-405e00 660->665 667 405e0d-405e29 lstrlenW FindFirstFileW 664->667 665->664 665->667 683 405f12-405f15 666->683 684 405f28-405f2b call 4056ca 666->684 668 405ed3-405ed7 667->668 669 405e2f-405e37 667->669 668->652 674 405ed9 668->674 671 405e57-405e6b call 406668 669->671 672 405e39-405e41 669->672 685 405e82-405e8d call 405d2c 671->685 686 405e6d-405e75 671->686 675 405e43-405e4b 672->675 676 405eb6-405ec6 FindNextFileW 672->676 674->652 675->671 679 405e4d-405e55 675->679 676->669 682 405ecc-405ecd FindClose 676->682 679->671 679->676 682->668 683->659 687 405f17-405f26 call 4056ca call 406428 683->687 684->648 696 405eae-405eb1 call 4056ca 685->696 697 405e8f-405e92 685->697 686->676 688 405e77-405e80 call 405d74 686->688 687->648 688->676 696->676 700 405e94-405ea4 call 4056ca call 406428 697->700 701 405ea6-405eac 697->701 700->676 701->676
                                      APIs
                                      • DeleteFileW.KERNELBASE(?,?,74DF3420,74DF2EE0,00000000), ref: 00405D9D
                                      • lstrcatW.KERNEL32(00425750,\*.*,00425750,?,?,74DF3420,74DF2EE0,00000000), ref: 00405DE5
                                      • lstrcatW.KERNEL32(?,0040A014,?,00425750,?,?,74DF3420,74DF2EE0,00000000), ref: 00405E08
                                      • lstrlenW.KERNEL32(?,?,0040A014,?,00425750,?,?,74DF3420,74DF2EE0,00000000), ref: 00405E0E
                                      • FindFirstFileW.KERNEL32(00425750,?,?,?,0040A014,?,00425750,?,?,74DF3420,74DF2EE0,00000000), ref: 00405E1E
                                      • FindNextFileW.KERNEL32(00000000,00000010,000000F2,?,?,?,?,0000002E), ref: 00405EBE
                                      • FindClose.KERNEL32(00000000), ref: 00405ECD
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FileFind$lstrcat$CloseDeleteFirstNextlstrlen
                                      • String ID: .$.$PWB$\*.*
                                      • API String ID: 2035342205-2468439962
                                      • Opcode ID: eb4081a649fdbb44c8907daec76b44e1c805ca5b036c6d0867ef95af4715127c
                                      • Instruction ID: 3801e3340fbbb9c460ab277ab089a7ece50ce31247a5b640c745bca9484d7288
                                      • Opcode Fuzzy Hash: eb4081a649fdbb44c8907daec76b44e1c805ca5b036c6d0867ef95af4715127c
                                      • Instruction Fuzzy Hash: 46410330800A15AADB21AB61CC49BBF7678EF41715F50413FF881711D1DB7C4A82CEAE

                                      Control-flow Graph

                                      APIs
                                      • GetDlgItem.USER32(?,00000000), ref: 6FBB1813
                                      • GetWindowRect.USER32(00000000,?), ref: 6FBB181E
                                      • MapWindowPoints.USER32(00000000,?,?,00000002), ref: 6FBB182E
                                      • CreateDialogParamW.USER32(00000001,?,6FBB14D6,00000000), ref: 6FBB1843
                                      • SetWindowPos.USER32(00000000,00000000,?,?,?,?,00000014), ref: 6FBB1876
                                      • SetWindowLongW.USER32(?,00000004,6FBB1407), ref: 6FBB1884
                                      • GetProcessHeap.KERNEL32(00000008,00000000), ref: 6FBB189E
                                      • HeapAlloc.KERNEL32(00000000), ref: 6FBB18A5
                                        • Part of subcall function 6FBB1E9C: GlobalAlloc.KERNEL32(00000040,?,?,6FBB10BE,error,?,00000104), ref: 6FBB1EB2
                                        • Part of subcall function 6FBB1E9C: lstrcpynW.KERNEL32(00000004,?,?,6FBB10BE,error,?,00000104), ref: 6FBB1EC8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Window$AllocHeap$CreateDialogGlobalItemLongParamPointsProcessRectlstrcpyn
                                      • String ID: error$p^v
                                      • API String ID: 1928716940-3986241059
                                      • Opcode ID: 45ad1c21b225c6985424454a6b0ff2e55e94e14ccd24695b2c0f14891c00f9b2
                                      • Instruction ID: e807eb3a5376f6452a98a8595d463309d5f394ff6a3bc17510076afe8e20742d
                                      • Opcode Fuzzy Hash: 45ad1c21b225c6985424454a6b0ff2e55e94e14ccd24695b2c0f14891c00f9b2
                                      • Instruction Fuzzy Hash: 0B312976800A54ABCF119FA6DD49AAE7FBAFB0B721B444049F605A7241DF705922CFA0
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 6ae840c17bc4cb012e3c6e2f9739eb08ea49decd14d2b7f73774d31e5ba5825a
                                      • Instruction ID: 02c1e40b0c9780dd067322b7733c474732bd0f187a49f53fd7fd3c108ee94619
                                      • Opcode Fuzzy Hash: 6ae840c17bc4cb012e3c6e2f9739eb08ea49decd14d2b7f73774d31e5ba5825a
                                      • Instruction Fuzzy Hash: 7CF15570D04229CBDF28CFA8C8946ADBBB0FF44305F24816ED456BB281D7386A86DF45
                                      APIs
                                      • CoCreateInstance.OLE32(004084E4,?,00000001,004084D4,?,?,00000045,000000CD,00000002,000000DF,000000F0), ref: 00402229
                                      Strings
                                      • C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES, xrefs: 00402269
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CreateInstance
                                      • String ID: C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES
                                      • API String ID: 542301482-923977919
                                      • Opcode ID: 077b7362f6a1d4038be91bf7f4b9e5842d68daf9de23732b557fb751e09ce78c
                                      • Instruction ID: f110e38d5ccd8909b9e85e2ea6b1342c5fae2602ce40754bea02e3b472428d32
                                      • Opcode Fuzzy Hash: 077b7362f6a1d4038be91bf7f4b9e5842d68daf9de23732b557fb751e09ce78c
                                      • Instruction Fuzzy Hash: BC411771A00209EFCF40DFE4C989E9D7BB5BF49304B20456AF505EB2D1DB799981CB94
                                      APIs
                                      • FindFirstFileW.KERNELBASE(74DF3420,00426798,00425F50,00406088,00425F50,00425F50,00000000,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0), ref: 004069A9
                                      • FindClose.KERNEL32(00000000), ref: 004069B5
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Find$CloseFileFirst
                                      • String ID:
                                      • API String ID: 2295610775-0
                                      • Opcode ID: 1093b80bdde5f117a2aeaff90f04fc035896fcf98737a4a628a8a679d5dfa397
                                      • Instruction ID: 0ca7534fdffec89160a31ceabb6ef5ff718bfc83d1618d69d17f9e635378cbc3
                                      • Opcode Fuzzy Hash: 1093b80bdde5f117a2aeaff90f04fc035896fcf98737a4a628a8a679d5dfa397
                                      • Instruction Fuzzy Hash: 5ED012B15192205FC34057387E0C84B7A989F563317268A36B4AAF11E0CB348C3297AC

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 194 4040c5-4040d7 195 4040dd-4040e3 194->195 196 40423e-40424d 194->196 195->196 197 4040e9-4040f2 195->197 198 40429c-4042b1 196->198 199 40424f-40428a GetDlgItem * 2 call 4045c4 KiUserCallbackDispatcher call 40140b 196->199 200 4040f4-404101 SetWindowPos 197->200 201 404107-40410e 197->201 203 4042f1-4042f6 call 404610 198->203 204 4042b3-4042b6 198->204 225 40428f-404297 199->225 200->201 206 404110-40412a ShowWindow 201->206 207 404152-404158 201->207 212 4042fb-404316 203->212 209 4042b8-4042c3 call 401389 204->209 210 4042e9-4042eb 204->210 213 404130-404143 GetWindowLongW 206->213 214 40422b-404239 call 40462b 206->214 215 404171-404174 207->215 216 40415a-40416c DestroyWindow 207->216 209->210 235 4042c5-4042e4 SendMessageW 209->235 210->203 211 404591 210->211 223 404593-40459a 211->223 220 404318-40431a call 40140b 212->220 221 40431f-404325 212->221 213->214 222 404149-40414c ShowWindow 213->222 214->223 226 404176-404182 SetWindowLongW 215->226 227 404187-40418d 215->227 224 40456e-404574 216->224 220->221 232 40432b-404336 221->232 233 40454f-404568 DestroyWindow EndDialog 221->233 222->207 224->211 231 404576-40457c 224->231 225->198 226->223 227->214 234 404193-4041a2 GetDlgItem 227->234 231->211 236 40457e-404587 ShowWindow 231->236 232->233 237 40433c-404389 call 4066a5 call 4045c4 * 3 GetDlgItem 232->237 233->224 238 4041c1-4041c4 234->238 239 4041a4-4041bb SendMessageW IsWindowEnabled 234->239 235->223 236->211 266 404393-4043cf ShowWindow KiUserCallbackDispatcher call 4045e6 KiUserCallbackDispatcher 237->266 267 40438b-404390 237->267 241 4041c6-4041c7 238->241 242 4041c9-4041cc 238->242 239->211 239->238 243 4041f7-4041fc call 40459d 241->243 244 4041da-4041df 242->244 245 4041ce-4041d4 242->245 243->214 247 404215-404225 SendMessageW 244->247 249 4041e1-4041e7 244->249 245->247 248 4041d6-4041d8 245->248 247->214 248->243 252 4041e9-4041ef call 40140b 249->252 253 4041fe-404207 call 40140b 249->253 262 4041f5 252->262 253->214 263 404209-404213 253->263 262->243 263->262 270 4043d1-4043d2 266->270 271 4043d4 266->271 267->266 272 4043d6-404404 GetSystemMenu EnableMenuItem SendMessageW 270->272 271->272 273 404406-404417 SendMessageW 272->273 274 404419 272->274 275 40441f-40445e call 4045f9 call 4040a6 call 406668 lstrlenW call 4066a5 SetWindowTextW call 401389 273->275 274->275 275->212 286 404464-404466 275->286 286->212 287 40446c-404470 286->287 288 404472-404478 287->288 289 40448f-4044a3 DestroyWindow 287->289 288->211 290 40447e-404484 288->290 289->224 291 4044a9-4044d6 CreateDialogParamW 289->291 290->212 292 40448a 290->292 291->224 293 4044dc-404533 call 4045c4 GetDlgItem GetWindowRect ScreenToClient SetWindowPos call 401389 291->293 292->211 293->211 298 404535-404548 ShowWindow call 404610 293->298 300 40454d 298->300 300->224
                                      APIs
                                      • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000013), ref: 00404101
                                      • ShowWindow.USER32(?), ref: 00404121
                                      • GetWindowLongW.USER32(?,000000F0), ref: 00404133
                                      • ShowWindow.USER32(?,00000004), ref: 0040414C
                                      • DestroyWindow.USER32 ref: 00404160
                                      • SetWindowLongW.USER32(?,00000000,00000000), ref: 00404179
                                      • GetDlgItem.USER32(?,?), ref: 00404198
                                      • SendMessageW.USER32(00000000,000000F3,00000000,00000000), ref: 004041AC
                                      • IsWindowEnabled.USER32(00000000), ref: 004041B3
                                      • GetDlgItem.USER32(?,00000001), ref: 0040425E
                                      • GetDlgItem.USER32(?,00000002), ref: 00404268
                                      • KiUserCallbackDispatcher.NTDLL(?,000000F2,?), ref: 00404282
                                      • SendMessageW.USER32(0000040F,00000000,00000001,?), ref: 004042D3
                                      • GetDlgItem.USER32(?,00000003), ref: 00404379
                                      • ShowWindow.USER32(00000000,?), ref: 0040439A
                                      • KiUserCallbackDispatcher.NTDLL(?,?), ref: 004043AC
                                      • KiUserCallbackDispatcher.NTDLL(?,?), ref: 004043C7
                                      • GetSystemMenu.USER32(?,00000000,0000F060,00000001), ref: 004043DD
                                      • EnableMenuItem.USER32(00000000), ref: 004043E4
                                      • SendMessageW.USER32(?,000000F4,00000000,00000001), ref: 004043FC
                                      • SendMessageW.USER32(?,00000401,00000002,00000000), ref: 0040440F
                                      • lstrlenW.KERNEL32(00423748,?,00423748,00000000), ref: 00404439
                                      • SetWindowTextW.USER32(?,00423748), ref: 0040444D
                                      • ShowWindow.USER32(?,0000000A), ref: 00404581
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Window$Item$MessageSendShow$CallbackDispatcherUser$LongMenu$DestroyEnableEnabledSystemTextlstrlen
                                      • String ID: $*K$H7B
                                      • API String ID: 435344536-1988553056
                                      • Opcode ID: 2f4dad2f818047668635e16f952da299a81014d83ff1599baf972819d0fbfd0c
                                      • Instruction ID: 1d4a55fced449df2e2a9dfc159c1061f424388fbea236c5341ec002980a30b6c
                                      • Opcode Fuzzy Hash: 2f4dad2f818047668635e16f952da299a81014d83ff1599baf972819d0fbfd0c
                                      • Instruction Fuzzy Hash: C0C1C2B1600604FBDB216F61EE85E2A3B78EB85745F40097EF781B51F0CB3958529B2E

                                      Control-flow Graph

                                      APIs
                                      • GetProcessHeap.KERNEL32(00000008,?), ref: 6FBB18E3
                                      • HeapAlloc.KERNEL32(00000000), ref: 6FBB18E6
                                      • GetProcessHeap.KERNEL32(00000000,00000000,error,00000000,00000000), ref: 6FBB1959
                                      • HeapFree.KERNEL32(00000000), ref: 6FBB1B8D
                                        • Part of subcall function 6FBB1E9C: GlobalAlloc.KERNEL32(00000040,?,?,6FBB10BE,error,?,00000104), ref: 6FBB1EB2
                                        • Part of subcall function 6FBB1E9C: lstrcpynW.KERNEL32(00000004,?,?,6FBB10BE,error,?,00000104), ref: 6FBB1EC8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Heap$AllocProcess$FreeGloballstrcpyn
                                      • String ID: BUTTON$COMBOBOX$EDIT$LINK$LISTBOX$NSIS: nsControl pointer property$RICHEDIT_CLASS$RichEdit$STATIC$error$p^v
                                      • API String ID: 1913068523-1412186473
                                      • Opcode ID: 61cae35f9547631246a5eba31b5c7261aad35df14c968faed303f801462911f0
                                      • Instruction ID: aae6dfda47070a5a1974f2e306427c9ecaeeecaabba38178d3e3c5f6ec83f74a
                                      • Opcode Fuzzy Hash: 61cae35f9547631246a5eba31b5c7261aad35df14c968faed303f801462911f0
                                      • Instruction Fuzzy Hash: 4E81AE72904698EBDB119FA5DD89FAEBBBCFF0A314F49505AE900B7241DE30AD118B50

