Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Gwyddion-2.65.win64.exe

Overview

General Information

Sample name:Gwyddion-2.65.win64.exe
Analysis ID:1431474
MD5:e8bf214322468427498ea461d2eb6877
SHA1:60b37ab0f9c02feff7675482bdf776e30e9bdc60
SHA256:7e7db531308ab8ff8574796279b086bdf3e36a62f32702b7c04ea878bb8135c4
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Contains functionality for read data from the clipboard
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
  • System is w10x64
  • Gwyddion-2.65.win64.exe (PID: 7296 cmdline: "C:\Users\user\Desktop\Gwyddion-2.65.win64.exe" MD5: E8BF214322468427498EA461D2EB6877)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: Gwyddion-2.65.win64.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeWindow detected: I &AgreeCancelNullsoft Install System v3.08 Nullsoft Install System v3.08License AgreementPlease review the license terms before installing Gwyddion.Press Page Down to see the rest of the agreement.Gwyddion is Free Software published under the GNU General Public License version 2 (or later) that can be found as COPYING-GPLv2.txt in the installation directory.This package contains also other components covered by various Free Software licenses: ATK Cairo dlfcn-win32 gettext GLib GTK+ GtkGLExt iconv Pango pthreads-win32 pygtk2 and pygobject2 (COPYING-LGPLv2.txt) D-BUS FFTW and freetype (COPYING-GPLv2.txt) gtksourceview (COPYING-LGPLv2.txt and COPYING-GPLv2.txt) pycairo (COPYING-LGPLv2.txt and COPYING-MPL-1.1.txt) expat (COPYING-expat.txt) fontconfig (COPYING-fontconfig.txt) jansson (LICENSE-jansson.txt) JasPer (LICENSE-JasPer.txt) harfbuzz (COPYING-harfbuzz.txt) HDF5 (LICENSE-HDF5.txt) libaec (Copyright-libaec.txt) libffi (LICENSE-libffi.txt) libjpeg (COPYING-libjpeg.txt) libpng (COPYING-libpng.txt) libtiff (Copyright-libtiff.txt) libwebp (COPYING-libwebp.txt) libxml2 (Copyright-libxml2.txt) OpenEXR (LICENSE-OpenEXR.txt) PCRE (LICENSE-pcre.txt) libzip (LICENSE-libzip.txt) zlib (COPYING-zlib.txt) and libbz2 (LICENSE-bzip2.txt). These components were repackaged unmodified from the Fedora MinGW32/MinGW64 cross-compilation environment.If you accept the terms of the agreement click I Agree to continue. You must accept the agreement to install Gwyddion.
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-expat.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-fontconfig.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-GPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-harfbuzz.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-LGPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libjpeg.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libwebp.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-MPL-1.1.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-zlib.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libaec.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libtiff.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libxml2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\binJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-list.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdbus.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gsettings.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\iconv.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libaec.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libdl.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjansson.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libsz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\zlib1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etcJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\gtk.immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\im-multipress.confJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\libJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders.cacheJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loadersJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\enginesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmapJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\fileJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graphJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layerJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\processJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\toolJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volumeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyzJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\shareJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterialsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Alien-AlloyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BrassJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Bright-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ChromeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Coolish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\EmeraldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\JadeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ObsidianJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PearlJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PewterJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\RubyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\SilverJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\TurquoiseJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Warmish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradientsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BodyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\CaribbeanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Code-VJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ColdJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DFitJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DigitalisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gray-invertedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-Stripes-4Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gwyddion.netJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\HalcyonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\LinesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MapleJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MetroProJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NT-MDTJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NeonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\OliveJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PainbowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PinkJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PlumJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Pm3dJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-Stripes-5Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RustJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Saw1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ShameJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SkyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Sm2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Spectral-whiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpringJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ViridisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WarmJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-monoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-spectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WykoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ZonesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmapsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_3d_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_arithmetic-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_binning-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_bold-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cantilever-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_adaptive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_auto-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_fixed-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_full-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correct_affine-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_length-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cross_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_curvature-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_data_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_deconvolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_disconnected-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_displacement_field-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance_transform-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_angle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_dwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_enforce_distribution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_entropy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extend-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extract_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_analysis-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_1d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_find_peaks-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fit_shape-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fix_zero-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_diagonally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_correction-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_frequency_split-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_bounding_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_correlation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_exscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_otsu-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_water-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_align-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_cut-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_dos-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_ascii-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_png-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_vector-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_fd-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_function-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_halfgauss-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_palette-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_pointer-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_ruler-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_period_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_fit-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_in-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_out-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hough-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_clear-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_replace-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_immerse-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_iso_roughness-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_image_relation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_italic-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_less-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_flatten_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_median-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_triangle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_light_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_limit_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_line_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_debug-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_info-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_warning-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_local_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_outliers-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_with-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_add-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_distribute-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_editor-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_extract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_grow-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_intersect-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_morph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_noisify-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_set-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shrink-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_subtract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_thin-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_measure_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_merge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_convert_to_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_current_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_find_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_parallel-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_perpendicular-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_more-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mutual_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_apply-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_train-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_next-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_null_offsets-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_path_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_perspective_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pointer_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_poly_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_previous-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile_multiple-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pygwy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rasterize-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_radial_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rank_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_remove_under_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_arc-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_sphere-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_180-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_3d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_ccw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_cw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scientific_number_format-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_selections-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_shader-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spectrum-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spot_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_square_samples-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stat_quantities-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stitch-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_straighten_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_subscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_superscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_anneal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_ballistic_deposition-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_brownian_motion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_columnar-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_diffusion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_discs-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_domains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_dunes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_fibres-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_line_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_objects-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_particles-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_phases-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pileup-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_plateaus-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_spectral-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_turing_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_waves-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tilt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_dilation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_erosion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_estimation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_indent_analyze-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_lateral_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_map-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_model-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_pid-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_unrotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_value_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume_arithmetic-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume_calibrate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume_dimensions-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: Gwyddion-2.65.win64.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405D74
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_0040699E FindFirstFileW,FindClose,0_2_0040699E
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_0040290B FindFirstFileW,0_2_0040290B
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmp, atk10.mo6.0.dr, atk10.mo8.0.drString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=atk&keywords=I18N
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18N
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&component=general
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&keywords=I18N
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmp, Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=gtksourceview&component=general
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://bugzilla.gnome.org/show_bug.cgi?id=%s
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://bugzilla.gnome.org/show_bug.cgi?id=%sg_type_is_a
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmp, def.lang.0.drString found in binary or memory: http://docs.python.org/lib/built-in-funcs.html)
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/lib/typesseq-strings.html
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/ref/strings.html
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://freedesktop.org
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://freedesktop.orgtypenameexeccounttimestamp
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://gwyddion.net/
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2898235375.00000000006D8000.00000004.00000020.00020000.00000000.sdmp, nsfDF4E.tmp.0.drString found in binary or memory: http://gwyddion.net/.gwyGwyddion.NativeDataGwyddion
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://gwyddion.net/Report
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://icon-theme.freedesktop.org/releases
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://library.gnome.org/devel/gtk-faq/stable/
Source: Gwyddion-2.65.win64.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://relaxng.org/ns/compatibility/annotations/1.0
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmp, language2.rng.0.drString found in binary or memory: http://relaxng.org/ns/structure/1.0
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.brynosaurus.com/cachedir/
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.cmi.cz/
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.cmi.cz/Credits%s
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/dbus/1.0/introspect.dtd
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarks
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/desktop-bookmarksgroupapplicationsgroupsprivateiconmime-typehtt
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.freedesktop.org/standards/shared-mime-info
Source: nsfDF4E.tmp.0.drString found in binary or memory: http://www.mozilla.org/MPL/
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.gnome.org/enter_bug.cgi?product=gdk-pixbuf&keywords=I18N
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18N
Source: nsfDF4E.tmp.0.drString found in binary or memory: https://cairographics.org)
Source: nsfDF4E.tmp.0.drString found in binary or memory: https://cairographics.org))
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/iobataya/gwyddion-ja-translation
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gitlab.gnome.org/GNOME/gdk-pixbuf/issues
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gnu.org/licenses/gpl.html
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://translationproject.org/team/pt_BR.html
Source: nsfDF4E.tmp.0.drString found in binary or memory: https://www.gnu.org/licenses/
Source: nsfDF4E.tmp.0.drString found in binary or memory: https://www.gnu.org/licenses/gpl-2.0.html
Source: nsfDF4E.tmp.0.drString found in binary or memory: https://www.gnu.org/licenses/gpl-2.0.htmlLicenseGtkGLExt
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/peps/pep-0263.html
Source: Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/peps/pep-0263.html.
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00405809 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,FindCloseChangeNotification,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_00405809
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,0_2_00403640
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00406D5F0_2_00406D5F
Source: libasprintf-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libtiff-5.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: zonfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpixmap.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgthread-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: process.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libhdf5_hl-100.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: spmxfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libffi-6.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libjpeg-62.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: sensofarx.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: xyz.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: npyfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgobject-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libwinpthread-1.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgwyprocess2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-thai.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpixbufloader-xpm.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgwyddion2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgwydgets2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgwydraw2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libintl-8.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: apedaxfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: nanoscantech.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpixbufloader-jasper.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libstdc++-6.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpangoft2-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: nanoobserver.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libjansson.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libatk-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libpixbufloader-xbm.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: im-ti-et.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: matfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libdl.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: opengps.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: rhk-sm4.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: volume.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libcairo-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libwimp.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: jpkscan.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: createc.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgail.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgdkglext-win32-1.0-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgtkglext-win32-1.0-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libjasper-4.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpcre-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: pixmap.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libfreetype-6.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgwymodule2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-ti-er.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: graph.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libIex-2_5.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libfftw3-3.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: im-inuktitut.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: im-cyrillic-translit.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: cmap.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-cedilla.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libfontconfig-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: hdrimage.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libpng16-16.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gspawn-win64-helper.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: hdf5file.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: plugin-proxy.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: keyence.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libhdf5-103.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libsz.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libssp-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgmodule-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gdbus.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: libpixman-1-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libcairo-script-interpreter-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libexpat-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: imgexport.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-multipress.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: iconv.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: tools.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-ime.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgcc_s_seh-1.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libbz2-1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gwyddion.exe.0.drStatic PE information: Number of sections : 17 > 10
Source: libpixbufloader-tga.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpango-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgtk-win32-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: psppt.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libglib-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libImath-2_5.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: Number of sections : 17 > 10
Source: im-ipa.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgtksourceview-2.0-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: gdk-pixbuf-query-loaders.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: layer.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgwyapp2-0.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgomp-1.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libaec.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libharfbuzz-0.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libgailutil-18.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: nrrdfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgio-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: anasys_xml.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libxml2-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: file.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: libgdk_pixbuf-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libgdk-win32-2.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gsettings.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: libpixbufloader-qtif.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libcairo-gobject-2.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: oirfile.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-am-et.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libwebp-7.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpangowin32-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: gspawn-win64-helper-console.exe.0.drStatic PE information: Number of sections : 11 > 10
Source: spml.dll.0.drStatic PE information: Number of sections : 19 > 10
Source: im-viqr.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpixbufloader-pnm.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: libpangocairo-1.0-0.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: Gwyddion-2.65.win64.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engineClassification label: clean3.winEXE@1/615@0/0
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,0_2_00403640
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00404AB5 GetDlgItem,SetWindowTextW,SHAutoComplete,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceExW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_00404AB5
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_004021AA CoCreateInstance,0_2_004021AA
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Users\user\AppData\Local\Temp\nspDEEF.tmpJump to behavior
Source: Gwyddion-2.65.win64.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile read: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeAutomated click: I Agree
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeAutomated click: Next >
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeAutomated click: Install
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeWindow detected: I &AgreeCancelNullsoft Install System v3.08 Nullsoft Install System v3.08License AgreementPlease review the license terms before installing Gwyddion.Press Page Down to see the rest of the agreement.Gwyddion is Free Software published under the GNU General Public License version 2 (or later) that can be found as COPYING-GPLv2.txt in the installation directory.This package contains also other components covered by various Free Software licenses: ATK Cairo dlfcn-win32 gettext GLib GTK+ GtkGLExt iconv Pango pthreads-win32 pygtk2 and pygobject2 (COPYING-LGPLv2.txt) D-BUS FFTW and freetype (COPYING-GPLv2.txt) gtksourceview (COPYING-LGPLv2.txt and COPYING-GPLv2.txt) pycairo (COPYING-LGPLv2.txt and COPYING-MPL-1.1.txt) expat (COPYING-expat.txt) fontconfig (COPYING-fontconfig.txt) jansson (LICENSE-jansson.txt) JasPer (LICENSE-JasPer.txt) harfbuzz (COPYING-harfbuzz.txt) HDF5 (LICENSE-HDF5.txt) libaec (Copyright-libaec.txt) libffi (LICENSE-libffi.txt) libjpeg (COPYING-libjpeg.txt) libpng (COPYING-libpng.txt) libtiff (Copyright-libtiff.txt) libwebp (COPYING-libwebp.txt) libxml2 (Copyright-libxml2.txt) OpenEXR (LICENSE-OpenEXR.txt) PCRE (LICENSE-pcre.txt) libzip (LICENSE-libzip.txt) zlib (COPYING-zlib.txt) and libbz2 (LICENSE-bzip2.txt). These components were repackaged unmodified from the Fedora MinGW32/MinGW64 cross-compilation environment.If you accept the terms of the agreement click I Agree to continue. You must accept the agreement to install Gwyddion.
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeWindow detected: Number of UI elements: 14
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\GwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-expat.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-fontconfig.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-GPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-harfbuzz.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-LGPLv2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libjpeg.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-libwebp.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-MPL-1.1.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\COPYING-zlib.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libaec.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libtiff.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\Copyright-libxml2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\binJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\fc-list.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdbus.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gsettings.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\iconv.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libaec.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libdl.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjansson.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libsz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\zlib1.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etcJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\gtk.immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\etc\gtk-2.0\im-multipress.confJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\libJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders.cacheJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loadersJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\enginesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modulesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmapJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\fileJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graphJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layerJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\processJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\toolJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volumeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyzJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\shareJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddionJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterialsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Alien-AlloyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Black-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BrassJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Bright-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ChromeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Coolish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Cyan-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\EmeraldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Green-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\JadeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\ObsidianJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PearlJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\PewterJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-BronzeJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-CopperJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Polished-GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Red-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\RubyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\SilverJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\TurquoiseJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Warmish-WhiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\White-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-PlasticJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\glmaterials\Yellow-RubberJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradientsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BW2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blend2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Blue-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\BodyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\CaribbeanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Code-VJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ColdJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DFitJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\DigitalisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GoldJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gray-invertedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-Stripes-4Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Green-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Gwyddion.netJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\HalcyonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\LinesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MapleJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\MetroProJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NT-MDTJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\NeonJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\OliveJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PainbowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PinkJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\PlumJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Pm3dJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Rainbow2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-CyanJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-Stripes-5Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-VioletJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Red-YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-RedJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-GreenJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RGB-BlueJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\RustJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Saw1Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ShameJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SkyJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Sm2Jump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Spectral-whiteJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\SpringJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ViridisJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WarmJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-monoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\Warpp-spectralJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\WykoJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\YellowJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\gradients\ZonesJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmapsJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_3d_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_arithmetic-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_binning-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_bold-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cantilever-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_adaptive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_auto-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_fixed-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_color_range_full-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_convolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correct_affine-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_correlation_length-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cross_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_curvature-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_cwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_data_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_deconvolve-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_disconnected-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_displacement_field-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distance_transform-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_angle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_distribution_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_dwt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_enforce_distribution-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_entropy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extend-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_extract_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_analysis-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_facet_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_1d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fft_filter_2d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_find_peaks-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fit_shape-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fix_zero-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_diagonally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_flip_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_fractal_correction-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_frequency_split-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_gradient_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_bounding_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_correlation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_exscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_box-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grain_inscribed_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_edge_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_otsu-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_grains_water-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_align-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_cut-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_dos-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_ascii-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_png-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_export_vector-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_fd-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_function-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_halfgauss-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_palette-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_pointer-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_ruler-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_statistics-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_period_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_fit-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_in-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_graph_zoom_out-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hough-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_clear-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_hold_selection_replace-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_immerse-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_iso_roughness-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_image_relation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_italic-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_less-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_flatten_base-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_median-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_level_triangle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_light_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_limit_range-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_line_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_debug-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_info-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_load_warning-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_local_slope-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_horizontal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_logscale_vertical-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_outliers-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mark_with-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_add-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_circle_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_distribute-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_editor-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_exclude_circle-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_extract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_fill_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_grow-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_intersect-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_morph-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_noisify-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_draw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_paint_erase-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_exclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_rect_inclusive-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_set-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_shrink-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_subtract-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mask_thin-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_measure_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_merge-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_convert_to_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_current_line-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_find_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_field_shift-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_parallel-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mfm_perpendicular-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_more-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_mutual_crop-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_apply-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_neural_train-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_next-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_null_offsets-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-16.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_palettes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_path_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_perspective_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pointer_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_poly_distort-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_polynom_level-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_previous-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_profile_multiple-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_pygwy-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rasterize-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_radial_profile-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rank_filter-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_remove_under_mask-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_arc-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_revolve_sphere-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_180-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_3d-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_ccw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_rotate_90_cw-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_horizontally-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scale_vertically-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scars-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_scientific_number_format-18.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_selections-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_shader-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spectrum-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_spot_remove-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_square_samples-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stat_quantities-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_stitch-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_straighten_path-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_subscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_superscript-20.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_anneal-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_ballistic_deposition-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_brownian_motion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_columnar-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_diffusion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_discs-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_domains-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_dunes-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_fibres-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_lattice-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_line_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_noise-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_objects-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_particles-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_phases-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_pileup-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_plateaus-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_spectral-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_turing_pattern-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_synthetic_waves-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_terrace_measure-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tilt-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_dilation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_erosion-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_estimation-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_indent_analyze-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_lateral_force-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_map-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_model-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_tip_pid-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_unrotate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_value_invert-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume_arithmetic-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume_calibrate-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDirectory created: C:\Program Files\Gwyddion\share\gwyddion\pixmaps\gwy_volume_dimensions-24.pngJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GwyddionJump to behavior
Source: Gwyddion-2.65.win64.exeStatic file information: File size 25494309 > 1048576
Source: Gwyddion-2.65.win64.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: libjpeg-62.dll.0.drStatic PE information: real checksum: 0xeda30b00 should be: 0xba3ed
Source: libjasper-4.dll.0.drStatic PE information: real checksum: 0xcf720500 should be: 0x572cf
Source: uninstall.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x124bd
Source: nsDialogs.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x2f9b
Source: libpixbufloader-jasper.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-jasper.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-pnm.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-pnm.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-qtif.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-qtif.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-tga.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-tga.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-xbm.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-xbm.dll.0.drStatic PE information: section name: /4
Source: libpixbufloader-xpm.dll.0.drStatic PE information: section name: .xdata
Source: libpixbufloader-xpm.dll.0.drStatic PE information: section name: /4
Source: libpixmap.dll.0.drStatic PE information: section name: .xdata
Source: libpixmap.dll.0.drStatic PE information: section name: /4
Source: libwimp.dll.0.drStatic PE information: section name: .xdata
Source: libwimp.dll.0.drStatic PE information: section name: /4
Source: im-am-et.dll.0.drStatic PE information: section name: .xdata
Source: im-am-et.dll.0.drStatic PE information: section name: /4
Source: im-cedilla.dll.0.drStatic PE information: section name: .xdata
Source: im-cedilla.dll.0.drStatic PE information: section name: /4
Source: im-cyrillic-translit.dll.0.drStatic PE information: section name: .xdata
Source: im-cyrillic-translit.dll.0.drStatic PE information: section name: /4
Source: im-ime.dll.0.drStatic PE information: section name: .xdata
Source: im-ime.dll.0.drStatic PE information: section name: /4
Source: im-inuktitut.dll.0.drStatic PE information: section name: .xdata
Source: im-inuktitut.dll.0.drStatic PE information: section name: /4
Source: im-ipa.dll.0.drStatic PE information: section name: .xdata
Source: im-ipa.dll.0.drStatic PE information: section name: /4
Source: im-multipress.dll.0.drStatic PE information: section name: .xdata
Source: im-multipress.dll.0.drStatic PE information: section name: /4
Source: im-thai.dll.0.drStatic PE information: section name: .xdata