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 349 403d17-403d2f call 406a35 352 403d31-403d41 call 4065af 349->352 353 403d43-403d7a call 406536 349->353 360 403d9d-403dc6 call 403fed call 40603f 352->360 358 403d92-403d98 lstrcatW 353->358 359 403d7c-403d8d call 406536 353->359 358->360 359->358 367 403e58-403e60 call 40603f 360->367 368 403dcc-403dd1 360->368 374 403e62-403e69 call 4066a5 367->374 375 403e6e-403e93 LoadImageW 367->375 368->367 369 403dd7-403df1 call 406536 368->369 373 403df6-403dff 369->373 373->367 376 403e01-403e05 373->376 374->375 378 403f14-403f1c call 40140b 375->378 379 403e95-403ec5 RegisterClassW 375->379 381 403e17-403e23 lstrlenW 376->381 382 403e07-403e14 call 405f64 376->382 390 403f26-403f31 call 403fed 378->390 391 403f1e-403f21 378->391 383 403fe3 379->383 384 403ecb-403f0f SystemParametersInfoW CreateWindowExW 379->384 388 403e25-403e33 lstrcmpiW 381->388 389 403e4b-403e53 call 405f37 call 406668 381->389 382->381 387 403fe5-403fec 383->387 384->378 388->389 394 403e35-403e3f GetFileAttributesW 388->394 389->367 402 403f37-403f51 ShowWindow call 4069c5 390->402 403 403fba-403fbb call 40579d 390->403 391->387 395 403e41-403e43 394->395 396 403e45-403e46 call 405f83 394->396 395->389 395->396 396->389 410 403f53-403f58 call 4069c5 402->410 411 403f5d-403f6f GetClassInfoW 402->411 406 403fc0-403fc2 403->406 408 403fc4-403fca 406->408 409 403fdc-403fde call 40140b 406->409 408->391 412 403fd0-403fd7 call 40140b 408->412 409->383 410->411 415 403f71-403f81 GetClassInfoW RegisterClassW 411->415 416 403f87-403faa DialogBoxParamW call 40140b 411->416 412->391 415->416 420 403faf-403fb8 call 403c67 416->420 420->387
                                      APIs
                                        • Part of subcall function 00406A35: GetModuleHandleA.KERNEL32(?,00000020,?,00403750,0000000B), ref: 00406A47
                                        • Part of subcall function 00406A35: GetProcAddress.KERNEL32(00000000,?), ref: 00406A62
                                      • lstrcatW.KERNEL32(1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000,00000002,74DF3420,C:\Users\user\AppData\Local\Temp\,?,00000000,?), ref: 00403D98
                                      • lstrlenW.KERNEL32(00428200,?,?,?,00428200,00000000,C:\Program Files\Gwyddion,1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000,00000002,74DF3420), ref: 00403E18
                                      • lstrcmpiW.KERNEL32(004281F8,.exe,00428200,?,?,?,00428200,00000000,C:\Program Files\Gwyddion,1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000), ref: 00403E2B
                                      • GetFileAttributesW.KERNEL32(00428200,?,00000000,?), ref: 00403E36
                                      • LoadImageW.USER32(00000067,00000001,00000000,00000000,00008040,C:\Program Files\Gwyddion), ref: 00403E7F
                                        • Part of subcall function 004065AF: wsprintfW.USER32 ref: 004065BC
                                      • RegisterClassW.USER32(00429200), ref: 00403EBC
                                      • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00403ED4
                                      • CreateWindowExW.USER32(00000080,_Nb,00000000,80000000,?,?,?,?,00000000,00000000,00000000), ref: 00403F09
                                      • ShowWindow.USER32(00000005,00000000,?,00000000,?), ref: 00403F3F
                                      • GetClassInfoW.USER32(00000000,RichEdit20W,00429200), ref: 00403F6B
                                      • GetClassInfoW.USER32(00000000,RichEdit,00429200), ref: 00403F78
                                      • RegisterClassW.USER32(00429200), ref: 00403F81
                                      • DialogBoxParamW.USER32(?,00000000,004040C5,00000000), ref: 00403FA0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Class$Info$RegisterWindow$AddressAttributesCreateDialogFileHandleImageLoadModuleParamParametersProcShowSystemlstrcatlstrcmpilstrlenwsprintf
                                      • String ID: .DEFAULT\Control Panel\International$.exe$1033$C:\Program Files\Gwyddion$C:\Users\user\AppData\Local\Temp\$Control Panel\Desktop\ResourceLocale$H7B$RichEd20$RichEd32$RichEdit$RichEdit20W$_Nb
                                      • API String ID: 1975747703-1484214092
                                      • Opcode ID: 78a63079156de9a95659751e2075cee6996798d0e51b0c114acce594fd97feca
                                      • Instruction ID: e235badc60aeba35c86cf297cd954ec43a22164425911800af60bc979c7621a1
                                      • Opcode Fuzzy Hash: 78a63079156de9a95659751e2075cee6996798d0e51b0c114acce594fd97feca
                                      • Instruction Fuzzy Hash: E661D570640201BAD730AF66AD45E2B3A7CEB84B49F40457FF945B22E1DB3D5911CA3D

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 423 404783-404795 424 4048b5-4048c2 423->424 425 40479b-4047a3 423->425 426 4048c4-4048cd 424->426 427 40491f-404923 424->427 428 4047a5-4047b4 425->428 429 4047b6-4047da 425->429 434 4048d3-4048d9 426->434 435 4049f8 426->435 432 4049e9-4049f0 427->432 433 404929-404941 GetDlgItem 427->433 428->429 430 4047e3-40485e call 4045c4 * 2 CheckDlgButton call 4045e6 GetDlgItem call 4045f9 SendMessageW 429->430 431 4047dc 429->431 465 404860-404863 GetSysColor 430->465 466 404869-4048b0 SendMessageW * 2 lstrlenW SendMessageW * 2 430->466 431->430 432->435 437 4049f2 432->437 439 404943-40494a 433->439 440 4049aa-4049b1 433->440 434->435 441 4048df-4048ea 434->441 438 4049fb-404a02 call 40462b 435->438 437->435 449 404a07-404a0b 438->449 439->440 445 40494c-404967 439->445 440->438 446 4049b3-4049ba 440->446 441->435 442 4048f0-40491a GetDlgItem SendMessageW call 4045e6 call 404a0e 441->442 442->427 445->440 450 404969-4049a7 SendMessageW LoadCursorW SetCursor call 404a32 LoadCursorW SetCursor 445->450 446->438 451 4049bc-4049c0 446->451 450->440 455 4049d2-4049d6 451->455 456 4049c2-4049d0 SendMessageW 451->456 457 4049e4-4049e7 455->457 458 4049d8-4049e2 SendMessageW 455->458 456->455 457->449 458->457 465->466 466->449
                                      APIs
                                      • CheckDlgButton.USER32(?,-0000040A,00000001), ref: 00404821
                                      • GetDlgItem.USER32(?,000003E8), ref: 00404835
                                      • SendMessageW.USER32(00000000,0000045B,00000001,00000000), ref: 00404852
                                      • GetSysColor.USER32(?), ref: 00404863
                                      • SendMessageW.USER32(00000000,00000443,00000000,?), ref: 00404871
                                      • SendMessageW.USER32(00000000,00000445,00000000,04010000), ref: 0040487F
                                      • lstrlenW.KERNEL32(?), ref: 00404884
                                      • SendMessageW.USER32(00000000,00000435,00000000,00000000), ref: 00404891
                                      • SendMessageW.USER32(00000000,00000449,00000110,00000110), ref: 004048A6
                                      • GetDlgItem.USER32(?,0000040A), ref: 004048FF
                                      • SendMessageW.USER32(00000000), ref: 00404906
                                      • GetDlgItem.USER32(?,000003E8), ref: 00404931
                                      • SendMessageW.USER32(00000000,0000044B,00000000,00000201), ref: 00404974
                                      • LoadCursorW.USER32(00000000,00007F02), ref: 00404982
                                      • SetCursor.USER32(00000000), ref: 00404985
                                      • LoadCursorW.USER32(00000000,00007F00), ref: 0040499E
                                      • SetCursor.USER32(00000000), ref: 004049A1
                                      • SendMessageW.USER32(00000111,00000001,00000000), ref: 004049D0
                                      • SendMessageW.USER32(00000010,00000000,00000000), ref: 004049E2
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend$Cursor$Item$Load$ButtonCheckColorlstrlen
                                      • String ID: $*K$N
                                      • API String ID: 3103080414-565173907
                                      • Opcode ID: 7b7ce6e7f04c0852b245e81234b58653da2c4cab9b10fb98097c13f3cf17b06e
                                      • Instruction ID: 690b4d321b533a2a97605fa3f7bb2423a24794fe1ec6c961d913f822d5f12d1b
                                      • Opcode Fuzzy Hash: 7b7ce6e7f04c0852b245e81234b58653da2c4cab9b10fb98097c13f3cf17b06e
                                      • Instruction Fuzzy Hash: AB6181F1900209FFDB109F61CD85A6A7B69FB84304F00813AF705B62E0C7799951DFA9

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 570 4030d0-40311e GetTickCount GetModuleFileNameW call 406158 573 403120-403125 570->573 574 40312a-403158 call 406668 call 405f83 call 406668 GetFileSize 570->574 575 40336a-40336e 573->575 582 403243-403251 call 40302e 574->582 583 40315e 574->583 590 403322-403327 582->590 591 403257-40325a 582->591 585 403163-40317a 583->585 587 40317c 585->587 588 40317e-403187 call 4035e2 585->588 587->588 595 40318d-403194 588->595 596 4032de-4032e6 call 40302e 588->596 590->575 593 403286-4032d2 GlobalAlloc call 406b90 call 406187 CreateFileW 591->593 594 40325c-403274 call 4035f8 call 4035e2 591->594 621 4032d4-4032d9 593->621 622 4032e8-403318 call 4035f8 call 403371 593->622 594->590 616 40327a-403280 594->616 600 403210-403214 595->600 601 403196-4031aa call 406113 595->601 596->590 605 403216-40321d call 40302e 600->605 606 40321e-403224 600->606 601->606 619 4031ac-4031b3 601->619 605->606 612 403233-40323b 606->612 613 403226-403230 call 406b22 606->613 612->585 620 403241 612->620 613->612 616->590 616->593 619->606 624 4031b5-4031bc 619->624 620->582 621->575 630 40331d-403320 622->630 624->606 626 4031be-4031c5 624->626 626->606 629 4031c7-4031ce 626->629 629->606 631 4031d0-4031f0 629->631 630->590 632 403329-40333a 630->632 631->590 633 4031f6-4031fa 631->633 634 403342-403347 632->634 635 40333c 632->635 636 403202-40320a 633->636 637 4031fc-403200 633->637 638 403348-40334e 634->638 635->634 636->606 639 40320c-40320e 636->639 637->620 637->636 638->638 640 403350-403368 call 406113 638->640 639->606 640->575
                                      APIs
                                      • GetTickCount.KERNEL32 ref: 004030E4
                                      • GetModuleFileNameW.KERNEL32(00000000,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,00000400), ref: 00403100
                                        • Part of subcall function 00406158: GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,80000000,00000003), ref: 0040615C
                                        • Part of subcall function 00406158: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                      • GetFileSize.KERNEL32(00000000,00000000,00439000,00000000,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,80000000,00000003), ref: 00403149
                                      • GlobalAlloc.KERNELBASE(00000040,?), ref: 0040328B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: File$AllocAttributesCountCreateGlobalModuleNameSizeTick
                                      • String ID: C:\Users\user\AppData\Local\Temp\$C:\Users\user\Desktop$C:\Users\user\Desktop\Gwyddion-2.67.win64.exe$Error launching installer$Error writing temporary file. Make sure your temp folder is valid.$Inst$Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author $Null$soft
                                      • API String ID: 2803837635-774728556
                                      • Opcode ID: e541a5f8c6dece2e8afc31f1679abbe6e625a0cbceb2fdcb1154e7c345c65132
                                      • Instruction ID: 6a7077609e6cbe8902eef3654a796be60faa9129f620d49927b75729aeb44cd1
                                      • Opcode Fuzzy Hash: e541a5f8c6dece2e8afc31f1679abbe6e625a0cbceb2fdcb1154e7c345c65132
                                      • Instruction Fuzzy Hash: 74710271A40204ABDB20DFB5DD85B9E3AACAB04315F21457FF901B72D2CB789E418B6D

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 707 4066a5-4066b0 708 4066b2-4066c1 707->708 709 4066c3-4066d9 707->709 708->709 710 4066f1-4066fa 709->710 711 4066db-4066e8 709->711 713 406700 710->713 714 4068d5-4068e0 710->714 711->710 712 4066ea-4066ed 711->712 712->710 715 406705-406712 713->715 716 4068e2-4068e6 call 406668 714->716 717 4068eb-4068ec 714->717 715->714 718 406718-406721 715->718 716->717 720 4068b3 718->720 721 406727-406764 718->721 722 4068c1-4068c4 720->722 723 4068b5-4068bf 720->723 724 406857-40685c 721->724 725 40676a-406771 721->725 726 4068c6-4068cf 722->726 723->726 727 40685e-406864 724->727 728 40688f-406894 724->728 729 406773-406775 725->729 730 406776-406778 725->730 726->714 733 406702 726->733 734 406874-406880 call 406668 727->734 735 406866-406872 call 4065af 727->735 731 4068a3-4068b1 lstrlenW 728->731 732 406896-40689e call 4066a5 728->732 729->730 736 4067b5-4067b8 730->736 737 40677a-406798 call 406536 730->737 731->726 732->731 733->715 749 406885-40688b 734->749 735->749 739 4067c8-4067cb 736->739 740 4067ba-4067c6 GetSystemDirectoryW 736->740 744 40679d-4067a1 737->744 746 406834-406836 739->746 747 4067cd-4067db GetWindowsDirectoryW 739->747 745 406838-40683c 740->745 751 4067a7-4067b0 call 4066a5 744->751 752 40683e-406842 744->752 745->752 753 40684f-406855 call 4068ef 745->753 746->745 750 4067dd-4067e5 746->750 747->746 749->731 754 40688d 749->754 758 4067e7-4067f0 750->758 759 4067fc-406812 SHGetSpecialFolderLocation 750->759 751->745 752->753 756 406844-40684a lstrcatW 752->756 753->731 754->753 756->753 764 4067f8-4067fa 758->764 762 406830 759->762 763 406814-40682e SHGetPathFromIDListW CoTaskMemFree 759->763 762->746 763->745 763->762 764->745 764->759
                                      APIs
                                      • GetSystemDirectoryW.KERNEL32(00428200,00000400), ref: 004067C0
                                      • GetWindowsDirectoryW.KERNEL32(00428200,00000400,00000000,Completed,?,00405701,Completed,00000000,00000000,00000000,00000000), ref: 004067D3
                                      • lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                      • lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                      Strings
                                      • \Microsoft\Internet Explorer\Quick Launch, xrefs: 00406844
                                      • Completed, xrefs: 004066CA
                                      • Software\Microsoft\Windows\CurrentVersion, xrefs: 0040678E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Directory$SystemWindowslstrcatlstrlen
                                      • String ID: Completed$Software\Microsoft\Windows\CurrentVersion$\Microsoft\Internet Explorer\Quick Launch
                                      • API String ID: 4260037668-2193954744
                                      • Opcode ID: a56a8a4d956183f5ceef7ff9e42496adb417aa599aaeb911d527621cdebcfcc9
                                      • Instruction ID: 414c90a3e727c3679fd522760d05a71ccfd37451a898d0680c6fb4b4ce958948
                                      • Opcode Fuzzy Hash: a56a8a4d956183f5ceef7ff9e42496adb417aa599aaeb911d527621cdebcfcc9