Source: im-thai.dll.0.drStatic PE information: section name: /4
Source: im-ti-er.dll.0.drStatic PE information: section name: .xdata
Source: im-ti-er.dll.0.drStatic PE information: section name: /4
Source: im-ti-et.dll.0.drStatic PE information: section name: .xdata
Source: im-ti-et.dll.0.drStatic PE information: section name: /4
Source: im-viqr.dll.0.drStatic PE information: section name: .xdata
Source: im-viqr.dll.0.drStatic PE information: section name: /4
Source: libgail.dll.0.drStatic PE information: section name: .xdata
Source: libgail.dll.0.drStatic PE information: section name: /4
Source: plugin-proxy.dll.0.drStatic PE information: section name: .xdata
Source: plugin-proxy.dll.0.drStatic PE information: section name: /4
Source: plugin-proxy.dll.0.drStatic PE information: section name: /19
Source: plugin-proxy.dll.0.drStatic PE information: section name: /31
Source: plugin-proxy.dll.0.drStatic PE information: section name: /45
Source: plugin-proxy.dll.0.drStatic PE information: section name: /57
Source: plugin-proxy.dll.0.drStatic PE information: section name: /70
Source: plugin-proxy.dll.0.drStatic PE information: section name: /81
Source: plugin-proxy.dll.0.drStatic PE information: section name: /92
Source: cmap.dll.0.drStatic PE information: section name: .xdata
Source: cmap.dll.0.drStatic PE information: section name: /4
Source: cmap.dll.0.drStatic PE information: section name: /19
Source: cmap.dll.0.drStatic PE information: section name: /31
Source: cmap.dll.0.drStatic PE information: section name: /45
Source: cmap.dll.0.drStatic PE information: section name: /57
Source: cmap.dll.0.drStatic PE information: section name: /70
Source: cmap.dll.0.drStatic PE information: section name: /81
Source: cmap.dll.0.drStatic PE information: section name: /92
Source: file.dll.0.drStatic PE information: section name: .xdata
Source: file.dll.0.drStatic PE information: section name: /4
Source: file.dll.0.drStatic PE information: section name: /19
Source: file.dll.0.drStatic PE information: section name: /31
Source: file.dll.0.drStatic PE information: section name: /45
Source: file.dll.0.drStatic PE information: section name: /57
Source: file.dll.0.drStatic PE information: section name: /70
Source: file.dll.0.drStatic PE information: section name: /81
Source: file.dll.0.drStatic PE information: section name: /92
Source: createc.dll.0.drStatic PE information: section name: .xdata
Source: createc.dll.0.drStatic PE information: section name: /4
Source: createc.dll.0.drStatic PE information: section name: /19
Source: createc.dll.0.drStatic PE information: section name: /31
Source: createc.dll.0.drStatic PE information: section name: /45
Source: createc.dll.0.drStatic PE information: section name: /57
Source: createc.dll.0.drStatic PE information: section name: /70
Source: createc.dll.0.drStatic PE information: section name: /81
Source: createc.dll.0.drStatic PE information: section name: /92
Source: imgexport.dll.0.drStatic PE information: section name: .xdata
Source: imgexport.dll.0.drStatic PE information: section name: /4
Source: imgexport.dll.0.drStatic PE information: section name: /19
Source: imgexport.dll.0.drStatic PE information: section name: /31
Source: imgexport.dll.0.drStatic PE information: section name: /45
Source: imgexport.dll.0.drStatic PE information: section name: /57
Source: imgexport.dll.0.drStatic PE information: section name: /70
Source: imgexport.dll.0.drStatic PE information: section name: /81
Source: imgexport.dll.0.drStatic PE information: section name: /92
Source: jpkscan.dll.0.drStatic PE information: section name: .xdata
Source: jpkscan.dll.0.drStatic PE information: section name: /4
Source: jpkscan.dll.0.drStatic PE information: section name: /19
Source: jpkscan.dll.0.drStatic PE information: section name: /31
Source: jpkscan.dll.0.drStatic PE information: section name: /45
Source: jpkscan.dll.0.drStatic PE information: section name: /57
Source: jpkscan.dll.0.drStatic PE information: section name: /70
Source: jpkscan.dll.0.drStatic PE information: section name: /81
Source: jpkscan.dll.0.drStatic PE information: section name: /92
Source: keyence.dll.0.drStatic PE information: section name: .xdata
Source: keyence.dll.0.drStatic PE information: section name: /4
Source: keyence.dll.0.drStatic PE information: section name: /19
Source: keyence.dll.0.drStatic PE information: section name: /31
Source: keyence.dll.0.drStatic PE information: section name: /45
Source: keyence.dll.0.drStatic PE information: section name: /57
Source: keyence.dll.0.drStatic PE information: section name: /70
Source: keyence.dll.0.drStatic PE information: section name: /81
Source: keyence.dll.0.drStatic PE information: section name: /92
Source: npyfile.dll.0.drStatic PE information: section name: .xdata
Source: npyfile.dll.0.drStatic PE information: section name: /4
Source: npyfile.dll.0.drStatic PE information: section name: /19
Source: npyfile.dll.0.drStatic PE information: section name: /31
Source: npyfile.dll.0.drStatic PE information: section name: /45
Source: npyfile.dll.0.drStatic PE information: section name: /57
Source: npyfile.dll.0.drStatic PE information: section name: /70
Source: npyfile.dll.0.drStatic PE information: section name: /81
Source: npyfile.dll.0.drStatic PE information: section name: /92
Source: nrrdfile.dll.0.drStatic PE information: section name: .xdata
Source: nrrdfile.dll.0.drStatic PE information: section name: /4
Source: nrrdfile.dll.0.drStatic PE information: section name: /19
Source: nrrdfile.dll.0.drStatic PE information: section name: /31
Source: nrrdfile.dll.0.drStatic PE information: section name: /45
Source: nrrdfile.dll.0.drStatic PE information: section name: /57
Source: nrrdfile.dll.0.drStatic PE information: section name: /70
Source: nrrdfile.dll.0.drStatic PE information: section name: /81
Source: nrrdfile.dll.0.drStatic PE information: section name: /92
Source: fc-cache.exe.0.drStatic PE information: section name: .xdata
Source: fc-cache.exe.0.drStatic PE information: section name: /4
Source: fc-list.exe.0.drStatic PE information: section name: .xdata
Source: fc-list.exe.0.drStatic PE information: section name: /4
Source: gdbus.exe.0.drStatic PE information: section name: .xdata
Source: gdbus.exe.0.drStatic PE information: section name: /4
Source: gdk-pixbuf-query-loaders.exe.0.drStatic PE information: section name: .xdata
Source: gdk-pixbuf-query-loaders.exe.0.drStatic PE information: section name: /4
Source: gsettings.exe.0.drStatic PE information: section name: .xdata
Source: gsettings.exe.0.drStatic PE information: section name: /4
Source: gspawn-win64-helper-console.exe.0.drStatic PE information: section name: .xdata
Source: gspawn-win64-helper-console.exe.0.drStatic PE information: section name: /4
Source: gspawn-win64-helper.exe.0.drStatic PE information: section name: .xdata
Source: gspawn-win64-helper.exe.0.drStatic PE information: section name: /4
Source: gtk-query-immodules-2.0.exe.0.drStatic PE information: section name: .xdata
Source: gtk-query-immodules-2.0.exe.0.drStatic PE information: section name: /4
Source: gwyddion.exe.0.drStatic PE information: section name: .xdata
Source: gwyddion.exe.0.drStatic PE information: section name: /4
Source: gwyddion.exe.0.drStatic PE information: section name: /19
Source: gwyddion.exe.0.drStatic PE information: section name: /31
Source: gwyddion.exe.0.drStatic PE information: section name: /45
Source: gwyddion.exe.0.drStatic PE information: section name: /57
Source: gwyddion.exe.0.drStatic PE information: section name: /70
Source: gwyddion.exe.0.drStatic PE information: section name: /81
Source: gwyddion.exe.0.drStatic PE information: section name: /92
Source: oirfile.dll.0.drStatic PE information: section name: .xdata
Source: oirfile.dll.0.drStatic PE information: section name: /4
Source: oirfile.dll.0.drStatic PE information: section name: /19
Source: oirfile.dll.0.drStatic PE information: section name: /31
Source: oirfile.dll.0.drStatic PE information: section name: /45
Source: oirfile.dll.0.drStatic PE information: section name: /57
Source: oirfile.dll.0.drStatic PE information: section name: /70
Source: oirfile.dll.0.drStatic PE information: section name: /81
Source: oirfile.dll.0.drStatic PE information: section name: /92
Source: pixmap.dll.0.drStatic PE information: section name: .xdata
Source: pixmap.dll.0.drStatic PE information: section name: /4
Source: pixmap.dll.0.drStatic PE information: section name: /19
Source: pixmap.dll.0.drStatic PE information: section name: /31
Source: pixmap.dll.0.drStatic PE information: section name: /45
Source: pixmap.dll.0.drStatic PE information: section name: /57
Source: pixmap.dll.0.drStatic PE information: section name: /70
Source: pixmap.dll.0.drStatic PE information: section name: /81
Source: pixmap.dll.0.drStatic PE information: section name: /92
Source: rhk-sm4.dll.0.drStatic PE information: section name: .xdata
Source: rhk-sm4.dll.0.drStatic PE information: section name: /4
Source: rhk-sm4.dll.0.drStatic PE information: section name: /19
Source: rhk-sm4.dll.0.drStatic PE information: section name: /31
Source: rhk-sm4.dll.0.drStatic PE information: section name: /45
Source: rhk-sm4.dll.0.drStatic PE information: section name: /57
Source: rhk-sm4.dll.0.drStatic PE information: section name: /70
Source: rhk-sm4.dll.0.drStatic PE information: section name: /81
Source: rhk-sm4.dll.0.drStatic PE information: section name: /92
Source: anasys_xml.dll.0.drStatic PE information: section name: .xdata
Source: anasys_xml.dll.0.drStatic PE information: section name: /4
Source: anasys_xml.dll.0.drStatic PE information: section name: /19
Source: anasys_xml.dll.0.drStatic PE information: section name: /31
Source: anasys_xml.dll.0.drStatic PE information: section name: /45
Source: anasys_xml.dll.0.drStatic PE information: section name: /57
Source: anasys_xml.dll.0.drStatic PE information: section name: /70
Source: anasys_xml.dll.0.drStatic PE information: section name: /81
Source: anasys_xml.dll.0.drStatic PE information: section name: /92
Source: apedaxfile.dll.0.drStatic PE information: section name: .xdata
Source: apedaxfile.dll.0.drStatic PE information: section name: /4
Source: apedaxfile.dll.0.drStatic PE information: section name: /19
Source: apedaxfile.dll.0.drStatic PE information: section name: /31
Source: apedaxfile.dll.0.drStatic PE information: section name: /45
Source: apedaxfile.dll.0.drStatic PE information: section name: /57
Source: apedaxfile.dll.0.drStatic PE information: section name: /70
Source: apedaxfile.dll.0.drStatic PE information: section name: /81
Source: apedaxfile.dll.0.drStatic PE information: section name: /92
Source: hdf5file.dll.0.drStatic PE information: section name: .xdata
Source: hdf5file.dll.0.drStatic PE information: section name: /4
Source: hdf5file.dll.0.drStatic PE information: section name: /19
Source: hdf5file.dll.0.drStatic PE information: section name: /31
Source: hdf5file.dll.0.drStatic PE information: section name: /45
Source: hdf5file.dll.0.drStatic PE information: section name: /57
Source: hdf5file.dll.0.drStatic PE information: section name: /70
Source: hdf5file.dll.0.drStatic PE information: section name: /81
Source: hdf5file.dll.0.drStatic PE information: section name: /92
Source: hdrimage.dll.0.drStatic PE information: section name: .xdata
Source: hdrimage.dll.0.drStatic PE information: section name: /4
Source: hdrimage.dll.0.drStatic PE information: section name: /19
Source: hdrimage.dll.0.drStatic PE information: section name: /31
Source: hdrimage.dll.0.drStatic PE information: section name: /45
Source: hdrimage.dll.0.drStatic PE information: section name: /57
Source: hdrimage.dll.0.drStatic PE information: section name: /70
Source: hdrimage.dll.0.drStatic PE information: section name: /81
Source: hdrimage.dll.0.drStatic PE information: section name: /92
Source: matfile.dll.0.drStatic PE information: section name: .xdata
Source: matfile.dll.0.drStatic PE information: section name: /4
Source: matfile.dll.0.drStatic PE information: section name: /19
Source: matfile.dll.0.drStatic PE information: section name: /31
Source: matfile.dll.0.drStatic PE information: section name: /45
Source: matfile.dll.0.drStatic PE information: section name: /57
Source: matfile.dll.0.drStatic PE information: section name: /70
Source: matfile.dll.0.drStatic PE information: section name: /81
Source: matfile.dll.0.drStatic PE information: section name: /92
Source: nanoobserver.dll.0.drStatic PE information: section name: .xdata
Source: nanoobserver.dll.0.drStatic PE information: section name: /4
Source: nanoobserver.dll.0.drStatic PE information: section name: /19
Source: nanoobserver.dll.0.drStatic PE information: section name: /31
Source: nanoobserver.dll.0.drStatic PE information: section name: /45
Source: nanoobserver.dll.0.drStatic PE information: section name: /57
Source: nanoobserver.dll.0.drStatic PE information: section name: /70
Source: nanoobserver.dll.0.drStatic PE information: section name: /81
Source: nanoobserver.dll.0.drStatic PE information: section name: /92
Source: nanoscantech.dll.0.drStatic PE information: section name: .xdata
Source: nanoscantech.dll.0.drStatic PE information: section name: /4
Source: nanoscantech.dll.0.drStatic PE information: section name: /19
Source: nanoscantech.dll.0.drStatic PE information: section name: /31
Source: nanoscantech.dll.0.drStatic PE information: section name: /45
Source: nanoscantech.dll.0.drStatic PE information: section name: /57
Source: nanoscantech.dll.0.drStatic PE information: section name: /70
Source: nanoscantech.dll.0.drStatic PE information: section name: /81
Source: nanoscantech.dll.0.drStatic PE information: section name: /92
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: .xdata
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /4
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /19
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /31
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /45
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /57
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /70
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /81
Source: gwyddion-thumbnailer.exe.0.drStatic PE information: section name: /92
Source: iconv.dll.0.drStatic PE information: section name: .xdata
Source: iconv.dll.0.drStatic PE information: section name: /4
Source: libaec.dll.0.drStatic PE information: section name: .xdata
Source: libaec.dll.0.drStatic PE information: section name: /4
Source: libasprintf-0.dll.0.drStatic PE information: section name: .xdata
Source: libasprintf-0.dll.0.drStatic PE information: section name: /4
Source: libatk-1.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libatk-1.0-0.dll.0.drStatic PE information: section name: /4
Source: libbz2-1.dll.0.drStatic PE information: section name: .xdata
Source: libbz2-1.dll.0.drStatic PE information: section name: /4
Source: libdl.dll.0.drStatic PE information: section name: .xdata
Source: libdl.dll.0.drStatic PE information: section name: /4
Source: libcairo-2.dll.0.drStatic PE information: section name: .xdata
Source: libcairo-2.dll.0.drStatic PE information: section name: /4
Source: libcairo-gobject-2.dll.0.drStatic PE information: section name: .xdata
Source: libcairo-gobject-2.dll.0.drStatic PE information: section name: /4
Source: libcairo-script-interpreter-2.dll.0.drStatic PE information: section name: .xdata
Source: libcairo-script-interpreter-2.dll.0.drStatic PE information: section name: /4
Source: opengps.dll.0.drStatic PE information: section name: .xdata
Source: opengps.dll.0.drStatic PE information: section name: /4
Source: opengps.dll.0.drStatic PE information: section name: /19
Source: opengps.dll.0.drStatic PE information: section name: /31
Source: opengps.dll.0.drStatic PE information: section name: /45
Source: opengps.dll.0.drStatic PE information: section name: /57
Source: opengps.dll.0.drStatic PE information: section name: /70
Source: opengps.dll.0.drStatic PE information: section name: /81
Source: opengps.dll.0.drStatic PE information: section name: /92
Source: psppt.dll.0.drStatic PE information: section name: .xdata
Source: psppt.dll.0.drStatic PE information: section name: /4
Source: psppt.dll.0.drStatic PE information: section name: /19
Source: psppt.dll.0.drStatic PE information: section name: /31
Source: psppt.dll.0.drStatic PE information: section name: /45
Source: psppt.dll.0.drStatic PE information: section name: /57
Source: psppt.dll.0.drStatic PE information: section name: /70
Source: psppt.dll.0.drStatic PE information: section name: /81
Source: psppt.dll.0.drStatic PE information: section name: /92
Source: sensofarx.dll.0.drStatic PE information: section name: .xdata
Source: sensofarx.dll.0.drStatic PE information: section name: /4
Source: sensofarx.dll.0.drStatic PE information: section name: /19
Source: sensofarx.dll.0.drStatic PE information: section name: /31
Source: sensofarx.dll.0.drStatic PE information: section name: /45
Source: sensofarx.dll.0.drStatic PE information: section name: /57
Source: sensofarx.dll.0.drStatic PE information: section name: /70
Source: sensofarx.dll.0.drStatic PE information: section name: /81
Source: sensofarx.dll.0.drStatic PE information: section name: /92
Source: spml.dll.0.drStatic PE information: section name: .xdata
Source: spml.dll.0.drStatic PE information: section name: /4
Source: spml.dll.0.drStatic PE information: section name: /19
Source: spml.dll.0.drStatic PE information: section name: /31
Source: spml.dll.0.drStatic PE information: section name: /45
Source: spml.dll.0.drStatic PE information: section name: /57
Source: spml.dll.0.drStatic PE information: section name: /70
Source: spml.dll.0.drStatic PE information: section name: /81
Source: spml.dll.0.drStatic PE information: section name: /92
Source: spmxfile.dll.0.drStatic PE information: section name: .xdata
Source: spmxfile.dll.0.drStatic PE information: section name: /4
Source: spmxfile.dll.0.drStatic PE information: section name: /19
Source: spmxfile.dll.0.drStatic PE information: section name: /31
Source: spmxfile.dll.0.drStatic PE information: section name: /45
Source: spmxfile.dll.0.drStatic PE information: section name: /57
Source: spmxfile.dll.0.drStatic PE information: section name: /70
Source: spmxfile.dll.0.drStatic PE information: section name: /81
Source: spmxfile.dll.0.drStatic PE information: section name: /92
Source: zonfile.dll.0.drStatic PE information: section name: .xdata
Source: zonfile.dll.0.drStatic PE information: section name: /4
Source: zonfile.dll.0.drStatic PE information: section name: /19
Source: zonfile.dll.0.drStatic PE information: section name: /31
Source: zonfile.dll.0.drStatic PE information: section name: /45
Source: zonfile.dll.0.drStatic PE information: section name: /57
Source: zonfile.dll.0.drStatic PE information: section name: /70
Source: zonfile.dll.0.drStatic PE information: section name: /81
Source: zonfile.dll.0.drStatic PE information: section name: /92
Source: graph.dll.0.drStatic PE information: section name: .xdata
Source: graph.dll.0.drStatic PE information: section name: /4
Source: graph.dll.0.drStatic PE information: section name: /19
Source: graph.dll.0.drStatic PE information: section name: /31
Source: graph.dll.0.drStatic PE information: section name: /45
Source: graph.dll.0.drStatic PE information: section name: /57
Source: graph.dll.0.drStatic PE information: section name: /70
Source: graph.dll.0.drStatic PE information: section name: /81
Source: graph.dll.0.drStatic PE information: section name: /92
Source: libexpat-1.dll.0.drStatic PE information: section name: .xdata
Source: libexpat-1.dll.0.drStatic PE information: section name: /4
Source: libffi-6.dll.0.drStatic PE information: section name: .xdata
Source: libffi-6.dll.0.drStatic PE information: section name: /4
Source: libfftw3-3.dll.0.drStatic PE information: section name: .xdata
Source: libfftw3-3.dll.0.drStatic PE information: section name: /4
Source: libfontconfig-1.dll.0.drStatic PE information: section name: .xdata
Source: libfontconfig-1.dll.0.drStatic PE information: section name: /4
Source: libfreetype-6.dll.0.drStatic PE information: section name: .xdata
Source: libfreetype-6.dll.0.drStatic PE information: section name: /4
Source: libgailutil-18.dll.0.drStatic PE information: section name: .xdata
Source: libgailutil-18.dll.0.drStatic PE information: section name: /4
Source: libgdkglext-win32-1.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgdkglext-win32-1.0-0.dll.0.drStatic PE information: section name: /4
Source: libgdk_pixbuf-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgdk_pixbuf-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgdk-win32-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgdk-win32-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: .xdata
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /4
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /19
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /31
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /45
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /57
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /70
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /81
Source: libgcc_s_seh-1.dll.0.drStatic PE information: section name: /92
Source: layer.dll.0.drStatic PE information: section name: .xdata
Source: layer.dll.0.drStatic PE information: section name: /4
Source: layer.dll.0.drStatic PE information: section name: /19
Source: layer.dll.0.drStatic PE information: section name: /31
Source: layer.dll.0.drStatic PE information: section name: /45
Source: layer.dll.0.drStatic PE information: section name: /57
Source: layer.dll.0.drStatic PE information: section name: /70
Source: layer.dll.0.drStatic PE information: section name: /81
Source: layer.dll.0.drStatic PE information: section name: /92
Source: process.dll.0.drStatic PE information: section name: .xdata
Source: process.dll.0.drStatic PE information: section name: /4
Source: process.dll.0.drStatic PE information: section name: /19
Source: process.dll.0.drStatic PE information: section name: /31
Source: process.dll.0.drStatic PE information: section name: /45
Source: process.dll.0.drStatic PE information: section name: /57
Source: process.dll.0.drStatic PE information: section name: /70
Source: process.dll.0.drStatic PE information: section name: /81
Source: process.dll.0.drStatic PE information: section name: /92
Source: tools.dll.0.drStatic PE information: section name: .xdata
Source: tools.dll.0.drStatic PE information: section name: /4
Source: tools.dll.0.drStatic PE information: section name: /19
Source: tools.dll.0.drStatic PE information: section name: /31
Source: tools.dll.0.drStatic PE information: section name: /45
Source: tools.dll.0.drStatic PE information: section name: /57
Source: tools.dll.0.drStatic PE information: section name: /70
Source: tools.dll.0.drStatic PE information: section name: /81
Source: tools.dll.0.drStatic PE information: section name: /92
Source: volume.dll.0.drStatic PE information: section name: .xdata
Source: volume.dll.0.drStatic PE information: section name: /4
Source: volume.dll.0.drStatic PE information: section name: /19
Source: volume.dll.0.drStatic PE information: section name: /31
Source: volume.dll.0.drStatic PE information: section name: /45
Source: volume.dll.0.drStatic PE information: section name: /57
Source: volume.dll.0.drStatic PE information: section name: /70
Source: volume.dll.0.drStatic PE information: section name: /81
Source: volume.dll.0.drStatic PE information: section name: /92
Source: xyz.dll.0.drStatic PE information: section name: .xdata
Source: xyz.dll.0.drStatic PE information: section name: /4
Source: xyz.dll.0.drStatic PE information: section name: /19
Source: xyz.dll.0.drStatic PE information: section name: /31
Source: xyz.dll.0.drStatic PE information: section name: /45
Source: xyz.dll.0.drStatic PE information: section name: /57
Source: xyz.dll.0.drStatic PE information: section name: /70
Source: xyz.dll.0.drStatic PE information: section name: /81
Source: xyz.dll.0.drStatic PE information: section name: /92
Source: libssp-0.dll.0.drStatic PE information: section name: .xdata
Source: libssp-0.dll.0.drStatic PE information: section name: /4
Source: libssp-0.dll.0.drStatic PE information: section name: /19
Source: libssp-0.dll.0.drStatic PE information: section name: /31
Source: libssp-0.dll.0.drStatic PE information: section name: /45
Source: libssp-0.dll.0.drStatic PE information: section name: /57
Source: libssp-0.dll.0.drStatic PE information: section name: /70
Source: libssp-0.dll.0.drStatic PE information: section name: /81
Source: libssp-0.dll.0.drStatic PE information: section name: /92
Source: libgio-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgio-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libglib-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libglib-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgmodule-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgmodule-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgobject-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgobject-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgomp-1.dll.0.drStatic PE information: section name: .xdata
Source: libgomp-1.dll.0.drStatic PE information: section name: /4
Source: libgomp-1.dll.0.drStatic PE information: section name: /19
Source: libgomp-1.dll.0.drStatic PE information: section name: /31
Source: libgomp-1.dll.0.drStatic PE information: section name: /45
Source: libgomp-1.dll.0.drStatic PE information: section name: /57
Source: libgomp-1.dll.0.drStatic PE information: section name: /70
Source: libgomp-1.dll.0.drStatic PE information: section name: /81
Source: libgomp-1.dll.0.drStatic PE information: section name: /92
Source: libgthread-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgthread-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgtkglext-win32-1.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgtkglext-win32-1.0-0.dll.0.drStatic PE information: section name: /4
Source: libgtk-win32-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgtk-win32-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libgtksourceview-2.0-0.dll.0.drStatic PE information: section name: .xdata
Source: libgtksourceview-2.0-0.dll.0.drStatic PE information: section name: /4
Source: libharfbuzz-0.dll.0.drStatic PE information: section name: .xdata
Source: libharfbuzz-0.dll.0.drStatic PE information: section name: /4
Source: libhdf5-103.dll.0.drStatic PE information: section name: .xdata
Source: libhdf5-103.dll.0.drStatic PE information: section name: /4
Source: libhdf5_hl-100.dll.0.drStatic PE information: section name: .xdata
Source: libhdf5_hl-100.dll.0.drStatic PE information: section name: /4
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /4
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /19
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /31
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /45
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /57
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /70
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /81
Source: libgwyddion2-0.dll.0.drStatic PE information: section name: /92
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /4
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /19
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /31
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /45
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /57
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /70
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /81
Source: libgwyprocess2-0.dll.0.drStatic PE information: section name: /92
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /4
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /19
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /31
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /45
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /57
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /70
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /81
Source: libgwydraw2-0.dll.0.drStatic PE information: section name: /92
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /4
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /19
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /31
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /45
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /57
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /70
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /81
Source: libgwydgets2-0.dll.0.drStatic PE information: section name: /92
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /4
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /19
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /31
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /45
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /57
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /70
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /81
Source: libgwymodule2-0.dll.0.drStatic PE information: section name: /92
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: .xdata
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /4
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /19
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /31
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /45
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /57
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /70
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /81
Source: libgwyapp2-0.dll.0.drStatic PE information: section name: /92
Source: libintl-8.dll.0.drStatic PE information: section name: .xdata
Source: libintl-8.dll.0.drStatic PE information: section name: /4
Source: libjansson.dll.0.drStatic PE information: section name: .xdata
Source: libjansson.dll.0.drStatic PE information: section name: /4
Source: libjasper-4.dll.0.drStatic PE information: section name: .xdata
Source: libjasper-4.dll.0.drStatic PE information: section name: /4
Source: libjpeg-62.dll.0.drStatic PE information: section name: .xdata
Source: libjpeg-62.dll.0.drStatic PE information: section name: /4
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gsettings.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libjansson.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libsz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\fc-list.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\zlib1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\uninstall.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\iconv.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gdbus.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libaec.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libdl.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Users\user\AppData\Local\Temp\nsmFD66.tmp\nsDialogs.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-bzip2.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-HDF5.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-JasPer.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libffi.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libpng.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-libzip.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-OpenEXR.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\Program Files\Gwyddion\LICENSE-pcre.txtJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gwyddion (64bit).lnkJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\fc-cache.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpangocairo-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgdk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libxml2-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\apedaxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-viqr.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gsettings.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\createc.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libjansson.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpng16-16.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\imgexport.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-thai.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdf5file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\anasys_xml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libjpeg-62.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-inuktitut.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spmxfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-er.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\spml.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgtkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-tga.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgobject-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-jasper.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libexpat-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwymodule2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cyrillic-translit.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\plugin-proxy.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgio-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-icns.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ti-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\hdrimage.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ime.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-am-et.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libsz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\rhk-sm4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\fc-list.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libatk-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libzip-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libjasper-4.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\zlib1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoscantech.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libstdc++-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\oirfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\jpkscan.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\matfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\layer\layer.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\file.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xpm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\pixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\opengps.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libglib-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libcairo-script-interpreter-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\tool\tools.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\uninstall.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgthread-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nrrdfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libpixmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\iconv.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gdbus.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\npyfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgdkglext-win32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-pnm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-qtif.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\volume\volume.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\graph\graph.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\sensofarx.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libfftw3-3.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpcre-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\cmap\cmap.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpango-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpixman-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libffi-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libhdf5-103.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libbz2-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\xyz\xyz.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgailutil-18.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libfontconfig-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\keyence.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpangoft2-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\modules\libgail.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-ani.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwyprocess2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gwyddion.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\process\process.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwydgets2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libintl-8.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIexMath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libImath-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libharfbuzz-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libcairo-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgcc_s_seh-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libtiff-5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libwinpthread-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libssp-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\psppt.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libpangowin32-1.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libaec.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-multipress.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libhdf5_hl-100.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libdl.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\engines\libwimp.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-cedilla.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgtk-win32-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgdk_pixbuf-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\zonfile.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwyddion2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgomp-1.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libcairo-gobject-2.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libwebp-7.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwydraw2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libasprintf-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gdk-pixbuf-2.0\2.10.0\loaders\libpixbufloader-xbm.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libfreetype-6.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIex-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gwyddion\modules\file\nanoobserver.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmFD66.tmp\nsDialogs.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgtksourceview-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgmodule-2.0-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libgwyapp2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exeJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\bin\libHalf-2_5.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeDropped PE file which has not been started: C:\Program Files\Gwyddion\lib\gtk-2.0\2.10.0\immodules\im-ipa.dllJump to dropped file
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile Volume queried: C:\Program Files FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeFile Volume queried: C:\Program Files FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405D74
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_0040699E FindFirstFileW,FindClose,0_2_0040699E
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_0040290B FindFirstFileW,0_2_0040290B
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeAPI call chain: ExitProcess graph end nodegraph_0-3722
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeAPI call chain: ExitProcess graph end nodegraph_0-3942
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_6E211407 CallWindowProcW,DestroyWindow,GetProcessHeap,RtlFreeHeap,0_2_6E211407
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\Gwyddion-2.65.win64.exeCode function: 0_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,0_2_00403640
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Windows Service
1
Access Token Manipulation
2
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network Medium1
System Shutdown/Reboot
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Windows Service
1
Access Token Manipulation
LSASS Memory2
File and Directory Discovery
Remote Desktop Protocol1
Clipboard Data
Junk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
1
DLL Side-Loading
Security Account Manager14
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Registry Run Keys / Startup Folder
Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Gwyddion-2.65.win64.exe1%VirustotalBrowse
Gwyddion-2.65.win64.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files\Gwyddion\bin\fc-cache.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\fc-cache.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\fc-list.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\fc-list.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gdbus.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gdbus.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gdk-pixbuf-query-loaders.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gsettings.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gsettings.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gspawn-win64-helper-console.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gspawn-win64-helper.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gtk-query-immodules-2.0.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gwyddion-thumbnailer.exe0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\gwyddion.exe0%ReversingLabs
C:\Program Files\Gwyddion\bin\gwyddion.exe1%VirustotalBrowse
C:\Program Files\Gwyddion\bin\iconv.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\iconv.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libHalf-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libHalf-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libIex-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIex-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libIexMath-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIexMath-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIlmImf-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIlmImfUtil-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libIlmThread-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libImath-2_5.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libImath-2_5.dll0%VirustotalBrowse
C:\Program Files\Gwyddion\bin\libaec.dll0%ReversingLabs
C:\Program Files\Gwyddion\bin\libaec.dll0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://relaxng.org/ns/structure/1.00%URL Reputationsafe
https://cairographics.org))0%Avira URL Cloudsafe
https://cairographics.org)0%Avira URL Cloudsafe
http://gwyddion.net/.gwyGwyddion.NativeDataGwyddion0%Avira URL Cloudsafe
http://freedesktop.orgtypenameexeccounttimestamp0%Avira URL Cloudsafe
http://gwyddion.net/0%Avira URL Cloudsafe
http://gwyddion.net/Report0%Avira URL Cloudsafe
http://relaxng.org/ns/compatibility/annotations/1.00%Avira URL Cloudsafe
http://www.brynosaurus.com/cachedir/0%Avira URL Cloudsafe
https://translationproject.org/team/pt_BR.html0%Avira URL Cloudsafe
https://translationproject.org/team/pt_BR.html0%VirustotalBrowse
http://www.brynosaurus.com/cachedir/0%VirustotalBrowse
http://gwyddion.net/.gwyGwyddion.NativeDataGwyddion0%VirustotalBrowse
http://relaxng.org/ns/compatibility/annotations/1.00%VirustotalBrowse
http://gwyddion.net/Report0%VirustotalBrowse
http://gwyddion.net/0%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://bugzilla.gnome.org/enter_bug.cgi?product=gdk-pixbuf&keywords=I18NGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
    high
    https://www.gnu.org/licenses/gpl-2.0.htmlLicenseGtkGLExtnsfDF4E.tmp.0.drfalse
      high
      https://cairographics.org))nsfDF4E.tmp.0.drfalse
      • Avira URL Cloud: safe
      low
      http://docs.python.org/lib/typesseq-strings.htmlGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://www.gnu.org/licenses/nsfDF4E.tmp.0.drfalse
          high
          http://www.freedesktop.org/standards/desktop-bookmarksnsfDF4E.tmp.0.drfalse
            high
            http://freedesktop.orgtypenameexeccounttimestampnsfDF4E.tmp.0.drfalse
            • Avira URL Cloud: safe
            unknown
            http://gwyddion.net/nsfDF4E.tmp.0.drfalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            http://nsis.sf.net/NSIS_ErrorErrorGwyddion-2.65.win64.exefalse
              high
              http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&component=generalGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                http://bugzilla.gnome.org/show_bug.cgi?id=%sg_type_is_ansfDF4E.tmp.0.drfalse
                  high
                  http://www.cmi.cz/nsfDF4E.tmp.0.drfalse
                    high
                    http://docs.python.org/lib/built-in-funcs.html)Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmp, def.lang.0.drfalse
                      high
                      http://icon-theme.freedesktop.org/releasesnsfDF4E.tmp.0.drfalse
                        high
                        https://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18NGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://cairographics.org)nsfDF4E.tmp.0.drfalse
                          • Avira URL Cloud: safe
                          low
                          http://www.freedesktop.org/standards/dbus/1.0/introspect.dtdnsfDF4E.tmp.0.drfalse
                            high
                            https://www.gnu.org/licenses/gpl-2.0.htmlnsfDF4E.tmp.0.drfalse
                              high
                              http://bugzilla.gnome.org/enter_bug.cgi?product=gtksourceview&component=generalGwyddion-2.65.win64.exe, 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmp, Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                http://gwyddion.net/.gwyGwyddion.NativeDataGwyddionGwyddion-2.65.win64.exe, 00000000.00000002.2898235375.00000000006D8000.00000004.00000020.00020000.00000000.sdmp, nsfDF4E.tmp.0.drfalse
                                • 0%, Virustotal, Browse
                                • Avira URL Cloud: safe
                                unknown
                                http://docs.python.org/ref/strings.htmlGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://gwyddion.net/ReportnsfDF4E.tmp.0.drfalse
                                  • 0%, Virustotal, Browse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://gitlab.gnome.org/GNOME/gdk-pixbuf/issuesGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    http://bugzilla.gnome.org/enter_bug.cgi?product=atk&keywords=I18NGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmp, atk10.mo6.0.dr, atk10.mo8.0.drfalse
                                      high
                                      http://www.freedesktop.org/standards/shared-mime-infonsfDF4E.tmp.0.drfalse
                                        high
                                        http://www.brynosaurus.com/cachedir/nsfDF4E.tmp.0.drfalse
                                        • 0%, Virustotal, Browse
                                        • Avira URL Cloud: safe
                                        unknown
                                        http://www.cmi.cz/Credits%snsfDF4E.tmp.0.drfalse
                                          high
                                          http://www.freedesktop.org/standards/desktop-bookmarksgroupapplicationsgroupsprivateiconmime-typehttnsfDF4E.tmp.0.drfalse
                                            high
                                            https://gnu.org/licenses/gpl.htmlGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              http://relaxng.org/ns/compatibility/annotations/1.0Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                              • 0%, Virustotal, Browse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://translationproject.org/team/pt_BR.htmlGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                              • 0%, Virustotal, Browse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://library.gnome.org/devel/gtk-faq/stable/nsfDF4E.tmp.0.drfalse
                                                high
                                                https://www.python.org/peps/pep-0263.htmlGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  http://relaxng.org/ns/structure/1.0Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmp, language2.rng.0.drfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  http://bugzilla.gnome.org/enter_bug.cgi?product=gtk%2b&keywords=I18NGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    high
                                                    http://freedesktop.orgnsfDF4E.tmp.0.drfalse
                                                      high
                                                      http://bugzilla.gnome.org/enter_bug.cgi?product=glib&keywords=I18NGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        high
                                                        http://bugzilla.gnome.org/show_bug.cgi?id=%snsfDF4E.tmp.0.drfalse
                                                          high
                                                          https://www.python.org/peps/pep-0263.html.Gwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            high
                                                            https://github.com/iobataya/gwyddion-ja-translationGwyddion-2.65.win64.exe, 00000000.00000002.2899265009.000000000273B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              high
                                                              No contacted IP infos
                                                              Joe Sandbox version:40.0.0 Tourmaline
                                                              Analysis ID:1431474
                                                              Start date and time:2024-04-25 09:07:04 +02:00
                                                              Joe Sandbox product:CloudBasic
                                                              Overall analysis duration:0h 6m 53s
                                                              Hypervisor based Inspection enabled:false
                                                              Report type:full
                                                              Cookbook file name:default.jbs
                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                              Number of analysed new started processes analysed:7
                                                              Number of new started drivers analysed:0
                                                              Number of existing processes analysed:0
                                                              Number of existing drivers analysed:0
                                                              Number of injected processes analysed:0
                                                              Technologies:
                                                              • HCA enabled
                                                              • EGA enabled
                                                              • AMSI enabled
                                                              Analysis Mode:default
                                                              Analysis stop reason:Timeout
                                                              Sample name:Gwyddion-2.65.win64.exe
                                                              Detection:CLEAN
                                                              Classification:clean3.winEXE@1/615@0/0
                                                              EGA Information:
                                                              • Successful, ratio: 100%
                                                              HCA Information:
                                                              • Successful, ratio: 100%
                                                              • Number of executed functions: 57
                                                              • Number of non-executed functions: 23
                                                              Cookbook Comments:
                                                              • Found application associated with file extension: .exe
                                                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                              • Not all processes where analyzed, report is missing behavior information
                                                              • Report size getting too big, too many NtOpenKeyEx calls found.
                                                              • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                                              • Report size getting too big, too many NtSetInformationFile calls found.