                                      • Instruction Fuzzy Hash: CD61E172A02115EBDB20AF64CD40BAA37A5EF10314F22C13EE946B62D0DB3D49A1CB5D

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 776 40176f-401794 call 402da6 call 405fae 781 401796-40179c call 406668 776->781 782 40179e-4017b0 call 406668 call 405f37 lstrcatW 776->782 787 4017b5-4017b6 call 4068ef 781->787 782->787 791 4017bb-4017bf 787->791 792 4017c1-4017cb call 40699e 791->792 793 4017f2-4017f5 791->793 801 4017dd-4017ef 792->801 802 4017cd-4017db CompareFileTime 792->802 794 4017f7-4017f8 call 406133 793->794 795 4017fd-401819 call 406158 793->795 794->795 803 40181b-40181e 795->803 804 40188d-4018b6 call 4056ca call 403371 795->804 801->793 802->801 805 401820-40185e call 406668 * 2 call 4066a5 call 406668 call 405cc8 803->805 806 40186f-401879 call 4056ca 803->806 818 4018b8-4018bc 804->818 819 4018be-4018ca SetFileTime 804->819 805->791 838 401864-401865 805->838 816 401882-401888 806->816 821 402c33 816->821 818->819 820 4018d0-4018db CloseHandle 818->820 819->820 824 4018e1-4018e4 820->824 825 402c2a-402c2d 820->825 823 402c35-402c39 821->823 827 4018e6-4018f7 call 4066a5 lstrcatW 824->827 828 4018f9-4018fc call 4066a5 824->828 825->821 834 401901-402398 827->834 828->834 839 40239d-4023a2 834->839 840 402398 call 405cc8 834->840 838->816 841 401867-401868 838->841 839->823 840->839 841->806
                                      APIs
                                      • lstrcatW.KERNEL32(00000000,00000000,0040A5F8,C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES,?,?,00000031), ref: 004017B0
                                      • CompareFileTime.KERNEL32(-00000014,?,0040A5F8,0040A5F8,00000000,00000000,0040A5F8,C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES,?,?,00000031), ref: 004017D5
                                        • Part of subcall function 00406668: lstrcpynW.KERNEL32(?,?,00000400,004037B0,00429260,NSIS Error), ref: 00406675
                                        • Part of subcall function 004056CA: lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                        • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                        • Part of subcall function 004056CA: lstrcatW.KERNEL32(Completed,004030A8,004030A8,Completed,00000000,00000000,00000000), ref: 00405725
                                        • Part of subcall function 004056CA: SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                      Strings
                                      • C:\Program Files\Gwyddion\uninstall.exe, xrefs: 00401835, 00401851
                                      • C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES, xrefs: 0040179E
                                      • C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1", xrefs: 00401821, 0040183F
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend$lstrcatlstrlen$CompareFileTextTimeWindowlstrcpyn
                                      • String ID: C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1"$C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES$C:\Program Files\Gwyddion\uninstall.exe
                                      • API String ID: 1941528284-3563039379
                                      • Opcode ID: 8523f3ae37f4176a2d63e539cb594509097e8e98a7304b2b57234137f625434c
                                      • Instruction ID: 87dd38174d63fc88252c3cacf76d35d2aef1a13c6195c1d88e2760da23471212
                                      • Opcode Fuzzy Hash: 8523f3ae37f4176a2d63e539cb594509097e8e98a7304b2b57234137f625434c
                                      • Instruction Fuzzy Hash: DE41B771500205BACF10BBB5CD85DAE7A75EF45328B20473FF422B21E1D63D89619A2E

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 842 4056ca-4056df 843 4056e5-4056f6 842->843 844 405796-40579a 842->844 845 405701-40570d lstrlenW 843->845 846 4056f8-4056fc call 4066a5 843->846 848 40572a-40572e 845->848 849 40570f-40571f lstrlenW 845->849 846->845 851 405730-405737 SetWindowTextW 848->851 852 40573d-405741 848->852 849->844 850 405721-405725 lstrcatW 849->850 850->848 851->852 853 405743-405785 SendMessageW * 3 852->853 854 405787-405789 852->854 853->854 854->844 855 40578b-40578e 854->855 855->844
                                      APIs
                                      • lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                      • lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                      • lstrcatW.KERNEL32(Completed,004030A8,004030A8,Completed,00000000,00000000,00000000), ref: 00405725
                                      • SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                      • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                      • SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                      • SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                        • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                        • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSendlstrlen$lstrcat$TextWindow
                                      • String ID: Completed
                                      • API String ID: 1495540970-3087654605
                                      • Opcode ID: da0887550f177a20a5adca650a80eb3065253b4758cf57a6ba66e38fd01475e6
                                      • Instruction ID: 7f52a71d89202be05388d2ae90ba5930d13dcc1e6093ad3ff4eaa481a322a782
                                      • Opcode Fuzzy Hash: da0887550f177a20a5adca650a80eb3065253b4758cf57a6ba66e38fd01475e6
                                      • Instruction Fuzzy Hash: C6217A71900518FACB119FA5DD84A8EBFB8EB45360F10857AF904B62A0D67A4A509F68

                                      Control-flow Graph

                                      APIs
                                      • SendMessageW.USER32(?,0000040D,00000000), ref: 6FBB1CE6
                                      • ShowWindow.USER32(00000008), ref: 6FBB1CF4
                                      • KiUserCallbackDispatcher.NTDLL(?,00000000,00000000,00000000), ref: 6FBB1D10
                                      • IsDialogMessageW.USER32(?), ref: 6FBB1D20
                                      • IsDialogMessageW.USER32(?), ref: 6FBB1D30
                                      • TranslateMessage.USER32(?), ref: 6FBB1D3A
                                      • DispatchMessageW.USER32(?), ref: 6FBB1D44
                                      • SetWindowLongW.USER32(?,00000004), ref: 6FBB1D5E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Message$DialogWindow$CallbackDispatchDispatcherLongSendShowTranslateUser
                                      • String ID:
                                      • API String ID: 4159918924-0
                                      • Opcode ID: 997aa8e5985fd1df189c88df856f17d993819e649d9336f0b72cf63bc2781d46
                                      • Instruction ID: 50ad7c6459d08c6891b65a211447a3c476eea1089b916a6c47a8b3943ece7574
                                      • Opcode Fuzzy Hash: 997aa8e5985fd1df189c88df856f17d993819e649d9336f0b72cf63bc2781d46
                                      • Instruction Fuzzy Hash: 6B110932900949BBCF119BA3DC09E9A3B7EFB46722B444055F601A7011EF34A927CF50

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 864 40302e-40303d 865 403057-40305d 864->865 866 40303f-403046 864->866 869 403067-403073 GetTickCount 865->869 870 40305f-403065 call 406a71 865->870 867 403048-403049 DestroyWindow 866->867 868 40304f-403055 866->868 867->868 871 4030cd-4030cf 868->871 869->871 873 403075-40307b 869->873 870->871 875 4030aa-4030c7 CreateDialogParamW ShowWindow 873->875 876 40307d-403084 873->876 875->871 876->871 877 403086-4030a3 call 403012 wsprintfW call 4056ca 876->877 881 4030a8 877->881 881->871
                                      APIs
                                      • DestroyWindow.USER32(00000000,00000000), ref: 00403049
                                      • GetTickCount.KERNEL32 ref: 00403067
                                      • wsprintfW.USER32 ref: 00403095
                                        • Part of subcall function 004056CA: lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                        • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                        • Part of subcall function 004056CA: lstrcatW.KERNEL32(Completed,004030A8,004030A8,Completed,00000000,00000000,00000000), ref: 00405725
                                        • Part of subcall function 004056CA: SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                      • CreateDialogParamW.USER32(0000006F,00000000,00402F93,00000000), ref: 004030B9
                                      • ShowWindow.USER32(00000000,00000005), ref: 004030C7
                                        • Part of subcall function 00403012: MulDiv.KERNEL32(00000000,00000064,00000ECE), ref: 00403027
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSendWindow$lstrlen$CountCreateDestroyDialogParamShowTextTicklstrcatwsprintf
                                      • String ID: ... %d%%
                                      • API String ID: 722711167-2449383134
                                      • Opcode ID: a65563718f57099a27635650194dd277da09fbe66beefc8d93bb4be83c5e7891
                                      • Instruction ID: 5af6bf9b0b70cf9307c1258d0e5a667b07be53d22b58a3258066d7aee54b172b
                                      • Opcode Fuzzy Hash: a65563718f57099a27635650194dd277da09fbe66beefc8d93bb4be83c5e7891
                                      • Instruction Fuzzy Hash: E8018E70553614DBC7317F60AE08A5A3EACAB00F06F54457AF841B21E9DAB84645CBAE
                                      APIs
                                      • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 004069DC
                                      • wsprintfW.USER32 ref: 00406A17
                                      • LoadLibraryExW.KERNEL32(?,00000000,00000008), ref: 00406A2B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: DirectoryLibraryLoadSystemwsprintf
                                      • String ID: %s%S.dll$UXTHEME$\
                                      • API String ID: 2200240437-1946221925
                                      • Opcode ID: 63130bafcb32548bd4340548baa3f8658423137b3882cd96386db367ad08b740
                                      • Instruction ID: e2ac2e7087162e0187f8b4d6776822ec24d6e31928394cf94a41c199a4feb156
                                      • Opcode Fuzzy Hash: 63130bafcb32548bd4340548baa3f8658423137b3882cd96386db367ad08b740
                                      • Instruction Fuzzy Hash: 3AF096B154121DA7DB14AB68DD0EF9B366CAB00705F11447EA646F20E0EB7CDA68CB98
                                      APIs
                                      • GlobalAlloc.KERNELBASE(00000040,?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 004029B1
                                      • GlobalAlloc.KERNEL32(00000040,?,00000000,?), ref: 004029CD
                                      • GlobalFree.KERNEL32(?), ref: 00402A06
                                      • GlobalFree.KERNEL32(00000000), ref: 00402A19
                                      • CloseHandle.KERNEL32(?,?,?,?,?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 00402A35
                                      • DeleteFileW.KERNEL32(?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 00402A48
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Global$AllocFree$CloseDeleteFileHandle
                                      • String ID:
                                      • API String ID: 2667972263-0
                                      • Opcode ID: 2421e7d21af3a58438b8f2604f73b0c275452346c617808a2d043735fc6309d0
                                      • Instruction ID: 78b93316678d616cb595922dcd62a83f4062aa2fb33f08fb70827f98fa9650ab
                                      • Opcode Fuzzy Hash: 2421e7d21af3a58438b8f2604f73b0c275452346c617808a2d043735fc6309d0
                                      • Instruction Fuzzy Hash: E131B171D00124BBCF216FA9CE89D9EBE79AF09364F10023AF461762E1CB794D429B58
                                      APIs
                                      • lstrlenW.KERNEL32(00423748,00423748,?,%u.%u%s%s,00000005,00000000,00000000,?,000000DC,00000000,?,000000DF,00000000,00000400,?), ref: 00404F12
                                      • wsprintfW.USER32 ref: 00404F1B
                                      • SetDlgItemTextW.USER32(?,00423748), ref: 00404F2E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: ItemTextlstrlenwsprintf
                                      • String ID: %u.%u%s%s$H7B
                                      • API String ID: 3540041739-107966168
                                      • Opcode ID: 2edccdcb36c72f9bdce7a586f7ca7ee262dfb9f9a49697097ea36a1117f17e36
                                      • Instruction ID: 20619224473e8c08b4fba53027c62ddcf1c3fef784a2ba69f514aa474de30786
                                      • Opcode Fuzzy Hash: 2edccdcb36c72f9bdce7a586f7ca7ee262dfb9f9a49697097ea36a1117f17e36
                                      • Instruction Fuzzy Hash: 1A11D8736041283BDB00A5ADDC45E9F3298AB81338F150637FA26F61D1EA79882182E8
                                      APIs
                                      • CreateDirectoryW.KERNELBASE(?,?,C:\Users\user\AppData\Local\Temp\), ref: 00405BDC
                                      • GetLastError.KERNEL32 ref: 00405BF0
                                      • SetFileSecurityW.ADVAPI32(?,80000007,00000001), ref: 00405C05
                                      • GetLastError.KERNEL32 ref: 00405C0F
                                      Strings
                                      • C:\Users\user\AppData\Local\Temp\, xrefs: 00405BBF
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: ErrorLast$CreateDirectoryFileSecurity
                                      • String ID: C:\Users\user\AppData\Local\Temp\
                                      • API String ID: 3449924974-3081826266
                                      • Opcode ID: 4d8c721838b8a92ea27708fe49d100345a2f80ebd1be40878b53e15a1b169c58
                                      • Instruction ID: 886f74eda6482ab63e8fe18d08a652fea41827dc0a526659a7d7b5e138c44e4e
                                      • Opcode Fuzzy Hash: 4d8c721838b8a92ea27708fe49d100345a2f80ebd1be40878b53e15a1b169c58
                                      • Instruction Fuzzy Hash: 95010871D04219EAEF009FA1CD44BEFBBB8EF14314F04403ADA44B6180E7789648CB99
                                      APIs
                                      • SendMessageTimeoutW.USER32(00000000,00000000,?,?,?,00000002,?), ref: 00401CB3
                                      • SendMessageW.USER32(00000000,00000000,?,?), ref: 00401CCB
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend$Timeout
                                      • String ID: !