                                                              No simulations
                                                              No context
                                                              No context
                                                              No context
                                                              No context
                                                              No context
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):18107
                                                              Entropy (8bit):4.671170220500741
                                                              Encrypted:false
                                                              SSDEEP:384:oEUwi5rPL67cyV12rPd34FomzM2/R+dWb7+Ud:o7F4ExGFzeda7+Ud
                                                              MD5:D0FC6D9576B29914AF3C2F8586D0B40E
                                                              SHA1:DD3C2E9061F0A16CE21517D3989C7C80CBA7D02B
                                                              SHA-256:62F859793A07E5AFAE04229F79FF279EECC1FD1FC9B253B024545A00FB273E7E
                                                              SHA-512:485AD1D4FE0E4F77491C3543D1C2458F2FDCC51BD2FD9D62D1D13854AD7FF019EE0B76F4610D0766C4B5C8F88E3AD136226C52BA5F6547D1AE84A689FB46B920
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:. GNU GENERAL PUBLIC LICENSE. Version 2, June 1991.. Copyright (C) 1989, 1991 Free Software Foundation, Inc.. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.. Everyone is permitted to copy and distribute verbatim copies. of this license document, but changing it is not allowed... Preamble.. The licenses for most software are designed to take away your.freedom to share and change it. By contrast, the GNU General Public.License is intended to guarantee your freedom to share and change free.software--to make sure the software is free for all its users. This.General Public License applies to most of the Free Software.Foundation's software and to any other program whose authors commit to.using it. (Some other Free Software Foundation software is covered by.the GNU Library General Public License instead.) You can apply it to.your programs, too... When we speak of free software, we are referring to freedom
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):25293
                                                              Entropy (8bit):4.6202271784571005
                                                              Encrypted:false
                                                              SSDEEP:384:xv5UwOVAIZ4zZyydV+X6wFDVxnFw7xqsv/t+zP8EfHinIhFkspNM9b/7upt0M6QC:xvuFmIHiV+DnFM/gReSNm/7GtX6QC
                                                              MD5:F3FEA5E763F8885B6BB5D02D9EB29D46
                                                              SHA1:456B3F002866889CB197564C71292E8D1C332614
                                                              SHA-256:677D431F8B6D8BC3685D74B82F64A5594A5F9A9D722D9CFED42DB5A99F50A678
                                                              SHA-512:1AFB31E3F905B97CF276AD59E59200A5059C9C3B4A36CC5DB9C775911862AA4DB61474D4A0DFB67F0AFF743B84E5D4A057E48FDDCD2DEE11F23AC099CFEAEAE6
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:.. GNU LIBRARY GENERAL PUBLIC LICENSE... Version 2, June 1991.. Copyright (C) 1991 Free Software Foundation, Inc.. 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.. Everyone is permitted to copy and distribute verbatim copies. of this license document, but changing it is not allowed...[This is the first released version of the library GPL. It is. numbered 2 because it goes with version 2 of the ordinary GPL.]..... Preamble.. The licenses for most software are designed to take away your.freedom to share and change it. By contrast, the GNU General Public.Licenses are intended to guarantee your freedom to share and change.free software--to make sure the software is free for all its users... This license, the Library General Public License, applies to some.specially designated Free Software Foundation software, and to any.other libraries whose authors decide to use it. You can use it for.your libraries, too... When we speak of free software, we are referring to
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):25755
                                                              Entropy (8bit):4.627449807901279
                                                              Encrypted:false
                                                              SSDEEP:384:ZuCPLhqsT7Wlj7gwZFUoBjyKddfnpdp9dlKBAbN1EkhbVs5IsUfTNTukkv2n:bPLhCAijy+F9T9hGdasUfTkkkv2n
                                                              MD5:BFE1F75D606912A4111C90743D6C7325
                                                              SHA1:ABA8D76D0AF67D57DA3C3C321CAA59F3D242386B
                                                              SHA-256:53692A2ED6C6A2C6EC9B32DD0B820DFAE91E0A1FCDF625CA9ED0BDF8705FCC4F
                                                              SHA-512:FBDDECCEA689BA830DF464C144C1258EC696AE6D797B5E98AD86AA9419A8BFFBF6CC2E4614CC1A8497B495D3BB18BFD0CB7B1CF2B0BB4459E9C31DBEE1CF70F6
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview: MOZILLA PUBLIC LICENSE. Version 1.1.. ---------------..1. Definitions... 1.0.1. "Commercial Use" means distribution or otherwise making the. Covered Code available to a third party... 1.1. "Contributor" means each entity that creates or contributes to. the creation of Modifications... 1.2. "Contributor Version" means the combination of the Original. Code, prior Modifications used by a Contributor, and the Modifications. made by that particular Contributor... 1.3. "Covered Code" means the Original Code or Modifications or the. combination of the Original Code and Modifications, in each case. including portions thereof... 1.4. "Electronic Distribution Mechanism" means a mechanism generally. accepted in the software development community for the electronic. transfer of data... 1.5. "Executable" means Covered Code in any form other than Source. C
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1208
                                                              Entropy (8bit):5.126710469799819
                                                              Encrypted:false
                                                              SSDEEP:24:CnEoiJHxRHuyPP3GtIHw1h39QH+sUW8Ok4odZo3U/qldFD:AtiJzfPvGt7NQH+sfINi3OMFD
                                                              MD5:1B71F681713D1256E1C23B0890920874
                                                              SHA1:FD02365360C1936FDD069B08D29C16C6B16E4EA4
                                                              SHA-256:F6EEB2310D0B00E5CECAC39C73A0696A5BDBFB754B26325ED5A502FC1A6C338C
                                                              SHA-512:89275719E2E791B26BC82D788CF75823496367D7E06C144C07B3B8C78B5CF8FF4A4F49ADDE81767812B869D8E7566FF9199366A7EDB59F54EDC1FB9797B0270C
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:Copyright (c) 1998, 1999, 2000 Thai Open Source Software Center Ltd. and Clark Cooper.Copyright (c) 2001, 2002, 2003, 2004, 2005, 2006 Expat maintainers...Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be included.in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:Unicode text, UTF-8 text
                                                              Category:dropped
                                                              Size (bytes):1124
                                                              Entropy (8bit):5.125484636623076
                                                              Encrypted:false
                                                              SSDEEP:24:zEIBH50q6k8mq6jItjX4DViyYA/TjAUiaw/ea:zEIJmt+t0taViyYykUin/ea
                                                              MD5:F3AD4145DEA6CA7EFA2F1BEE8165A7A1
                                                              SHA1:97CBFA7E8BD49934F04133699D444E53A8647B09
                                                              SHA-256:853046EC5C75C400CD64887C49DD7B0BD3C4CF6B8102AFEDAE52BF79DB23F800
                                                              SHA-512:B47FF690A64C1CEAE1688491C522EAB810E74636FAA2D9BB32C00A8AD38CE28D4F1BE2E1C72B7BD0D162155CFD64FD2F83F8C6FE751A6F83378658AD4F4BDEDD
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:fontconfig/COPYING..Copyright . 2001,2003 Keith Packard..Permission to use, copy, modify, distribute, and sell this software and its.documentation for any purpose is hereby granted without fee, provided that.the above copyright notice appear in all copies and that both that.copyright notice and this permission notice appear in supporting.documentation, and that the name of Keith Packard not be used in.advertising or publicity pertaining to distribution of the software without.specific, written prior permission. Keith Packard makes no.representations about the suitability of this software for any purpose. It.is provided "as is" without express or implied warranty...THE AUTHOR(S) DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE,.INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS, IN NO.EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY SPECIAL, INDIRECT OR.CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE,.DATA OR PROFITS, WHETHER IN AN ACTION OF CO
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:Unicode text, UTF-8 text
                                                              Category:dropped
                                                              Size (bytes):1690
                                                              Entropy (8bit):5.316577102282905
                                                              Encrypted:false
                                                              SSDEEP:24:0F1JTGywLbvX8EU0CqA/99D+Z0IR/8jtk9fTsOBtfPxsmWOkN8IAgKe:0F1J5wLbvAfD+ZiOt9jPxsrN8IAgKe
                                                              MD5:E021DD6DDA6FF1E6B1044002FC662B9B
                                                              SHA1:E911ADF5641A09F13FDD5D59962AD37DA043DF79
                                                              SHA-256:2A886915DE4F296CDAE5ED67064F86DBA01D0C55286D86E8487F2A5CAAF40216
                                                              SHA-512:6C6425A23C4EFD4D6D35CD300D0B1F6D486D91A4B97A579AFD3EFE5A2F5C94657F2A3B3501C89F0CE50A8814D98C90947A7DAB1AF35092DBA51DA7C50C9741DF
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:HarfBuzz is licensed under the so-called "Old MIT" license. Details follow..For parts of HarfBuzz that are licensed under different licenses see individual.files names COPYING in subdirectories where applicable...Copyright . 2010,2011,2012 Google, Inc..Copyright . 2012 Mozilla Foundation.Copyright . 2011 Codethink Limited.Copyright . 2008,2010 Nokia Corporation and/or its subsidiary(-ies).Copyright . 2009 Keith Stribley.Copyright . 2009 Martin Hosken and SIL International.Copyright . 2007 Chris Wilson.Copyright . 2006 Behdad Esfahbod.Copyright . 2005 David Turner.Copyright . 2004,2007,2008,2009,2010 Red Hat, Inc..Copyright . 1998-2004 David Turner and Werner Lemberg..For full copyright notices consult the individual files in the package....Permission is hereby granted, without written agreement and without.license or royalty fees, to use, copy, modify, and distribute this.software and its documentation for any purpose, provided that the.above copyright notice and
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2259
                                                              Entropy (8bit):4.7030113384031464
                                                              Encrypted:false
                                                              SSDEEP:48:cKDQHSxpTM6Lck1Z7nPg+ubwc3FT+2tRteDSLNjyNAg36Gb1B:ZDA6Zi8w6McC1yKaz
                                                              MD5:2578FEA3829F3FE60EE71023F264FE40
                                                              SHA1:BD2DB031B873E6949E6297FA3DC550F95C33C78D
                                                              SHA-256:F9769D0238C1806CA5C998343F3C7BA3499E0F8928B91753A1A92D582E76396E
                                                              SHA-512:80F373922E6CDF2975AF91F0639F7102E1091F9AA3D3D606B2BD249580EBCAAD88B1E177E5742DF56C23E1D5E6C884419490E1C73C23C01F9B87D4EA36433437
                                                              Malicious:false
                                                              Preview:..LEGAL ISSUES..============....In plain English:....1. We don't promise that this software works. (But if you find any bugs,.. please let us know!)..2. You can use this software for whatever you want. You don't have to pay us...3. You may not pretend that you wrote this software. If you use it in a.. program, you must acknowledge somewhere in your documentation that.. you've used the IJG code.....In legalese:....The authors make NO WARRANTY or representation, either express or implied,..with respect to this software, its quality, accuracy, merchantability, or..fitness for a particular purpose. This software is provided "AS IS", and you,..its user, assume the entire risk as to its quality and accuracy.....This software is copyright (C) 1991-1998, Thomas G. Lane...All Rights Reserved except as specified below.....Permission is hereby granted to use, copy, modify, and distribute this..software (or portions thereof) for any purpose, without fee, subject to these..conditions:..(1
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1496
                                                              Entropy (8bit):5.089007947804457
                                                              Encrypted:false
                                                              SSDEEP:24:DiK7jUnoc+bOI/rYFTY+Jy/rYFTcqLef09RdozFDBTP4894Os43sEskuK8WROLTe:DiYdOYrYJarYJFS8dozFVP4+4943Je58
                                                              MD5:6E8DEE932C26F2DAB503ABF70C96D8BB
                                                              SHA1:59CD938FCBD6735B1EF91781280D6EB6C4B7C5D9
                                                              SHA-256:5AEC868F669E384A22372A4E8A1A6CD7D44C64CD451F960CA69CC170D1E13ACF
                                                              SHA-512:04702240D3D891CACEA23641652FA8E001733538E5671360B411CA5AF94813968F992268142E054B34478C3B1BCCB22E76C32F09B88130C2F5BAD32C50F7E065
                                                              Malicious:false
                                                              Preview:Copyright (c) 2010, Google Inc. All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are.met:.. * Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer... * Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in. the documentation and/or other materials provided with the. distribution... * Neither the name of Google nor the names of its contributors may. be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS."AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL TH
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1472
                                                              Entropy (8bit):4.5247018409170945
                                                              Encrypted:false
                                                              SSDEEP:24:1jxsMvvcxAbr2tQNNMTpxGvNbyo8POABZ86o1NXgmr+JxV8BJhny:1e4vcebyt6NMTpxe1ypWqZ86YNXx+pAy
                                                              MD5:E2106A42E424045D9AB6F5D18ADC7135
                                                              SHA1:F934726236DE2FF4DC610F5D6F43A2B77CC16C6D
                                                              SHA-256:D7F6C672A25722455192BBDE2F2A1F6619F3B3DE35C8D8AD3BB8000D66546824
                                                              SHA-512:7B8F420D41E5C9AC52984D21477ABC8706A39D8C5C300C994229299E00CD79D9DC9ED60641D76AAC10C1826DAC65B19142F4AAD5206959F25270A254F19A93C5
                                                              Malicious:false
                                                              Preview:..Copyright notice:.... (C) 1995-1998 Jean-loup Gailly and Mark Adler.... This software is provided 'as-is', without any express or implied.. warranty. In no event will the authors be held liable for any damages.. arising from the use of this software..... Permission is granted to anyone to use this software for any purpose,.. including commercial applications, and to alter it and redistribute it.. freely, subject to the following restrictions:.... 1. The origin of this software must not be misrepresented; you must not.. claim that you wrote the original software. If you use this software.. in a product, an acknowledgment in the product documentation would be.. appreciated but is not required... 2. Altered source versions must be plainly marked as such, and must not be.. misrepresented as being the original software... 3. This notice may not be removed or altered from any source distribution..... Jean-loup Gailly Mark Adler.. jloup@gzip.org m
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1500
                                                              Entropy (8bit):5.262012915401088
                                                              Encrypted:false
                                                              SSDEEP:24:KFrFLPA+5DUnogbOIhrYFThJyhrYFTX79LFmr43sEskuK8WROLTt3hyxLTfyL3tY:I5EhOorYJKrYJBxmr43Je53hELmL3tqL
                                                              MD5:3D460E16A7D7C854DF7C0E91991C7A3B
                                                              SHA1:C4BEAFCB1437CA0F701803FB22323419C65527B1
                                                              SHA-256:EFCEF27F44A3FAAB503B3B29B05C8A6B9AD9746E7C7A72A17B056E5842AAF119
                                                              SHA-512:CD5DE660C66F46EB39A180076208995D01E24D3C58B8A5AB06667D3D6F2084F7D80E351FAF90F87863A3985D46A41ED9C3A5529075E53CA8439871E0EA901321
                                                              Malicious:false
                                                              Preview:Copyright 2012 - 2017..Mathis Rosenhauer, Moritz Hanke, Joerg Behrens.Deutsches Klimarechenzentrum GmbH.Bundesstr. 45a.20146 Hamburg.Germany..Luis Kornblueh.Max-Planck-Institut fuer Meteorologie.Bundesstr. 53.20146 Hamburg.Germany..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer..2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS.``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHA
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1146
                                                              Entropy (8bit):5.165452112098906
                                                              Encrypted:false
                                                              SSDEEP:24:5/fpCHTHImq6fTYAP1ynM98HTS0OkhpybVAJTJ8oVwF3Ow:53portjP1yO8HTd/yRABJ8oSF3Ow
                                                              MD5:34DA3DB46FAB7501992F9615D7E158CF
                                                              SHA1:A2F64F2A85F5FD34BDA8EB713C3AAD008ADBB589
                                                              SHA-256:FBD6FED7938541D2C809C0826225FC85E551FDBFA8732B10F0C87E0847ACAFD7
                                                              SHA-512:A550BF004806C7B3DA2E6DFC187B0D5FCFC8FB1C965440471925DE496C44CC3712FCCA9E901162516BF3FB48078A7348F5C1E6F69BD46B9F338D5A5A9252FDC9
                                                              Malicious:false
                                                              Preview:Copyright (c) 1988-1997 Sam Leffler.Copyright (c) 1991-1997 Silicon Graphics, Inc...Permission to use, copy, modify, distribute, and sell this software and .its documentation for any purpose is hereby granted without fee, provided.that (i) the above copyright notices and this permission notice appear in.all copies of the software and related documentation, and (ii) the names of.Sam Leffler and Silicon Graphics may not be used in any advertising or.publicity relating to the software without the specific, prior written.permission of Sam Leffler and Silicon Graphics...THE SOFTWARE IS PROVIDED "AS-IS" AND WITHOUT WARRANTY OF ANY KIND, .EXPRESS, IMPLIED OR OTHERWISE, INCLUDING WITHOUT LIMITATION, ANY .WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. ..IN NO EVENT SHALL SAM LEFFLER OR SILICON GRAPHICS BE LIABLE FOR.ANY SPECIAL, INCIDENTAL, INDIRECT OR CONSEQUENTIAL DAMAGES OF ANY KIND,.OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER OR NOT ADVI
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1498
                                                              Entropy (8bit):5.040468071401183
                                                              Encrypted:false
                                                              SSDEEP:24:EYNhVoLrmJHHH0yN3gtbHw1hj9QHOsUv4DOk4qyoaqXmFGTrPnaFwyJ:EYNXwaJHlxEs5QHOs5NjaVFIryFwk
                                                              MD5:BB90C48926316D9AF6E2D70CA7013ADE
                                                              SHA1:23A1E6369B12379F07C61BBBAA73E13704EBC30E
                                                              SHA-256:013556FF1AA847AC0E365337321C200EEE1C69051DB8870DB37002C852A4E98D
                                                              SHA-512:E025659C8C069B7CE5CF74FC38D085628B2C74A225197E3359F3A4EF37FC7A26C7C22C1732645C5507AF387A15FD0F06435F2BC0C61D13EAD8618CF51F0BB7EF
                                                              Malicious:false
                                                              Preview:Except where otherwise noted in the source code (e.g. the files hash.c,.list.c and the trio files, which are covered by a similar licence but.with different Copyright notices) all the files are:.. Copyright (C) 1998-2003 Daniel Veillard. All Rights Reserved...Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is fur-.nished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FIT-.NESS FOR A PARTICULAR
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):4677
                                                              Entropy (8bit):4.704074341157644
                                                              Encrypted:false
                                                              SSDEEP:96:7sOyHQyHzu6uvmdoFe32qmchF3ccrdCwjeCEQdaQ:IOGQGHrdowmdcnMidVjeJnQ
                                                              MD5:57E5351B17591E659EEDAE107265C606
                                                              SHA1:489C0C5DE66E7BD4D419E7E556F951DA223B4AFF
                                                              SHA-256:3D8E39397A04652AE54F04A6DA8B51B2472CDE8C721A1F00E4329C512D6A016F
                                                              SHA-512:1EDC3F2CE62EA4F3CDD4E25C158596ADB1D87786E4F79CABA4D56202645BF6185DD19F81761F4F9F182ACA3F99FDC8C92995B47BAEDCBC8E66FE832CFBB8512E
                                                              Malicious:false
                                                              Preview:.Copyright Notice and License Terms for .HDF5 (Hierarchical Data Format 5) Software Library and Utilities.-----------------------------------------------------------------------------..HDF5 (Hierarchical Data Format 5) Software Library and Utilities.Copyright 2006-2016 by The HDF Group...NCSA HDF5 (Hierarchical Data Format 5) Software Library and Utilities.Copyright 1998-2006 by the Board of Trustees of the University of Illinois...All rights reserved...Redistribution and use in source and binary forms, with or without .modification, are permitted for any purpose (including commercial purposes) .provided that the following conditions are met:..1. Redistributions of source code must retain the above copyright notice, . this list of conditions, and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright notice, . this list of conditions, and the following disclaimer in the documentation . and/or materials provided with the distribution...3. I
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):2744
                                                              Entropy (8bit):5.0942183084478545
                                                              Encrypted:false
                                                              SSDEEP:48:bhPJ1lPvcw4iP+HSs5SaWmurkmxF3es4cozFL/XWzUzgYaobqc:brPpx+HjW5TeGozFL/EPY5
                                                              MD5:BAA697D7510288A9CDCCE9BD7EDAF9BC
                                                              SHA1:14B5D0210560128E1A5D5204698CF705011EF792
                                                              SHA-256:EDF9F4257CC33A1F396F9B062CA4A01DCA7C79747C7D85B8947E603E5166760E
                                                              SHA-512:55E7BD1B4B17CB311F7F40632759D88940751AFC9A13CE50A05049B763784F36F8B4A469C2647843C56FD0595544F8C44614769847EBB0FD483E6EA7A856FF77
                                                              Malicious:false
                                                              Preview:JasPer License Version 2.0..Copyright (c) 2001-2006 Michael David Adams.Copyright (c) 1999-2000 Image Power, Inc..Copyright (c) 1999-2000 The University of British Columbia..All rights reserved...Permission is hereby granted, free of charge, to any person (the."User") obtaining a copy of this software and associated documentation.files (the "Software"), to deal in the Software without restriction,.including without limitation the rights to use, copy, modify, merge,.publish, distribute, and/or sell copies of the Software, and to permit.persons to whom the Software is furnished to do so, subject to the.following conditions:..1. The above copyright notices and this permission notice (which.includes the disclaimer below) shall be included in all copies or.substantial portions of the Software...2. The name of a copyright holder shall not be used to endorse or.promote products derived from the Software without specific prior.written permission...THIS DISCLAIMER OF WARRANTY CONSTITUTES AN E
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:Algol 68 source, ASCII text
                                                              Category:dropped
                                                              Size (bytes):1697
                                                              Entropy (8bit):5.055574007641632
                                                              Encrypted:false
                                                              SSDEEP:48:U+RAtO4rYJMrYJ5uVAIV+Pli432sf32sBEtI33tEH3:GA4rYJMrYJ5uObJ3T3d9uX
                                                              MD5:459493CEC2D4A115E731C482FFFC4B8A
                                                              SHA1:72F59FBAC43FA1A7F0607D7FDBA747832E626656
                                                              SHA-256:14EBA5F05238F57C77E94F0EBD29A0B3736BA0456FF990CDA16E21B6903AC453
                                                              SHA-512:3819C12557FB5DEEC9250C51399D7B598A927FFF26E46C52FECAF653EFC284DF58D8C44F36D86D953742C4BC265BC107DD9E4C2B7F0CDCCC0FA501C6BAC41788
                                                              Malicious:false
                                                              Preview:Copyright (c) 2006, Industrial Light & Magic, a division of Lucasfilm.Entertainment Company Ltd. Portions contributed and copyright held by.others as indicated. All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are.met:.. * Redistributions of source code must retain the above. copyright notice, this list of conditions and the following. disclaimer... * Redistributions in binary form must reproduce the above. copyright notice, this list of conditions and the following. disclaimer in the documentation and/or other materials provided with. the distribution... * Neither the name of Industrial Light & Magic nor the names of. any other contributors to this software may be used to endorse or. promote products derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONT
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1901
                                                              Entropy (8bit):5.1923513949066304
                                                              Encrypted:false
                                                              SSDEEP:48:doO3DJOorYJD6LraxZC6EPtiVn432sv532s3qtY1BtEHJ:dlIorYJ+sZC6kH393zrup
                                                              MD5:7023994919680C533B77301B306EA1C9
                                                              SHA1:D964DBE91CBF7511E4F1857DB9E99FDAF6658055
                                                              SHA-256:E8A6B63336018EEC09AC3A7CDFE5A80BDA635641BC0397A77B8BAA25BED03800
                                                              SHA-512:9F6294D3AC4B5D8FD56059F764B1F2E0A73B5B598FA468B1A9E0ACE76971F672EAD7327DC256B14C7117220DA4DCF98F720BF751ED830ED4A75095630D74E6F4
                                                              Malicious:false
                                                              Preview:.--------------------------------------------------------------------------..This program, "bzip2", the associated library "libbzip2", and all.documentation, are copyright (C) 1996-2007 Julian R Seward. All.rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. The origin of this software must not be misrepresented; you must . not claim that you wrote the original software. If you use this . software in a product, an acknowledgment in the product . documentation would be appreciated but is not required...3. Altered source versions must be plainly marked as such, and must. not be misrepresented as being the original software...4. The name of the author may not be used to endorse or promote . products derived from this software without sp
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1132
                                                              Entropy (8bit):5.126128868977439
                                                              Encrypted:false
                                                              SSDEEP:24:KDXiJHTHuyPP3GtIHw1Gg9WPH+sUW8Ok4odZo3U/qldFD:KTiJTfPvGt7ICWPH+sfINi3OMFD
                                                              MD5:0CAA055E49A3FB6C57780595E995E2AB
                                                              SHA1:874F526BC4A51D56E52F2FEEB52EE45D98D483EC
                                                              SHA-256:14FC11F72068E29AAF50306A33BFF2503D932DA1A2068FCC0641E6A5B7166D57
                                                              SHA-512:CA73AAFB080970564AC16604DE59DC934831150457DCC8EF92FCE6072E39ED761F6568025967757B387773F0551DD78A931981E10578A23A68F23C22827686D2
                                                              Malicious:false
                                                              Preview:libffi - Copyright (c) 1996-2011 Anthony Green, Red Hat, Inc and others..See source files for details...Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the.``Software''), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED ``AS IS'', WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):4195
                                                              Entropy (8bit):4.806906509727483
                                                              Encrypted:false
                                                              SSDEEP:96:aUaBPvSsJ1g1z7WCgms1mLKK9SMon1E4Ubg2O8vBddz7:aUaZSeeR7W9msw4Mon1E4o5pP7
                                                              MD5:A294A2BB08B7F25558119EDBFD6B2E92
                                                              SHA1:DBFB42F6E975CA9FD5DD96176B31975A9B068220
                                                              SHA-256:2A995675EF33E51B186EDBCE58A6520C3601332EE8595FA7603466D6B97DDD88
                                                              SHA-512:7CD4E1DC72CAB6F6D7BCD6F3D16699052FE8B2667E92CFF9F6F946B4BE76387BE775E2849013147F6E9C172BF9018BDAFB0A398A31CCD18947E47B6A76301D1F
                                                              Malicious:false
                                                              Preview:.This copy of the libpng notices is provided for your convenience. In case of.any discrepancy between this copy and the notices in the file png.h that is.included in the libpng distribution, the latter shall prevail...COPYRIGHT NOTICE, DISCLAIMER, and LICENSE:..If you modify libpng you may insert additional notices immediately following.this sentence...This code is released under the libpng license...libpng versions 1.2.6, August 15, 2004, through 1.2.44, June 26, 2010, are.Copyright (c) 2004, 2006-2009 Glenn Randers-Pehrson, and are.distributed according to the same disclaimer and license as libpng-1.2.5.with the following individual added to the list of Contributing Authors.. Cosmin Truta..libpng versions 1.0.7, July 1, 2000, through 1.2.5 - October 3, 2002, are.Copyright (c) 2000-2002 Glenn Randers-Pehrson, and are.distributed according to the same disclaimer and license as libpng-1.0.6.with the following individuals added to the list of Contributing Authors.. Simon-Pierre Cadi
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1452
                                                              Entropy (8bit):5.165301888670777
                                                              Encrypted:false
                                                              SSDEEP:24:XD5x4yBMcUnogbOInrYFT5JynrYFTcCLqtRIBTPP99Vn432s4EOk8NwROF32s3q5:TgyBmOYrYJGrYJl8EPl9Vn432svIP323
                                                              MD5:067E9870BBA57E1CE20695C4D5672F30
                                                              SHA1:45318F6FA59E6E142CC7E81FDB34ABF273B75E88
                                                              SHA-256:DEAE392DE70503672793EE784D603BFA8069DCD5974A325DFBF91160F3A147D6
                                                              SHA-512:9B908923B183C7462E88E9D18AE2FC03CE11875988FA0591B6B2CD2091DB0BA6A33039332F3C4BFF007F847E98103C33FB604C7DA6BFE7AD0436C07CCAFF8019
                                                              Malicious:false
                                                              Preview:Copyright (C) 1999-2020 Dieter Baron and Thomas Klausner..The authors can be contacted at <libzip@nih.at>..Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in. the documentation and/or other materials provided with the. distribution...3. The names of the authors may not be used to endorse or promote. products derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS.OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS BE LIABL
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):3182
                                                              Entropy (8bit):5.165985964776611
                                                              Encrypted:false
                                                              SSDEEP:96:wWclPcU13MKIiB9JyrYJWPkLY5F3X31EBQ:gPDeMTyrs1E5F3X3OQ
                                                              MD5:B8221CBF43C5587F90CCF228F1185CC2
                                                              SHA1:F3F2DED535A8B33041E9A818B2BEECEB690E39C1
                                                              SHA-256:3441595E1A5F7970ADB99286B68962CC20252AA0FB8B5D7D775F97760083D563
                                                              SHA-512:01E28BA8D5259BFDDE3423ED6717F5FF8BBAF047706E8E26F3A842EFCBF9441589CF4FDF730A608A1A2D61ACA12D6888269049920EFCB218262D5D940C03DAAC
                                                              Malicious:false
                                                              Preview:PCRE LICENCE.------------..PCRE is a library of functions to support regular expressions whose syntax.and semantics are as close as possible to those of the Perl 5 language...Release 8 of PCRE is distributed under the terms of the "BSD" licence, as.specified below. The documentation for PCRE, supplied in the "doc".directory, is distributed under the same terms as the software itself. The data.in the testdata directory is not copyrighted and is in the public domain...The basic library functions are written in C and are freestanding. Also.included in the distribution is a set of C++ wrapper functions, and a.just-in-time compiler that can be used to optimize pattern matching. These.are both optional features that can be omitted when the library is built....THE BASIC LIBRARY FUNCTIONS.---------------------------..Written by: Philip Hazel.Email local part: ph10.Email domain: cam.ac.uk..University of Cambridge Computing Service,.Cambridge, England...Copyright (c) 1997-2016 Universi
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):57227
                                                              Entropy (8bit):5.854878740915308
                                                              Encrypted:false
                                                              SSDEEP:768:AaeZuM6JdE6PAhVQGUQPY8Z+tD2MpPmVXrA/uG+EuJlCMpgt6tA6eIu1x7Um:APGJO64nQZ8ICMdkXSRuDpgt6ti
                                                              MD5:D57AEB2D3FC4A7790C2B097D9405634F
                                                              SHA1:F9A52182CAB41EA606C25B34095CB6E24EA84A53
                                                              SHA-256:B0F31F361D4F3CBD33F74A345C3DDD3279A5F3802D08564EBE7B92E95F47FAC3
                                                              SHA-512:248755E61EA9F4A36B415FDA1C80E0960E1A73A3AFCD9F0CC83158A7FAC534F729D3FBAC342F09FCBEC5978C3948459238EFB8F75DC4C852885A21C42716CB0D
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................'...."......................@..............................@............... .................................................(...............................................................(...................(................................text...H...........................`.P`.data...0...........................@.P..rdata..p...........................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..idata..(...........................@.0..CRT....h...........................@.@..tls......... ......................@.@./4...........0......................@.0B................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):53533
                                                              Entropy (8bit):5.829360944152274
                                                              Encrypted:false
                                                              SSDEEP:768:2kP0SvXAfJdTmJwNA2UoPK8a0R2w12LmVZcS/DG+B+qwi+ZRHgGt8ldbu1xbt:PcSvAJRM0Af8zwwckZd/+JZRA4
                                                              MD5:01F989B5E5764A422BA1EAC95C04DF6F
                                                              SHA1:C1078402F924A2178D546A089F1A1AE9E759BF1A
                                                              SHA-256:2E4DA27E6BE41FE66E7C548F314AE5638B327E40DE5CDDA43EEC2C2A5651A236
                                                              SHA-512:F425F90BDD9FD3509A7AFC0CAA2E9DA6CF22E1A22009C60F9F1E40D1A50FB14506F4A878AC62B03AD220B5A317EB308CB95BF9684336995A4E545D29BC58774A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................'....".~....................@..............................0......U......... .................................................,...........................................................@...(.......................@............................text...x|.......~..................`.P`.data...0...........................@.P..rdata..............................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..idata..,...........................@.0..CRT....h...........................@.@..tls................................@.@./4........... ......................@.0B................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):59006
                                                              Entropy (8bit):5.571070102327143
                                                              Encrypted:false
                                                              SSDEEP:768:y2wL6ElDW3/Wi1JecI5HakiF0FHYkWq3vy42wi+mdd9Vjt8Z0n9vmemaBSffRNWA:Vwx+/lJnI5H37FUn+mdF8+NBSfpNW8F
                                                              MD5:9EB50DA35CA9D48152D5367FE86A5834
                                                              SHA1:697B24CDE4061CD2D641AD71CAC5284007013323
                                                              SHA-256:C545DFB726C9811A3F2172186C86EB3B48DE71A6D1020CD8E69A1AF2532FAE26
                                                              SHA-512:1EAAEB1BC6F27F6B4F2A1322E085C84065AABDF04C11123FECCAC2F2D0F7732E0AD15C54761A218CB180190F162DCD009B565863F599D444C194D8B83133614D
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........p.....&....$.^.....................@.............................@.......Y....`... .................................................T...............0............ ..............................@...(....................................................text....].......^..................`.P`.data........p.......b..............@.P..rdata... ......."...d..............@.`@.pdata..0...........................@.0@.xdata..............................@.0@.bss....@.............................`..idata..T...........................@.0..CRT....h...........................@.@..tls................................@.@..reloc....... ......................@.0B/4...........0......................@.0B........................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):29392
                                                              Entropy (8bit):5.115809326826697
                                                              Encrypted:false
                                                              SSDEEP:384:cJU6v7WdnrowwRlMMsmrJJmz0r6xMgzNJJD4jam67g38vv3SViOM6OwXbifrsF:MDWdWUkJJ76Ogp4XuEIqVioOwbyrsF
                                                              MD5:9DA2DEE453F85FAC37691BE49069EB3C
                                                              SHA1:27144C941B934E310DF86E9357CA59FF3E92239B
                                                              SHA-256:EB3D7ABD1A1112370F0CD333D4E1F80E93C6A7A5869A3AA7AAF9D428C565899C
                                                              SHA-512:82A3B9E0116619B84774D2292D9E63C5043729E20DAE1BDD8E3AD9B4F97586425528B8F7A2CF0234E8081E6F6957F01AAD8B8624C1A960C3D5840BECAA02FA15
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........V........&....$.$...P.................@..........................................`... .................................................x............`..4...........................................@S..(...................$................................text....".......$..................`.P`.data........@.......(..............@.P..rdata.......P.......*..............@.`@.pdata..4....`.......:..............@.0@.xdata.......p.......>..............@.0@.bss..................................`..idata..x............@..............@.0..CRT....h............N..............@.@..tls.................P..............@.@..reloc...............R..............@.0B/4......(............T..............@.0B........................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):40700
                                                              Entropy (8bit):5.300536509625396
                                                              Encrypted:false
                                                              SSDEEP:384:k9WcZ4bpackG9V0pUmxJxtxdjgJPumOPZbGarVvxhmNkt4wvwOMJNFogf:exEa89V0W4njgJGmGbXjVt4tPNFogf
                                                              MD5:9B56E1E1B617C71A8A594F740C057D05
                                                              SHA1:58C62160B3892A463BEC64A0099704E9E15ED225
                                                              SHA-256:E9998EFF343271BD63BE5014348342F06DFA8129CD765D090591272C5A4D3F34
                                                              SHA-512:CAC5B33C7D20051615E1F54395F09D3E7972A679CD062AE1AB0D67624892956B4C0B527D2156909CA2AC68C6062B4530142EB234F5CE06B9AAD14954E57509D0
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........t..(.....&....$.2...n.................@..........................................`... .................................................D............................................................k..(.......................x............................text....0.......2..................`.P`.data........P.......6..............@.P..rdata.......`.......8..............@.`@.pdata...............P..............@.0@.xdata...............T..............@.0@.bss..................................`..idata..D............X..............@.0..CRT....h............l..............@.@..tls.................n..............@.@..reloc...............p..............@.0B/4...................r..............@.0B........................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):24867
                                                              Entropy (8bit):4.936942371647577
                                                              Encrypted:false
                                                              SSDEEP:384:RCL1EY9k82NZ0qpzBlJGplBi8eLjVsVBKJhQxxiOMvyqgl/0:RCLpClZ0IBlJ27i86Kj+kipyqgl/0
                                                              MD5:3716D87B022C519B4BC3982822822921
                                                              SHA1:9145160DD2A625CC9AD39511156FBA0E0703E94E
                                                              SHA-256:49394562AF9AEEECEB84AD0EAFACA5CE43F64971FEFFB9AC1313F1207C796C6B
                                                              SHA-512:83A0269591E0652BB76371518C58472629160BEC332775C19F6BF5AD13F6921DA1B5B50DBFDDD4E99281008D4328B8C43B7A91D82722C680D4D08044A7BFD81E
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........L........&....$. ...F.................@.....................................!....`... ..............................................................P..@...........................................`@..(...................\................................text...H........ ..................`.P`.data........0.......$..............@.P..rdata.......@.......&..............@.`@.pdata..@....P.......4..............@.0@.xdata.......`.......8..............@.0@.bss.........p........................`..idata...............:..............@.0..CRT....h............D..............@.@..tls.................F..............@.@..reloc...............H..............@.0B/4......,............J..............@.0B........................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):24903
                                                              Entropy (8bit):4.962246739250747
                                                              Encrypted:false
                                                              SSDEEP:384:iE7EPkzT5bWeZiZ8BWtXDJhVggwB6M389jVsVBKJhQUpH/OMvyqgl/0:iEDNDkztXDJ+lmKj+hhpyqgl/0
                                                              MD5:A9C07424EF0E9C3843221C22FB2A4E96
                                                              SHA1:908FFCFEE50AC6C410F501DC4628B895954827D6
                                                              SHA-256:085230EDE2EEA210F332315B474B1C68164AFFF2F4926885A797FCDF8A4B7546
                                                              SHA-512:9C7B42ACE2674FAE0424F161085DC05B0134D9FC66A4DBAAC2D2181717B983262DF750E8D850B6C1FB43C8E382418641823A2AF7D3B1229F4E3EB1452742BF0E
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........L........&....$. ...F.................@..........................................`... ..............................................................P..L...........................................`@..(...................\................................text............ ..................`.P`.data........0.......$..............@.P..rdata.. ....@.......&..............@.`@.pdata..L....P.......4..............@.0@.xdata.......`.......8..............@.0@.bss.........p........................`..idata...............:..............@.0..CRT....h............D..............@.@..tls.................F..............@.@..reloc...............H..............@.0B/4......$............J..............@.0B........................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):23107
                                                              Entropy (8bit):5.125716149412629
                                                              Encrypted:false
                                                              SSDEEP:384:hE0kYSCFkYTXH8ZdlQVJZ6AhrmMLA3X3g5Oxhtdw9MOMSq:9koFlUlQVJZ6AAHwsrgMwq
                                                              MD5:1183F1C7477504F694A0D6A43BA5829F
                                                              SHA1:3D34696067500C7D6495CD3416177376D8FB7849
                                                              SHA-256:58D950AAC438F5680FBCFCAFACEFC7486D8634E51D08A73D12DE3503A2A87AB5
                                                              SHA-512:3A7E2E26FF441831CEC382A5FD81904182F5C772FE0BF4B2A150036F5C3D7DCC33B6DF2C3F5329733B58FA8941ECE94CD68DDDC316EBF8BEC91E9B251849AEE3
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........L..y.....'....". ...F................@......................................C........ ..............................................................P..@...........................................`A..(......................H............................text............ ..................`.P`.data........0.......$..............@.P..rdata.......@.......&..............@.`@.pdata..@....P.......4..............@.0@.xdata.......`.......8..............@.0@.bss.........p........................`..idata...............:..............@.0..CRT....h............F..............@.@..tls.................H..............@.@./4......(............J..............@.0B................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):125725
                                                              Entropy (8bit):5.184947372474151
                                                              Encrypted:false
                                                              SSDEEP:1536:tH1RLJ38lEm6hoXWVKLGpiAOpkMgu9S01yDNHhKp2iUD7yXkr:tH1XMlX6hoWVKAcC5WeLNhp
                                                              MD5:4075607747B325A89DE53DA052E9D9A2
                                                              SHA1:A56368F3D4ED93927D3571F25E6809DDE3084996
                                                              SHA-256:121F96AFB20F893FAA773B8D5BB2D4E33C5A7DBFC80E6BDFA3968304306A59D7
                                                              SHA-512:F2DA3CD61F2EC3093CB6BCF8ADE3CE99B8BB3225BE6AB133DB9762EDFFBCFE4272BFD5851C86CE4AB8E3455490F06BF12F296C33734ED1E76C71BEA6C77BBBC6
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e.N........'....".0...l................@............................................... ..............................................................p..............................................@[..(....................................................text............0..................`.P`.data........@.......6..............@.P..rdata.......P.......8..............@.`@.pdata.......p.......R..............@.0@.xdata...............V..............@.0@.bss..................................`..idata...............Z..............@.0..CRT....h............n..............@.@..tls.................p..............@.@./4...................r..............@.PB/19......x.......z...t..............@..B/31.....L....p......................@..B/45.....{...........................@..B/57..... ...........................@.@B/70.....q...........................@..B/81.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):678139
                                                              Entropy (8bit):5.649183560529718
                                                              Encrypted:false
                                                              SSDEEP:12288:HoLmyWeO2dGIzOI+qCM42DGKZuY+v6oq718TicdopmxCKQkNQ66353YvVmB9jyK0:HoLoeO2dGIzOI+qC0/ZL+Fv1NQ6AuvVH
                                                              MD5:69E880CE36FF20F597EFAAD5F0DBBFC8
                                                              SHA1:D34CF5D1D3DD92101EDB55E760B922510FC50093
                                                              SHA-256:968580409D9CE48681896CB2B073472154E402F7619AC34BB9E417AF67AA1FA6
                                                              SHA-512:C79CE3380F195261236042CCA12AC76F8C7F7944843E11C7F680B0FC009A401E0840954898CE98C392DE8B36BA267879F58E1482AC0FB4E94E75883618C4767C
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 1%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...Y..e.P........'...."..... ................@............................................... ..................................................c..............4...............................................(.......................X............................text...............................`.P`.data....*.......,..................@.`..rdata..`....0......................@.`@.pdata..4...........................@.0@.xdata..............................@.0@.bss..................................`..idata...c.......d..................@.0..CRT....h....p......."..............@.@..tls.................$..............@.@./4...................&..............@.PB/19..................*..............@..B/31......-...0......................@..B/45.....A....`......................@..B/57.....P%.......&..................@.@B/70......M...@...N..................@..B/81.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):36575
                                                              Entropy (8bit):5.2613733608161715
                                                              Encrypted:false
                                                              SSDEEP:384:ir99D06+Tmdt9Dnws9Bu+hlEnJOg1KATGIEoS+A1UacrL2LSjtV+R+sOOFOMss9O:q9qYVjBuQ6nJHDTGIET+A1UaCRwb15A
                                                              MD5:136A1A91F56672F47DD16C9980FC7BB8
                                                              SHA1:3B22E2EA9AC7EF6EADA2584DA2339120EC96C5EB
                                                              SHA-256:688DA51277925EE0A06C6741E79591FD465BE8128CB61AB94C164D84A395ADD0
                                                              SHA-512:195816FD536C0DA3A40CB65AA40E79709AC7AACFABF9EE8CFE38044271A1FE7C04C71ED24ABD39C158EDD027305F5F040FD929D4B03D3AFD8A1279B183FFBA68
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........`.....& ...".4...~......P..........c............................. ................ .................................................<...............................D...........................`...(.......................h............................text....2.......4..................`.P`.data...@....P.......8..............@.`..rdata..P+...`...,...<..............@.`@.pdata...............h..............@.0@.xdata..X............l..............@.0@.bss....0.............................`..edata...............p..............@.0@.idata..<............r..............@.0..CRT....X............z..............@.@..tls.................|..............@.@..reloc..D............~..............@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):282154
                                                              Entropy (8bit):5.636827130073007
                                                              Encrypted:false
                                                              SSDEEP:6144:FlHWP0bUtZIWqt8DWHs3jhb4wcwl/9ZRvQQEkrl:FNvb+HE8SHs3dv/T58krl
                                                              MD5:7B1FD1057A538352595CCEEFDF681DB3
                                                              SHA1:0E71AC6B2A2BF88B70118C5FA379549F5898CE2E
                                                              SHA-256:459322E7AB737DCCA893C7AD74C6BEE76DECCD86CBDACA0A9527168104DA8F41
                                                              SHA-512:823A07A4352CB119D728C8E65614AC564BFFE28FC0A1B0BDD13D3251032D1C34BECB350AB1C731CD16477A09E637529DCDD57EE8AE33A315803A5FDB055F2B52
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........D..R.....& ...".....>......P..........m.....................................i........ ..............................................................P..L...............`...........................@D..(...................@................................text...............................`.P`.data...p....0....... ..............@.P..rdata..p....@......."..............@.`@.pdata..L....P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata...............4..............@.0@.idata...............6..............@.0..CRT....X............<..............@.@..tls.................>..............@.@..reloc..`............@..............@.0B/4...................B..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):480436
                                                              Entropy (8bit):5.863390700343565
                                                              Encrypted:false
                                                              SSDEEP:3072:54jAh6snCOQPutssC+VE3b7MyXk/Uxl/+cinPSE0xxJuHhkrL:Jh2bh3bLXjxl/b0SNxmh4L
                                                              MD5:4569280F74CC127A0A8570B39A583C55
                                                              SHA1:79CEDE0B9C2BDAD697D59A32F7AA617682221644
                                                              SHA-256:E6DEF34FD302F70B00BF93024A9F85B5DA5947FD055A990E49337F8107A750E9
                                                              SHA-512:EC4EC951CCE30FDEC20CF30EC50632AB1EF69A151CD210A82BAF8371E17DDFA2164F50F2558BFADC9E299B21AFB3780906EBB3876285A9FA7940FD1C37FA0EF8
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".>..........P..........k............................. ......:&........ ......................................p...U......|...............@J..............l...........................@c..(....................................................text....<.......>..................`.P`.data...p....P.......B..............@.P..rdata...b...`...d...D..............@.`@.pdata..@J.......L..................@.0@.xdata..83... ...4..................@.0@.bss.........`........................`..edata...U...p...V...(..............@.0@.idata..|............~..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..l...........................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):19623
                                                              Entropy (8bit):4.673944030439923
                                                              Encrypted:false
                                                              SSDEEP:384:mv9Ds18iwJOzu6b7b7b8eX7u+ogrZMl6vWTnMs:a9gCiwJ4Fb7b7b8/l6+J
                                                              MD5:2EE8B80794D316236B93555E22F7DB69
                                                              SHA1:DBDE31E51C268FBF680134DFC214EACD7F62E7B3
                                                              SHA-256:9F0ED8B986EA820CA7CE46D0219C3309A149D9E030FA6D29C170DD4FDA6BC7E1
                                                              SHA-512:74B9994A196C5A1C3D4110AC16E0EFDF3A415E2FA1E95E98D286C500547560C33B83534723B19533EBBEF45595F4FB166CE73270E1F81FF1248B580930AB756E
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........B..S.....& ...".....<......P.........`c.............................................. .........................................R.......d............P..@...........................................@@..(......................`............................text...8...........................`.P`.data...p....0......................@.P..rdata.......@......................@.`@.pdata..@....P.......*..............@.0@.xdata..t....`......................@.0@.bss.........p........................`..edata..R............0..............@.0@.idata..d............2..............@.0..CRT....X............:..............@.@..tls.................<..............@.@..reloc...............>..............@.0B/4...... ............@..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):3258844
                                                              Entropy (8bit):6.42454283558418
                                                              Encrypted:false
                                                              SSDEEP:24576:mAmPl4tsPSkMJR5qdKgRI9R1j9fHdkkkkkkkkkkJfuBH/v3RN:CMIE2KgGRXuB/P7
                                                              MD5:97503EEC52E517268B6DB695AFA8D8D8
                                                              SHA1:120E26EF681E9DEBF5F1D2704D40788A81374FD2
                                                              SHA-256:46994BBAD2EEFF320BB562EE966E16771ABB22C290DA74A96DFB09C31C619154
                                                              SHA-512:C248A36A0C3D13F98B27A2E5CF6105B8DB239419550A934A07ECD654BF9EF24358332DA807A8B28C4CC1D958324FFF50A96E753F378785D3FAB12C0DE23BD8CD
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........n,.......& ...".....h,.....P..........b..............................-.....R.2....... ...................................... +.Rn....,.L*............)..l............,.p...........................`]).(....................,..............................text...............................`.P`.data...............................@.P..rdata..............................@.`@.pdata...l....)..n....).............@.0@.xdata..H....0*.......).............@.0@.bss....@.....+.......................`..edata..Rn... +..p....*.............@.0@.idata..L*....,..,...4,.............@.0..CRT....X.....,......`,.............@.@..tls..........,......b,.............@.@..reloc..p.....,......d,.............@.0B/4............,......l,.............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):189301
                                                              Entropy (8bit):6.223989300733396
                                                              Encrypted:false
                                                              SSDEEP:3072:1J9ouvsbVQ8LlubhgpYnnAlZQAB9tWAQmM3f8jWgwls/EASfmM1M:TeuvsrluChXWAbMmWgwlsyfmM1M
                                                              MD5:3EAE841634062119D9F09890580AAA40
                                                              SHA1:A69EE63792A36E786C9F4540925FAE78E77700C3
                                                              SHA-256:F028BBE17E13A724C1B27352C0A913E011C5AEC795ACF2ED7716165E23440BFA
                                                              SHA-512:E162424FF00EA9C8481207E599D58BEA87A445E8263511703E2A84280B9520BFDE55797D45DCF6971D64BD248EFECC0BD7EB653D3A3AF0E0E53CAEDED5E00434
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".R..........P.........<f....................................`V........ ..........................................6...@...&..............................................................(....................E...............................text....Q.......R..................`.P`.data...p....p.......V..............@.P..rdata...!......."...X..............@.`@.pdata...............z..............@.0@.xdata..............................@.0@.bss..................................`..edata...6.......8..................@.0@.idata...&...@...(..................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B/4...... ...........................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):37287
                                                              Entropy (8bit):5.541612106723831
                                                              Encrypted:false
                                                              SSDEEP:768:69T5p6gZwB4FJgoeVsSRiRlDkg4jJu3YJ:6p5twIJeVsSRiRlD3YJ
                                                              MD5:74E656742519434DCBAD979D8A28EE65
                                                              SHA1:E280BF8CD118F2CB932FFCA660250F83C94DF282
                                                              SHA-256:93595FFC5EA945EB39E6D571A8225DA2C53935A58B1A408D29AB3BF6774DB26E
                                                              SHA-512:5A14FB1349CB351F972A3EDC69BE2AB81B6639E078FB7B6078746BE9E5B5C63A0F78CAA6B394677721E9159D57602A0B0C2D369D30896AE99CB8205CDA52B6C7
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........p........& ...".....j......P.........,d...................................."&........ ..............................................................p...............................................R..(....................................................text....-..........................`.P`.data...p....@.......2..............@.P..rdata.......P.......4..............@.`@.pdata.......p.......F..............@.0@.xdata...............L..............@.0@.bss....0.............................`..edata...............R..............@.0@.idata...............\..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..reloc...............l..............@.0B/4...... ............n..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):105157
                                                              Entropy (8bit):6.173482003245648
                                                              Encrypted:false
                                                              SSDEEP:1536:xz5xbJG9dz8m9opYJEPs4qA4dbV0z3kNLpHMB4Q6lzS:nXG9dzrqyhA4dbVoUNLvQ6lm
                                                              MD5:660808EBEEB271E6C52DAEF5048CAC1A
                                                              SHA1:A3C7B956267E1238A7DB96B5E3E537DA2E683C74
                                                              SHA-256:68D482F13EA30586C0F487563324E894588C379A2999D0004EDD7028B1ACF270
                                                              SHA-512:4367662A1678CF219D0CB0C77D9009610DCB8BBCACC93A94674995525DD3C4D049250893F27F2F96B63CDC873993524E05EC429066C08EA34AE0407713D8131D
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........^........& ...".....X......P..........e.....................................J........ ......................................p...)......\............@..............................................`"..(.......................X............................text...............................`.P`.data...p...........................@.P..rdata....... ......................@.`@.pdata.......@......................@.0@.xdata.......P......................@.0@.bss.........`........................`..edata...)...p...*...$..............@.0@.idata..\............N..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc...............Z..............@.0B/4...................\..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):38124
                                                              Entropy (8bit):5.754263910108255
                                                              Encrypted:false
                                                              SSDEEP:384:bb9fNGZtlEhKZkWnyvVLPC5fvcdJ9nPEfaNcZJOWS7BhrOypAIra55M/Fu:P9fNGZ8sytzUfkdJ9nsyeZJFeAI1Fu
                                                              MD5:3387FBF9D240CA0D69439AA7A56F7E37
                                                              SHA1:9EB30567B61E8C86C69B078BDC3FA725622914E4
                                                              SHA-256:4A1F150220CC745828F15A6F77FC16DCA0D4B9C4B3E44690CDA2129D6C0A190C
                                                              SHA-512:694B896D906D821DD9F3B682869FA3194D49768A1275C51657E9300219D0D1F9144DE74021870BF5C35CED0AD37A7C1DE437F66EEA446BD1F86EC523C30C8027
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              • Antivirus: Virustotal, Detection: 0%, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.X...|......P........................................ ......F.....`... .................................................................D...............|...............................(....................................................text....V.......X..................`.P`.data...p....p.......\..............@.P..rdata...............^..............@.`@.pdata..D............h..............@.0@.xdata...............n..............@.0@.bss....p.............................`..edata...............r..............@.0@.idata...............v..............@.0..CRT....X............z..............@.@..tls.................|..............@.@..reloc..|............~..............@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):33498
                                                              Entropy (8bit):5.564451442653682
                                                              Encrypted:false
                                                              SSDEEP:768:d9e9z3adJ9Pr5gSs1xAdyburYRsyztJPZYuH2A:duz3q9PWSsDssJBPHv
                                                              MD5:45F1A65ED814C0C86BC4A4616E1BA6D9
                                                              SHA1:B9C0B4F327BF2F0D0E9E468CC967B17918B045B3
                                                              SHA-256:1FD3AD4C979DE56174B07504C34D573E3824839198BAAA06473E88646B792ABB
                                                              SHA-512:7B0EBF062CDC9828C70DEBB8227981D530064801445FE10FE2D9AD9F51F1292A73102A6755B8364EFB046246B41B89475EC9EDA62F19CE3BD31A8770418F6980
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........v..l.....& ...".F...p......P.........dl............................. ......z7........ .................................................................................`............................s..(.......................@............................text...@D.......F..................`.P`.data...p....`.......J..............@.P..rdata.......p.......L..............@.`@.pdata...............X..............@.0@.xdata...............\..............@.0@.bss..................................`..edata...............^..............@.0@.idata...............b..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..rsrc................l..............@.0..reloc..`............r..............@.0B/4...................t..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):176338
                                                              Entropy (8bit):5.875368464272613
                                                              Encrypted:false
                                                              SSDEEP:3072:F2VVCzpF/ktxFBnU2ZZCI5/3J+g9ur5FXsF8T:skmH1llJorvsOT
                                                              MD5:08B8E206C57E35B95B2F4576BFDA978A
                                                              SHA1:1EFF2F6FCD53454A2AD3D8AF4679E0C355872DDF
                                                              SHA-256:B85BA4EC193B955E6FF36EC9A14B3F60E52F7BFFE867C9FA1932040D3621F2C9
                                                              SHA-512:4EF74B038706CFD507DD79B5A59F849C2AA4EE479C1EA8A83257956FE8A01F6A434F86F75DA951167FF746C52E6870B27D571EAF8305345DE0A877FCF800A675
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........>........& ...$.2...8......P.........d.....................................q.....`... ......................................@...(...p..........0...................................................@...(....................t...............................text....0.......2..................`.P`.data........P.......6..............@.P..rdata..P....`.......8..............@.`@.pdata..............................@.0@.xdata..`...........................@.0@.bss....0....0........................`..edata...(...@...*..................@.0@.idata.......p......................@.0..CRT....X...........................@.@..tls.................0..............@.@..rsrc...0............2..............@.0..reloc...............6..............@.0B/4...................<..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):103974
                                                              Entropy (8bit):6.153679599111177
                                                              Encrypted:false
                                                              SSDEEP:1536:L07r8Vg7wsNwmUMdKx7l13XsGYrHlJLP/+8EjYmkWQZz8LfQ2M:ar8/sNRdKZ3cGyD1MYcQ6LhM
                                                              MD5:08E0C9D5520049AAD2F459E606D9B8EC
                                                              SHA1:09F48177670ECE6250FB28257FC10D4A23D85FB4
                                                              SHA-256:2964BAE4C347877437E4DBEF9D21C2096AC11D1C19D8538DAD368B1325B06B10
                                                              SHA-512:50BACCA09961BAB4B378EF1C8E9E63F4742B8FA9DB01532EC7DF1E0F0C32B3C36B105126A31A9720DD510887C011BF3B8F595EC262BB217D8703F2332B05C661
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".....z......P..........i............................................. ..............................................................p..H...........................................@[..(...................................................text....-..........................`.P`.data........@.......2..............@.`..rdata..p....P.......@..............@.`@.pdata..H....p.......\..............@.0@.xdata...............d..............@.0@.bss..................................`..edata...............l..............@.0@.idata...............p..............@.0..CRT....X............x..............@.@..tls.................z..............@.@..reloc...............|..............@.0B/4...................~..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1159948
                                                              Entropy (8bit):6.380882269309101
                                                              Encrypted:false
                                                              SSDEEP:24576:mqeK7qOibql/URQe+M/SyM2m/AHuwjf9i1:mqepOiul/Uufl2m/WuwZi1
                                                              MD5:F4CF11F766C87EB2EFB91B7BE2DBFFF7
                                                              SHA1:A8669D5EC09AEC531C6EFB4A8BF96BB81FBEAFD3
                                                              SHA-256:7B4ABAC4119866130CFD3254367E0C35FAB1987A11E7B311091FF0E3664D246F
                                                              SHA-512:62BE9CFF51A52C8089A7EB62A46C3C6D3E3C050C6745CCCAC8AB32E775518B055C08E1C4FFFB86DB617806929A1493966BAFB9092E2835D4D3DECBBFFCB9B7F6
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........0.....& ...".........$..P..........h.............................`.......D........ .........................................R9.......-..............|t...........@..T............................@..(....................................................text...............................`.P`.data... ...........................@.`..rdata..`...........................@.`@.pdata..|t.......v...f..............@.0@.xdata...}.......~..................@.0@.bss....."............................`..edata..R9.......:...Z..............@.0@.idata...-..........................@.0..CRT....X.... ......................@.@..tls.........0......................@.@..reloc..T....@......................@.0B/4...........P......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):38449
                                                              Entropy (8bit):5.168362177112994
                                                              Encrypted:false
                                                              SSDEEP:384:3vi9UsYYoqFP8/DWHJOgxxeBDLi5RPdfEq0+z+HeeyoEhytykWrcDaWIQdtkMK:fi9PKsU/DWHJRxeM1F0ZeelEnWzdtW
                                                              MD5:416CABF3237F1C63701659B0B8B93DDE
                                                              SHA1:130BF60FBEF1DD6A4BFE9C544C7EC835FAFE083B
                                                              SHA-256:D2AFBDDF69FEC5AB9234406538745952BF74FC3DDE6A7FACA72A71E1BFB51540
                                                              SHA-512:9C972681E9D35DD33135C3F71DC0FE9205DC60116FC2D6488E85C464665FE0E313DE70B7B919B35070C650A81C04BF80463E112925A84190233A490B73263A76
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........|.....& ...".&...~......P..........l............................. .......8........ .................................................h...............`...............<...........................@|..(...................,................................text...x$.......&..................`.P`.data...p....@.......*..............@.P..rdata...4...P...6...,..............@.`@.pdata..`............b..............@.0@.xdata..8............f..............@.0@.bss..................................`..edata...............j..............@.0@.idata..h............p..............@.0..CRT....X............z..............@.@..tls.................|..............@.@..reloc..<............~..............@.0B/4......$...........................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):177321
                                                              Entropy (8bit):6.103041427092698
                                                              Encrypted:false
                                                              SSDEEP:1536:lO7waXMpkl4zNyZB/nA5jft1RxdJuUswu7ZIdk+Cwjcf15smC3dxK9ZPGqR3530:paYLNy/n6zPQZVIPCwju15sJqn3Z0
                                                              MD5:B7D2A0436FCD11C93A670C537A7CA3F9
                                                              SHA1:7E3F485D16D4186C965F6CF3687117E8A4FA2B81
                                                              SHA-256:CAFF90F100117E14B80B569A97E271B5B20BF9F9CEF40DC3DE95A3C788DCBA53
                                                              SHA-512:9C770CCD6733CA1FA9832618F7539CACD840AA4E9585FC31AC16E48353A9CC30B04B17BB92C08E26A54F6AA5179630BFBF2898149AB7B4726989EF863A933DFB
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........d..p.....& ...".....^......P.........0m....................................`......... ......................................`.......p...'.............................. ........................... ...(....................w..P............................text...8...........................`.P`.data... ...........................@.`..rdata...=.......>..................@.`@.pdata..............................@.0@.xdata..T....0......................@.0@.bss....@....P........................`..edata.......`.......$..............@.0@.idata...'...p...(...0..............@.0..CRT....X............X..............@.@..tls.................Z..............@.@..reloc.. ............\..............@.0B/4......,............b..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):45016
                                                              Entropy (8bit):5.826549834253712
                                                              Encrypted:false
                                                              SSDEEP:768:Y9fxr0RJSwxvvDUwPOcnstT2jSVfmVq7YYAtG+oD2OFSATVyHjprL1P:YDeJBxvGcQSjukq0YKB
                                                              MD5:5D694EF2B4A8485DBE7B999E9D157BEB
                                                              SHA1:A76B953E82A52191D4E2E314DA08A6AA7AADD1BB
                                                              SHA-256:9BC68903CD383D9433E20EBFDAEDD7E840B0CF09D1BB4B51C3C9EED2CDF1EBF4
                                                              SHA-512:97BCC2654655D82212891A2B3D679D849397BB55052A5A9CE95745AD8D2A92ABD37A3BCBCFF7A60E9495CEF229C5D22CB24FDC8655E0F4726BD46C7F1F5DDD41
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".n..........P..........q.............................0.......)........ .........................................w.......................P...............`...........................`...(....................................................text....m.......n..................`.P`.data................r..............@.P..rdata...............t..............@.`@.pdata..P...........................@.0@.xdata..............................@.0@.bss....p.............................`..edata..w...........................@.0@.idata..............................@.0..CRT....X...........................@.@..tls................................@.@..reloc..`...........................@.0B/4........... ......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):217543
                                                              Entropy (8bit):6.262587386570798
                                                              Encrypted:false
                                                              SSDEEP:6144:5WUtMhIF6VVJ1a4XD2zfAEJdZmNBuS7UHPCS:EUtELValJrSMX
                                                              MD5:07DEB7B6C536FA43AE2C1A6ECCF14161
                                                              SHA1:B89FA56216FC1E89D8E302A2ED9FD197FA86B07E
                                                              SHA-256:1A846C6EA8FA60198C4E0FBB6F0521EC717B33E956D19E369DA853FDC3E0F237
                                                              SHA-512:4F791B9727D4130389012F71F4AAEAA90F97CC11B645D2EBDD4528F80C9CDC0A591D2AB4E795E866A4F8242A6FCA4FC76F70CC4F62BD9912518C922EFB15B5F1
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".B..........P..........h.....................................)........ ......................................P.......`..............................................................@...(....................a..x............................text....A.......B..................`.P`.data........`.......F..............@.P..rdata..p....p.......H..............@.`@.pdata..............................@.0@.xdata..x....0......................@.0@.bss.... ....@........................`..edata.......P......................@.0@.idata.......`......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):30127
                                                              Entropy (8bit):5.545406166525639
                                                              Encrypted:false
                                                              SSDEEP:768:Ik9iadsHIeD3LSYjUVqS76xuDVhT0Jn+j5:lxso/9/JmJn+j5
                                                              MD5:DB43E0C412AF2682E720248B06258BD1
                                                              SHA1:198A9E8CEE03FE28846D81C50B16EC3C7F8119C7
                                                              SHA-256:3F525E791A423AE43707D19B4A635DC6526A005D83E90EB471A3FED83934D985
                                                              SHA-512:C8356E95E096BCE12B8C574ECAB67B834F3D5F928909BDE473819E5A0C39D0718D044F3E2B8E77D8AEAABBF2419CB7C5F9CAAB49112DB4D03F9DB348540C2D76
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..S.....& ...".D...f......P.........tk....................................j......... .................................................................d...............l........................... r..(....................................................text....C.......D..................`.P`.data...p....`.......H..............@.P..rdata.......p.......J..............@.`@.pdata..d............V..............@.0@.xdata...............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............`..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..l............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1153736
                                                              Entropy (8bit):6.016402131360048
                                                              Encrypted:false
                                                              SSDEEP:24576:pZUQ+U8i1uEvhr/cuHsSeMc5mQMeJh2ZVIKfck9:pB/R1u/uMnoeJM93
                                                              MD5:EFF9D6946942E8F7775828A1756B0B6A
                                                              SHA1:C4D07A5F7DBBEC4817EB151B2D5A857032AC17DD
                                                              SHA-256:F21653D274C3DDF86E2AD1DA7F137DB83B30A3967BAAD61F801899BF06AE7796
                                                              SHA-512:25F02F739C6A2F7FF6C8E0B05B89B9BF478FDFA7584FE2FC100EDC1AAB694F1ECE33BC51915084809807C34B882EB69C347B0D06F40D92AA5E019AEE62966813
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P.........hp.............................P.......W........ ..............................................................0..h=...........0..................................(....................................................text..............................`.P`.data...@...........................@.`..rdata...Z.......\..................@.`@.pdata..h=...0...>..................@.0@.xdata...^...p...`...L..............@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.......0......................@.0B/4...........@......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):345584
                                                              Entropy (8bit):6.062856786074557
                                                              Encrypted:false
                                                              SSDEEP:6144:auBYK0UHvIIM07TlBmO8NqSlsHp9NZqMG2:aFevrj8OhZ9G2
                                                              MD5:3109524E67A7F8FA6A2FB1DBCA23FC6A
                                                              SHA1:57DBB8755F253184B2546F2D86ABE4400E9515AE
                                                              SHA-256:317CFC114580BCDAB4EE24B39EBA2B87FD3F0B0C7978CC4E44231F77AA610B5C
                                                              SHA-512:8047A7967089B25FA3B3270A8F68B486929967CDAD8F12F08840218F6FF24BDDED452EE6400C2489CC9B6766093B493C3D53432787D5136BD84CA16CDEF07080
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........f.....& ..."."..........P..........d....................................T......... ..............................................0..................| ...........p...............................b..(...................$5...............................text....!......."..................`.P`.data...0....@.......&..............@.P..rdata...0...P...2...(..............@.`@.pdata..| ......."...Z..............@.0@.xdata..` ......."...|..............@.0@.bss..................................`..edata..............................@.0@.idata.......0......................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4...... ...........................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):774548
                                                              Entropy (8bit):6.418408919486473
                                                              Encrypted:false
                                                              SSDEEP:12288:vhFhyNWbJk9/WRTB47uHAFuzlavIeD/SWTD7fEWmPmDWNGbmls:vhFhy79sEF8l187TDQZ5W
                                                              MD5:51797D661B4CDF3DD08BFD497EAAD017
                                                              SHA1:9953A69C8B8136DBA08F392908B895980293E701
                                                              SHA-256:0FBE942A4FFD237B7B2482F8A046CA633D3B18A8B79E5A2CCB4255F7D8DFF9A5
                                                              SHA-512:E04DE093BF6C0E8BC49C0CBBFD50DDBC6167161CDCA60733ECE2731C710D9EA50B614F2A71A99B497236AF99EC7B5D08D4EC29BD5A04FF8459276B62AA359CBE
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........4.....& ...".2..........P..........l.............................................. .............................................. ..T....P.......P...C...........`..0............................4..(...................l#...............................text...(0.......2..................`.P`.data........P.......6..............@.`..rdata..p....`.......8..............@.`@.pdata...C...P...D...&..............@.0@.xdata...E.......F...j..............@.0@.bss..................................`..edata..............................@.0@.idata..T.... ......................@.0..CRT....X....0......................@.@..tls.........@......................@.@..rsrc........P......................@.0..reloc..0....`......................@.0B/4...........p......................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):43441
                                                              Entropy (8bit):5.406163163366608
                                                              Encrypted:false
                                                              SSDEEP:768:j9UMlqf8MtMy4UrLSBusVUQSpJ9n1wDEpf+Q+cfM:jKMlqYz3oJqUf+H