                                      • API String ID: 1777923405-2657877971
                                      • Opcode ID: b183ccb6ab3284ced798d12f720e161a9248df31e23c89b80f307d5b894ef539
                                      • Instruction ID: e1c20d37316975b9b94706f7b3abd8da4b7b3b5136eece5bd2aa3cbae88a6c19
                                      • Opcode Fuzzy Hash: b183ccb6ab3284ced798d12f720e161a9248df31e23c89b80f307d5b894ef539
                                      • Instruction Fuzzy Hash: 28219E7190420AEFEF05AFA4D94AAAE7BB4FF44304F14453EF601B61D0D7B88941CB98
                                      APIs
                                      • lstrlenW.KERNEL32(C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000023,00000011,00000002), ref: 004024D5
                                      • RegSetValueExW.KERNELBASE(?,?,?,?,C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000000,00000011,00000002), ref: 00402515
                                      • RegCloseKey.ADVAPI32(?,?,?,C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000000,00000011,00000002), ref: 004025FD
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CloseValuelstrlen
                                      • String ID: C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1"
                                      • API String ID: 2655323295-529217095
                                      • Opcode ID: c23fcdec70e9ceb7831d592374f9d693e5ab08b70c15ca3c3014b4063adf34c4
                                      • Instruction ID: a516967871aadb8e7373f7254d3c24ec0cdbd982f2b4049ed7d94b0996b6da2b
                                      • Opcode Fuzzy Hash: c23fcdec70e9ceb7831d592374f9d693e5ab08b70c15ca3c3014b4063adf34c4
                                      • Instruction Fuzzy Hash: 4011AF71E00108BEEF10AFA1CE49EAEB6B8EB44354F11443AF404B61C1DBB98D409658
                                      APIs
                                      • GetTickCount.KERNEL32 ref: 004061A5
                                      • GetTempFileNameW.KERNELBASE(?,?,00000000,?,?,?,?,0040363E,1033,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 004061C0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CountFileNameTempTick
                                      • String ID: C:\Users\user\AppData\Local\Temp\$nsa
                                      • API String ID: 1716503409-678247507
                                      • Opcode ID: 6315ab6e6f8253ba2c88c9b6803a176270f8621abb800126aa0f3c3b7b9ef66c
                                      • Instruction ID: 21b676f9b33da427d45e0b2d6905a63b6509bf3d89a4e990effff8b21c6fdcbe
                                      • Opcode Fuzzy Hash: 6315ab6e6f8253ba2c88c9b6803a176270f8621abb800126aa0f3c3b7b9ef66c
                                      • Instruction Fuzzy Hash: C3F09076700214BFEB008F59DD05E9AB7BCEBA1710F11803AEE05EB180E6B0A9648768
                                      APIs
                                      • GetModuleHandleW.KERNELBASE(00000000,00000001,000000F0), ref: 00402103
                                      • LoadLibraryExW.KERNEL32(00000000,?,00000008,00000001,000000F0), ref: 00402114
                                      • KiUserCallbackDispatcher.NTDLL(?,00000400,?,0040CE58,0040A000,?,00000008,00000001,000000F0), ref: 00402164
                                        • Part of subcall function 004056CA: lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                        • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                        • Part of subcall function 004056CA: lstrcatW.KERNEL32(Completed,004030A8,004030A8,Completed,00000000,00000000,00000000), ref: 00405725
                                        • Part of subcall function 004056CA: SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                        • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                      • FreeLibrary.KERNEL32(?,?,000000F7,?,?,00000008,00000001,000000F0), ref: 00402191
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend$Librarylstrlen$CallbackDispatcherFreeHandleLoadModuleTextUserWindowlstrcat
                                      • String ID:
                                      • API String ID: 719239633-0
                                      • Opcode ID: c0fc562415b006524e612b10bc8b4f19115c3b5e74acc175c6571b6fb39ea03e
                                      • Instruction ID: 1e7e134340f86907485d462c64894228b35b3344cd4f3d252167f9901203d809
                                      • Opcode Fuzzy Hash: c0fc562415b006524e612b10bc8b4f19115c3b5e74acc175c6571b6fb39ea03e
                                      • Instruction Fuzzy Hash: C521C231904104FADF11AFA5CF48A9D7A70BF48354F60413BF605B91E0DBBD8A929A5D
                                      APIs
                                      • CallWindowProcW.USER32(?,?,?,?), ref: 6FBB1447
                                      • DestroyWindow.USER32 ref: 6FBB145E
                                      • GetProcessHeap.KERNEL32(00000000), ref: 6FBB146B
                                      • RtlFreeHeap.NTDLL(00000000), ref: 6FBB1472
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: HeapWindow$CallDestroyFreeProcProcess
                                      • String ID:
                                      • API String ID: 1278960361-0
                                      • Opcode ID: e7e4cbc7e89440dccff205eae4db1c8fa35b49685a217c71f70c916a5e1f6aba
                                      • Instruction ID: 9c398a68ddab88518612f3394217dad3ec66e3fb36efe01c4383a33251ec401d
                                      • Opcode Fuzzy Hash: e7e4cbc7e89440dccff205eae4db1c8fa35b49685a217c71f70c916a5e1f6aba
                                      • Instruction Fuzzy Hash: A6012C32500A44ABCF018F96EC09AEA7B7AFF4B372B484569F65487152CF319872DF50
                                      APIs
                                        • Part of subcall function 00405FE2: CharNextW.USER32(?,?,00425F50,?,00406056,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0,00000000), ref: 00405FF0
                                        • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 00405FF5
                                        • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 0040600D
                                      • GetFileAttributesW.KERNELBASE(?,?,00000000,0000005C,00000000,000000F0), ref: 0040161A
                                        • Part of subcall function 00405B99: CreateDirectoryW.KERNELBASE(?,?,C:\Users\user\AppData\Local\Temp\), ref: 00405BDC
                                      • SetCurrentDirectoryW.KERNELBASE(?,C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES,?,00000000,000000F0), ref: 0040164D
                                      Strings
                                      • C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES, xrefs: 00401640
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CharNext$Directory$AttributesCreateCurrentFile
                                      • String ID: C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES
                                      • API String ID: 1892508949-923977919
                                      • Opcode ID: 5100f8edfc5c73fcce05ecfe13f7e88f84c01c09c33b7a9b27ef58f2b5b0e964
                                      • Instruction ID: a0118e7b9b939ef3ea3e51add98df8039a5aa70d3b8e99a19be4f9c31e9f39fe
                                      • Opcode Fuzzy Hash: 5100f8edfc5c73fcce05ecfe13f7e88f84c01c09c33b7a9b27ef58f2b5b0e964
                                      • Instruction Fuzzy Hash: 04112231508105EBCF30AFA0CD4099E36A0EF15329B28493BF901B22F1DB3E4982DB5E
                                      APIs
                                        • Part of subcall function 00406668: lstrcpynW.KERNEL32(?,?,00000400,004037B0,00429260,NSIS Error), ref: 00406675
                                        • Part of subcall function 00405FE2: CharNextW.USER32(?,?,00425F50,?,00406056,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0,00000000), ref: 00405FF0
                                        • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 00405FF5
                                        • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 0040600D
                                      • lstrlenW.KERNEL32(00425F50,00000000,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0,00000000), ref: 00406098
                                      • GetFileAttributesW.KERNELBASE(00425F50,00425F50,00425F50,00425F50,00425F50,00425F50,00000000,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0), ref: 004060A8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CharNext$AttributesFilelstrcpynlstrlen
                                      • String ID: P_B
                                      • API String ID: 3248276644-906794629
                                      • Opcode ID: 900e3a3aedd828ccf636743a116f58552bc6887dcb5d3e9637a901da882d1290
                                      • Instruction ID: df110f430b83b9381375b5fd3fa67f6c4419d4890c6468873e0fced3c2676832
                                      • Opcode Fuzzy Hash: 900e3a3aedd828ccf636743a116f58552bc6887dcb5d3e9637a901da882d1290
                                      • Instruction Fuzzy Hash: 0DF07826144A1216E622B23A0C05BAF05098F82354B07063FFC93B22E1DF3C8973C43E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 9f3cc98df1e3ecd253cf91825a4064c55af45d063240f038e3dc270cc3f81a7c
                                      • Instruction ID: 10cc2cc0f2c892254e5285b7a8bac4c216a70fda8fb68dfa7c3680dd08f727d3
                                      • Opcode Fuzzy Hash: 9f3cc98df1e3ecd253cf91825a4064c55af45d063240f038e3dc270cc3f81a7c
                                      • Instruction Fuzzy Hash: 55A15571E04228DBDF28CFA8C8547ADBBB1FF44305F10842AD856BB281D778A986DF45
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 97748a737734167d5846b9d8dd4738ada3f75d0b833fdafa89234df63502b4a5
                                      • Instruction ID: d49815ad38d406b3cd0a1a90ea7be1526168d9e39684835ffa6a026ef1ef4849
                                      • Opcode Fuzzy Hash: 97748a737734167d5846b9d8dd4738ada3f75d0b833fdafa89234df63502b4a5
                                      • Instruction Fuzzy Hash: 91913270D04228DBEF28CF98C8547ADBBB1FF44305F14816AD856BB281D778A986DF45
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 93c083d05bcdf6195ca23c2a54f1652f9efbc2f2339d63ff2f761c89645e7c92
                                      • Instruction ID: 0a676f48c9952aad729ccf503b6a86ce95496029d8c73069f89f3073be052f6e
                                      • Opcode Fuzzy Hash: 93c083d05bcdf6195ca23c2a54f1652f9efbc2f2339d63ff2f761c89645e7c92
                                      • Instruction Fuzzy Hash: C3813471D08228DFDF24CFA8C8847ADBBB1FB44305F24816AD456BB281D778A986DF05
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 42fe04b556333c9da529a864bcd0db0a91825228453d2ef5331aa29539740558
                                      • Instruction ID: 41bbaa2e3590000dceee7c9791d291245bc26db239967492cd44d063337b5de0
                                      • Opcode Fuzzy Hash: 42fe04b556333c9da529a864bcd0db0a91825228453d2ef5331aa29539740558
                                      • Instruction Fuzzy Hash: 3E814831D08228DBEF28CFA8C8447ADBBB1FF44305F14816AD856B7281D778A986DF45
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 7ccf24f4e081119859c9f0e48baaaa1d38e3934f3a3b1d8a87677b84cb71901f
                                      • Instruction ID: 4a3513360c1d1cc4287bdabe5afcaa460628bed3c0d7ae87261646ca99be8a9f
                                      • Opcode Fuzzy Hash: 7ccf24f4e081119859c9f0e48baaaa1d38e3934f3a3b1d8a87677b84cb71901f
                                      • Instruction Fuzzy Hash: 0D711271D04228DBEF28CF98C9947ADBBF1FB44305F14806AD856B7280D738A986DF05
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: c68610f165bc536a6a66ce61bc987e677a2aaa57ebbfa987bd426c3fc0f92c56
                                      • Instruction ID: aecab3f40db1f9fc07a3dc9ea3777efa7aa3d7dc23f88bc09ddd959c6243594a
                                      • Opcode Fuzzy Hash: c68610f165bc536a6a66ce61bc987e677a2aaa57ebbfa987bd426c3fc0f92c56
                                      • Instruction Fuzzy Hash: 2B711571D04228DBEF28CF98C8547ADBBB1FF44305F14806AD856BB281D778A986DF05
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: b33066b9a67caffcdb2859c2a3d237c195f810e8b6f417b46283b98aba377de3
                                      • Instruction ID: 947ff9f4813c08031b822263453b6bbc7859602ae013fffc9a74d3363ad91bbb
                                      • Opcode Fuzzy Hash: b33066b9a67caffcdb2859c2a3d237c195f810e8b6f417b46283b98aba377de3
                                      • Instruction Fuzzy Hash: FE713471E04228DBEF28CF98C8547ADBBB1FF44305F15806AD856BB281C778A986DF45
                                      APIs
                                      • GetTickCount.KERNEL32 ref: 0040348D
                                        • Part of subcall function 004035F8: SetFilePointer.KERNELBASE(00000000,00000000,00000000,004032F6,?), ref: 00403606
                                      • SetFilePointer.KERNELBASE(00000000,00000000,?,00000000,004033A3,00000004,00000000,00000000,?,?,0040331D,000000FF,00000000,00000000,?,?), ref: 004034C0
                                      • SetFilePointer.KERNELBASE(06E93C69,00000000,00000000,00414EF0,00004000,?,00000000,004033A3,00000004,00000000,00000000,?,?,0040331D,000000FF,00000000), ref: 004035BB
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FilePointer$CountTick
                                      • String ID:
                                      • API String ID: 1092082344-0
                                      • Opcode ID: ce02fe222e12e83d877d3b7aabf99e7a2bcb53596278d9d285b37d8023f85d8e