                                                              MD5:3E73162C0CFED3D76E4D194FC5F5F183
                                                              SHA1:20DEEB5278913764CCA7EB4DE1AB8D9DBE65E372
                                                              SHA-256:F90A3BB9280873A248F38D54431F46E152A7B634F4C6773A0C41952853CCD60A
                                                              SHA-512:27B6BB3D65A953D4E19BD7ADC3B5D33EBDE644E590A61553736D5C004102A098FFB6E697F23803BA3ED8D48EFA6771C54C3E16601CBDE091F1E41B66CDDF9FB1
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".T..........P..........j.............................0................ .........................................`.......................................`........................... ...(....................................................text....S.......T..................`.P`.data...p....p.......X..............@.P..rdata..P............Z..............@.`@.pdata...............d..............@.0@.xdata..0............h..............@.0@.bss..................................`..edata..`............l..............@.0@.idata...............p..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..`...........................@.0B/4...... .... ......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):565393
                                                              Entropy (8bit):5.1066638213809545
                                                              Encrypted:false
                                                              SSDEEP:6144:kwYmYW8e1aCKZ260YZ2OH5ufzyW7VoVxu7fjYd8wsrTbz3slPoxYHwdORaNEO:ezXe1hKZIOHkHalPoxYHYEO
                                                              MD5:EC5082EFD58FEA602DD97CD824D3D9B7
                                                              SHA1:E4CA5AE2C7513303D8046C98B9C973E79E3C0124
                                                              SHA-256:F79BF5E08C71F1DB0735A22AB7DFB6751A82545BFAF1C70FBC18CF99B45B187B
                                                              SHA-512:95B244FA646821DE6D5D980AF2BE92B3E5DB404C7175CE713C3FE7703A2124F8918E1BFEA8A0EADAFFEABA994BDC0E44B748C4E291568DB9769B20E11C36FDFD
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...3..a.f........& ...".....>......P.........Da.............................0......(......... ......................................p.......................@..................`...............................(.......................@............................text...............................`.P`.data...p...........................@.P..rdata..0*.......,..................@.`@.pdata.......@......................@.0@.xdata..H....P.......$..............@.0@.bss....0....`........................`..edata.......p.......,..............@.0@.idata...............8..............@.0..CRT....X............>..............@.@..tls.................@..............@.@..reloc..`............B..............@.0B/4...................D..............@.PB/19......!......."...Z..............@..B/31.....Ba.......b...|..............@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):842229
                                                              Entropy (8bit):6.347233803892302
                                                              Encrypted:false
                                                              SSDEEP:24576:hs2Yj10eBIFszwJEwbPDY4TARDj8M2SRTpBPCJ:HFszibnTAR/8MppBPG
                                                              MD5:4475108D84CCBB397F11956BC69C5D7B
                                                              SHA1:C8B52585429F3A3343262E690D9013F928D594D0
                                                              SHA-256:62D4939BE3E82B8EBE6E731BE3D8C45FABDB6E64B739D2FA64C3045FEAC64D8C
                                                              SHA-512:BFF43FDF3E1DBF531F82C4F4C208E7C90CD44A0FE813224B5BA8FA839B160D509E080DFB8D01354FCC0B3D7F46AFB62BC4A0B79A11116BC320DB4409D140BB20
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P.........4l.............................@................ ..........................................b...0...[.......h......<H........... ..L...........................@d..(...................tC.. ............................text...............................`.P`.data...............................@.`..rdata.. .... ......................@.`@.pdata..<H.......J..................@.0@.xdata..|F...P...H... ..............@.0@.bss....`.............................`..edata...b.......d...h..............@.0@.idata...[...0...\..................@.0..CRT....X............(..............@.@..tls.................*..............@.@..rsrc....h.......j...,..............@.0..reloc..L.... ......................@.0B/4......$....0......................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):247824
                                                              Entropy (8bit):6.1658005510125395
                                                              Encrypted:false
                                                              SSDEEP:6144:zTYOIokau6RgMRDAy6A/52h+y8moldlGVrSh:zpI/xKgMtAJ+kVrSh
                                                              MD5:E75939B59B63E8CC8BC33AEE9CE71315
                                                              SHA1:A080DDBB1BC3FC58366A04E2488B751B58C16EE7
                                                              SHA-256:2FE733D3772E6426014D9A89FF4725D5AA787CE545EBC4C38D3794645A7F9ED2
                                                              SHA-512:DB52BDB33154840195B8FF4C03B90E5D2C6EDF52A95EF7A9A968960289CF4E15120A30AE7AEBB52D965CEB383ACEF5C91204967543519913AF6FF9360C17C3B5
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........ ..F.....& ...$.&..........P.........D..................................... _....`... ...................................... .......@...2..............................@...........................@...(....................J...............................text....$.......&..................`.P`.data........@.......*..............@.`..rdata..0q...P...r...,..............@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata....... ......................@.0@.idata...2...@...4..................@.0..CRT....X...........................@.@..tls................................@.@..rsrc...............................@.0..reloc..@...........................@.0B/4......$...........................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):466711
                                                              Entropy (8bit):6.054309228794742
                                                              Encrypted:false
                                                              SSDEEP:6144:lpf3LOMBhLY/RCyrWz+nhwdyxq4+SeGH9KDnfP2daNHgOLdPkMOPbBUrR:lR7FM/l+AKLXJ3RumF
                                                              MD5:5A49616AA5CEE62E9446BAE37B746F6D
                                                              SHA1:65BC9993ABAB3B7F6E0B4E8321BC0BC62D846B46
                                                              SHA-256:AA366E9BBCEE47A5F52C6425539B427CE0F94E12AF3DF62F54B180D09F06A5DA
                                                              SHA-512:EE0AE0E07C25FA34850375DF5B5D845FB1BFB7165287F286EE29F02AFE5D3DB8F9703A7CA0ED7731D8A49710683ED2234FB4A7C67072BD9F2BFFB37470DF8A15
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.l..........P........................................`...........`... .........................................x....................p...F...........@..,...........................@]..(...................\...X............................text....k.......l..................`.P`.data...@,...........p..............@.`..rdata..`...........................@.`@.pdata...F...p...H...Z..............@.0@.xdata..L0.......2..................@.0@.bss..................................`..edata..x...........................@.0@.idata..............................@.0..CRT....X.... ......................@.@..tls.........0......................@.@..reloc..,....@......................@.0B/4......(....P......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1735073
                                                              Entropy (8bit):6.312685645644657
                                                              Encrypted:false
                                                              SSDEEP:49152:T24GYHS/8FT60qvkT97p2ER2iptNzvEMTEpajBj27W:XpFqvw7pXZtpvEkBj27W
                                                              MD5:855C789C5C95B1DB4DC71079A7DDCCA6
                                                              SHA1:138B6607053188DBCBC2CC66F60FBFA77FB08CE9
                                                              SHA-256:1C3C2DBDF6AE20D090D64FA4970DF505F054196EEDC605D5AF862BE9E6E5F247
                                                              SHA-512:7396936D59CEBC92AAFCC0041B5AD1DA23F2EF965AFD607820E5C783D597A975A5AFDAF4372A88BB0AB937C3995DC144CA42F03A94B5E4C284B2DBCED679E505
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.z.......8..P.........*...........................................`... .........................................\.......P.......`....................................................o..(...................d...8............................text....y.......z..................`.P`.data...p............~..............@.`..rdata..@...........................@.`@.pdata..............................@.0@.xdata...............x..............@.0@.bss....p6...p........................`..edata..\........ ...D..............@.0@.idata..P............d..............@.0..CRT....X....p......................@.@..tls................................@.@..rsrc...`...........................@.0..reloc..............................@.0B/4..................................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1264018
                                                              Entropy (8bit):6.284739836376171
                                                              Encrypted:false
                                                              SSDEEP:24576:0JhIYfp45umxRIoYEb+0EIrLVeUtvMiQ3KYuue32c+bGA2n20:0JbuRIoYEb3Eo/tvDQhe3PA2n20
                                                              MD5:2A952363638A702792FD3E3F01FBB294
                                                              SHA1:7D8C696E187231B95DE431CAFF5CF160584B0D9B
                                                              SHA-256:8E77DEE5D08D38AF2A3996872AAA3802F5BBEA746F3BC069BA336162D4E6B271
                                                              SHA-512:7F192C5238F0F04583BF18504E1E33060FE558751754CF49165A20A231EC7CE05D87057BA911BBE105289D9228233FC9748C8C9BBD95A52C81CA87DEF2793B4D
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.:..........P........./..............................P......U.....`... .................................................."... ..........@k...........0..................................(....................................................text...@9.......:..................`.P`.data........P.......>..............@.`..rdata.......`.......L..............@.`@.pdata..@k.......l..................@.0@.xdata...e...p...f...V..............@.0@.bss..................................`..edata..............................@.0@.idata...".......$..................@.0..CRT....X...........................@.@..tls................................@.@..rsrc........ ......................@.0..reloc.......0......................@.0B/4...........@......................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):27553
                                                              Entropy (8bit):4.972781576756485
                                                              Encrypted:false
                                                              SSDEEP:384:fp9GJSnNu9Kl4QATk8SJ5JOCmWQ1kk4phBoMdWuNggUMvoRm/+:h9GJSNTqFjSJ5JTrzdNxoRm/+
                                                              MD5:07CA708B4DEF1C6F3DFDEA61695D8839
                                                              SHA1:45E62109538EC88DF7C7C73E3C0AD6CAB76A6705
                                                              SHA-256:69D7F3408899AD807C2C8C32D216E7656717DF3B17AAA23665F2D753C2ACEA21
                                                              SHA-512:84F1AC0CE0B8F86BB841300512F8EAC671798466250C0D23D7BD7FA6B962D3426406ADFB49C6A4F5CE42556750CC78F91EB77868C207E9101E9EFF4C28815158
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........T........& ...$.&...N......P...............................................t.....`... .........................................O...............p....`..@...............`........................... R..(...................l................................text...($.......&..................`.P`.data........@.......*..............@.`..rdata.......P.......,..............@.`@.pdata..@....`.......6..............@.0@.xdata.......p.......:..............@.0@.bss....0.............................`..edata..O............<..............@.0@.idata...............>..............@.0..CRT....X............H..............@.@..tls.................J..............@.@..rsrc...p............L..............@.0..reloc..`............P..............@.0B/4...... ............R..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):331396
                                                              Entropy (8bit):6.18993407003996
                                                              Encrypted:false
                                                              SSDEEP:6144:dIFL8cCAcE773yLLezHU6ChvVd0kN9KufbOMp7fPQlcKHyL+cRVj9wUdaguqhAGQ:dI98cCjE77gok1Bdf79KCHIqhAGQ
                                                              MD5:2FF0DD6DA2BE0FFDAD5BE741D4670EEE
                                                              SHA1:7FF3EB6F67E63662789137CEE296966409EB83D2
                                                              SHA-256:6097E384FC2660ACC07448D76254ABEDD2ACC5EEA94F7CDD5164F78CDEF15FF5
                                                              SHA-512:39009AB8D5D37AB193ADF0CB583AE5F1E7B4E9954B2AF76B230A9FBA7333B647D0CC830EFF94E87B38708E5EDCCDC5595A09F4DD81692062B7C57E7CF5D897EF
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........H........& ...$.....B......P.........u...........................................`... ...................................... ..;9...`..................\(..............X...............................(....................f..@............................text...x...........................`.P`.data... ...........................@.P..rdata..,...........................@.`@.pdata..\(.......*..................@.0@.xdata...!......."..................@.0@.bss..................................`..edata..;9... ...:..................@.0@.idata.......`... ..................@.0..CRT....X............:..............@.@..tls.................<..............@.@..rsrc................>..............@.0..reloc..X............B..............@.0B/4...... ............F..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1620492
                                                              Entropy (8bit):5.399586686416974
                                                              Encrypted:false
                                                              SSDEEP:24576:H3lS39D/rMnrwg1KcArDfPJ3NEqOyu0w6:A9wIPJayu0w6
                                                              MD5:3E9127BCFF638781329AC5EB55F93F22
                                                              SHA1:A89D99F3EB77899502D52E4F56A090C6C548EE1C
                                                              SHA-256:2F29E7E72B3D21B47FF3F7691602FB07799B667101D9081004C7FCC6211EFA84
                                                              SHA-512:57A9456B3EE9B862E47404F7E683ADBD78D1F3CE5457DB7F98446E17CD18E93BEAC97FCE14899A673628E62A7D5F3614C8DCE0AA0B8C5217AD84A67DEEB2966F
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...O..a.J........& ...".....~......P.........`c.............................................. ..........................................4................... ...!..............................................(....................................................text...H...........................`.P`.data...............................@.`..rdata...C.......D..................@.`@.pdata...!... ..."..................@.0@.xdata... ...P..."..................@.0@.bss..................................`..edata...4.......6...<..............@.0@.idata...............r..............@.0..CRT....X............~..............@.@..tls................................@.@..reloc..............................@.0B/4..................................@.PB/19.......... ......................@..B/31..........0......................@..B/45.....PO.......P...N..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):18693
                                                              Entropy (8bit):4.528202239487991
                                                              Encrypted:false
                                                              SSDEEP:192:3zd+9NcoRdTD+NkSEQVJYZ4D5JOgZQYS5/5WrcrDuTxadvlnv1fDSMy4gxc:3zI9FloEQk65JOdZ/5WrcfuTxIvYMb
                                                              MD5:FDC4D49ED1B3032B025CFF09A95B8F83
                                                              SHA1:BEAB58D6EF9A46640AFDB107100DBFDECBC15517
                                                              SHA-256:65514E4D72D0D8061E902DFCDFE3808DA50B4F32E656AAD6DFA9995F3806ECD9
                                                              SHA-512:E869246563A585B2C4C5AA69C832850E635D91AA31549DB6F7FB8D0DB5776D047D8888A67EAF950B1AD74AD8499530CA5F13EA1DC4294F514A328681200A8DF5
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........<..g.....& ...$.....6......P...............................................m.....`... .................................................<............P..................`........................... A..(...................L................................text...............................`.P`.data...p....0......................@.P..rdata.......@......................@.`@.pdata.......P.......$..............@.0@.xdata..0....`.......&..............@.0@.bss.........p........................`..edata...............(..............@.0@.idata..<............*..............@.0..CRT....X............0..............@.@..tls.................2..............@.@..rsrc................4..............@.0..reloc..`............8..............@.0B/4...... ............:..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):4508683
                                                              Entropy (8bit):6.433770562702181
                                                              Encrypted:false
                                                              SSDEEP:98304:SttjZcj4G2MPzQNPhD6FfXmnsG2LtZZBHtlfZe:qusPPhD6FfXmnsG2LtZZBHtlfZe
                                                              MD5:B5095CCB9599617A9B73FD30FA18D3DC
                                                              SHA1:FFDCC0D95ABBD832A8C17CEF0BE3F3D9E090C51F
                                                              SHA-256:029BBDA30C6831A99623232D4AEB571FEB40BA25D23EB415F267A95A88E8CD23
                                                              SHA-512:83115869979F94BC3D16AAD01F137F5D9E33D048BB89E29A43F14BB7EA30E8832A6F937C2C034F71CED4486057BB59044E354951E314E9045B715CE3E02C8D57
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........=..-....& ..."..'...=..6..P.........xa..............................=.......D....... .......................................:..>...@<.p,....=...... 6...............=.............................@.5.(...................tv<..4...........................text...8.'.......'.................`.P`.data...0....0'.......'.............@.`..rdata.......@'.......'.............@.`@.pdata....... 6.......5.............@.0@.xdata........7.......7.............@.0@.bss.....4....9.......................`..edata...>....:..@...~9.............@.0@.idata..p,...@<.......;.............@.0..CRT....X....p=.......<.............@.@..tls..........=.......<.............@.@..rsrc.........=.......<.............@.0..reloc........=.......<.............@.0B/4......$.....=.......=.............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):27409
                                                              Entropy (8bit):4.964297349134333
                                                              Encrypted:false
                                                              SSDEEP:384:p7Ic9A27Fd1w/wTfz1rJO8CVDccHxr6R+vHM5q:pMc9z/1wY7hrJyHG+4q
                                                              MD5:67D79C4B05FB25A1949BB393A2B16CAC
                                                              SHA1:DE7076655702E9846FD9F159BF8F74D4CBE76CA7
                                                              SHA-256:26056FA23BB2935D82704C1327B8CC77DE198E8280A6D6C96E9C20ECDC547C68
                                                              SHA-512:8343A5C14BE3491ADE0E1A8BD6BC08C9BEB62F53FF38D92CEA7D47E364F781BC286A1EF847EB8698D168DD84E47CC7664F7F7251D86545CEB19A38793BC5356F
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........P........& ...$. ...J......P.........$...........................................`... .........................................,....................P..|...............`............................B..(....................................................text...h........ ..................`.P`.data...p....0.......$..............@.P..rdata..@....@.......&..............@.`@.pdata..|....P.......2..............@.0@.xdata.......`.......6..............@.0@.bss....0....p........................`..edata..,............8..............@.0@.idata...............<..............@.0..CRT....X............H..............@.@..tls.................J..............@.@..reloc..`............L..............@.0B/4......(............N..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):499812
                                                              Entropy (8bit):6.128024272252829
                                                              Encrypted:false
                                                              SSDEEP:12288:yvl6cydAiGIbA5C4L6dPR6tHKxxoxHNSX:4lzydqIbcC4LTHrNSX
                                                              MD5:CC9D06CD608B52CEF68081D0116531AE
                                                              SHA1:2921D881276A9E4E4B0F464F7577A87A1775B7E2
                                                              SHA-256:05EFF375B699F1859345A57D12DD69A7BBA400227AD390EC5457450AF8164938
                                                              SHA-512:682019587CC19CE6B8714820C9ABA9432F3F02CDE8CB46CBAB9BF5C5C98AC52BF80556E05700CF79184D4DB18814B22A40F6EF9E7A7643D84B93552E9CF2A690
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........C.....& ...$............P.....................................................`... .........................................B7.......................(...........p..h...............................(....................................................text...............................`.P`.data... ...........................@.`..rdata.. .... ......................@.`@.pdata...(.......*..................@.0@.xdata...*...@...,..................@.0@.bss.........p........................`..edata..B7.......8...:..............@.0@.idata...............r..............@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc..h....p......................@.0B/4......(...........................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):4207434
                                                              Entropy (8bit):5.649487500614031
                                                              Encrypted:false
                                                              SSDEEP:98304:hq03AmVXaE7uA27UIi8aQNZY08hlTnpFBnTzHEn3IwKnSL9uKQMsFBnTwRNsGlD6:805VXaE7uA27UIi8aQNZ0hlTnpFBnTIU
                                                              MD5:EC10BC5B73F9A9AF63EFA4E2298DE348
                                                              SHA1:9752EE1CABA19FA86E68AE51579459AD50B63DDA
                                                              SHA-256:96E2440F5170AD02B45EF8CFE00992254C1735770EB163F0A4AAFB2E495CBBA6
                                                              SHA-512:1198CE40C4C60A46AA56BE0ECDB79DF5B125A7DF00DA19A3A085430BC24C7BDA1D8BA42C21D8C055F5C987F723B03FA17D2561B60764E3716AA06BDBCC1FD3BB
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...V..e..:.H2....& ...".2...T......P..........j..............................;.......A....... ......................................p..cZ......................P@..............t........................... ...(...................L....%...........................text...(0.......2..................`.P`.data........P.......8..............@.`..rdata...N...`...P...:..............@.`@.pdata..P@.......B..................@.0@.xdata...I.......J..................@.0@.bss.........P........................`..edata..cZ...p...\..................@.0@.idata...............r..............@.0..CRT....X............P..............@.@..tls.................R..............@.@..reloc..t............T..............@.0B/4...................Z..............@.PB/19..................b..............@..B/31.....*....."......~!.............@..B/45..........."......4".............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1664970
                                                              Entropy (8bit):5.282714022310594
                                                              Encrypted:false
                                                              SSDEEP:24576:GmimJVCfdB/ALayS3mCgotrTmix8PHBfKz9fmH4H:gCSX1iiz9fvH
                                                              MD5:407636B98AEE85A320A2E0387E5B1BAB
                                                              SHA1:BC7250703B9A3C3F1DBE18465AD038E9AD8F460C
                                                              SHA-256:54500634ACCA2BBF5FE58E18B55CB6FF0E091019A77B4CF2BACBB4000B59D3E6
                                                              SHA-512:CA352FB3828BDBF26AF96633CE72A54CBABC49BFE1FB22623651F020F6BDF91FF9453F22A99CEFA9F719D3E60CE8BA06A34A5ED39B040527D3ADC20E897340E2
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...;..e.d........& ...".....,......P..........p............................................. ..........................................1...@...2..............T$..............D............................k..(....................J...............................text...............................`.P`.data...............................@.P..rdata.. ...........................@.`@.pdata..T$.......&...p..............@.0@.xdata...&.......(..................@.0@.bss.... .............................`..edata...1.......2..................@.0@.idata...2...@...4..................@.0..CRT....X............$..............@.@..tls.................&..............@.@..reloc..D............(..............@.0B/4...................2..............@.PB/19.....}........ ...8..............@..B/31......g.......h...X..............@..B/45......;...P...<..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):3892825
                                                              Entropy (8bit):5.75406100185014
                                                              Encrypted:false
                                                              SSDEEP:98304:a9vISFTOYWb8lSayN/RffiNcvZHKsSww9hdqMmz4E4RYN0JmP/tzE26C33v609z+:a9vISFTOYWb8lSayN/RffiNcvZHKsSw0
                                                              MD5:D7AC9552410F62463C6694A1518CFE16
                                                              SHA1:5FE62BA172EAA27AA5732EFEE7CA13000DFF601E
                                                              SHA-256:2EF7B7DB112DA2050C88F6878A6B2B498106D810F172F3C9EA2040C288190170
                                                              SHA-512:A04A61C02C5C0EC8938D3006EA8006AC88029575C8B78569343F7D472610573FA761CDCC08D11150A46046EFE1BD5572AF443DBFAA025270696FD8DDE776ADEF
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...K..e.07..)....& ...".....d......P..........e..............................7......R<....... .........................................lH... ..X............0...:..............0...........................`...(...................(<...............................text...(...........................`.P`.data... ...........................@.`..rdata....... ......................@.`@.pdata...:...0...<..................@.0@.xdata...A...p...B...>..............@.0@.bss..................................`..edata..lH.......J..................@.0@.idata..X.... ......................@.0..CRT....X............b..............@.@..tls.................d..............@.@..reloc..0............f..............@.0B/4......`............j..............@.PB/19.................v..............@..B/31.....r!....#.."...6#.............@..B/45.....4|....$..~...X$.............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):344109
                                                              Entropy (8bit):5.181788350024895
                                                              Encrypted:false
                                                              SSDEEP:3072:HLcTaiOPdzvSL83GPUyFKlorJ64uKJZNv83Pt/ErjyIchjEnR:HITaiOPZGPUyhpJZN8PtsCIVnR
                                                              MD5:FC1ED8C5944CC3DB8D1DF76B73AFBC5A
                                                              SHA1:8961F1F1DA40FFE9E37730A4A740B3E0BBC4B143
                                                              SHA-256:1213E462E671DE6BB81AD80DA3B0A1227DAA15146662AE2F97C47824AD47B400
                                                              SHA-512:54A311C44524F36C922BF903C221E121ECD7BB701CB923C5E6DEEF9B064933937984EB2E01773BC477DB365717073AF0CD6E757775A5DA1FC7BE40A2613DF912
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...C..e.|........& ..."............P..........b.............................@................ ...................................... ..e....0..|............................p..t...............................(...................<5..`............................text...h...........................`.P`.data...p...........................@.P..rdata..P........ ..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata..e.... ......................@.0@.idata..|....0......................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc..t....p......................@.0B/4..................................@.PB/19......U.......V..................@..B/31.............. ...^..............@..B/45.....Ze.......f...~..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):351400
                                                              Entropy (8bit):5.260233823061903
                                                              Encrypted:false
                                                              SSDEEP:3072:daxJQcvZEuHFS0KXVemzqaIDKuXOT0it2jYRSsw50hjDXrmijHp+:MlZEiFDKXVeJU2itMYRSGDyijHp+
                                                              MD5:73395CBEF42F8A6CED5E0E17023CA219
                                                              SHA1:CD8EA6F8B7A14308799974FE426DE052316AA2FB
                                                              SHA-256:2E5E36F1C47336414635BC8F0B7716FDDB885D886B97551AA7ADDD933B4BCA25
                                                              SHA-512:C85680D06B8711796C5247E4EE583912489A640D19C1E9F0ED2648496B781017D4A61C583D9B3DC3F739A3915CEACA939DDF22BF2DAB2178E1DA4DE3C6500E9C
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...O..e....2.....& ...".x..........P.........pj.............................@................ .........................................P.......P............................P..................................(.......................0............................text....v.......x..................`.P`.data...p............~..............@.P..rdata..`).......*..................@.`@.pdata..............................@.0@.xdata..(...........................@.0@.bss..................................`..edata..P...........................@.0@.idata..P...........................@.0..CRT....X....0......................@.@..tls.........@......................@.@..reloc.......P......................@.0B/4...........`......................@.PB/19..........p......................@..B/31......'... ...(..................@..B/45......a...P...b..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):5647075
                                                              Entropy (8bit):5.179993540725587
                                                              Encrypted:false
                                                              SSDEEP:49152:VATWvdSwyth1+3dvgOv7RQluaHfQVg6JK4RfAtOry74PJvfcxdvLbL+HfVg+vDLr:VASEwythfA7SovfcxFbiftLUbK
                                                              MD5:A340B5EFC7EBC3EAEC3FDEC0A70CF25A
                                                              SHA1:64C7598E6F332D8D8A1E5A5E86D89434049C59A1
                                                              SHA-256:60A8FEEDDB1DE577216642B6A3BBEB01313ACE934A727DE66DE99B25B1152543
                                                              SHA-512:F34763BB0FD3BFA95A8E8FA19F7FC8A5A2B351AC4D91DBD45CE15A0CACDD69B12A2DE9841FA8002B641681F65B8AB2166F9809E240A62287632B556C2C2D6582
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...@..e.TS.......& ...".....J......P..........f..............................S.......V....... .............................................P...(...............O..............l...............................(....................X...............................text...............................`.P`.data........ ......................@.P..rdata.......0......................@.`@.pdata...O.......P..................@.0@.xdata...|...0...~..................@.0@.bss..................................`..edata.............................@.0@.idata...(...P...*..................@.0..CRT....X............@..............@.@..tls.................B..............@.@..reloc..l............D..............@.0B/4...................P..............@.PB/19......9.......:...Z..............@..B/31...........$.......#.............@..B/45......x....%..z....$.............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1068487
                                                              Entropy (8bit):6.537919242293345
                                                              Encrypted:false
                                                              SSDEEP:12288:N5lfzOM6VJiPFmSY5Ynys5wNV8jBRuA47VudmKAtRokD8FUnTV5eTC:N5lf+FSBbFg0XZFUnTV5eW
                                                              MD5:0D06E0B8CD4FC1739F1CA3B31382B5AB
                                                              SHA1:7A8497FD27256DCA853A599A18A7FD766657828F
                                                              SHA-256:D5FBFBFC47E4B5EC63B54C7985D38C60E2DEDD37623966F3639B3FD381CDCFF5
                                                              SHA-512:58D35D42D3F7EA425933A0F97C921337D3EFCAEA52BCAF1365A23C5F4CA3694E08EC2F1D43DBA9FC0EFD5A5B2FA175771A49EDD380490C82692E5BDF02467160
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........K.....& ...".l..........P.........`a.............................................. ......................................p...8......\................>..........................................`...(...................0................................text....j.......l..................`.P`.data...`............p..............@.`..rdata...1.......2...z..............@.`@.pdata...>.......@..................@.0@.xdata...K.......L..................@.0@.bss....@....`........................`..edata...8...p...:...8..............@.0@.idata..\............r..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):3847574
                                                              Entropy (8bit):6.25682704458707
                                                              Encrypted:false
                                                              SSDEEP:49152:13kWv94TxtcOhCncm/5/rgNqOZsbYDBfqDD+D8Cz4fC7lGJZ6XdTYKFQhAsaUsz9:13Z4Tr+b++GfdEdFszW6IWeOvb
                                                              MD5:060E1037A1469B24939DB320A1BB653C
                                                              SHA1:021EE6E7D1F48AF88731CA8A751D63F512B48E5D
                                                              SHA-256:30A427E3BB3C053F2A27B04BF3C33D8F0A02D2DF63890D9766D9FDBEAD98A280
                                                              SHA-512:B8B942A4FBC91A8C462150944F96F686D75FC9ECCD26CE97489CD32A66B52BB0D9D8634741D861CDF01AE89F5C050B8FD4BB33B15B232A3D4DE715A98D0A7B2F
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........7.......& ...$..,...7..:..P.........................................8.....G{;...`... .......................................6.5d...08...............4..............p8.............................."4.(...................058..............................text.....,.......,.................`.P`.data....H....-..J....,.............@.`..rdata..`d...P-..f...:-.............@.`@.pdata........4.......4.............@.0@.xdata..<.....5......t5.............@.0@.bss....@8....6.......................`..edata..5d....6..f...R6.............@.0@.idata.......08.......7.............@.0..CRT....X....P8.......7.............@.@..tls.........`8.......7.............@.@..reloc.......p8.......7.............@.0B/4............8.......7.............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):166156
                                                              Entropy (8bit):6.032341889696207
                                                              Encrypted:false
                                                              SSDEEP:3072:fG5ACLS00SlJn08lbVZUw2Zkx6LIlilm2t1g1ap7L0+ONdgVLGx:fLktlG8Rl2ueIlilmY1g1aJopNdgVLGx
                                                              MD5:BAF7406F38D5DF5FCBFA54988B6232C3
                                                              SHA1:5CFD77A85DFEB4F12B98D7F16D23CAFF0BDB269E
                                                              SHA-256:4462983084F84C66AF7C77DD5B25E3CF04FB22F8587E368DACE62E00B68F3552
                                                              SHA-512:9F79DECC0949B26DA7CA0462C6743F8057ADD1DA1588C575BC411A6EFCC0C316F05AF51BBE16B9779122554489A81143AB58CE77A4F4212FF6E10C1401582F04
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........(........& ...$....."......P..........M....................................g.....`... ......................................@..c....`..4...............................................................(...................\f...............................text..............................`.P`.data...............................@.`..rdata...3.......4..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss......... ........................`..edata..c....@......................@.0@.idata..4....`......................@.0..CRT....X............ ..............@.@..tls................."..............@.@..reloc...............$..............@.0B/4...... ............&..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):98070
                                                              Entropy (8bit):6.053721811697992
                                                              Encrypted:false
                                                              SSDEEP:1536:CvZswjoSLZBCQ3r78PIGO4hNm9uNY6UCi7EdZzR93aSDxW/ea2LeP5p8JmeXLi66:CB1joyIPjgAY6Xi7QR93aZ/aVxF2F3zF
                                                              MD5:981594300418B252310860271E9AE83E
                                                              SHA1:9B1CD2DD01EA56726C61741E9122EA0F2C918984
                                                              SHA-256:CD6836A6DC5971B7BFFE718E48DDE7710851AC79F8A8C10D09AAD27F3A22B297
                                                              SHA-512:A06B244274C4F579A88DA44EB4E3180303CEE4E2548872D488D0710D9655395D1ED33A8C3DF1552AA7ECFA5E664B8824B898816BE19F852FA69D34322764EA8C
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........d........& ...".....^......P..........a.....................................A........ .........................................C....................P..................\............................>..(...................h................................text...............................`.P`.data...............................@.`..rdata...O.......P..................@.`@.pdata.......P.......*..............@.0@.xdata.......`.......2..............@.0@.bss....p....p........................`..edata..C............8..............@.0@.idata...............D..............@.0..CRT....X............R..............@.@..tls.................T..............@.@..rsrc................V..............@.0..reloc..\............\..............@.0B/4...................b..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):82194
                                                              Entropy (8bit):6.0362555944692975
                                                              Encrypted:false
                                                              SSDEEP:1536:pxUuRKm1lJLOynX3MkEbtDJDBZGHkJBk1aQUaBhCS6NK/aO:8/IpT4ZV2HU+aQb8jK/aO
                                                              MD5:B1D17913D79C9B73F34D06D68F480122
                                                              SHA1:27E7DA1F76B2CEC54CB6722150D879E34EC94ED1
                                                              SHA-256:AEE0DAF699BB2295BBFFB854C569789D61F3FC5AC6AD0870EBAA7AAE71D5A5D4
                                                              SHA-512:B39AAAA457023B4012CDD15CE37A2A49ECE89233F83B3F9F37B7A2D088E841489FD092767B0FFB4ECBF2EAC359034D725E0CF8A99C9B6FEBB8E5B2DD6115BA20
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........ ........& ..."............P..........p.............................................. ......................................P.......`............... ..................................................(...................$b...............................text...x...........................`.P`.data...............................@.P..rdata..............................@.`@.pdata....... ......................@.0@.xdata.......0......................@.0@.bss.........@........................`..edata.......P......................@.0@.idata.......`......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):354390
                                                              Entropy (8bit):6.414795060934278
                                                              Encrypted:false
                                                              SSDEEP:6144:nRb7l/kP5EdWY/1Ww/8YcqhC6vhpjtwgmY6VQYHy060LSix/:RN/MMRtWw/BF/eaKy060Gih
                                                              MD5:E0F118D905C704F3DAE86E5EB6C9FD3E
                                                              SHA1:868DDFF9614EF5A9503C9FBD2992730EF4052F0B
                                                              SHA-256:6CB70343248E41B5D491B587E8AF4CF71AC260B55D4DA5933ED5A1DDDD78DCA7
                                                              SHA-512:A97AC43F042248BFAA5970E4E3E3DF31A65D5D1B128924AB766E484D4807CB36FF7F410980DD04D56001CA37485BC5E8B3A657F40AED366452E894DC5E000D96
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................L..!hT!.p sirgorc maonnaeb tnur ni SODedom.......$....PE..d...........*.....& ...".........2..P..........g......................................r....... ......................................@.......`..................................t........................... ...(...................|c...............................text...............................`.P`.data...............................@.P..rdata..p...........................@.`@.pdata..............................@.0@.xdata........... ..................@.0@.bss.....1............................`..edata.......@......................@.0@.idata.......`......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..t...........................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):762100
                                                              Entropy (8bit):6.070183682990754
                                                              Encrypted:false
                                                              SSDEEP:12288:ntCvBJhZhpBzdeZkBLGphpDWJCDXYo4IYY7Kxd:tCjeGBLEhNWJCLKxd
                                                              MD5:F277B55DBAB50F60F4110234920FCCBD
                                                              SHA1:010FA2116343A2EEAC91C5458DAF942C939FF27A
                                                              SHA-256:9550AC314F125D1FEA7351DD800CB0A06137F890C10D53AD40F021A962C97FBC
                                                              SHA-512:CD39AB93E71D8AE03F058BEC3B9C2567702EC1811581D9382D725D39431E528D055D8094EABE0D8917CF8D6A605956352923DDCE4FBAB5ADC0E57DAB8E6A3C44
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................L..!hT!.p sirgorc maonnaeb tnur ni SODedom.......$....PE..d........P........& ...".....J......P..........p................>............................. ......................................p....................... ..................................................(...................................................text...x...........................`.``.data...............................@.P..rdata...o.......p..................@.`@.pdata....... ......................@.0@.xdata.......@... ..................@.0@.bss.........`........................`..edata.......p.......0..............@.0@.idata...............>..............@.0..CRT....X............F..............@.@..tls.................H..............@.@..reloc...............J..............@.0B/4...................N..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):329147
                                                              Entropy (8bit):5.957449197471745
                                                              Encrypted:false
                                                              SSDEEP:6144:MAOgQxT8ZxPzE9cvnm98Ol+Mw5tJWfGCnRqGEFOwdje5hTT:MFgQxT8nzE9Em98OlPVfGCnRqGEFOwp2
                                                              MD5:C6F5DF9383A8902D8E13A578C72FC2F9
                                                              SHA1:D0ACE63E7A4AB4F62EDECD8AEA2F686957E62CE0
                                                              SHA-256:E7BFDA6077198DEB0136EF1594FD311EBEE951606D7F9140EA302D55256DFECA
                                                              SHA-512:1DC8DB4636D53B8C2E1261D6B2F66951D9B3AD861084A1C3A21CF4130835A3674C687A23EFC2BEC7C54065FFAD64381695EBCC628CB36694B12239D5BD45A59D
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........f........& ...$.:...`......P.........+T....................................*\....`... ......................................@..+;......d.......0....................... ...............................(....................................................text...88.......:..................`.P`.data........P.......>..............@.P..rdata..0....`.......@..............@.`@.pdata..............................@.0@.xdata..p...........................@.0@.bss.........0........................`..edata..+;...@...<..................@.0@.idata..d............:..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..rsrc...0............Z..............@.0..reloc.. ............^..............@.0B/4...... ............d..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):87457
                                                              Entropy (8bit):5.601098622413987
                                                              Encrypted:false
                                                              SSDEEP:1536:5r9RdrCScVGhKlsB/0zm1JZMIuoRSKfpCMTaRa1iHSqHxE:l9RIS5/0zgIoRSSEMKa1iHSqHxE
                                                              MD5:24AECFA6FDE66276275A8477904C45E9
                                                              SHA1:35920C901F5126105C824141ECB138E447A13D36
                                                              SHA-256:052077A4D2142930CEA0C2276EC8267C9B4C96174AB31F88AD095FFC679F5BF0
                                                              SHA-512:0F9F0A1CFF7579437DF57D21936105AC9E431CF79B0146C67EAA4C162A2A17306CF2D2CA5732FD1E03330B5A61F51671AD6F57C0D7BE918B9DC2BC2024FB8232
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........p.....& ...$............P................................................n....`... ..................................................(...`..`.......t............p..|...............................(....................................................text..............................`.P`.data...............................@.`..rdata..............................@.`@.pdata..t...........................@.0@.xdata..............................@.0@.bss..................................`..edata..............................@.0@.idata...(.......*..................@.0..CRT....X....@......................@.@..tls.........P......................@.@..rsrc...`....`......................@.0..reloc..|....p......................@.0B/4......$...........................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):115051
                                                              Entropy (8bit):5.634472441690908
                                                              Encrypted:false
                                                              SSDEEP:3072:HtSDzYA0UhIqHqHq7AiRsrLBG7fottfai3Qm7a7P7cN7uO1DAf:SYAzIGRRs0QttBGrI1u
                                                              MD5:7E99586845BCC76AFCE740362632F8BA
                                                              SHA1:F90E38C79BF60CD8B4FE81AED20FEDA1311C48C5
                                                              SHA-256:56AA67AE75DB60D19160C9BC13F91CFD838DA02427E49954CD7288CEEB53A366
                                                              SHA-512:04CA488E23764841BF26227087F94F35141450D2C3D641D064DA68688B88F9ABDD896C1DDFE1AFF92FC83341946CC37719F4394FD55BD7DE0A0771DBC21D458C
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........8..C.....& ...$.....2......P.........A.....................................=s....`... ......................................0.......@..p2..............p...............t...............................(....................I...............................text..............................`.P`.data...p...........................@.P..rdata...'.......(..................@.`@.pdata..p...........................@.0@.xdata..@...........................@.0@.bss....p.... ........................`..edata.......0......................@.0@.idata..p2...@...4..................@.0..CRT....X............,..............@.@..tls................................@.@..rsrc................0..............@.0..reloc..t............4..............@.0B/4...... ............6..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):113606
                                                              Entropy (8bit):5.951391680564109
                                                              Encrypted:false
                                                              SSDEEP:3072:mgIGKirO8ao6L5IPQWbLzd3f0bPRe3q0M91jMgC:m3oEIYezd0bP50M91jMgC
                                                              MD5:80575EC4DE0615EA9D2A3EFBB9EE1A5C
                                                              SHA1:A76CC1FD5CBCAE8388E5887FC3B39C287866B385
                                                              SHA-256:E63AB6A72FBECEE4471AF837E961BEC8448B22716CA1BB1F18505D468A1E5646
                                                              SHA-512:4A79EF0A2168678195E7AF071CF3067E52710E1C098C305045AE7427566C4DE2C780B72A94B4F6098736BE5E8C2411CC355427A715BFFA75CF118347A668D676
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........`..[.....& ...$.....Z......P................................................G....`... ......................................p..-........#...........@..p............................................%..(....................................................text...X...........................`.P`.data...............................@.P..rdata...$.......&..................@.`@.pdata..p....@......................@.0@.xdata.......P....... ..............@.0@.bss....p....`........................`..edata..-....p.......*..............@.0@.idata...#.......$...0..............@.0..CRT....X............T..............@.@..tls.................V..............@.@..rsrc................X..............@.0..reloc...............\..............@.0B/4......$............^..............@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):284951
                                                              Entropy (8bit):6.16927796191791
                                                              Encrypted:false
                                                              SSDEEP:3072:gmi4YPf5tgppPB/3KxIVq4yzR9rUUeMbaCmg/VWGIDc8q4RlQ6+PiaAtF/lEj:rCP3SvXkrvvm8IDcYRi6+ad7l2
                                                              MD5:2CAB80FBA80EA4FB503A071D27ABF1A3
                                                              SHA1:2804E415DDBAE00C16B873155529C26FDBC82E21
                                                              SHA-256:B07B5953A13CFC33ED96AB1E028C703599D2676B84EA6DB26E42B0B690C37171
                                                              SHA-512:62C733EF2CA2D5CF33C362F847084CD139031A6600E64E81E47180E52F4F11BF1D98FFE3BFBB7D409E3131B8E6FEB3316919251D42DC4B9D013761810572B740
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........H........& ...".....B......P..........i.....................................'........ .........................................5....................P..h........................................... ?..(.......................h............................text...h...........................`.P`.data...............................@.P..rdata...|.......~..................@.`@.pdata..h....P.......&..............@.0@.xdata..|....`.......,..............@.0@.bss.........p........................`..edata..5............2..............@.0@.idata...............:..............@.0..CRT....X............@..............@.@..tls.................B..............@.@..reloc...............D..............@.0B/4...................F..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):735923
                                                              Entropy (8bit):6.433769847811494
                                                              Encrypted:false
                                                              SSDEEP:12288:8uWYdY3xY/Ji6gpWLIDu2plA5aRnxzzQ4AY:zVY3xY/JvgpW8D1fA5aVRzQ4T
                                                              MD5:EC9B5BBBF6480C1D3CB4305FBFA964E9
                                                              SHA1:5522D22D9F25CED0C2D3DDD4C4A3E7212D2D5034
                                                              SHA-256:E2ADAB099A3280BB39B23E398AAEEB131EF422114AB843EEEEEA84E2D393EBF9
                                                              SHA-512:B285C09D0BD8EDE5BB94408364E785E2718DE9D1BF0FE0DF695FD301CB5064547C3660770F9221B3B6A8F67EB664996E828E33118236ABE699FDEB58E82FD129
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........t........& ...".....n......P.........Pc....................................."........ .................................................,...............x3..............................................(.......................`............................text...............................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata..x3.......4..................@.0@.xdata..lO...0...P..................@.0@.bss....@.............................`..edata...............F..............@.0@.idata..,............\..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc...............h..............@.0B/4...................r..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):256789
                                                              Entropy (8bit):6.36729961832555
                                                              Encrypted:false
                                                              SSDEEP:6144:qFV2YByNs8WxeWttNZRhx+Rp6CFhoXK4O9KCnqWtEfmF:yVx8WxfRhx+zFhSKtKCREfmF
                                                              MD5:546AEF9D3B986B8211FACAF312BC6F9F
                                                              SHA1:B19F84C8191E81BEDA3DB6B587647C0D5BBEE9CE
                                                              SHA-256:CC2C2E273709439897F7A32159EB4D74E4E19B15FC1F92F92CCDA2DBCF3D2C72
                                                              SHA-512:B6FCDBEA3444C69E6FD8016B02F723E9FBB1F2981D9BB9415A73E8B1BC81ACC5EB402942625693C5B5E9BF5D8BE856DC996537915C6D0FD610ECCC8499BA2F84
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P..........h....................................-x........ ..............................................................P..X...............p........................... 7..(...................t................................text...............................`.P`.data...............................@.P..rdata..`\.......^..................@.`@.pdata..X....P......................@.0@.xdata.......p.......J..............@.0@.bss.... .............................`..edata...............b..............@.0@.idata..............................@.0..CRT....X...........................@.@..tls................................@.@..reloc..p...........................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):88316
                                                              Entropy (8bit):4.838596222049979
                                                              Encrypted:false
                                                              SSDEEP:768:w92MJy8UJhpPvFvPJiv7I7Bs5C+iOr6T/rxrc2YEpdAFdj:w0M0JXGv+3e6T/rxIFdj
                                                              MD5:2A2B179C03BE99147C4B724E3C3F0EC6
                                                              SHA1:5CC45BD900946A5CCB39606BE69DC7A02C54EB2A
                                                              SHA-256:73C7B73EBFA3BBD18B8E10084197DA15F516E3B45B28CC1B576D1A0DA0E2A69B
                                                              SHA-512:22EAE64D7718E5AAE77618C47542A7FFEA23317A23EAB9458D224D02A867B8321BEC2706626FC5321CA0A47F7A717F2C9E71947DD91BB78825554309605FAA93
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...@..a..........& ...".....<......P..........h....................................M......... .........................................i.......X............P..|...............`............................@..(.......................8............................text...`...........................`.P`.data...p....0....... ..............@.P..rdata..P....@......."..............@.`@.pdata..|....P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata..i............4..............@.0@.idata..X............6..............@.0..CRT....X............<..............@.@..tls.................>..............@.@..reloc..`............@..............@.0B/4......0............B..............@.PB/19......P.......R...F..............@..B/31..........@......................@..B/45..........P......................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):26189312
                                                              Entropy (8bit):5.577547696726397
                                                              Encrypted:false
                                                              SSDEEP:196608:hwLfcteXpnzVyC/iM4yI63M+2iOp1/jQwAQkWAYmKtT8/zEucOuj/ZD0qXlYqKEd:hbLkjwTkhujV0qXlvjd
                                                              MD5:226E92F75F84CFADE55E67BDBAC23087
                                                              SHA1:E78F709A5E4A0EB5286B519AF5AB910BAD662BA5
                                                              SHA-256:CDB43800431304675E4B454A7379AC558F33E511CA2A4AC0EA3DFF91C52EEDA3
                                                              SHA-512:AC6E9C156DE235ED51CEF88A1C8E2DA40C1E73745F848398545B9BAFE25896DBA5BA9C8DCC40E7A01EB454857FA8C488A357711A4325C569B0D92390D6EC39B0
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....a.|f.|.....& ..."............P..........o............................. g............... ......................................p...9.................................................................. ...(...................t................................text...............................`.P`.data...`9...0...:..."..............@.p..rdata.. x...p...z...\..............@.`@.pdata..............................@.0@.xdata...j.......l..................@.0@.bss.........`........................`..edata...9...p...:...4..............@.0@.idata...............n..............@.0..CRT....X...........................@.@..tls................................@.@..reloc........... ..................@.0B/4...... P.......R..................@.PB/19......U...p...V..................@..B/31......i.......j...R..............@..B/45.....K....@......................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):40389
                                                              Entropy (8bit):5.798464039126552
                                                              Encrypted:false
                                                              SSDEEP:768:Q9GQMXfVOZ8JytzUfkdJVnmWSRNJKomv7O7JD2F3l:Q0/fAuJyKsTEdJKomDA52F3l
                                                              MD5:28D766F182AC56E1550EBB1BA05178F9
                                                              SHA1:FCE30575E622FF53C1545D57785B8DF7BF613EAE
                                                              SHA-256:3A801C25F33E677404F85664F372EEFD9D0BE5ACC0C3F81B659B05CFCF55A8E3
                                                              SHA-512:C23236D3DAB638D806DE016FFF907BAC5EF53700C3529C1B4A0097E4B99D2B11CCD9CE17B7A62371317D2EC512CC105D181B995AC3D9B5CDE7AF0B090D995784
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$.`..........P..........)............................. ......-.....`... .................................................................t...............|...............................(....................................................text....^.......`..................`.P`.data...p....p.......d..............@.P..rdata...............f..............@.`@.pdata..t............p..............@.0@.xdata...............v..............@.0@.bss....p.............................`..edata...............z..............@.0@.idata...............~..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..|...........................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):509760
                                                              Entropy (8bit):5.835147726002544
                                                              Encrypted:false
                                                              SSDEEP:6144:Iy4lckklNynyIYaWrnLDSrwAB1eT2PhnoixlahbAsOkhsHu1nQbaL+cpDdO:IncN4ZWLDswi1Rhnh7aPhsQVVo
                                                              MD5:A3762A140A807AD2389B26D69224B3DE
                                                              SHA1:79771C20573693BE2C53CB9A8C753497FACE7429
                                                              SHA-256:19D8747778C3E35177758C6E3400B1E806D6118C420912784A9DBD5067DCEF4E
                                                              SHA-512:6FC8399E4E8775D3F7F2ABA7B2AC9B297E98E779CB597EC5412FE9636C020706E52B2BF631CFADCB4A6B978F712C07ACB6C1767D85C3BB74728C2A9B838C6125
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........`........& ...".X...Z......P..........h....................................p......... .........................................}........................ ..............0........................... ...(......................@............................text....V.......X..................`.P`.data........p.......\..............@.`..rdata..p............`..............@.`@.pdata... ......."..................@.0@.xdata...!...@..."..................@.0@.bss.... ....p........................`..edata..}............*..............@.0@.idata...............F..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc..0............Z..............@.0B/4...................^..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):485170
                                                              Entropy (8bit):6.471136624247681
                                                              Encrypted:false
                                                              SSDEEP:6144:KAVs3QsAR3aEd92iLcM8Sdpe2NZCa/0RHygzuj7Hmx2rdxuBchY3:dsiplNZCK6tzuj7GwjBO
                                                              MD5:BD9393441C4B449E0A021CBF629CC4AA
                                                              SHA1:FF2F1FFE9BEC909E64E25BC994E8F04CAC923D52
                                                              SHA-256:125F05AAB77AC2CC19D5AD707EDE401EDFE1A1B5005CCB468D56BE7DC3700836
                                                              SHA-512:CF3FA3EF103C0FF13B8416BC26666D19F5D05C285207148C1486D0C4805AF3E5705D46170C6A6F6DD6DC90551FD89F024D2BF34C2A757CFBEAA271983E94BC13
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...........8.....& ..."......... ..P..........a.............................p................ ..........................................;... ...............P..h+...........P..............................@...(....................!..X............................text...............................`.P`.data...............................@.`..rdata.. ...........................@.`@.pdata..h+...P...,...2..............@.0@.xdata..h1.......2...^..............@.0@.bss..... ............................`..edata...;.......<..................@.0@.idata....... ......................@.0..CRT....X....0......................@.@..tls.........@......................@.@..reloc.......P......................@.0B/4...........`......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):66133
                                                              Entropy (8bit):5.73685267962144
                                                              Encrypted:false
                                                              SSDEEP:1536:fPujTmyf1exgBF9gJtim3YN5gqRbymzDX:vyYwmtim3YNvbfzDX
                                                              MD5:9BDFBAD6C1CB82B3F93190D134EE3B21
                                                              SHA1:EDE0F18E0E784012150963DD6D51916ED2A7E34A
                                                              SHA-256:2ACE26664A0C7CD723874652805DEA3748AD21F6CF4BB22A197A785327D5CE7E
                                                              SHA-512:FF47C5BFC2F9CDD1AF3B2A8B22F9838D44D7E22230423BA0C2B55B72DD3C1BE7A701A50C13E5694E48F97B704B4BFAA5CAA7FF083A3125E6A2AEF945F908083E
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P..........d.............................p......0U........ ......................................................@..P.......8............P..`........................... ...(....................................................text...x...........................`.P`.data...............................@.P..rdata..@...........................@.`@.pdata..8...........................@.0@.xdata..h...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....`.... ......................@.@..tls.........0......................@.@..rsrc...P....@......................@.0..reloc..`....P......................@.0B/4...... ....`......................@.0B........................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1452692
                                                              Entropy (8bit):6.405789258500374
                                                              Encrypted:false
                                                              SSDEEP:24576:+7cxVEcfOOzjoebRBg7sbqu5EvYW3V71HTOqZyU4:+7cxGsO3q3g2quM9VZKq4
                                                              MD5:25AA4BCF34DE86D8D46E6AEF8D77A89B
                                                              SHA1:BF4431F6D24EBF2EFB02A1BF3F5AB046DA221EFF
                                                              SHA-256:5A97D215807F9DA14F99D2CFBF944145CC43E79D99E72AAFA4E8660A7788E5B5
                                                              SHA-512:1B11882E1579F031F94AC0F9DD9968B84B0F5C7B13FEAA2A9CD4E527A1BC484A6076FA8D33441F429F0F4624955FF29FA3EB96C93BBCCFD61BE692D1D5CF14A1
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........|..P.....& ...".....v..."..P..........p.............................................. ..................................................................~.......................................... s..(.......................x............................text...x...........................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata...~..........................@.0@.xdata...{... ...|..................@.0@.bss.... !............................`..edata..............................@.0@.idata...............F..............@.0..CRT....X............Z..............@.@..tls.................\..............@.@..reloc...............^..............@.0B/4...................z..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):160185
                                                              Entropy (8bit):6.105313141781387
                                                              Encrypted:false
                                                              SSDEEP:1536:MG+3ibUAGPWNxY4xOfrMEm+75SJVmmzloC2FsEJ9WLW86UAmkV8N6To1a0gwlcfa:G19o9AjMk8O/cdlA38ADml3
                                                              MD5:194E5927747D12886E7FFD073977CFC3
                                                              SHA1:4D84D14044DAFFC6E5186D97BADE88DE6D9C4ABE
                                                              SHA-256:BCCE9990533144B2873E26758290CFA2E52032CEC0BC0B8F91292B86F4493FA8
                                                              SHA-512:2533AC20880C1EA389D85C11C2131527E305E79110CB1FDA35A29329620234CC6825B086A82DC5077F29487CD9E227605871CD19EC01F59D016296AB3EFC3FEB
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........"........& ..."............P..........d.............................................. ......................................@.......P..................................d...............................(...................hT...............................text...H...........................`.P`.data...............................@.`..rdata...9.......:..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss.........0........................`..edata.......@......................@.0@.idata.......P......................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..d...........................@.0B/4................... ..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):123873
                                                              Entropy (8bit):6.327673262113837
                                                              Encrypted:false
                                                              SSDEEP:3072:SgRq5sPDRAED8/IGd+kZKjA0fxTBfoyQaPzWwDS:SgRtPDeED8/IU3ZK3TB9QaPzWr
                                                              MD5:D8851061A755A675A6CDEBE9984C882E
                                                              SHA1:80429536CDEE9B48AC41D749BAB5436FD7E5384E
                                                              SHA-256:AC43FDBE8D4B5B3DBFE436730B77CDADEE7C583F9D6B0CC5E2AB642446E2F60E
                                                              SHA-512:B95E6A3581A58EED9EF9E417ADB7788F3F8782C25660DBAC727131EFBC30281CA4184E5D20366822BD21ABB146CB1FE69CCC6C280DAF6C7BFCCBBA114B965A4E
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".6..........P..........e.............................P......2......... ..............................................................................0.................................(.......................h............................text....4.......6..................`.P`.data........P.......:..............@.P..rdata..@X...`...Z...<..............@.`@.pdata..............................@.0@.xdata..\...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.......0......................@.0B/4...........@......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with very long lines (301), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1735
                                                              Entropy (8bit):5.112605138685413
                                                              Encrypted:false
                                                              SSDEEP:24:tvY5MS2l5MS22cpMS2epMS2bcpMS29C8CjzivCB6MB+C40NLkCddeyC7vC0jYzV2:BGDjzbgMBZNdUupzMLtFRkG+8waj
                                                              MD5:26D2EF3EC4188D38C874BD2F445AD353
                                                              SHA1:69B0CACC173FFDED97CAFBC8DE351DAF2699A27A
                                                              SHA-256:5363E2B9349A32B28EADBB58AE7EADB283D2C7E3A544FEA4790228A5C4715131
                                                              SHA-512:48CFDD170099CD4EA8D271188F134D686982A4031BC2864D5FA6B497D552D10FC06A1F3D2B2D821A89B069BD933EF6AB26B01DF3B856BB87ECDC61744257BC2B
                                                              Malicious:false
                                                              Preview:# GTK+ Input Method Modules file..# Automatically generated file, do not edit..# Created by Z:\usr\i686-pc-mingw32\sys-root\mingw\bin\gtk-query-immodules-2.0.exe from gtk+-2.17.11..#..# ModulesPath = Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\2.10.0\i686-pc-mingw32\immodules;Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\2.10.0\immodules;Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\i686-pc-mingw32\immodules;Z:\usr\i686-pc-mingw32\sys-root\mingw\lib\gtk-2.0\immodules..#.."../lib/gtk-2.0/2.10.0/immodules/im-am-et.dll" .."am_et" "Amharic (EZ+)" "gtk20" "../share/locale" "am" ...."../lib/gtk-2.0/2.10.0/immodules/im-cyrillic-translit.dll" .."cyrillic_translit" "Cyrillic (Transliterated)" "gtk20" "../share/locale" "" ...."../lib/gtk-2.0/2.10.0/immodules/im-inuktitut.dll" .."inuktitut" "Inuktitut (Transliterated)" "gtk20" "../share/locale" "iu" ...."../lib/gtk-2.0/2.10.0/immodules/im-cedilla.dll" .."cedilla" "Cedilla" "gtk20" "../share/locale" "az:ca:co:fr:gv:oc:pt:sq:tr:wa" ..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:Unicode text, UTF-8 text
                                                              Category:dropped
                                                              Size (bytes):890
                                                              Entropy (8bit):5.202678107381836
                                                              Encrypted:false
                                                              SSDEEP:24:4MxI1KhRFJSk4VXpUb9GyJyk1jwiv3+3+Wk+ppJajhvxm7:XI8hrJT4Z49GyJRhv+OMShk
                                                              MD5:C358838E1789C1D4E6DA7F525FC922CF
                                                              SHA1:576FFC2F578A8B78B2295584C059338D976C485A
                                                              SHA-256:D52DFEA88F5964B7581C93CDEA1A3E47DD7B1D8334E8F5EB53018711428221ED
                                                              SHA-512:524FCCB13EAE05A54297320119626B668BD3F615772931F068344395A73CED6363A580B64431B9F739F15920CE541BBC5375FE4D399A749C52E75B73560CC778
                                                              Malicious:false
                                                              Preview:# Example configuration file for the GTK+ Multipress Input Method.# Authored by Openismus GmbH, 2009..#.# This file follows the GKeyFile format. On the left of the equal sign goes.# the key that you press repeatedly to iterate through the text items listed.# on the right-hand side. The list items are separated by semicolons ";" and.# consist of one or more characters each. The backslash "\" is used to escape.# characters; for instance "\;" for a literal semicolon..#.# The example configuration below imitates the behavior of a standard mobile.# phone by a major manufacturer, with German language setting..[keys].KP_1 = .;,;?;!;';";1;-;(;);@;/;:;_.KP_2 = a;b;c;2;.;.;.;.;.;.;.;..KP_3 = d;e;f;3;.;.;.;.;..KP_4 = g;h;i;4;.;.;.;..KP_5 = j;k;l;5;..KP_6 = m;n;o;6;.;.;.;.;.;.;..KP_7 = p;q;r;s;7;.;$.KP_8 = t;u;v;8;.;.;.;..KP_9 = w;x;y;z;9;.;..KP_0 = \s;0.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:SVG XML document
                                                              Category:dropped
                                                              Size (bytes):2285
                                                              Entropy (8bit):5.039478352344204
                                                              Encrypted:false
                                                              SSDEEP:48:4JWROXUoAtH6d5koN40ezkozdme+oVLrvenoDRkQxofWGno3DGholm8:4bEo5TkouxzkoZ3+oVveno9Dxornoahq
                                                              MD5:A7E34846279F076184736ED26698BA27
                                                              SHA1:99B7EDF0357CCB7BE4E44D13457EF87741C8504B
                                                              SHA-256:299E2323EBED8FC0A7E5DDB793F0057BFFEAA380DC6E81C40AEBD0D518D3BFC5
                                                              SHA-512:56CB068CE560FF9BE8A68FD41A06170EC10CAC55EA7E48CCBBE33E8CF8839D44090597D45C4BB333D0374F3C022BA03612A9EC955935CBA1FC3F5F02FEDAE339
                                                              Malicious:false
                                                              Preview:# GdkPixbuf Image Loader Modules file..# Automatically generated file, do not edit..# Created by gdk-pixbuf-query-loaders.exe from gdk-pixbuf-2.36.7..#..# LoaderDir = Z:\usr\i686-w64-mingw32\sys-root\mingw/lib/gdk-pixbuf-2.0/2.10.0/loaders..#.."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-ani.dll".."ani" 4 "gdk-pixbuf" "Windows animated cursor" "LGPL".."application/x-navi-animation" "".."ani" "".."RIFF ACON" " xxxx " 100...."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-icns.dll".."icns" 4 "gdk-pixbuf" "MacOS X icon" "GPL".."image/x-icns" "".."icns" "".."icns" "" 100...."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-jasper.dll".."jpeg2000" 4 "gdk-pixbuf" "JPEG 2000" "LGPL".."image/jp2" "image/jpeg2000" "image/jpx" "".."jp2" "jpc" "jpx" "j2k" "jpf" "".." jP" "!!!! " 100.."\377O\377Q" "" 100...."../lib/gdk-pixbuf-2.0/2.10.0/loaders/libpixbufloader-pnm.dll".."pnm" 4 "gdk-pixbuf" "PNM/PBM/PGM/PPM" "LGPL".."image/x-portable-anymap" "image/x-portable-bitmap
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):30126
                                                              Entropy (8bit):5.1562988744270495
                                                              Encrypted:false
                                                              SSDEEP:384:5o9wlaBZB9XoxgkjuYbBnT9mJOkkYcHFPI6QsrKlwAzAzCBan+SbsyJFMOYM8nLO:29UiZB9Xolj/9ToJMYgczi8LO
                                                              MD5:2A2C6A330D616B4C28CBEACCEF01F602
                                                              SHA1:44B066A2144D46B6668CA25D501CB983E2832BE0
                                                              SHA-256:44FADD8CBF6DC4D96D97DD709D8BA9293C2A1958589AD586725B49539CD791A5
                                                              SHA-512:5DF8AF980E20504E328A02C148E528DC9ABEF588C6449D3E17619B070680F175E0CF0501E70141DDBF1EF216FCA3F75CE94966CDE22AB0DAF0CD08E244B7E75A
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........X........& ...$.*...R......P.........).....................................m.....`... .........................................j....................`..................h............................R..(....................................................text....(.......*..................`.P`.data........@......................@.P..rdata.......P.......0..............@.`@.pdata.......`.......:..............@.0@.xdata..(....p.......>..............@.0@.bss....0.............................`..edata..j............B..............@.0@.idata...............D..............@.0..CRT....X............P..............@.@..tls.................R..............@.@..reloc..h............T..............@.0B/4......$............V..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):24091
                                                              Entropy (8bit):4.832512351006504
                                                              Encrypted:false
                                                              SSDEEP:192:8Qa/9cKXc+FZ65O+q/odIodzyrgsmrM6liSIJOL/MP6OUSUMrFK4ST/Xca+DzfGa:JG9k2xKI8zsmI6UVJOr3QrFy8DzM9to
                                                              MD5:7BDB63482497F7E2DF8179E9366B2367
                                                              SHA1:938809EA5EF6A7446A490ECB35B07D8CA173B50A
                                                              SHA-256:29B03D6CC8829FA074F7E6DAA4A6D12EAB76BC2B73E8A1312869BCC1175A439F
                                                              SHA-512:7A1190B78C77FDC7FCC33C0D29CACAFEAC1437B3B79BF5C2F379526F8C372043F471188E5F6F63B293005A66060A08B76B9062183D9F9F955F424BDCB6D00101
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........H........& ...$.....B......P...............................................=.....`... .........................................k....................P..................h...........................`A..(...................T................................text...............................`.P`.data........0......."..............@.P..rdata..`....@.......$..............@.`@.pdata.......P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata..k............4..............@.0@.idata...............6..............@.0..CRT....X............@..............@.@..tls.................B..............@.@..reloc..h............D..............@.0B/4......$............F..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):21617
                                                              Entropy (8bit):4.933393529217816
                                                              Encrypted:false
                                                              SSDEEP:384:W+9s/PiIc1YdWyRZJOIC1b+Om32wrcJasMpUM0g:L9sn9cI/RZJW1b7Jxa3p4g
                                                              MD5:5BCA09AC3BA1B34936BAE00317A37BA1
                                                              SHA1:8D23B02E6F7642F1E21651DAC2176CEB5759C62E
                                                              SHA-256:BCD2AC658D965765CB6184371CF4CAD30B317AB73038F5545FDFE3CDEC4D0436
                                                              SHA-512:D59D5375809DCE16DBB05B712FBDF9496113A9D382E7D2D50EC604D1AC4322B75142DFA214616038FEC214D78E077D098D2054939A766E9BABD69FA4FC58F336
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........B........& ...$.....<......P.........7e.....................................9....`... .........................................m....................P..................t............................B..(...................$................................text...H...........................`.P`.data........0....... ..............@.`..rdata..p....@......."..............@.`@.pdata.......P.......,..............@.0@.xdata..\....`......................@.0@.bss.........p........................`..edata..m............0..............@.0@.idata...............2..............@.0..CRT....X............:..............@.@..tls.................<..............@.@..reloc..t............>..............@.0B/4......(............@..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):26886
                                                              Entropy (8bit):5.108100184101569
                                                              Encrypted:false
                                                              SSDEEP:384:jR9lVYrU3ST1sz/eV9HYLkKHBV9PJOB9WSrLOY1Jv1TMNw+n4G:19RCT1szU4oO79PJOJz+9
                                                              MD5:72872FEC2D06F5F60B6A7D3677B507B8
                                                              SHA1:06D6CF1C80A29151C01C0ABD9F9BF32C3D83C8F9
                                                              SHA-256:3D3BD153613C84F709D13D1F3AE519BDFA0B5238C7A1491C7DD71D310ED5202C
                                                              SHA-512:6B3EB4DE80A5ADAD5324E09913EBC3DEC4C1B8F122E053662A7938379BEF4FFB1BFF4A8CCD7ECF66FF4437889FE106BDDDD720129A114F6F7F3664CF61D39EBF
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........V........& ...$.*...P......P...............................................yC....`... .........................................j....................`..(...............|............................V..(.......................p............................text....(.......*..................`.P`.data........@......................@.`..rdata.......P.......0..............@.`@.pdata..(....`.......>..............@.0@.xdata.......p.......B..............@.0@.bss..................................`..edata..j............D..............@.0@.idata...............F..............@.0..CRT....X............N..............@.@..tls.................P..............@.@..reloc..|............R..............@.0B/4......$............T..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):24286
                                                              Entropy (8bit):4.927914456719635
                                                              Encrypted:false
                                                              SSDEEP:192:0jc9d+lXb2FZqo9B+1M3+TEZSk3sCJOQCDSd/7cdVJlQrzgM+3DmAPLfk8SMy4KF:6c9ySvP+tTExJJOqd/+JlQrz511MrG
                                                              MD5:F09B8C98DE983C84B31D5F82658C2D50
                                                              SHA1:C6C87C4FF7F6DB071B2DBB04F3BF61FAE862DB49
                                                              SHA-256:2AF25E0CFD858AF6D37F494B70A2DA0E7AE081305B2B4761D2123F77146D3B4E
                                                              SHA-512:88EA21CC4C29228A5C0B7D722311D037FB573EF1389B5F962BAF1532FFAEC1B5D7E4FA2F8C36AD446534ABCA39D319F2E8CF1AB46501992DBFE7B3677FF4AD24
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........J........& ...$. ...D......P.....................................................`... .........................................k....................P..(...............p........................... C..(...................$................................text............ ..................`.P`.data........0.......$..............@.P..rdata.......@.......&..............@.`@.pdata..(....P.......2..............@.0@.xdata.......`.......6..............@.0@.bss.........p........................`..edata..k............8..............@.0@.idata...............:..............@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..p............F..............@.0B/4......$............H..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):30548
                                                              Entropy (8bit):5.263790902307366
                                                              Encrypted:false
                                                              SSDEEP:384:9G9TTB/I/z/fwQ5FZ+w5TMmACnfdLr9JOfcouFmkxrKlPVCCAxMlhnGwdd:I9v8/oQooTxACf1r9J+CLXuhpdd
                                                              MD5:56830F89D9B89F0C88424D90533BF4D6
                                                              SHA1:FCF79D5DEE3FD05B2BEB66D83CDF82E61D1C04BB
                                                              SHA-256:687693FB3300923B267D03686AF35C80E8C3DAA42D49FC3E0D8600E10812084E
                                                              SHA-512:DB0936B39851CBC8BD1F8F0135C1FD64098E484DF7A004A3D9EF6D01EBADE9A9D589C492B90E44660E59661B8582EAB0FEC75A82550F78670D9BA48DF7501833
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........^........& ...$.....X......P.....................................................`... .........................................j....................`..................|...........................@V..(...................\................................text...8-..........................`.P`.data........@.......2..............@.P..rdata.......P.......4..............@.`@.pdata.......`.......B..............@.0@.xdata..@....p.......F..............@.0@.bss..................................`..edata..j............J..............@.0@.idata...............L..............@.0..CRT....X............V..............@.@..tls.................X..............@.@..reloc..|............Z..............@.0B/4......$............\..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):66472