                                      • Instruction ID: 4a0f782daef8a724a5dada35133bb9654e3c612a62d69fcdf17392b9264be50a
                                      • Opcode Fuzzy Hash: ce02fe222e12e83d877d3b7aabf99e7a2bcb53596278d9d285b37d8023f85d8e
                                      • Instruction Fuzzy Hash: 3A31AEB2650205EFC7209F29EE848263BADF70475A755023BE900B22F1C7B59D42DB9D
                                      APIs
                                      • SendMessageW.USER32(00000408,?,00000000,004041FC), ref: 004045BB
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend
                                      • String ID: x
                                      • API String ID: 3850602802-2363233923
                                      • Opcode ID: a4e2778218c9fdeab8ae4952123a6e605dd424a78c20075fb3486bdcc909a4f1
                                      • Instruction ID: 271d720e87c3080f9bc4c684b425461430c88a900e0fa794081ec75d4c8aeb56
                                      • Opcode Fuzzy Hash: a4e2778218c9fdeab8ae4952123a6e605dd424a78c20075fb3486bdcc909a4f1
                                      • Instruction Fuzzy Hash: 58C01271646200FBCB208B00EE00F067A21B7A4B02F2088B9FB81240B48A314822DB2D
                                      APIs
                                      • SetFilePointer.KERNELBASE(?,00000000,00000000,00000000,00000000,?,?,0040331D,000000FF,00000000,00000000,?,?), ref: 00403396
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FilePointer
                                      • String ID:
                                      • API String ID: 973152223-0
                                      • Opcode ID: 9659739b35da8af7fb285d31f71ea9b2402f124514f270f9d6eabe2ecb184dd4
                                      • Instruction ID: 963a71f16df831595788c30304fa9cedbf2cad19eb63879c1ada4fe15c9ed8fa
                                      • Opcode Fuzzy Hash: 9659739b35da8af7fb285d31f71ea9b2402f124514f270f9d6eabe2ecb184dd4
                                      • Instruction Fuzzy Hash: 93319F70200219EFDB129F65ED84E9A3FA8FF00355B10443AF905EA1A1D778CE51DBA9
                                      APIs
                                      • RegQueryValueExW.ADVAPI32(00000000,00000000,?,?,?,?,?,?,?,?,00000033), ref: 0040255B
                                      • RegCloseKey.ADVAPI32(?,?,?,C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000000,00000011,00000002), ref: 004025FD
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CloseQueryValue
                                      • String ID:
                                      • API String ID: 3356406503-0
                                      • Opcode ID: 65252af27aff81f363bfff3291cf17b609d6a402d488cd426901fcd094bf1953
                                      • Instruction ID: eaee0c709954dca67eb2d1c59e66f6ca2c08a593dad46a4828cc6951ae7b5872
                                      • Opcode Fuzzy Hash: 65252af27aff81f363bfff3291cf17b609d6a402d488cd426901fcd094bf1953
                                      • Instruction Fuzzy Hash: 5C116D71900219EBDF14DFA4DE589AE7774FF04345B20443BE401B62D0E7B88A45EB5D
                                      APIs
                                      • RegQueryValueExW.KERNELBASE(00000020,00000020,00000000,00000000,00428200,00000800,00000000,?,00000000,00000020,00000020,00428200,?,?,0040679D,80000002), ref: 0040657C
                                      • RegCloseKey.KERNELBASE(00000020,?,0040679D,80000002,Software\Microsoft\Windows\CurrentVersion,00000020,00428200,00000020,00000000,Completed), ref: 00406587
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CloseQueryValue
                                      • String ID:
                                      • API String ID: 3356406503-0
                                      • Opcode ID: 5e421e957683aa7155fe1e1f393967b6404614e05e15b89e99e168e2dc4a01c3
                                      • Instruction ID: 52dd0fe420a7c1e2827d1a164217834099ee72e945ce70567094b216899e5676
                                      • Opcode Fuzzy Hash: 5e421e957683aa7155fe1e1f393967b6404614e05e15b89e99e168e2dc4a01c3
                                      • Instruction Fuzzy Hash: C4017C72500209FADF21CF51DD09EDB3BA8EF54364F01803AFD1AA2190D738D964DBA4
                                      APIs
                                      • MulDiv.KERNEL32(00007530,00000000,00000000), ref: 004013E4
                                      • SendMessageW.USER32(?,00000402,00000000), ref: 004013F4
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend
                                      • String ID:
                                      • API String ID: 3850602802-0
                                      • Opcode ID: 09e122a9c5ca6d14e20a0c17f6d9bb0c47d9e5f073d0cae9cf8d248ab6fa9320
                                      • Instruction ID: af17251ef12b8b272b5eaf8d1bef107274ce64b6e67bb2dd4604cf2723900e86
                                      • Opcode Fuzzy Hash: 09e122a9c5ca6d14e20a0c17f6d9bb0c47d9e5f073d0cae9cf8d248ab6fa9320
                                      • Instruction Fuzzy Hash: 6F012831724220EBEB295B389D05B6A3698E710714F10857FF855F76F1E678CC029B6D
                                      APIs
                                      • OleInitialize.OLE32(00000000), ref: 004057AD
                                        • Part of subcall function 00404610: SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                      • CoUninitialize.COMBASE(00000404,00000000,?,00000000,?), ref: 004057F9
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: InitializeMessageSendUninitialize
                                      • String ID:
                                      • API String ID: 2896919175-0
                                      • Opcode ID: b14588aebbadd05bc97f1dd14ffe2b6982532d9bfcd69c4411fdff16e8679f7d
                                      • Instruction ID: 683c9d360a8619809caff371317e20043972a5eac84f98be19084c03997f3dfe
                                      • Opcode Fuzzy Hash: b14588aebbadd05bc97f1dd14ffe2b6982532d9bfcd69c4411fdff16e8679f7d
                                      • Instruction Fuzzy Hash: 84F09072600600CBD6215B54AD01B17B764EB84304F45447FFF89732F0DB7A48529A6E
                                      APIs
                                      • GetModuleHandleA.KERNEL32(?,00000020,?,00403750,0000000B), ref: 00406A47
                                      • GetProcAddress.KERNEL32(00000000,?), ref: 00406A62
                                        • Part of subcall function 004069C5: GetSystemDirectoryW.KERNEL32(?,00000104), ref: 004069DC
                                        • Part of subcall function 004069C5: wsprintfW.USER32 ref: 00406A17
                                        • Part of subcall function 004069C5: LoadLibraryExW.KERNEL32(?,00000000,00000008), ref: 00406A2B
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: AddressDirectoryHandleLibraryLoadModuleProcSystemwsprintf
                                      • String ID:
                                      • API String ID: 2547128583-0
                                      • Opcode ID: a89557e88259ac32882439a66efe2bded2b7fe37332f597cb2162f61758b0433
                                      • Instruction ID: 0464b4a7853edb7079d0776797c383171681067eb8499b99987f1e8ea9f8efb8
                                      • Opcode Fuzzy Hash: a89557e88259ac32882439a66efe2bded2b7fe37332f597cb2162f61758b0433
                                      • Instruction Fuzzy Hash: E0E086727042106AD210A6745D08D3773E8ABC6711307883EF557F2040D738DC359A79
                                      APIs
                                      • GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,80000000,00000003), ref: 0040615C
                                      • CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: File$AttributesCreate
                                      • String ID:
                                      • API String ID: 415043291-0
                                      • Opcode ID: bc48b18717e6d0ecb647aea7fc0ab07bebcbb2e2e3a0bd9572a83b91cd6509df
                                      • Instruction ID: 0e1b57c135d9ed337dcee0f1630d7a3ffd6699826ab823f4ff8c6da5104765b0
                                      • Opcode Fuzzy Hash: bc48b18717e6d0ecb647aea7fc0ab07bebcbb2e2e3a0bd9572a83b91cd6509df
                                      • Instruction Fuzzy Hash: DCD09E71254201AFEF0D8F20DF16F2E7AA2EB94B04F11952CB682940E1DAB15C15AB19
                                      APIs
                                      • GetFileAttributesW.KERNELBASE(?,?,00405D38,?,?,00000000,00405F0E,?,?,?,?), ref: 00406138
                                      • SetFileAttributesW.KERNEL32(?,00000000), ref: 0040614C
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: AttributesFile
                                      • String ID:
                                      • API String ID: 3188754299-0
                                      • Opcode ID: a764032cc0ce64e7f87df91ab84dfb27e8fca44cfd77f22972d2dc2d25b91850
                                      • Instruction ID: 3e6336b5c460747e2e1e0fbe3c4db8defb42c0044e1a92967a1d29a512d2a4bc
                                      • Opcode Fuzzy Hash: a764032cc0ce64e7f87df91ab84dfb27e8fca44cfd77f22972d2dc2d25b91850
                                      • Instruction Fuzzy Hash: 73D0C972514130ABC2102728AE0889ABB56EB64271B014A35F9A5A62B0CB304C628A98
                                      APIs
                                      • CreateDirectoryW.KERNELBASE(?,00000000,00403633,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405C1C
                                      • GetLastError.KERNEL32 ref: 00405C2A
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CreateDirectoryErrorLast
                                      • String ID:
                                      • API String ID: 1375471231-0
                                      • Opcode ID: 3d774f31bfc7c5d70b6f8c035fc875d1b29c99f0800ffc9da4ab7b914865a185
                                      • Instruction ID: 66e62c5d6c7775ff4cea72667941029308d228c48495a605f612c1d2d9e1fc74
                                      • Opcode Fuzzy Hash: 3d774f31bfc7c5d70b6f8c035fc875d1b29c99f0800ffc9da4ab7b914865a185
                                      • Instruction Fuzzy Hash: FBC04C31218605AEE7605B219F0CB177A94DB50741F114839E186F40A0DA788455D92D
                                      APIs
                                      • GlobalFree.KERNEL32(00000000), ref: 00401C0B
                                      • GlobalAlloc.KERNELBASE(00000040,00000804), ref: 00401C1D
                                        • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                        • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Global$AllocFreelstrcatlstrlen
                                      • String ID:
                                      • API String ID: 3292104215-0
                                      • Opcode ID: 8fff9c0e4c5b0ae78a96e2b6671f0d610947169ea12ed52eae8356a764bd9261
                                      • Instruction ID: d74cddccbdd50a14e5bf5e3e63826a63b2a65df0fd836753f00777670cd3b466
                                      • Opcode Fuzzy Hash: 8fff9c0e4c5b0ae78a96e2b6671f0d610947169ea12ed52eae8356a764bd9261
                                      • Instruction Fuzzy Hash: 5321D872904210DBDB20EFA4DEC4E5E73A4AB047157150A3BF542F72D0D6BD9C518BAD
                                      APIs
                                      • RegCreateKeyExW.KERNELBASE(00000000,?,00000000,00000000,00000000,?,00000000,?,00000000,?,?,?,00402E57,00000000,?,?), ref: 0040652C
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Create
                                      • String ID:
                                      • API String ID: 2289755597-0
                                      • Opcode ID: f0170b29b94a961cdf0cc122a920c286c7e5b726b195fdee8f598fb45efbb6e4
                                      • Instruction ID: 390987c888b9fe28ccc3a202ccefe0e129b8fdbaba7b34d45eb5723cdb444700
                                      • Opcode Fuzzy Hash: f0170b29b94a961cdf0cc122a920c286c7e5b726b195fdee8f598fb45efbb6e4
                                      • Instruction Fuzzy Hash: C1E0ECB2010109BEEF099F90EC0ADBB372DEB04704F41492EF907E4091E6B5AE70AA34
                                      APIs
                                      • WriteFile.KERNELBASE(?,00000000,00000000,00000000,00000000,0040DDBE,0040CEF0,00403579,0040CEF0,0040DDBE,00414EF0,00004000,?,00000000,004033A3,00000004), ref: 0040621E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FileWrite
                                      • String ID:
                                      • API String ID: 3934441357-0
                                      • Opcode ID: 3dec9289c2e50997f5b7f42c7d661c3d3292bfbb80aff78175bf8fde073ef60e
                                      • Instruction ID: 398385dbb58ca0a44fa402a726e0ab0b2131cea3ae709c8a1b666252059dd88a
                                      • Opcode Fuzzy Hash: 3dec9289c2e50997f5b7f42c7d661c3d3292bfbb80aff78175bf8fde073ef60e
                                      • Instruction Fuzzy Hash: F6E08632141129EBCF10AE548C00EEB375CFB01350F014476F955E3040D330E93087A5
                                      APIs
                                      • ReadFile.KERNELBASE(?,00000000,00000000,00000000,00000000,00414EF0,0040CEF0,004035F5,?,?,004034F9,00414EF0,00004000,?,00000000,004033A3), ref: 004061EF
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FileRead
                                      • String ID:
                                      • API String ID: 2738559852-0