                                                              Entropy (8bit):5.830247127893983
                                                              Encrypted:false
                                                              SSDEEP:1536:cTrnuJJmCbd/iY1wdy3nFMhKvCcHsxBklaRsfxr1HWBJJFh:Nlbd/vudy3nO09HkOaal1H0JJFh
                                                              MD5:AE9468F874D41ADC6BBE50517AA4DE49
                                                              SHA1:67B4C3205A16BD5850AA634C6FCA4AB2D724A479
                                                              SHA-256:EC4D4DB3B2ADE9A1EA7514636FB31393D846D4485DDCE34EBFE5B6F6C6538046
                                                              SHA-512:158F0159A04253BBD84C05784C4455B8AFC1E0720BAFA4AD84925530B51CC8E4C8769F91CCA89F1477EE4763352E20307DDA4444FB9AE2E7AED9440C147C6371
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...$............P....................................................`... ...................................... ..j....0..x...............\............`..p...............................(....................2..@............................text...(...........................`.P`.data...............................@.P..rdata..............................@.`@.pdata..\...........................@.0@.xdata..0...........................@.0@.bss....0.............................`..edata..j.... ......................@.0@.idata..x....0......................@.0..CRT....X....@......................@.@..tls.........P......................@.@..reloc..p....`......................@.0B/4......$....p......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):80788
                                                              Entropy (8bit):6.041649105323227
                                                              Encrypted:false
                                                              SSDEEP:1536:BBFJ+tarN78biYYwd83vFshk9/hfrJaBk1aaM/WZrM3yH8Kdsqx6GOk8L:flrN78bvVd83vu+zrk+a96M3yH89e6GG
                                                              MD5:3B1E243B7701AC33E9435F14BC0E38CC
                                                              SHA1:EB6D29A69A15D0EF1724B2C3A6848CD3F9F08D54
                                                              SHA-256:1CD03652C78629DBD9B5CC1861E16FE4C89D2A1F43D864C145E47AF8B8107D73
                                                              SHA-512:188486869BFE1BD2D02550249D2C86601456AABD9BA625838A2EDD17E71235E9207BDF18A0AE92658233E9FBC998498578C309FEE4221AEE039EC731662E192E
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........../.....& ...$............P.........<...........................................`... ......................................@..j....P..D...............................................................(...................xS...............................text...8...........................`.P`.data...............................@.P..rdata...;.......<..................@.`@.pdata..............................@.0@.xdata..d.... ......................@.0@.bss.........0........................`..edata..j....@......................@.0@.idata..D....P......................@.0..CRT....X....`......................@.@..tls.........p......................@.@..reloc..............................@.0B/4......$...........................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):51185
                                                              Entropy (8bit):5.553102081938478
                                                              Encrypted:false
                                                              SSDEEP:768:Iv9oc1kmGPy3mE6BX8Sys+tK9+1mdJL+kbyF/UZ:Ivh1fGmeBsSyXtK9NJL+kui
                                                              MD5:FEEB4C3AA3658142B1C75502A6714024
                                                              SHA1:49F2D452D88BA8091BA779DC188DFD7DD0D1C1E5
                                                              SHA-256:E5F80CE21CDC457A325A5AA48C4230439BA431A0C440D40FA8C62D66A3267A72
                                                              SHA-512:E50C6FC38B15871E6645EDB7383FA29A41A6183D3F109D193F97874EA06FFA98EFD679752C3483D4E6500A2D0D557BC57D83D9187F750CE54992DD10717AA432
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".l..........P..........h.............................P......:......... .................................................D............................0.. ...............................(....................... ............................text....j.......l..................`.P`.data...p............p..............@.P..rdata...............r..............@.`@.pdata..............................@.0@.xdata..`...........................@.0@.bss....P.............................`..edata..............................@.0@.idata..D...........................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.. ....0......................@.0B/4...........@......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):70413
                                                              Entropy (8bit):5.696661490761055
                                                              Encrypted:false
                                                              SSDEEP:1536:CaztYCbgt/lKMxmIPNx8HJark6EG1w9+TUv+zZ6YybEdViAT:JYC0GvIPNSarkxG1wiT
                                                              MD5:89A11A2D77CD475965659048456A39BF
                                                              SHA1:ED77A7AF416AA0DF40741915AE771D990CB6A5DC
                                                              SHA-256:7C0158486DCFE16B21359359032A072CC8D123912361F471C405255F47525B24
                                                              SHA-512:D74E1E570291991B4702E1B42E4636542B62FE953AA4B31EF3E090018D130EF78478D2C976CB45902034B8000FD674983F687C1CC4C6494469357D3249145B15
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ..."............P..........b....................................8......... ...................................... .......0...............................p..................................(....................6...............................text..............................`.P`.data...`...........................@.`..rdata..P".......$..................@.`@.pdata..............................@.0@.xdata..............................@.0@.bss..................................`..edata....... ......................@.0@.idata.......0... ..................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4..................................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):29911
                                                              Entropy (8bit):4.0106519634753
                                                              Encrypted:false
                                                              SSDEEP:768:G9+QsZJ9SMLCRYkwxdOPBgBaWlKTv8BcWToe2jXuksE1UpryVh9mvxlm0RDmeQoN:GQhJ5pbRDR
                                                              MD5:328B6D04E15E76F4AEBF9C90FF106BA7
                                                              SHA1:0B770032120006AA11E5DBF8290036F200566738
                                                              SHA-256:EDD3CD871248461BC3AABFD5359EF4EEC485CBDC439651B16C0D653B35EE9BAC
                                                              SHA-512:096EF52724BDAED272054EF543602115560BCD2BF0BC86E2299C887D3AB6D8EDE146DD7FFF190F0BA965E302C18FD7D1E1121300940E608534B83764EB0831C3
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..J.....& ...".....f......P..........f.....................................A........ .................................................................................t............................p..(...................x................................text...............................`.P`.data....4...0...6..................@.`..rdata.......p.......P..............@.`@.pdata...............X..............@.0@.xdata..D............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............^..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..t............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):16603
                                                              Entropy (8bit):4.6548754089028925
                                                              Encrypted:false
                                                              SSDEEP:192:eV89dQQC1/dODPXE/LZa+oKJOfVCV5ZBV8qHtrcr0A/H0uf5OSMy43Z:q890dGXE/LA+NJOwFHrrc9vLMN
                                                              MD5:746E2D25885AA53230A2685FB4C627E2
                                                              SHA1:CD17D63D0D94FA8A9087B60E3586CA0DAF266901
                                                              SHA-256:3573F5614444591BB05A43D8692DEE49CB3F8F8E0B88BA9CCE0D14A35549EC8B
                                                              SHA-512:CDFFB8932C2B33A434D02C3FC2B6D8A510AAD4F001DEA498FD30BFA35523FAC10FAB469944ADF51CB20379D18B9454F15B4BDF10D2A4392B8D677B57A612CAB6
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........8..J.....& ...".....2......P..........o.............................................. ..............................................................P..................h............................A..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@......................@.`@.pdata.......P.......$..............@.0@.xdata..D....`.......&..............@.0@.bss.........p........................`..edata...............(..............@.0@.idata...............*..............@.0..CRT....X............0..............@.@..tls.................2..............@.@..reloc..h............4..............@.0B/4...................6..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):18159
                                                              Entropy (8bit):4.556575201115682
                                                              Encrypted:false
                                                              SSDEEP:384:V1n89NdGXE/LA+NJOJbDt/oLdCHoBrcmM7MN:Q9UALAkJsbMN
                                                              MD5:47CDAD5FE3E9321A162FF58F297C9786
                                                              SHA1:1864C3F97AEB98F9BCAD8A17220ADC1CAF7579E2
                                                              SHA-256:DBC63B0E25B953545CF81409C75117F30AF289B1EA943E1449FFFB875623A842
                                                              SHA-512:6980544DB70BDA517A3C2630145D823471160CAD36F107D6DA251CE86D3B6ADA40B9D471EF09FC51A6E35C83F3A5B3FE9B0F98366DBCCFC57C8EC979A20C78D4
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........>..J.....& ...".....8......P..........e.............................................. ..............................................................P..................h............................A..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@......."..............@.`@.pdata.......P.......*..............@.0@.xdata..D....`.......,..............@.0@.bss.........p........................`..edata..............................@.0@.idata...............0..............@.0..CRT....X............6..............@.@..tls.................8..............@.@..reloc..h............:..............@.0B/4......$............<..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):31963
                                                              Entropy (8bit):5.18964700946902
                                                              Encrypted:false
                                                              SSDEEP:384:hP90OQLtOME2KqRHQg0MQRiYhg1JO7wLqeJxereTbuLrc7EKMRrlG:h9+tOyv0XoCg1JzqjKHujBG
                                                              MD5:44A0140362019588F4E5C1BAEFF58E4E
                                                              SHA1:D195006DDA9B390270103011A9F7EC405FA1F0D2
                                                              SHA-256:FD44373CFCD446247A1F2EFE7748821EDAC57ACB70564A3FD39924D1AB975D6C
                                                              SHA-512:4624B7BF1FBA904808C155C972211F219A4D4C50DD100B36D9EA3767CAF50B4FF450FACAF80563786D81722EEA7CC7FE83D0E06D931B95B48F29B69B20289A08
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........h........& ...".2...b......P.........,i.............................................. ..............................................................p..................l............................e..(...................................................text...(0.......2..................`.P`.data........P.......6..............@.P..rdata..@....`.......8..............@.`@.pdata.......p.......F..............@.0@.xdata..h............J..............@.0@.bss..................................`..edata...............N..............@.0@.idata...............P..............@.0..CRT....X............`..............@.@..tls.................b..............@.@..reloc..l............d..............@.0B/4...................f..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):18655
                                                              Entropy (8bit):4.537004954002481
                                                              Encrypted:false
                                                              SSDEEP:192:sVX99MQo1/BjPXEfLZ6kqJOfVhvQMpg13I0EwZBVWqHtrcr0LDUOdfuSMy43Z:sX9aVXEfLgZJOTDOVEsHRrcMlMN
                                                              MD5:64331F4F52478F07F3C89ED8619533F3
                                                              SHA1:92EC9C9C65AEB6550D459238C2DF2E661EBD6551
                                                              SHA-256:3A601DB718DF72D9AD4A5E7BF110FB766691D69CFA008BB82250393940471288
                                                              SHA-512:182EB6967CFA95BD118F4E718C28774FC8DAD4D29819F31A0FD553CD7DD9231639C3E0A18F1CD2812D7C1B87E90DBB7663C2CF54546281F49D496F7AD0D6729E
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........@..J.....& ...".....:......P..........k....................................n\........ ..............................................................P..................h............................@..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@.......$..............@.`@.pdata.......P.......,..............@.0@.xdata..D....`......................@.0@.bss.........p........................`..edata...............0..............@.0@.idata...............2..............@.0..CRT....X............8..............@.@..tls.................:..............@.@..reloc..h............<..............@.0B/4...................>..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):17098
                                                              Entropy (8bit):4.602296422922742
                                                              Encrypted:false
                                                              SSDEEP:192:nxZX9dOQ04/hePXE/LZa+dKJOfVLCpXaZBVuIqHtrcr0aFhu9NfpSMy43Z:3X934XE/LAZJOqaHyrcXhLMN
                                                              MD5:1FC750C7E69477837F6EB51DDDC943D4
                                                              SHA1:F8DF9A0E713A62E0B6ACC099FD084843A461A5AF
                                                              SHA-256:BA638CE05DF4E4DF4B8C26ECA830256ACC747E09186549856CFB5138C65F43E6
                                                              SHA-512:14066427A05CE9117C8135582A95718AC7D4205D3D97F2856A14BFB8714FCC317F431EC58D6285C9B4A9A6B24D2E5F77F81B7A67ACBA4AD344703D11A5FA4D26
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........:..J.....& ...".....4......P.........Dk.....................................8........ ..............................................................P..................h............................@..(...................x................................text...............................`.P`.data........0......................@.`..rdata.......@......................@.`@.pdata.......P.......&..............@.0@.xdata..D....`.......(..............@.0@.bss.........p........................`..edata...............*..............@.0@.idata...............,..............@.0..CRT....X............2..............@.@..tls.................4..............@.@..reloc..h............6..............@.0B/4...................8..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):22674
                                                              Entropy (8bit):4.891526718310465
                                                              Encrypted:false
                                                              SSDEEP:384:TD69UZzCT59T9g4nJODrKRc1rcYuZhWMj:f69UKO4nJkrotht
                                                              MD5:ACED12D5BAA49E6D4A472C4B22199518
                                                              SHA1:C303D34172FFB4E95A53EF921B64E58B8A5B3010
                                                              SHA-256:2C462DB083D0C8CEECA72556A0A65BD7CC62ACD91F3552BC6091450520EAFC36
                                                              SHA-512:2C8F4441EED4B685404BACC9C0B14C9A378D8E1FBFBE23ACBE1D87303AE498C171D8E7EBEDA54DDD177E6C8E17003187937EDB44E1FA7669F97E65AFAB5D4E98
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........J..q.....& ...".....D......P.........<a.............................................. .................................................p............P..p...............l............................B..(....................................................text...(...........................`.P`.data........0......."..............@.P..rdata.......@.......$..............@.`@.pdata..p....P......................@.0@.xdata.......`.......2..............@.0@.bss.........p........................`..edata...............4..............@.0@.idata..p............6..............@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..l............F..............@.0B/4...................H..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):21915
                                                              Entropy (8bit):4.757418617440637
                                                              Encrypted:false
                                                              SSDEEP:384:y79G36RT65F18KX6jPNJOj9NtKrcRCnME7:O9G36RO5FTqjPNJyXCn
                                                              MD5:B701790AF77DF279C0C5D309BAC53661
                                                              SHA1:78AD28AE8215C82EC16E0FF53A9F424CF86C8ACC
                                                              SHA-256:71075A55864F3A64DE5656422D9EB4E459B0029661D00C4B7ED0DA485E1894FB
                                                              SHA-512:D6C9E4C37AAB6A54460BA20811C3997EA84A7E878D12EC98EB3297E1E06A3DFF6D0887FBE2109AE0F80CC8D5A3F90BBE23C64ECE8020D4F70330CE0E3A5E02C4
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........J..\.....& ...".....D......P.........@l............................................. ..............................................................P..X...............l............................F..(.......................X............................text...............................`.P`.data........0....... ..............@.P..rdata.......@......."..............@.`@.pdata..X....P.......2..............@.0@.xdata.......`.......6..............@.0@.bss....0....p........................`..edata...............8..............@.0@.idata...............:..............@.0..CRT....X............B..............@.@..tls.................D..............@.@..reloc..l............F..............@.0B/4...................H..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):29911
                                                              Entropy (8bit):4.00968808206656
                                                              Encrypted:false
                                                              SSDEEP:768:LO99QsZJtSMLCRYkwxdOPBgBaWlKTv8BcLToe2jXuksE1UpryVh9mvxlm0RDmeQN:yDhJ2pbRDM
                                                              MD5:1DDE855360F923B1FE26E3F9957A9D9E
                                                              SHA1:A8E907B0E99B6D5C3EA7072CEABF33B8EB1CAB36
                                                              SHA-256:D91668159C495259C197584477CE8ACE78A8C72641F2A9F652A5949CABCF955A
                                                              SHA-512:CA0D2E0B347B027A78D242E07745F71E091E5277CD29118D8D12B99714EF79FE63198C6B86954825243CD69561A4323D455ADB482B84D085F95B7B16529AD6DD
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..J.....& ...".....f......P..........i.....................................V........ .................................................................................t............................p..(...................x................................text...............................`.P`.data....4...0...6..................@.`..rdata.......p.......P..............@.`@.pdata...............X..............@.0@.xdata..D............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............^..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..t............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):29911
                                                              Entropy (8bit):4.009652718050617
                                                              Encrypted:false
                                                              SSDEEP:768:U9kQsZJlSMLCRYkwxdOPBgBaWlKTv8BcLToe2jXuksE1UpryVh9mvxlm0RDmeQoJ:UWhJOpbRDN
                                                              MD5:B15FE82A5ED54CB3DF2D893F1BC686DE
                                                              SHA1:0E81E14E53BF9933F53EED2BA631B948DEDD2E8A
                                                              SHA-256:1A4271E7C6DC2D9E6132380690F24D4FB1FDEABCBA92BD6B7611AE4D28269D28
                                                              SHA-512:0B2861DAA8D139C8187D9E13C0FDFB9C782FFE0A2B48E8DE65D00550D4E71219F9ACB77C16FBB41606A3E6AC5F9EE4453DF13D4BDA52B7881C1A3BF07D2C079B
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........l..J.....& ...".....f......P.........lg....................................^O........ .................................................................................t............................p..(...................x................................text...............................`.P`.data....4...0...6..................@.`..rdata.......p.......P..............@.`@.pdata...............X..............@.0@.xdata..D............Z..............@.0@.bss..................................`..edata...............\..............@.0@.idata...............^..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..t............h..............@.0B/4...................j..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):18645
                                                              Entropy (8bit):4.5095948752797215
                                                              Encrypted:false
                                                              SSDEEP:192:mxX991Q31/BjPXEfLZ6kqJOfVCkxMHYp+wn7voZBVxqHtrcr0ShVcyfQSMy43Z:eX9yVXEfLgZJOxM4pbn7v0HorcFhpMN
                                                              MD5:77257C225BFC65B49C8C34C9CB1C0C3F
                                                              SHA1:1A659952983FBF57AC6D8CE5260F190FFBD4BDBD
                                                              SHA-256:5B82CA52A8C1916E655A36385B91F046FF8F0D744AF8C7943D7F5CE30DFD4E85
                                                              SHA-512:F7C3E1A3AD5F8D0D375D9A295E79AEE97759D0B1414F1E67D6BD31313A104D46DB6295F9F51CE2D24EE05E98500E26A330BC5DB60BED5D8C8B90C7097F44F8D4
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d........@..J.....& ...".....:......P.........dg....................................2......... ..............................................................P..................h............................@..(...................x................................text...............................`.P`.data...@....0......................@.`..rdata.......@.......$..............@.`@.pdata.......P.......,..............@.0@.xdata..D....`......................@.0@.bss.........p........................`..edata...............0..............@.0@.idata...............2..............@.0..CRT....X............8..............@.@..tls.................:..............@.@..reloc..h............<..............@.0B/4...................>..............@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):389587
                                                              Entropy (8bit):6.065853382051008
                                                              Encrypted:false
                                                              SSDEEP:6144:3Ae5AZRQrKIa0pAl7SddEMfRt+WLWkzb1+K6IJFqtnFNZAYBZAyU4UkDIg8EaSyb:weHKFXl8FT+WLWkzb1+K6IJFqtbZA1yK
                                                              MD5:8059FF4FEE3A2A9AF43D03A555B184DE
                                                              SHA1:6B222720DD5650B9BCAB534AF3369BE06C333736
                                                              SHA-256:A91553E15DE1A663608578A486962239DFE3AF7CE5BD6B00A22F7A1D53687E33
                                                              SHA-512:C447612F311D5470CC524016CB41367FDDB87AA3D9CC05B1DE7F7126E5C4A003CB6662F38233C761583A2002E3F614DD4407926E48D76123823426CF412C19B9
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................& ...".(..........P.........Ll.............................@......<......... ......................................p..........xo...............<........... .................................(....................................................text...H&.......(..................`.P`.data........@.......,..............@.`..rdata..Pv...P...x...0..............@.`@.pdata...<.......>..................@.0@.xdata...2.......4..................@.0@.bss....p....P........................`..edata.......p......................@.0@.idata..xo.......p..................@.0..CRT....X...........................@.@..tls................................@.@..reloc....... ......................@.0B/4...........0......................@.0B................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1057027
                                                              Entropy (8bit):5.705746635573194
                                                              Encrypted:false
                                                              SSDEEP:24576:LIhMyEz6HdYaAC0s9MTtfQRoVL4xtbyJFRGrG/1QJ2TzL:LGfHR3SCSUjMAy/SJ2HL
                                                              MD5:6D12AC485DFA03B5F1BEEC4122ED3E55
                                                              SHA1:FEA993D484F1FF2914B166035B02466BC2FAD029
                                                              SHA-256:30B6BBD922E9DC600F9FA7A418D51C92714559900E40DC543CE24A62FFE4676B
                                                              SHA-512:DCF63E2651E14D57A3BAF413371297443EBEF66013D33B56E0B3AFAA79DB1F088F0634A73D262978B963C1E61F75C1CE3B9C5C9053F700ECC36DEDC5BCF601F1
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...a..e..........& ...".....H......P..........h.............................`......~......... ......................................@..M....P...G..............................................................(....................]...............................text...H...........................`.P`.data...............................@.`..rdata.. ;.......<..................@.`@.pdata..............................@.0@.xdata....... ......................@.0@.bss....`....0........................`..edata..M....@......................@.0@.idata...G...P...H..................@.0..CRT....X............H..............@.@..tls.................J..............@.@..reloc...............L..............@.0B/4...... ............N..............@.PB/19.............. ...R..............@..B/31......H.......J...r..............@..B/45..........P...0..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):122521
                                                              Entropy (8bit):5.10564723030005
                                                              Encrypted:false
                                                              SSDEEP:1536:Crw0jHcZQPJTnEOJv8AzcRvujqZGK5jaAxQiGTen+cm/BRXxLhbceOiKCiJ:IfdJUAzdmvP5GdX6
                                                              MD5:57BEF84CDA41E7C527504B86425BB142
                                                              SHA1:334CE858FF5B1936FDF88507769864C037ACDFD3
                                                              SHA-256:B4C4736A19FD377CE05D8E4E9105F2BC7FF6B36146DC3534CBB6477F4671D1D6
                                                              SHA-512:104CEC260E2D947025038738D0FA38B51E1C16B8E3F4B20DA4750EE5A7118531FB909F5113A8D49A4F00F949B00F48E6086E8078B43AA572927B36E0481C1E17
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m..e.d..2.....& ...".4...d......P..........p.............................@......AR........ .........................................S.......h............p..................l...........................`d..(...................................................text...X2.......4..................`.P`.data........P.......:..............@.`..rdata..0....`.......<..............@.`@.pdata.......p.......J..............@.0@.xdata...............N..............@.0@.bss.... .............................`..edata..S............P..............@.0@.idata..h............R..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..l............h..............@.0B/4...................j..............@.PB/19......u.......v...l..............@..B/31.................................@..B/45.....p...........................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):132204
                                                              Entropy (8bit):5.099861464770627
                                                              Encrypted:false
                                                              SSDEEP:1536:C6BmQxJj7FXlubvBd0NKh/BwWSsbajCU3SeD6dGcyMhD0VRiK:DmmCb51haIkGIT
                                                              MD5:48602523FF8257A617B55C2AAFA83CC7
                                                              SHA1:57E86767D253DF4AFE991A4C14AF722D59B6C207
                                                              SHA-256:A6B1C04432AA897FBF7820604019AFDAA28CF32BC8BEC0B3C895577A5C68CB35
                                                              SHA-512:1B60BFE6BA0D282F23364F015C547FD705877260DA32B60E30DDED60601762FEC7B17A720ABDADE78D99C507683C2655B43C6B0E46402F99A0113F13DC22AA81
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m..e.... .....& ...".0...`......P..........k.............................P.......k........ .........................................S....................`..4........................................... W..(...................................................text..../.......0..................`.P`.data........@.......6..............@.`..rdata.......P.......8..............@.`@.pdata..4....`.......H..............@.0@.xdata.......p.......L..............@.0@.bss.... .............................`..edata..S............N..............@.0@.idata...............P..............@.0..CRT....X............`..............@.@..tls.................b..............@.@..reloc...............d..............@.0B/4...................f..............@.PB/19.................h..............@..B/31.................................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):111500
                                                              Entropy (8bit):5.0766613918299806
                                                              Encrypted:false
                                                              SSDEEP:768:79dDDHAOo5dSyMkJ5GB+t5Y4EdPJiv3UHLCkAjn+zQ8SHlIr6Kxrv8m2mytnMlp1:7fzLKJw+9vWAj3Ir1v8m2mbu/9NpKnrp
                                                              MD5:BBBBFCFF619B9555A0A37BDF1BB04BD2
                                                              SHA1:81D38322B6FA903A5ED3425D3DB9942CF20DB716
                                                              SHA-256:CA17008F627BAEBBE490074D4B2198A2146E5A4CDF2FD620CD94C9F397E418E8
                                                              SHA-512:79476CCF22B0724D9D1E450FA61820AD8C91ACFB633A5B5006C30EC13708775C97786C1DC51C351D7234203DAA963038ED1E2D96984F6DE5BEE3A151F9F2F1D3
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j..e.L..h.....& ...".*...b......P..........n............................. ......K......... .........................................P.......p............p..................p........................... c..(...................P...`............................text....(.......*..................`.P`.data........@.......0..............@.`..rdata.......P.......2..............@.`@.pdata.......p.......N..............@.0@.xdata..|............P..............@.0@.bss..................................`..edata..P............R..............@.0@.idata..p............T..............@.0..CRT....X............b..............@.@..tls.................d..............@.@..reloc..p............f..............@.0B/4...................h..............@.PB/19.....Zh.......j...j..............@..B/31..........p......................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):7957796
                                                              Entropy (8bit):5.3800748018134925
                                                              Encrypted:false
                                                              SSDEEP:98304:9w0FZFAPmuUeV/F5nW1Mj8gLzdtTyEfbxCo1WgaYP7KPSQR:emTvyVtH8uzHWEfbxCt2Be
                                                              MD5:905679E16429DDBD4D5AEBC2DB23E197
                                                              SHA1:055BF64F10CFFCB43A9B5F78B367A1D7DE3C6977
                                                              SHA-256:E7255EC95FBD9D94F8E47B3721E516F32AA76EC3B6A23777A4403072920AA3D4
                                                              SHA-512:7737410C40E6E7BE838AC583C485563D79121EA80CF5A1025B6FF2F7EE8E81F9AE86A12812C1B86985A4B37ADF1AA0E6F5CCA88EA6E4CF16CF6A700B21A31E10
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...k..e.ju.W-....& ...".j..........P..........p..............................v.....y.z....... ......................................p..M........v..............dA........... ..............................`...(...................D................................text...Hi.......j..................`.P`.data...P".......$...p..............@.`..rdata..............................@.`@.pdata..dA.......B..................@.0@.xdata...I.......J..................@.0@.bss.........`........................`..edata..M....p.......(..............@.0@.idata...v.......x...*..............@.0..CRT....X...........................@.@..tls................................@.@..reloc....... ......................@.0B/4......P....0......................@.PB/19.....S/)..P...0).................@..B/31.....\K....<..L....;.............@..B/45...........>......H>.............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):279634
                                                              Entropy (8bit):5.070876347664025
                                                              Encrypted:false
                                                              SSDEEP:3072:XuOjYCaZuzgk8m20A5nl77IPzh5SmGiWO4qQ9Yuwzxq:+Qk8C5lvIrh5SQW56fxq
                                                              MD5:C39F6FFE2D2398B8CB4020EDEDF1C9DF
                                                              SHA1:34958016DB2CC4550CD6F7337B54391E518B28BF
                                                              SHA-256:37AF0D6EABA23D2C30DE20230125FE64D3CF81C8FBAB5798A58741752D76B80E
                                                              SHA-512:3E673000080BD1A0B0CFB09D02CB534F4CBAFFB7CC60C2CA4B3B298C49BDA089B152241A8B99791A554B16119BFB1D0AEEF50360B837369501095D7D134384B7
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...n..e..........& ..."............P..........e.............................@......e......... .........................................Q.......0............................@..|...............................(....................................................text...H~..........................`.P`.data...............................@.`..rdata..............................@.`@.pdata..............................@.0@.xdata..D...........................@.0@.bss....@.............................`..edata..Q...........................@.0@.idata..0........ ..................@.0..CRT....X.... ......................@.@..tls.........0......................@.@..reloc..|....@......................@.0B/4...........P......................@.PB/19.....`....`......................@..B/31.....,...........................@..B/45......G.......H..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):703099
                                                              Entropy (8bit):5.730490249232137
                                                              Encrypted:false
                                                              SSDEEP:6144:euIUX1XhlJsw5wtdH0qor/ZPJYUgu4PR9HfEu1UNi3+cUR1ElE5uw2UQKezKgXwL:eAJH5wtdH0qo/u9HcuONi3z+10VJC
                                                              MD5:81087C209FCAC602787FA6D318C88ADC
                                                              SHA1:4B5A1EC96CEB55EBCB98861DA6F81B00FA73F762
                                                              SHA-256:2184C9001CAC32F5F8E2B716D417C3862E66CF3CBE875DAFD484D240F3BABC54
                                                              SHA-512:9ADCDF2178BC4F643AD5DEB4FD3A9522A54F0D848A1957002B29BB4802FFF7BAEEF8D1822E18CAF3CC6CA77240BE4DE1C854FAA2DF5E63702B920B0E24002C62
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...n..e..........& ...".....&......P..........j.............................@.......@........ ......................................0..Q....@...1..............d...............................................(....................I..h............................text..............................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata..d...........................@.0@.xdata..p...........................@.0@.bss....@.... ........................`..edata..Q....0......................@.0@.idata...1...@...2..................@.0..CRT....X............&..............@.@..tls.................(..............@.@..reloc...............*..............@.0B/4...................,..............@.PB/19.....d...........................@..B/31..................:..............@..B/45..................V..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):614596
                                                              Entropy (8bit):5.512510856445139
                                                              Encrypted:false
                                                              SSDEEP:12288:vIs75tmt4Jxx7tIM3jBAyInViTp1oALRdLN8MW:vIeyt4Ph6gjYnViTpmALRdLN8MW
                                                              MD5:8466A77D8C7AA85834CC6B614AC159B6
                                                              SHA1:C952DAD1811263C1860D91EA8EE842FC22ABCB7F
                                                              SHA-256:F54C0DBB542B5C4B45A02E00C46C5517A2C63F64F52F9AD90C8B92E072D7AA03
                                                              SHA-512:8CDD35971097538AA9633B4A76B80602C30ADFF07515F492EB0D8FBF83144E5517662D0544D664BCDEDAAC67AD3DA40AF7842F3DEEA98F5300047367B13089FE
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j..e..........& ...".....T......P..........i.............................p......1......... ......................................@..R....P..|N..............t...............l...............................(...................p_...............................text...h...........................`.P`.data...P...........................@.`..rdata...-..........................@.`@.pdata..t...........................@.0@.xdata....... ......................@.0@.bss....@....0........................`..edata..R....@......................@.0@.idata..|N...P...P..................@.0..CRT....X............T..............@.@..tls.................V..............@.@..reloc..l............X..............@.0B/4...................Z..............@.PB/19.....Qp.......r...\..............@..B/31..........`......................@..B/45.....U....p......................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):375011
                                                              Entropy (8bit):5.125453701644306
                                                              Encrypted:false
                                                              SSDEEP:6144:9eAUCQYG3qk9r1fzZKAdHmavDCxo3bfBTcS:UiG3rzmaOx4dcS
                                                              MD5:2099F81E34A008581145D859BF2B0703
                                                              SHA1:767F86AB0F6AF3CFBAD654AF71F84F9FE35B0E6A
                                                              SHA-256:FEE53507C5A919B96465A17B031CE3B3EA5BA8833465D49CC3C3FCF3F0FA19CD
                                                              SHA-512:4F951DA2593320E98B170DB0187529743B5E6059805AE171988D1CFB48A50F742DBA12128BA8E60447B591EFFCAA98E1CE03504EA90BF37C37C70541BAA133B6
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j..e..........& ..."............P..........n.............................................. ...................................... ..P....0..................t............p..t...............................(....................6...............................text..............................`.P`.data...............................@.`..rdata.. ........ ..................@.`@.pdata..t...........................@.0@.xdata..............................@.0@.bss..................................`..edata..P.... ......................@.0@.idata.......0... ..................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc..t....p......................@.0B/4..................................@.PB/19.....j...........................@..B/31.......... ......................@..B/45......j...0...l..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):194943
                                                              Entropy (8bit):5.096486515309165
                                                              Encrypted:false
                                                              SSDEEP:1536:SuErP3zmbS4mGUtJX5v0+m3/ILvFS1FxnctninWBYxcjnyNglf8iRkKzrqsYELXD:o3Kb9yX5Rm3/I5fgWBII8iRkK/T
                                                              MD5:109ADE7757187891B0C28201505E6D82
                                                              SHA1:AFF96861213732EF9150C0C90997E2ED041478EF
                                                              SHA-256:3B1C7A4BF6441778A9E8AD06984EDFBBBF6A313B6070F712754E3EC4E24CE0FF
                                                              SHA-512:048AC283EBA41CD4995077DC854180F7F09E7A1BDE417BD48EA3E6F84FB6FBCA16440FFA943C9C0454AEC68C771FE9D9D7DFB20A67D640355F9F7B99BE2997E7
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j..e.r........& ...".N..........P..........h.............................P................ .........................................P...................................................................`{..(....................................................text....L.......N..................`.P`.data........`.......T..............@.`..rdata..P....p.......V..............@.`@.pdata...............j..............@.0@.xdata...............n..............@.0@.bss..................................`..edata..P............r..............@.0@.idata...............t..............@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B/4........... ......................@.PB/19.....M....0......................@..B/31.....w............f..............@..B/45.....`2... ...4...r..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):89604