                                      • Opcode ID: 0024165f2f5d2011be9120f41fe866c54f7b8e58de784a1218c53157080e4b8c
                                      • Instruction ID: 689b8facb1381159ac92aeccc4703b7db47ce2620db9a14c340ec3ef8a35c8b1
                                      • Opcode Fuzzy Hash: 0024165f2f5d2011be9120f41fe866c54f7b8e58de784a1218c53157080e4b8c
                                      • Instruction Fuzzy Hash: C1E0863250021AABDF10AE518C04AEB375CEB01360F014477F922E2150D230E82187E8
                                      APIs
                                      • RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000020,00428200,?,00000020,?,00406563,?,00000000,00000020,00000020,00428200,?), ref: 004064F9
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Open
                                      • String ID:
                                      • API String ID: 71445658-0
                                      • Opcode ID: 759d75b29ffd137612e455953a298f0698f5beae901813cd77d6ec234b014f3e
                                      • Instruction ID: 5036765eb4ab6e58186d81024f5778724aa2024cd81e2e1d5ca813995cf5404a
                                      • Opcode Fuzzy Hash: 759d75b29ffd137612e455953a298f0698f5beae901813cd77d6ec234b014f3e
                                      • Instruction Fuzzy Hash: BAD0123210020DBBDF115F90AD01FAB375DAB08310F018426FE06A4092D775D534A728
                                      APIs
                                        • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                        • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                      • SetDlgItemTextW.USER32(?,?,00000000), ref: 004045DE
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: ItemTextlstrcatlstrlen
                                      • String ID:
                                      • API String ID: 281422827-0
                                      • Opcode ID: 73b3e70f26523695344aa313222f8106b15ff01fe64d2e6c86eba35ea0453547
                                      • Instruction ID: ac81fd1055ba0297197cac3df011722fda0f302089e5b839fe348bc6695a069d
                                      • Opcode Fuzzy Hash: 73b3e70f26523695344aa313222f8106b15ff01fe64d2e6c86eba35ea0453547
                                      • Instruction Fuzzy Hash: 77C04C7554C300BFE641A755CC42F1FB799EF94319F04C92EB19DE11D1C63984309A2A
                                      APIs
                                      • SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend
                                      • String ID:
                                      • API String ID: 3850602802-0
                                      • Opcode ID: 8557fc69485774ba4641c6a2d2b4437b1a5152abf7221d5f63999a85994ee7b6
                                      • Instruction ID: 1d0f09303225af8c469e983b8f6ba21d59f3f36861eec243a4bc5be8392dea83
                                      • Opcode Fuzzy Hash: 8557fc69485774ba4641c6a2d2b4437b1a5152abf7221d5f63999a85994ee7b6
                                      • Instruction Fuzzy Hash: 9EC09B71741700FBDE209B509F45F077794A754701F154979B741F60E0D775D410D62D
                                      APIs
                                      • SetFilePointer.KERNELBASE(00000000,00000000,00000000,004032F6,?), ref: 00403606
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FilePointer
                                      • String ID:
                                      • API String ID: 973152223-0
                                      • Opcode ID: e1e4f0b9cbde4cef3e4374ef9de0ac4f9a9ec0cef6a377cf2568efe91b529ef4
                                      • Instruction ID: 036c8468b6dd2e012b37e6e875261c5f60c7cf4634656b07e897873a541603b6
                                      • Opcode Fuzzy Hash: e1e4f0b9cbde4cef3e4374ef9de0ac4f9a9ec0cef6a377cf2568efe91b529ef4
                                      • Instruction Fuzzy Hash: 1FB01231140304BFDA214F10DF09F067B21BB94700F20C034B384380F086711435EB0D
                                      APIs
                                      • SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend
                                      • String ID:
                                      • API String ID: 3850602802-0
                                      • Opcode ID: 70666cfd2db8a5712e0e3ed728d50a5e19955e25533eceda6abdc0f56bdf790a
                                      • Instruction ID: 26063d6d883ff380d2e1d7f9fe2b9d631bf033e6200e0a233fd0d302f8c02db7
                                      • Opcode Fuzzy Hash: 70666cfd2db8a5712e0e3ed728d50a5e19955e25533eceda6abdc0f56bdf790a
                                      • Instruction Fuzzy Hash: 5BB01235286A00FBDE614B00DE09F457E62F764B01F048078F741240F0CAB300B5DF19
                                      APIs
                                      • KiUserCallbackDispatcher.NTDLL(?,004043BD), ref: 004045F0
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CallbackDispatcherUser
                                      • String ID:
                                      • API String ID: 2492992576-0
                                      • Opcode ID: b9cabee76f1705efe6df0b682491f715d60f75bd340f366a7093c5de42737780
                                      • Instruction ID: 97f05af551d2e904d84950d91e3a9b28448307360fbef328a82585e9573e9e03
                                      • Opcode Fuzzy Hash: b9cabee76f1705efe6df0b682491f715d60f75bd340f366a7093c5de42737780
                                      • Instruction Fuzzy Hash: DBA001B6604500ABDE129F61EF09D0ABB72EBA4B02B418579A28590034CA365961FB1D
                                      APIs
                                      • FindFirstFileW.KERNEL32(00000000,?,00000002), ref: 0040291A
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: FileFindFirst
                                      • String ID:
                                      • API String ID: 1974802433-0
                                      • Opcode ID: b2f27a8a5f9b700f187602bb898c1293859530a573ae52e9df8ecc114fa703e5
                                      • Instruction ID: b84bdfeecc4e8c0803ac0e71b8711fc90ef1d688bdc4be786e729a17b55638d3
                                      • Opcode Fuzzy Hash: b2f27a8a5f9b700f187602bb898c1293859530a573ae52e9df8ecc114fa703e5
                                      • Instruction Fuzzy Hash: 47F05E71A04105EBDB01DBB4EE49AAEB378EF14314F60457BE101F21D0E7B88E529B29
                                      APIs
                                      • GetDlgItem.USER32(?,000003F9), ref: 00405049
                                      • GetDlgItem.USER32(?,00000408), ref: 00405054
                                      • GlobalAlloc.KERNEL32(00000040,?), ref: 0040509E
                                      • LoadImageW.USER32(0000006E,00000000,00000000,00000000,00000000), ref: 004050B5
                                      • SetWindowLongW.USER32(?,000000FC,0040563E), ref: 004050CE
                                      • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000006,00000000), ref: 004050E2
                                      • ImageList_AddMasked.COMCTL32(00000000,00000000,00FF00FF), ref: 004050F4
                                      • SendMessageW.USER32(?,00001109,00000002), ref: 0040510A
                                      • SendMessageW.USER32(?,0000111C,00000000,00000000), ref: 00405116
                                      • SendMessageW.USER32(?,0000111B,00000010,00000000), ref: 00405128
                                      • DeleteObject.GDI32(00000000), ref: 0040512B
                                      • SendMessageW.USER32(?,00000143,00000000,00000000), ref: 00405156
                                      • SendMessageW.USER32(?,00000151,00000000,00000000), ref: 00405162
                                      • SendMessageW.USER32(?,00001132,00000000,?), ref: 004051FD
                                      • SendMessageW.USER32(?,0000110A,00000003,00000110), ref: 0040522D
                                        • Part of subcall function 004045F9: SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                      • SendMessageW.USER32(?,00001132,00000000,?), ref: 00405241
                                      • GetWindowLongW.USER32(?,000000F0), ref: 0040526F
                                      • SetWindowLongW.USER32(?,000000F0,00000000), ref: 0040527D
                                      • ShowWindow.USER32(?,00000005), ref: 0040528D
                                      • SendMessageW.USER32(?,00000419,00000000,?), ref: 00405388
                                      • SendMessageW.USER32(?,00000147,00000000,00000000), ref: 004053ED
                                      • SendMessageW.USER32(?,00000150,00000000,00000000), ref: 00405402
                                      • SendMessageW.USER32(?,00000420,00000000,00000020), ref: 00405426
                                      • SendMessageW.USER32(?,00000200,00000000,00000000), ref: 00405446
                                      • ImageList_Destroy.COMCTL32(?), ref: 0040545B
                                      • GlobalFree.KERNEL32(?), ref: 0040546B
                                      • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 004054E4
                                      • SendMessageW.USER32(?,00001102,?,?), ref: 0040558D
                                      • SendMessageW.USER32(?,0000113F,00000000,00000008), ref: 0040559C
                                      • InvalidateRect.USER32(?,00000000,00000001), ref: 004055C7
                                      • ShowWindow.USER32(?,00000000), ref: 00405615
                                      • GetDlgItem.USER32(?,000003FE), ref: 00405620
                                      • ShowWindow.USER32(00000000), ref: 00405627
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: MessageSend$Window$Image$ItemList_LongShow$Global$AllocCreateDeleteDestroyFreeInvalidateLoadMaskedObjectRect
                                      • String ID: $M$N
                                      • API String ID: 2564846305-813528018
                                      • Opcode ID: 950969970af6d10ef62121ad67a768569704eb6391eae900e1ce4f9d1827afee
                                      • Instruction ID: a1eb65f7683e17450fca8d4cb4c1055b074660be5b1b810df034ff690b7f681c
                                      • Opcode Fuzzy Hash: 950969970af6d10ef62121ad67a768569704eb6391eae900e1ce4f9d1827afee
                                      • Instruction Fuzzy Hash: 2A025CB0900609EFDF20DF65CD45AAE7BB5FB44315F10817AEA10BA2E1D7798A52CF18
                                      APIs
                                      • CloseHandle.KERNEL32(00000000,?,00000000,00000001,?,00000000,?,?,00406449,?,?), ref: 004062E9
                                      • GetShortPathNameW.KERNEL32(?,00426DE8,00000400), ref: 004062F2
                                        • Part of subcall function 004060BD: lstrlenA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060CD
                                        • Part of subcall function 004060BD: lstrlenA.KERNEL32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060FF
                                      • GetShortPathNameW.KERNEL32(?,004275E8,00000400), ref: 0040630F
                                      • wsprintfA.USER32 ref: 0040632D
                                      • GetFileSize.KERNEL32(00000000,00000000,004275E8,C0000000,00000004,004275E8,?,?,?,?,?), ref: 00406368
                                      • GlobalAlloc.KERNEL32(00000040,0000000A,?,?,?,?), ref: 00406377
                                      • lstrcpyA.KERNEL32(00000000,[Rename],00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004063AF
                                      • SetFilePointer.KERNEL32(0040A5B0,00000000,00000000,00000000,00000000,004269E8,00000000,-0000000A,0040A5B0,00000000,[Rename],00000000,00000000,00000000), ref: 00406405
                                      • GlobalFree.KERNEL32(00000000), ref: 00406416
                                      • CloseHandle.KERNEL32(00000000,?,?,?,?), ref: 0040641D
                                        • Part of subcall function 00406158: GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,80000000,00000003), ref: 0040615C
                                        • Part of subcall function 00406158: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: File$CloseGlobalHandleNamePathShortlstrlen$AllocAttributesCreateFreePointerSizelstrcpywsprintf
                                      • String ID: %ls=%ls$[Rename]$mB$uB$uB
                                      • API String ID: 2171350718-2295842750
                                      • Opcode ID: b2067825d6455a5a6fbc0e1ac0a55e75a76fa2936571f052824e5b49ab30fb97
                                      • Instruction ID: df9b4e9fb9d32bd4c250032a1d399944af7a2e4c2f0bdec2b7d3959d12e60cc8
                                      • Opcode Fuzzy Hash: b2067825d6455a5a6fbc0e1ac0a55e75a76fa2936571f052824e5b49ab30fb97
                                      • Instruction Fuzzy Hash: B8314331200315BBD2206B619D49F5B3AACEF85704F16003BFD02FA2C2EA7DD82186BD
                                      APIs
                                      • DefWindowProcW.USER32(?,00000046,?,?), ref: 0040102C
                                      • BeginPaint.USER32(?,?), ref: 00401047
                                      • GetClientRect.USER32(?,?), ref: 0040105B
                                      • CreateBrushIndirect.GDI32(00000000), ref: 004010CF
                                      • FillRect.USER32(00000000,?,00000000), ref: 004010E4
                                      • DeleteObject.GDI32(?), ref: 004010ED
                                      • CreateFontIndirectW.GDI32(?), ref: 00401105
                                      • SetBkMode.GDI32(00000000,00000001), ref: 00401126
                                      • SetTextColor.GDI32(00000000,000000FF), ref: 00401130
                                      • SelectObject.GDI32(00000000,?), ref: 00401140
                                      • DrawTextW.USER32(00000000,00429260,000000FF,00000010,00000820), ref: 00401156
                                      • SelectObject.GDI32(00000000,00000000), ref: 00401160
                                      • DeleteObject.GDI32(?), ref: 00401165
                                      • EndPaint.USER32(?,?), ref: 0040116E
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Object$CreateDeleteIndirectPaintRectSelectText$BeginBrushClientColorDrawFillFontModeProcWindow
                                      • String ID: F
                                      • API String ID: 941294808-1304234792
                                      • Opcode ID: 8da9fae8b34351ceae2931000ebd9f39a308799c7d87b7a6dbcfe72b45b7384c
                                      • Instruction ID: e2f9fea5dfd6f059ba8eeb08e8d10ac227d01a2162b8a260283931f50cd0bfbf
                                      • Opcode Fuzzy Hash: 8da9fae8b34351ceae2931000ebd9f39a308799c7d87b7a6dbcfe72b45b7384c
                                      • Instruction Fuzzy Hash: 33418B71800209EFCF058FA5DE459AF7BB9FF45315F00802AF991AA2A0C7349A55DFA4
                                      APIs
                                        • Part of subcall function 6FBB1E4E: lstrcpynW.KERNEL32(6FBB1054,?,?,?,6FBB1054,?), ref: 6FBB1E7B
                                        • Part of subcall function 6FBB1E4E: GlobalFree.KERNEL32 ref: 6FBB1E8B
                                      • lstrcmpiW.KERNEL32(?,save,6FBB4920,00000400,6FBB5128,00000400,?,00000005), ref: 6FBB1168
                                      • GetFileAttributesW.KERNEL32(6FBB5128), ref: 6FBB117A
                                      • lstrcpyW.KERNEL32(6FBB5928,6FBB5128), ref: 6FBB1193
                                      • lstrcpyW.KERNEL32(6FBB4920,All Files|*.*), ref: 6FBB11B8
                                      • CharNextW.USER32(6FBB4920), ref: 6FBB11D9
                                      • GetCurrentDirectoryW.KERNEL32(00000400,6FBB4120), ref: 6FBB11F1
                                      • GetSaveFileNameW.COMDLG32(0000004C), ref: 6FBB1205
                                      • GetOpenFileNameW.COMDLG32(0000004C), ref: 6FBB120D
                                      • CommDlgExtendedError.COMDLG32 ref: 6FBB1213
                                      • GetSaveFileNameW.COMDLG32(0000004C), ref: 6FBB1230
                                      • GetOpenFileNameW.COMDLG32(0000004C), ref: 6FBB1238
                                      • SetCurrentDirectoryW.KERNEL32(6FBB4120,6FBB5128), ref: 6FBB1250
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: File$Name$CurrentDirectoryOpenSavelstrcpy$AttributesCharCommErrorExtendedFreeGlobalNextlstrcmpilstrcpyn
                                      • String ID: All Files|*.*$L$save
                                      • API String ID: 3853173656-601108453
                                      • Opcode ID: 2472321d548df4a95eaaa8bc4876e3628212bf27928c71a8358ba28930300504
                                      • Instruction ID: 8e0ccf31084bdcced8fd6f80aabf7a3568e0e7f34e3bdb42fa99c65f84f45a80
                                      • Opcode Fuzzy Hash: 2472321d548df4a95eaaa8bc4876e3628212bf27928c71a8358ba28930300504
                                      • Instruction Fuzzy Hash: 8841C675900B88EFDB009F6AE848BAE7BB8FF46325F48411DE811E7184DF349856CB61
                                      APIs
                                      • SendMessageW.USER32(?,?,?), ref: 6FBB1531
                                      • GetDlgItem.USER32(?,?), ref: 6FBB1544
                                      • SetWindowLongW.USER32(?,00000000,00000000), ref: 6FBB1659
                                      • GetWindowTextW.USER32(?,00000000,00000400), ref: 6FBB16B0
                                      • DrawTextW.USER32(?,00000000,000000FF,?,00000414), ref: 6FBB16D1
                                      • GetWindowLongW.USER32(?,000000EB), ref: 6FBB171C
                                      • SetTextColor.GDI32(?,00000000), ref: 6FBB172F
                                      • DrawTextW.USER32(?,00000000,000000FF,00000000,?), ref: 6FBB1749
                                      • DrawFocusRect.USER32(?,00000010), ref: 6FBB176A
                                      • RemovePropW.USER32(00000000,NSIS: nsControl pointer property), ref: 6FBB178E
                                      Strings
                                      • NSIS: nsControl pointer property, xrefs: 6FBB1786
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Text$DrawWindow$Long$ColorFocusItemMessagePropRectRemoveSend
                                      • String ID: NSIS: nsControl pointer property
                                      • API String ID: 2008169532-1714965683
                                      • Opcode ID: c60c562d0abc0e45c7f19c10c695b3c305fd87a633d62118dda51ccba10b5a06
                                      • Instruction ID: f29b78390fbc680f0d3a81ed093652ae7ba5e1abc0f6a8ee41ec63f5ce2a4f9f
                                      • Opcode Fuzzy Hash: c60c562d0abc0e45c7f19c10c695b3c305fd87a633d62118dda51ccba10b5a06
                                      • Instruction Fuzzy Hash: 5381CFB18042859FDF11CF15EC84BBA7BE9FF06310F48856AE8119B1A2CF71E991CB91
                                      APIs
                                      • GetWindowLongW.USER32(?,000000EB), ref: 00404648
                                      • GetSysColor.USER32(00000000), ref: 00404686
                                      • SetTextColor.GDI32(?,00000000), ref: 00404692
                                      • SetBkMode.GDI32(?,?), ref: 0040469E
                                      • GetSysColor.USER32(?), ref: 004046B1
                                      • SetBkColor.GDI32(?,?), ref: 004046C1
                                      • DeleteObject.GDI32(?), ref: 004046DB
                                      • CreateBrushIndirect.GDI32(?), ref: 004046E5
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Color$BrushCreateDeleteIndirectLongModeObjectTextWindow
                                      • String ID:
                                      • API String ID: 2320649405-0
                                      • Opcode ID: f4fe220c79686689299554ac50abea47664d32920eac269e7a43003585d3568b
                                      • Instruction ID: e78b8cc9c8042372c9a7340b9b8aa9b23ded286a9f8ddc7240a2e2d8bd1f46c0
                                      • Opcode Fuzzy Hash: f4fe220c79686689299554ac50abea47664d32920eac269e7a43003585d3568b
                                      • Instruction Fuzzy Hash: DE2197715007049FC7309F28D908B5BBBF8AF42714F008D2EE992A22E1D739D944DB58
                                      APIs
                                      • ReadFile.KERNEL32(?,?,?,?), ref: 00402758
                                      • MultiByteToWideChar.KERNEL32(?,00000008,?,?,?,00000001), ref: 00402793
                                      • SetFilePointer.KERNEL32(?,?,?,00000001,?,00000008,?,?,?,00000001), ref: 004027B6
                                      • MultiByteToWideChar.KERNEL32(?,00000008,?,00000000,?,00000001,?,00000001,?,00000008,?,?,?,00000001), ref: 004027CC
                                        • Part of subcall function 00406239: SetFilePointer.KERNEL32(?,00000000,00000000,00000001), ref: 0040624F
                                      • SetFilePointer.KERNEL32(?,?,?,00000001,?,?,00000002), ref: 00402878
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: File$Pointer$ByteCharMultiWide$Read
                                      • String ID: 9
                                      • API String ID: 163830602-2366072709
                                      • Opcode ID: c494a9c5f1831dca55446a6dfc25bb45b63b896379fbbdb0ec38153142a3ac1c
                                      • Instruction ID: 581cf2785626502de532f206a1de9da9d9b8d20bcd24121b7f7bd1133decb9a2
                                      • Opcode Fuzzy Hash: c494a9c5f1831dca55446a6dfc25bb45b63b896379fbbdb0ec38153142a3ac1c
                                      • Instruction Fuzzy Hash: CE51FB75D00219AADF20EF95CA88AAEBB75FF04304F50417BE541B62D4D7B49D82CB58
                                      APIs
                                      • CharNextW.USER32(?,*?|<>/":,00000000,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406952
                                      • CharNextW.USER32(?,?,?,00000000,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406961
                                      • CharNextW.USER32(?,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406966
                                      • CharPrevW.USER32(?,?,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406979
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Char$Next$Prev
                                      • String ID: *?|<>/":$C:\Users\user\AppData\Local\Temp\
                                      • API String ID: 589700163-4010320282
                                      • Opcode ID: 4a25a2118415850d7bb15acf585ec7f7b5de772317bec8c7d00468289de3f440
                                      • Instruction ID: d28fb8c2eefe6f61a155ceb01790bbf8b21f4710aa7989e54d8eeb8481a577c9
                                      • Opcode Fuzzy Hash: 4a25a2118415850d7bb15acf585ec7f7b5de772317bec8c7d00468289de3f440
                                      • Instruction Fuzzy Hash: 2611089580061295DB303B18CC40BB762F8AF99B50F12403FE98A776C1E77C4C9286BD
                                      APIs
                                        • Part of subcall function 6FBB1E4E: lstrcpynW.KERNEL32(6FBB1054,?,?,?,6FBB1054,?), ref: 6FBB1E7B
                                        • Part of subcall function 6FBB1E4E: GlobalFree.KERNEL32 ref: 6FBB1E8B
                                      • SHBrowseForFolderW.SHELL32(?), ref: 6FBB10A8
                                      • SHGetPathFromIDListW.SHELL32(00000000,?), ref: 6FBB10C8
                                      • CoTaskMemFree.OLE32(00000000,error), ref: 6FBB10E6
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Free$BrowseFolderFromGlobalListPathTasklstrcpyn
                                      • String ID: 0vu$E$error
                                      • API String ID: 1728609016-1006580955
                                      • Opcode ID: ac8e674bd759533a1a93888de6fe2371e7dc5a221dc48512ed007edc8c9a1f08
                                      • Instruction ID: 6ca8d3d9fb0ac5aef77c673fe622d411c9aa6600b54d2660ad3c410f46d02c67
                                      • Opcode Fuzzy Hash: ac8e674bd759533a1a93888de6fe2371e7dc5a221dc48512ed007edc8c9a1f08
                                      • Instruction Fuzzy Hash: 06213A76900258ABCB00DFA1E954BEE77B8EF09354F44416AD504E7240EF34EB448F91
                                      APIs
                                      • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00404F9A
                                      • GetMessagePos.USER32 ref: 00404FA2
                                      • ScreenToClient.USER32(?,?), ref: 00404FBC
                                      • SendMessageW.USER32(?,00001111,00000000,?), ref: 00404FCE
                                      • SendMessageW.USER32(?,0000113E,00000000,?), ref: 00404FF4
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Message$Send$ClientScreen
                                      • String ID: f
                                      • API String ID: 41195575-1993550816
                                      • Opcode ID: b2affdf3b53bee8738e3b61904ea6c87bda347b462d3853a737802ef9deed65a
                                      • Instruction ID: ce4c7d6d39dceca23aa6ebdb29af7737867007859e7bede0b388bd4d525dd41f
                                      • Opcode Fuzzy Hash: b2affdf3b53bee8738e3b61904ea6c87bda347b462d3853a737802ef9deed65a
                                      • Instruction Fuzzy Hash: 3C014C71940219BADB00DBA4DD85BFEBBB8AF54711F10012BBB50B61C0D6B49A058BA5
                                      APIs
                                      • GetDC.USER32(?), ref: 00401E51
                                      • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00401E6B
                                      • MulDiv.KERNEL32(00000000,00000000), ref: 00401E73
                                      • ReleaseDC.USER32(?,00000000), ref: 00401E84
                                        • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                        • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                      • CreateFontIndirectW.GDI32(0040CDF8), ref: 00401ED3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CapsCreateDeviceFontIndirectReleaselstrcatlstrlen
                                      • String ID: MS Shell Dlg
                                      • API String ID: 2584051700-76309092
                                      • Opcode ID: e128970cf71a0b284ce18b21917758e509e5717976d06807f88455f58f814df6
                                      • Instruction ID: b9cc094806d22c325402cb6ccb5f5134c2025175c414775df3ff87de861ccae2
                                      • Opcode Fuzzy Hash: e128970cf71a0b284ce18b21917758e509e5717976d06807f88455f58f814df6
                                      • Instruction Fuzzy Hash: 8401B571900241EFEB005BB4EE89A9A3FB0AB15301F208939F541B71D2C6B904459BED
                                      APIs
                                      • SetTimer.USER32(?,00000001,000000FA,00000000), ref: 00402FB1
                                      • wsprintfW.USER32 ref: 00402FE5
                                      • SetWindowTextW.USER32(?,?), ref: 00402FF5
                                      • SetDlgItemTextW.USER32(?,00000406,?), ref: 00403007
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Text$ItemTimerWindowwsprintf
                                      • String ID: unpacking data: %d%%$verifying installer: %d%%
                                      • API String ID: 1451636040-1158693248
                                      • Opcode ID: b65fa6b26e28fa793ab4966251e07a6fe500b79f9b1e2f9c66e5bc42e84335f7
                                      • Instruction ID: 34ad84b97f90b05cf42cbebec4ee1aaae98efe268bf46a139428006d78f28757
                                      • Opcode Fuzzy Hash: b65fa6b26e28fa793ab4966251e07a6fe500b79f9b1e2f9c66e5bc42e84335f7
                                      • Instruction Fuzzy Hash: 25F0497050020DABEF246F60DD49BEA3B69FB00309F00803AFA05B51D0DFBD9A559F59
                                      APIs
                                      • RegEnumValueW.ADVAPI32(?,00000000,?,?,00000000,00000000,00000000,00000000,?,?,00100020,?,?,?), ref: 00402EFD
                                      • RegEnumKeyW.ADVAPI32(?,00000000,?,00000105), ref: 00402F49
                                      • RegCloseKey.ADVAPI32(?,?,?), ref: 00402F52
                                      • RegDeleteKeyW.ADVAPI32(?,?), ref: 00402F69
                                      • RegCloseKey.ADVAPI32(?,?,?), ref: 00402F74
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CloseEnum$DeleteValue
                                      • String ID:
                                      • API String ID: 1354259210-0
                                      • Opcode ID: 2f5760c81b9bdb573da93a40119b3bcbbfe2770e9a6cbc48a05e82d61b54c679
                                      • Instruction ID: 37c7ba0f9c491dd7f389852fcb35a119484072d927876f68e32cbd91f0a54eef
                                      • Opcode Fuzzy Hash: 2f5760c81b9bdb573da93a40119b3bcbbfe2770e9a6cbc48a05e82d61b54c679
                                      • Instruction Fuzzy Hash: 6D216B7150010ABBDF11AF94CE89EEF7B7DEB50384F110076F909B21E0D7B49E54AA68
                                      APIs
                                      • GetDlgItem.USER32(?,?), ref: 00401D9A
                                      • GetClientRect.USER32(?,?), ref: 00401DE5
                                      • LoadImageW.USER32(?,?,?,?,?,?), ref: 00401E15
                                      • SendMessageW.USER32(?,00000172,?,00000000), ref: 00401E29
                                      • DeleteObject.GDI32(00000000), ref: 00401E39
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: ClientDeleteImageItemLoadMessageObjectRectSend
                                      • String ID:
                                      • API String ID: 1849352358-0
                                      • Opcode ID: 100b3177012869429c2005611ce111630833f28d1ab152a2d5a2575cfc39775b
                                      • Instruction ID: 4d725fdcf847a80329c23b38d7164c003567f542edd6fcacfb34c9ebeef40da9
                                      • Opcode Fuzzy Hash: 100b3177012869429c2005611ce111630833f28d1ab152a2d5a2575cfc39775b
                                      • Instruction Fuzzy Hash: 67212672904119AFCB05CBA4DE45AEEBBB5EF08304F14003AF945F62A0CB389951DB98
                                      APIs
                                        • Part of subcall function 6FBB13D2: GetPropW.USER32(?,NSIS: nsControl pointer property), ref: 6FBB13DB
                                      • LoadCursorW.USER32(00000000,00007F89), ref: 6FBB14A8
                                      • SetCursor.USER32(00000000,?,?,?), ref: 6FBB14AF
                                      • CallWindowProcW.USER32(?,?,00000020,?,?), ref: 6FBB14CC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Cursor$CallLoadProcPropWindow
                                      • String ID:
                                      • API String ID: 1635134901-3916222277
                                      • Opcode ID: ce440a0355c4d83aa9a5ac7219c9cc262dbd759d9e91294ee24d1c1c398f9f52
                                      • Instruction ID: 4ba2c1ed25d738d0a843dc75a7d179ae94d9148815bd15170e4a1c6332fb8563
                                      • Opcode Fuzzy Hash: ce440a0355c4d83aa9a5ac7219c9cc262dbd759d9e91294ee24d1c1c398f9f52
                                      • Instruction Fuzzy Hash: F2E06D32044249FBDF015FA2DC05EAA3B69EF09321F48C024FA0989060CF71D431DF61
                                      APIs
                                      • lstrlenW.KERNEL32(?,C:\Users\user\AppData\Local\Temp\,0040362D,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405F3D
                                      • CharPrevW.USER32(?,00000000,?,C:\Users\user\AppData\Local\Temp\,0040362D,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405F47
                                      • lstrcatW.KERNEL32(?,0040A014), ref: 00405F59
                                      Strings
                                      • C:\Users\user\AppData\Local\Temp\, xrefs: 00405F37
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CharPrevlstrcatlstrlen
                                      • String ID: C:\Users\user\AppData\Local\Temp\
                                      • API String ID: 2659869361-3081826266
                                      • Opcode ID: 7317fb0b60a0da6156192e69c80d181f5022b3d5f83b8f009beaa75eacd33bdb
                                      • Instruction ID: 9007417a49851ea4d61da9c71e51c63d156abd36d345156a737e00ee84923012
                                      • Opcode Fuzzy Hash: 7317fb0b60a0da6156192e69c80d181f5022b3d5f83b8f009beaa75eacd33bdb
                                      • Instruction Fuzzy Hash: 59D05E611019246AC111AB548D04DDB63ACAE85304742046AF601B60A0CB7E196287ED
                                      APIs
                                      • lstrlenA.KERNEL32(C:\Program Files\Gwyddion\uninstall.exe), ref: 00402695
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: lstrlen
                                      • String ID: C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1"$C:\Program Files\Gwyddion\uninstall.exe
                                      • API String ID: 1659193697-875172512
                                      • Opcode ID: 3cd7dd4fa08ce330ceb9fc547222c09b9309161f54410083866a53871864bccb
                                      • Instruction ID: f1e3379d491753f9d96dc3c217618d2e64da59e9cc8309568291ba5d2d488428
                                      • Opcode Fuzzy Hash: 3cd7dd4fa08ce330ceb9fc547222c09b9309161f54410083866a53871864bccb
                                      • Instruction Fuzzy Hash: D511C472A00205EBCB10BBB18E4AA9E76619F44758F21483FE402B61C1DAFD8891965F
                                      APIs
                                      • lstrlenW.KERNEL32(74DEF380,?,00000400,00000400,?,74DEF380,00000000), ref: 6FBB133E
                                      • CharPrevW.USER32(74DEF380,00000000,?,74DEF380,00000000), ref: 6FBB1349
                                      • MulDiv.KERNEL32(?,00000000,00000064), ref: 6FBB136D
                                      • MapDialogRect.USER32(74DEF380,74DEF380), ref: 6FBB1393
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2949276677.000000006FBB1000.00000020.00000001.01000000.00000006.sdmp, Offset: 6FBB0000, based on PE: true
                                      • Associated: 00000000.00000002.2949251951.000000006FBB0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949300698.000000006FBB3000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949328606.000000006FBB4000.00000008.00000001.01000000.00000006.sdmpDownload File
                                      • Associated: 00000000.00000002.2949357339.000000006FBB8000.00000002.00000001.01000000.00000006.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6fbb0000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CharDialogPrevRectlstrlen
                                      • String ID:
                                      • API String ID: 3411278111-0
                                      • Opcode ID: d786b7014db6fddc5543996b124246b28e030e209ef17f726a364f84e3755a46
                                      • Instruction ID: dcef5202ca1751f4318c9ca7e5d21e3de3c183274fdfe4aea549b5a5747118fa
                                      • Opcode Fuzzy Hash: d786b7014db6fddc5543996b124246b28e030e209ef17f726a364f84e3755a46
                                      • Instruction Fuzzy Hash: 0D11B235D00A65FB8B10CF59D904AEEBBB9EF46710B08851AF814A7600FF719A11CB90
                                      APIs
                                      • CloseHandle.KERNEL32(000002DC,C:\Users\user\AppData\Local\Temp\,00403B71,?), ref: 00403C37
                                      • CloseHandle.KERNEL32(000002F8,C:\Users\user\AppData\Local\Temp\,00403B71,?), ref: 00403C4B
                                      Strings
                                      • C:\Users\user\AppData\Local\Temp\, xrefs: 00403C2A
                                      • C:\Users\user\AppData\Local\Temp\nspC29F.tmp, xrefs: 00403C5B
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CloseHandle
                                      • String ID: C:\Users\user\AppData\Local\Temp\$C:\Users\user\AppData\Local\Temp\nspC29F.tmp
                                      • API String ID: 2962429428-4246053413
                                      • Opcode ID: 3450910aa3eb4a83e9339ad550daa728f038e8843dee50fd20da138f79135bda
                                      • Instruction ID: ab9e488bef71b432d29da19662b82269d7b8f1628316f3e3d8f7e3aa77a32ace
                                      • Opcode Fuzzy Hash: 3450910aa3eb4a83e9339ad550daa728f038e8843dee50fd20da138f79135bda
                                      • Instruction Fuzzy Hash: 3BE0863244471496E5246F7DAF4D9853B285F413357248726F178F60F0C7389A9B4A9D
                                      APIs
                                      • IsWindowVisible.USER32(?), ref: 0040566D
                                      • CallWindowProcW.USER32(?,?,?,?), ref: 004056BE
                                        • Part of subcall function 00404610: SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: Window$CallMessageProcSendVisible
                                      • String ID:
                                      • API String ID: 3748168415-3916222277
                                      • Opcode ID: a73dc4e993bde12ea44745026bd4b5676165c6f206d332bc9731ab0fc1b08652
                                      • Instruction ID: 537e1cae7e4c88fb21f4f8cfd237bdd46b0b38e99f2a5e053ca6ba0093d9a5c8
                                      • Opcode Fuzzy Hash: a73dc4e993bde12ea44745026bd4b5676165c6f206d332bc9731ab0fc1b08652
                                      • Instruction Fuzzy Hash: 4401B171200608AFEF205F11DD84A6B3A35EB84361F904837FA08752E0D77F8D929E6D
                                      APIs
                                      • lstrlenW.KERNEL32(80000000,C:\Users\user\Desktop,0040313C,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,80000000,00000003), ref: 00405F89
                                      • CharPrevW.USER32(80000000,00000000,80000000,C:\Users\user\Desktop,0040313C,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,C:\Users\user\Desktop\Gwyddion-2.67.win64.exe,80000000,00000003), ref: 00405F99
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: CharPrevlstrlen
                                      • String ID: C:\Users\user\Desktop
                                      • API String ID: 2709904686-224404859
                                      • Opcode ID: 176def5b2db9ef34a9f22db2929791273b03e08e07d7b66f37effa829582f156
                                      • Instruction ID: bd974b3f77e4b05eb9372a1ad14375fba7b947cfa10dd8d614d5bb7090e452f7
                                      • Opcode Fuzzy Hash: 176def5b2db9ef34a9f22db2929791273b03e08e07d7b66f37effa829582f156
                                      • Instruction Fuzzy Hash: 6CD05EB2401D219EC3126B04DC00D9F63ACEF51301B4A4866E441AB1A0DB7C5D9186A9
                                      APIs
                                      • lstrlenA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060CD
                                      • lstrcmpiA.KERNEL32(00000000,00000000), ref: 004060E5
                                      • CharNextA.USER32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060F6
                                      • lstrlenA.KERNEL32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060FF
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2947367328.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                      • Associated: 00000000.00000002.2947345984.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947529471.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947599879.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2947737443.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                      Similarity
                                      • API ID: lstrlen$CharNextlstrcmpi
                                      • String ID:
                                      • API String ID: 190613189-0
                                      • Opcode ID: 4f145c51a58837bd7eda372618efc6ab74ada67201017ca859b4805a40dfc06b
                                      • Instruction ID: 2f06b96f93541eceebcae48a9adfe7aedd37cb678349478f8cad11de2473fd3e
                                      • Opcode Fuzzy Hash: 4f145c51a58837bd7eda372618efc6ab74ada67201017ca859b4805a40dfc06b
                                      • Instruction Fuzzy Hash: 0BF0F631104054FFDB12DFA4CD00D9EBBA8EF06350B2640BAE841FB321D674DE11A798