                                                              Entropy (8bit):5.112777329910465
                                                              Encrypted:false
                                                              SSDEEP:768:L9RZCmtbbAdUZJHVSHyaPJivRzuV2kxDcdnRelL2VFv2XGhkZs564hJv6twRroxx:LUm1auJH3vToDcdniL23urf4nv7r9ecG
                                                              MD5:7A97DF37749CCAA88665203E5B11A36F
                                                              SHA1:1049F715556E31064DE5B571F2015278736FD242
                                                              SHA-256:6609E4319BB87B625A4C8FF3DB4B356938CAE1FD04362AD3D333A8223FE888C4
                                                              SHA-512:AD918D8287B0B0CCD7C5AA0CFD759AE9DE6C3E93FA8613713A0185185567B352EDA5E4A1C292DD411B69088633065B3D341FA4A460207D7378307D1D89DFD64C
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...p..e....,.....& ..."."...J......P..........q....................................E......... .........................................P....................`..................l............................T..(....................... ............................text....!......."..................`.P`.data........@.......(..............@.`..rdata.......P.......*..............@.`@.pdata.......`.......6..............@.0@.xdata.......p.......:..............@.0@.bss..................................`..edata..P............<..............@.0@.idata...............>..............@.0..CRT....X............J..............@.@..tls.................L..............@.@..reloc..l............N..............@.0B/4...................P..............@.PB/19......Y.......Z...R..............@..B/31..........P......................@..B/45...../....`......................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):235466
                                                              Entropy (8bit):5.367258360443586
                                                              Encrypted:false
                                                              SSDEEP:3072:EYhtArt7vMtNfIWiC7MuaMFffOqeE20c8WOdH/OBHYMTwk3ux+hNV+:4aMuVf3eRuH/OBHYMvex+hNV+
                                                              MD5:7B45D7B76CA570F2DB97EFD0DCBBFA7B
                                                              SHA1:89A2C63B3018A044CDD1975198836E19868CCAB8
                                                              SHA-256:3D467209A0C321B6F67C3D29DFE5D64312F2A20CC82C2E0F954F0F878B884184
                                                              SHA-512:9799830341505D8A1043ED870EFD15C8C446B9EB20A7AC1C4F377BE25C1315FC54C60091CD90E37BE01A7002369635E51B25513572CC2E83C6BF85A26357BB99
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...p..e..........& ..."............P......... q.............................................. ......................................P..U....`............... ..................................................(....................e...............................text...............................`.P`.data...............................@.`..rdata..............................@.`@.pdata....... ......................@.0@.xdata..P....0......................@.0@.bss.........@........................`..edata..U....P......................@.0@.idata.......`......................@.0..CRT....X...........................@.@..tls................................@.@..reloc............... ..............@.0B/4..................."..............@.PB/19..................$..............@..B/31.................................@..B/45..............0..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):168258
                                                              Entropy (8bit):4.956822399028388
                                                              Encrypted:false
                                                              SSDEEP:1536:jY6ZoJVhM9MUFv5xbCxy6AxOxsgnU5YLLdYPuoF/wZOI9DTzOve3tcAI7YyNFWCC:tmo/7bC8Oxsp5YLLawNTO1+
                                                              MD5:8BAB861F8AF06217CCF8B38C64458D12
                                                              SHA1:483ED3133E6B088F05F0DB496850A488212301C8
                                                              SHA-256:56F69CF75C426DD84A0ED3ABF173C8F2D19DD78C8920F134567886FB6C5EF482
                                                              SHA-512:70BF61B673C0FD4216059A083491F22A63DC56E2FD01D099A6B9F818854E9C6FA1FADC70FE90F4D4DE86454E64BBB94B8697B3BC3C3FAD3B2D7EA112EB496B06
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...p..e..........& ...".D...t......P..........i.............................................. .........................................U.......................................l...........................@s..(....................................................text....B.......D..................`.P`.data........`.......J..............@.`..rdata.......p.......L..............@.`@.pdata...............X..............@.0@.xdata...............\..............@.0@.bss.... .............................`..edata..U............^..............@.0@.idata...............`..............@.0..CRT....X............t..............@.@..tls.................v..............@.@..reloc..l............x..............@.0B/4...................z..............@.PB/19......... .......|..............@..B/31.................................@..B/45.....3'.......(... ..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):114864
                                                              Entropy (8bit):5.105606323836388
                                                              Encrypted:false
                                                              SSDEEP:1536:AbSmIm0JfvfHfVJlobdr1soxKEh3R3rsGbkc9s+l9:AuZf3fVMhr1aEhRYe
                                                              MD5:AAAA668EA6BD4A9B5C4713A3B8CD737F
                                                              SHA1:C805220F759AAD63149671AADD95862CAEB1ED26
                                                              SHA-256:50ED317DDD3657BFA2A14F538E9CAC1AB6E47884D6B59F965AC780C248CB2D31
                                                              SHA-512:1D669AD1EEAE32C859EE81CA80D7D7526EEF6BC9221C8385C266191DED5FFC5A87F3EF1F54936405AF23175161E1EA4807FB9C5525290E9426BD302142F5C124
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j..e.L........& ...".,...Z......P..........d....................................c......... .........................................P.......4............`..(............................................U..(...................................................text....+.......,..................`.P`.data........@.......2..............@.`..rdata.......P.......4..............@.`@.pdata..(....`.......B..............@.0@.xdata.......p.......F..............@.0@.bss..................................`..edata..P............H..............@.0@.idata..4............J..............@.0..CRT....X............Z..............@.@..tls.................\..............@.@..reloc...............^..............@.0B/4...................`..............@.PB/19.....Hw.......x...b..............@..B/31.....Q....p......................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):242432
                                                              Entropy (8bit):5.380306064007686
                                                              Encrypted:false
                                                              SSDEEP:3072:BHH17JjvICQ2oSqswjOaciSaabb/fWoEwU8dDGIi5TPJBIxFnPHnHfu83y:BwDjO3aibSAdD25TPJBIHnPHnHfu83y
                                                              MD5:108FA77BAB50F62BCC92AFD6B0BD27B1
                                                              SHA1:3898C6FAA262A3251EB710E1930A7154512AF640
                                                              SHA-256:BB6FC5A9F5A6DFD777E122CA97A0437E05169B5BB5986B9766F6DF4BD841A13B
                                                              SHA-512:74FC3E45794C69ADD96203FC8B2309C32E74202F249FEB861912680730F1A9FC428C00A04915DEF9D0A5DF498E95C37BA9D0347E49C817B6D28C45043C75450E
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...j..e....2.....& ..."............P..........h....................................)L........ ......................................P..Q....`............... ..................................................(....................f...............................text...............................`.P`.data...............................@.`..rdata.. ........ ..................@.`@.pdata....... ......................@.0@.xdata.......0......................@.0@.bss.... ....@........................`..edata..Q....P......................@.0@.idata.......`......................@.0..CRT....X...........................@.@..tls.................0..............@.@..reloc...............2..............@.0B/4...................4..............@.PB/19.................6..............@..B/31.................................@..B/45......1.......2..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):160310
                                                              Entropy (8bit):5.028502917700471
                                                              Encrypted:false
                                                              SSDEEP:1536:rjIoqzvxMFcJzIvx4ZCFVDXnAez8kGl7ZJIx5LaTrpmUzMExKJBgim:PSk4CFVD/OiLaTrEu5
                                                              MD5:49D119347D4B16749FE0E35827F4FBD0
                                                              SHA1:9D248A67A2B5CA0F0BC710D804C61EE15376E8AF
                                                              SHA-256:AD6F93B6B3E5FCEF8CD01B1A502AB37FCB973D85026422D94D167639535B369F
                                                              SHA-512:672EB115D676D30B678603CCB50CB3EE829224810BBAFA7C70C628FD662B1D13B679E15133CAB4998DB70A34F07B05B45C75E32E8E603CCD0B984186A2FDA080
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m..e..........& ...".>...v......P..........e.....................................b........ .........................................P.......................................|............................i..(...................\................................text....<.......>..................`.P`.data........P.......D..............@.`..rdata.......`.......F..............@.`@.pdata...............X..............@.0@.xdata..<............\..............@.0@.bss..................................`..edata..P............`..............@.0@.idata...............b..............@.0..CRT....X............v..............@.@..tls.................x..............@.@..reloc..|............z..............@.0B/4...................|..............@.PB/19.....U.... .......~..............@..B/31.................................@..B/45.....g).......*...*..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):134374
                                                              Entropy (8bit):5.121473815083218
                                                              Encrypted:false
                                                              SSDEEP:1536:cJWNgAsKJ/NPCv6mL6mA828U2bgorScYhYewCGPyP78y1xHHIjbNxX3:wWNTQumA2bgodYFyaPZ1Vwv
                                                              MD5:861D0AE7C11350867D5E8B8929850FB7
                                                              SHA1:92158408BB486BC1D8D47805A613ED320E899371
                                                              SHA-256:04FD3F7106A57FF2FBDDD91471A79A76C41F0EADDF378BA014785A0ECDFBA576
                                                              SHA-512:8825511B0D5A7AB1B01E25145714FD50BEC6F9FAE0FF139853A280453866B3793382915B31DB3685B8E1CD052E7874DEE1E1F280C9DD999E05205629E669FE9F
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...p..e..........& ...".2...h......P.........Ph.............................`................ .........................................P.......(...............4...............x............................i..(....................................................text...h1.......2..................`.P`.data........P.......8..............@.`..rdata.......`.......:..............@.`@.pdata..4............L..............@.0@.xdata...............P..............@.0@.bss..................................`..edata..P............R..............@.0@.idata..(............T..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..reloc..x............l..............@.0B/4...................n..............@.PB/19.....Q.... .......p..............@..B/31.................................@..B/45.....^...........................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):154473
                                                              Entropy (8bit):5.262041601006301
                                                              Encrypted:false
                                                              SSDEEP:1536:fcWr2AJfn7m9/AW3vHbcvwfd965Sw14dHrDKkZXL/0tznw8sT3zVDFBe09yw3sPv:EAKQuG1kL2KU
                                                              MD5:707598427805EC996E2C524688F3B454
                                                              SHA1:4CED87197E4B94938708148D86982C92EED4A6CB
                                                              SHA-256:06AEF40A862EE56811C7EA412A4087137440BC19404F4AA88886080E721021AB
                                                              SHA-512:3484DDB39FFC1DD16C8DB82DBCF118B5E28DC861363AD8F01947FD9321399113BA90205F7715EE5D88B6FDA29AAB571608D4B35F8FF8BE750DA9BE6C4394D69B
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m..e..........& ...".>...~......P..........k.............................................. .........................................O...................................................................`i..(....................................................text...x=.......>..................`.P`.data........P.......D..............@.`..rdata.......`.......F..............@.`@.pdata...............X..............@.0@.xdata..<............\..............@.0@.bss.... .............................`..edata..O............`..............@.0@.idata...............b..............@.0..CRT....X............~..............@.@..tls................................@.@..reloc..............................@.0B/4..................................@.PB/19......... ......................@..B/31.................."..............@..B/45.....L".......$..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):122111
                                                              Entropy (8bit):5.057737914389553
                                                              Encrypted:false
                                                              SSDEEP:1536:4MKq/susJMyCebvDvQcGCMMjkL6L0T957SYPaS:iUebLvQcQlN
                                                              MD5:AD31ED68F42F7395D4AC0EF7DB5922FB
                                                              SHA1:8E14D92CEA8C8F031F2DFD573790D635D6099640
                                                              SHA-256:86B4C6A5D3ADB53390A88649C2886A87C921667EECD15AE8247B8E85F5906F59
                                                              SHA-512:E18ADC8F3092A10BC7026912F64BEC281545BC3C1E61AD1640043DC376B1642E28E240C0AC54917EE75C43A75AB0872BDB7F9A48419B13F5DDDB1062C6E9BDFB
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...p..e.d..%.....& ...".2...b......P..........b.............................@.......Q........ .........................................N....................p..@...............x............................d..(...................................................text...(1.......2..................`.P`.data........P.......8..............@.`..rdata.......`.......:..............@.`@.pdata..@....p.......H..............@.0@.xdata...............L..............@.0@.bss.... .............................`..edata..N............N..............@.0@.idata...............P..............@.0..CRT....X............b..............@.@..tls.................d..............@.@..reloc..x............f..............@.0B/4...................h..............@.PB/19.....(s.......t...j..............@..B/31.................................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):194817
                                                              Entropy (8bit):5.015223676738041
                                                              Encrypted:false
                                                              SSDEEP:3072:GGfRGMK73NwksLEYarbftoFQOOpaPwcQRXTlf+M:+H6tEYq2ypwwcQRXTX
                                                              MD5:05DA305508A17DBB266E3D0DF7CA79D3
                                                              SHA1:5E9F83E87CFF400C5BF4A0C4FC86E946FBE07839
                                                              SHA-256:1CFB84765407087E0FD59D2FFE51BF671DF9B358087DFDEFC7DE0EC22F12348A
                                                              SHA-512:8603B4A81EEF5E89D12DF21DF7D8B7B8ADD3914F343B51DD4B9F2E8476E66EE2883EA7A2ADE7DE141B3831E374C4359C5614E7A6B4A1071DBAA14062F0D5AD41
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m..e.~..;.....& ...".H...~......P..........k.............................P.......2........ .........................................P.......,............................................................}..(...................@...P............................text....G.......H..................`.P`.data........`.......N..............@.`..rdata.......p.......P..............@.`@.pdata...............f..............@.0@.xdata..x............h..............@.0@.bss..................................`..edata..P............j..............@.0@.idata..,............l..............@.0..CRT....X............~..............@.@..tls................................@.@..reloc..............................@.0B/4........... ......................@.PB/19.....&....0......................@..B/31.....I............f..............@..B/45....._/... ...0...r..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):121615
                                                              Entropy (8bit):5.030068393553714
                                                              Encrypted:false
                                                              SSDEEP:1536:BQigVXLhb0mJ0XvNqCXVqDI2n3AHuskQsCou2cOQxJ7:+iIN0XV7X8DI23AHlo+OG
                                                              MD5:0FE8DBCFE7395B03838ED93FF4B7F68C
                                                              SHA1:E445B6B78946D90C9C8B600FC83472E1936744A0
                                                              SHA-256:2C7406EE14060F5FDF1E7325117368356E5716B870133DE3D07165DC2314FD39
                                                              SHA-512:2BEE56C38CBEEE76708B0A73D926ED5B88B2CDA8FFDA5862ABC88E4897E54E2F9A262DF6B6F39A3E3AE8E326DA540B30866AC797E2D52C825DAF57A9C051EABD
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...q..e.^..N.....& ...".,...\......P.........,e.............................0......X......... .........................................R.......0............`..4...........................................@U..(...................4...X............................text...X+.......,..................`.P`.data........@.......2..............@.`..rdata..`....P.......4..............@.`@.pdata..4....`.......B..............@.0@.xdata.......p.......F..............@.0@.bss..................................`..edata..R............H..............@.0@.idata..0............J..............@.0..CRT....X............\..............@.@..tls.................^..............@.@..reloc...............`..............@.0B/4...................b..............@.PB/19......t.......v...d..............@..B/31.................................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):130169
                                                              Entropy (8bit):5.1217523049793625
                                                              Encrypted:false
                                                              SSDEEP:1536:FSqonD2JRSYus2/vcWKtWJUwllUt7FG6Xo1jePQ4r0ae4JEeuV:poqk92sFlJ+o1KPQs+
                                                              MD5:0A0DEA55F3E536BB2E5E2177932588FA
                                                              SHA1:A8F2346395729A332A0314258CA0058A340AD586
                                                              SHA-256:3F5A759BABE1211BD750973520C8ABB928459E101AFF42928834967F2F013F5C
                                                              SHA-512:1FCA68F31AC4596ED369C1D66E1DFED2E08796B6B6F0BC58B79D32DDDEB55EF2C99A98845FFC287766A04DB6966D0CFEAD2B1C6577FD0C10C42168B38E45579C
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...q..e..........& ...".8...h......P.........<n.............................P................ .........................................M....................p..@............................................g..(...................................................text....6.......8..................`.P`.data........P.......>..............@.`..rdata..`....`.......@..............@.`@.pdata..@....p.......P..............@.0@.xdata...............T..............@.0@.bss.... .............................`..edata..M............V..............@.0@.idata...............X..............@.0..CRT....X............h..............@.@..tls.................j..............@.@..reloc...............l..............@.0B/4...................n..............@.PB/19.....[............p..............@..B/31.................................@..B/45.............. ..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):125388
                                                              Entropy (8bit):5.154269013413642
                                                              Encrypted:false
                                                              SSDEEP:1536:C1l0gaoyJOYVvTAjQo6lM3xUzyd9sXSBSSwXBSExW2WJrr:K0gavnbAMM3xU+sXSLr
                                                              MD5:ADE75392888360709691C999D98CE339
                                                              SHA1:D34BAEA3ADD7EB7F87E0E25615BD1D561612F238
                                                              SHA-256:29DC5639ECC0492C4A968D2E1C09A00C944892014794CE04AB6B7C07C6F43EA5
                                                              SHA-512:F6145C0EB125AAE78B6C8AD8D9D3314147678A161271CD3327D1B8ACEF4945D12A335926C80C3D92E3649FFFD677EAE9806D9D32FEDA1AF67E3A8B731726BBD0
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...r..e.l..].....& ...".2...d......P..........a.............................0................ .........................................Q.......t............p..X...............p...........................@d..(.......................8............................text...X1.......2..................`.P`.data........P.......8..............@.`..rdata.......`.......:..............@.`@.pdata..X....p.......H..............@.0@.xdata...............L..............@.0@.bss.... .............................`..edata..Q............P..............@.0@.idata..t............R..............@.0..CRT....X............d..............@.@..tls.................f..............@.@..reloc..p............h..............@.0B/4...................j..............@.PB/19.....$o.......p...l..............@..B/31.................................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):118897
                                                              Entropy (8bit):4.997581949743692
                                                              Encrypted:false
                                                              SSDEEP:1536:AwCqsJfk0ev+Td+gNS+BbhBbSldNZD59fAOx6XN87M+bt3mgE0kr:9C3CcggMgtBbkdd0N87Mj
                                                              MD5:8BA01A3BF41C5FAD4C4A8BEEBAF6633A
                                                              SHA1:2F57DDCDC2A31A46BADF54F422AC968C10C81A71
                                                              SHA-256:4FE21ABB136FD35C381F9E3DE789CB1FA6E2C8A2C40D1E4953E463490692CE14
                                                              SHA-512:448555653D609DC2C4CD0CE8BE040A006AB834667F353DC5E2B1DA4E6ED0F6E955CCEF2B73859DBF3C818C8D8B1D66D11E0737373862B204E8563C65E5D50082
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...r..e.T..J.....& ...".*...X......P.........|a.............................0......6......... .........................................P.......4............`..................p............................T..(...................4...X............................text...x(.......*..................`.P`.data........@.......0..............@.`..rdata.......P.......2..............@.`@.pdata.......`.......>..............@.0@.xdata.......p.......B..............@.0@.bss..................................`..edata..P............D..............@.0@.idata..4............F..............@.0..CRT....X............X..............@.@..tls.................Z..............@.@..reloc..p............\..............@.0B/4...................^..............@.PB/19.....6q.......r...`..............@..B/31.................................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1462583
                                                              Entropy (8bit):5.840625158975508
                                                              Encrypted:false
                                                              SSDEEP:24576:I/+sqIO25cH4loA8nCO876D1Cv8AGdpfW45ZqZvNpe5uusTFeK:H2OYG/6OvpnLwvNI5uusTQK
                                                              MD5:C931120134E19A51A98DFE193E444D6D
                                                              SHA1:C03054CFC1D2DC686A6B6FD7A4685795D76DAF66
                                                              SHA-256:EA2F87C47352D08A3C9E3717E30F0D655B497BB885E7855AA9414B44D86F09F3
                                                              SHA-512:2AE0C6D93D8C460E901C35FD16CE4E440D89F1C5F849882D1E916A37735C1B0DAC608E8FE5C1EF5A81D5316EFAEBCE2F886FF957807D54586D1F768E31891CB8
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...x..e.d........& ..."."..........P..........p.............................................. .........................................N.......TZ...........................p..................................(.......................P............................text...h ......."..................`.P`.data...@....@.......(..............@.`..rdata...W...P...X...2..............@.`@.pdata..............................@.0@.xdata..(...........................@.0@.bss..................................`..edata..N...........................@.0@.idata..TZ.......\..................@.0..CRT....X....P......................@.@..tls.........`......................@.@..reloc.......p......................@.0B/4......0...........................@.PB/19.....:...........................@..B/31......h...p...j..................@..B/45..................X..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):762657
                                                              Entropy (8bit):5.610032351376408
                                                              Encrypted:false
                                                              SSDEEP:12288:/kY//E4stn70QEPjnwz0JXoNxhaP013Q+3u:/kY//Ezn7lEPjnwz0Jwg
                                                              MD5:84702F84BA26C4540040AFA69DF6C741
                                                              SHA1:6145023756E4FC22F055303468B8C6882F12A766
                                                              SHA-256:8ED8B540AACB2230C94BDD2DCE101A07071A03AC8A36F8C421C40BF87194807F
                                                              SHA-512:15C53061A725C6DF3062D33E586D3477D952A4D3E1A9244E6354C72D0D8628542ED6F558323DE7A0BDE648A6F06DA36FDF1B5B223525D92A9DF4FA463ED54FA4
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...{..e..........& ...".P..........P..........j.............................P.......:........ .........................................N....................................0..............................@...(.......................p............................text....N.......P..................`.P`.data........`.......V..............@.`..rdata...3...p...4...Z..............@.`@.pdata..............................@.0@.xdata..@...........................@.0@.bss..................................`..edata..N...........................@.0@.idata........... ..................@.0..CRT....X...........................@.@..tls......... ......................@.@..reloc.......0......................@.0B/4......`....@......................@.PB/19..........P......................@..B/31.....O=... ...>..................@..B/45.....~....`......................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):140687
                                                              Entropy (8bit):5.169796485877359
                                                              Encrypted:false
                                                              SSDEEP:1536:JX45JC2KMAv0yzNtdCnOtpXw7bZBoRxmDKLnQ0f+lXv2KdXh84QzRQ0hUkr:FCDKR/X4aA/ZBQ86mZvFu
                                                              MD5:FD00F86FE90B93FDFD840F0FB05FD720
                                                              SHA1:76EC44EDE67ACFB98F06FE67AE2B78FA80E3E53A
                                                              SHA-256:EE85770240A5FCA430D22728501FDBE0974D6EE7DE32A538E2589D13C9B4A9AE
                                                              SHA-512:909725407E3A25BA80317E30F3962E4A2A3B44C6027BE2B9E441A4A67167F97BCF3CAE9031809F1E8A6A38B345B3F74399C3F606F760EBAEBABB5853BCD39429
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e..........& ...".>...v......P.........lg.............................`................ .........................................U....................p..d...............|...........................@h..(...................................................text...x=.......>..................`.P`.data........P.......D..............@.`..rdata..0....`.......F..............@.`@.pdata..d....p.......V..............@.0@.xdata..T............Z..............@.0@.bss..................................`..edata..U............^..............@.0@.idata...............`..............@.0..CRT....X............v..............@.@..tls.................x..............@.@..reloc..|............z..............@.0B/4...................|..............@.PB/19.................~..............@..B/31.....h...........................@..B/45...... ......."..................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):9097483
                                                              Entropy (8bit):5.853921971528212
                                                              Encrypted:false
                                                              SSDEEP:98304:d7JX9Mf3PlKOBos8/9F6kJuYP6h7r8uyUaxbazl5e+pXEJ6LinxEst1vrkKHlZqu:Ps8/O4cKFn5u57tgOzk6hcH8ciA
                                                              MD5:4DB43DC97D853E95DE5445D5E41FE2DA
                                                              SHA1:FE7238C3C3CA59824D36BDC7D285F587D63C98DE
                                                              SHA-256:FD770FE2CF45004C7EA97B52B41E66CF5E8D929DDC51C6631E54584474FCB377
                                                              SHA-512:C5F8E6AA7938E5A019D80D0A2C9F57A72C0A05F11553D43AAC40609A9A13DA1BE5253B5B9223D25F10371D6FE85B9E49127D351E07B9FC865BCA3F0FB3A747F5
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e.^..!E....& ..."............P..........m....................................K......... .........................................P........................N..........................................@...(.......................x)...........................text...............................`.P`.data....)... ...*..................@.`..rdata...~...P...~...<..............@.`@.pdata...N.......P..................@.0@.xdata..T~... ......................@.0@.bss..................................`..edata..P...........................@.0@.idata..............................@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B/4..................................@.PB/19.......=..0....=.................@..B/31...........R......zR.............@..B/45.....3.....U......4U.............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1846322
                                                              Entropy (8bit):5.774212388670086
                                                              Encrypted:false
                                                              SSDEEP:49152:PsueVDrc5VuefhkkcTNQWqu8yqC/sjuFvys:OVDKVumcTNQWqu8yD/sjuFvys
                                                              MD5:D507C9510978092E10A23C9E04C1A1AB
                                                              SHA1:2E83D495A48DD89E87141CA4445A57F2E6712FA6
                                                              SHA-256:E1B4F4A50E987FD415BF03BD29B43EB38E9D42AE9095F4764821AAB2070C9E86
                                                              SHA-512:435AEEE43497E2887FBD6E7565F9759E965CFEADB86A895A02C9017663D5BF6B1744B716CEC69AC3FFC3433A0438EAF5EAF64B486FADE786B90785709314BC98
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e.|........& ...".....B......P..........a.............................0................ .........................................N.......................................................................(...................|&..P............................text...............................`.P`.data...@...........................@.`..rdata....... ......................@.`@.pdata..............................@.0@.xdata..8...........................@.0@.bss..................................`..edata..N...........................@.0@.idata..............................@.0..CRT....X............@..............@.@..tls.................B..............@.@..reloc...............D..............@.0B/4...................H..............@.PB/19......O.......P...N..............@..B/31......{...0...|..................@..B/45.................................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):2353163
                                                              Entropy (8bit):5.761453680586188
                                                              Encrypted:false
                                                              SSDEEP:49152:VkVTzjZkOSo1tKuhu7el3Qkx5CzavofZPEvGDaVYFM:YkOSkou0gQEPvofFEvGDaVYFM
                                                              MD5:F00E2A0C92F8663CCAB5E672A0B7A63C
                                                              SHA1:2A53A758BE9D04A60FE5886ED9D21A1E19FC193A
                                                              SHA-256:E0DAC9A5A735D215EFADF456C5CC3E344578ECCBE282D442A771A58311028982
                                                              SHA-512:9F8BCD49EFEA4AC160712AB8F1AC098BDC38AE86674FB1C233CB46B2D15F93F0160765D808AF7EC2E4C37222BF067872581318233D54213D9D17ABA58BAD1D8A
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e.. .......& ...".....8......P..........c..............................!......<$....... .........................................O.......T...............................4............................s..(...................h................................text...............................`.P`.data... ...........................@.`..rdata..............................@.`@.pdata...............n..............@.0@.xdata..t...........................@.0@.bss..................................`..edata..O...........................@.0@.idata..T...........................@.0..CRT....X............4..............@.@..tls.................6..............@.@..reloc..4............8..............@.0B/4...................>..............@.PB/19.................F..............@..B/31.....3...........................@..B/45..........P......................@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):487524
                                                              Entropy (8bit):5.624691733733092
                                                              Encrypted:false
                                                              SSDEEP:6144:QUnoicbR/Q9EemrKSSp3NyYFtIS2IDYPhLlTdfBebpE0/4zwsyQ4XZdiRa9CHK7:3nDceuFrZSRNZIdLlTEe0/FhQ4Xu84K7
                                                              MD5:C0ED17E3D828AD838339FABB448FE147
                                                              SHA1:D35BB40249B2BF3A3A3314F5B4D01CB98200FD75
                                                              SHA-256:48083429538D4ADEA244569568744AD50E92DC82D9232119C0D0D703714C2558
                                                              SHA-512:327D1E69C2BB65021161CDE1275C4805621572221A01288B56D3C958AAEDA75BE9B99F3C16F36B6E2A203474AC570F90A5BBF2391572DEB90FF86E0A5BFF5B66
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e.N........& ...".....4......P..........e............................. ......]......... ......................................P..L....`...2........... ..4........................................... ...(....................i...............................text...............................`.P`.data...............................@.`..rdata... ......."..................@.`@.pdata..4.... ......................@.0@.xdata..(....0......................@.0@.bss.........@........................`..edata..L....P......................@.0@.idata...2...`...4..................@.0..CRT....X............4..............@.@..tls.................6..............@.@..reloc...............8..............@.0B/4......0............:..............@.PB/19..................>..............@..B/31......).......*..................@..B/45..................@..............@..B/57.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):10320
                                                              Entropy (8bit):4.576136228832107
                                                              Encrypted:false
                                                              SSDEEP:192:lySIB2jtyhc10+AlXV6y279BovSRWnxQopafSqUoJko7fKWXfiNzM9:lySIB2jty00Ll0y2ZfopafSqUoGo7yW5
                                                              MD5:8E997374B060E1B5450814F731306016
                                                              SHA1:AB7530FB426F2D41BBC149C33B9DADFB4A065F52
                                                              SHA-256:08CF0580D5FB9AFCBC5DDCF45E4C0C653F9ACFDBEBEB394AC670B94FDB0553C6
                                                              SHA-512:33B01561723DC4BFBDB861568B278DD79FAED06B261C18E1CDBD1E8E9CE1CDA8C68E2159FF3BCD58DD2F72CFAEDA030B66F30FF060BC47B2F9B52868D2576114
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Authors: Marco Barisione, Emanuele Aina. Copyright (C) 2005-2007 Marco Barisione <barisione@gmail.com>. Copyright (C) 2005-2007 Emanuele Aina.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<language id="def" _name="Defaults" hidden="true" version="2.0">. <styles>.. <!
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):11071
                                                              Entropy (8bit):4.638238373756212
                                                              Encrypted:false
                                                              SSDEEP:192:iySgpyg6ZXlGsMyHntZbnqbnan2narXBnafXGPSenX7YfYbpofafamigennYk:iySHgDMHntXdSe7hbpiIa7D
                                                              MD5:AAEAF316490E5A11A4727066FC40E87A
                                                              SHA1:BEFE460F91BBDCDC9DA3090C046DF74FCED865A6
                                                              SHA-256:8BA47A33D3076C9574D1ECABFD0E1F81CF5C3AC2799BD46F598ED02EEA5F47FF
                                                              SHA-512:CEE30CD21C74B370CC9EEA716957DB6D4F1C3176AA29F839A9CE3120C1710EEA80B2D8A72D1648DD0170A8F18C0295833FF23BAEB5A2FDE37945D711FB2154B7
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2005-2007 Marco Barisione <barisione@gmail.com>. Copyright (C) 2005-2007 Emanuele Aina.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->. . This file describes the XML format used for syntax highlight. descriptions for the GtkSourceView 1.x library.. . .lang f
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):13615
                                                              Entropy (8bit):4.011935129443769
                                                              Encrypted:false
                                                              SSDEEP:384:iySeI/b1N9mrYAzolzIXq0JxfNBo1rYLaAh9LNkd0IaalAhv9LNkL9vCkzVaNk5u:PSeIazolzI/xroa
                                                              MD5:5DE2E8ED11BBCCBDED825D7CF57D9711
                                                              SHA1:0FF99208DAD1FF41A17E065D8F3ABF3ED4D0CE2F
                                                              SHA-256:52B433E5854C37C22D341C4EC106675500CEB83FEB5DD16BE0EEB4EB9705FFD4
                                                              SHA-512:0F8180923802A995251C66B30745EA192EC98C79391D4798A2ED450505D5AA479688687F6EF08ED2F4C1AE9D4B677D37A7908088DDF815015600B2035899B952
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2005-2007 Marco Barisione <barisione@gmail.com>. Copyright (C) 2005-2007 Emanuele Aina.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<grammar xmlns="http://relaxng.org/ns/structure/1.0". datatypeLibrary="http://www.w3.org/2001/XMLSchema-datatypes">.<start
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text
                                                              Category:dropped
                                                              Size (bytes):15026
                                                              Entropy (8bit):4.705271831904072
                                                              Encrypted:false
                                                              SSDEEP:192:XSICmdXBwFK9IAW0Ye477DRK9mOYgR7B7611wYj:XSICm8A9IAW0Ye477DRK9mODEnj
                                                              MD5:6DA7821D0372C966A2B3BF8CE0780212
                                                              SHA1:27BA4722800897DEE588FF03B847066E8A9B75D6
                                                              SHA-256:DB2C396EC8F4A1D27742E458E6BDD23E9F37546E899D7E6DF197AC82AAF477E8
                                                              SHA-512:E6E9531B4B59B891B925C3BD73BA7D62417B35480F764B87A800C233B3757155889892AB02F6BBECA61AC9F65EBC48767E4AA46080B49B041CC2CC9FF59998CF
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Author: Gustavo Gir.ldez <gustavo.giraldez@gmx.net>. Copyright (C) 2003 Gustavo Gir.ldez <gustavo.giraldez@gmx.net>. Copyright (C) 2004 Beno.t Dejean <TaZForEver@free.fr>. Copyright (C) 2006 Steve Fr.cinaux <nud@apinc.org>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<lan
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):4269
                                                              Entropy (8bit):4.77474899491439
                                                              Encrypted:false
                                                              SSDEEP:48:c2bFNJyvHqiawfCSNr6RSaeTeqitFQu6RvIWbVz4UAYz+jX:/NA/awcH0g2+b
                                                              MD5:27D2D1C51143C4DEE887C7B052655AA3
                                                              SHA1:D192E93BA04F08C3176B7031D4A5CED028C049AC
                                                              SHA-256:6CFCE53C79B7BE66F23E6C33F12268E3A9F4D0381B8DBA0D7F8873BE00A154AC
                                                              SHA-512:80E896189759B6A6FCA3317C40832877FD7CC2029FDF27DAABA104F0E2B7505956E1D1F4D9E6DE7B323DD58D0318F1D490C45A8BECFA3F67CDAD5FE71E2E8D63
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 GtkSourceView team. Author: Yevgen Muntyan <muntyan@tamu.edu>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<style-scheme id="classic" _name="Classic" version="1.0">. <author>GtkSourceView team</author>. <_description>Classic color scheme</_descriptio
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):6522
                                                              Entropy (8bit):4.617281808911092
                                                              Encrypted:false
                                                              SSDEEP:48:cEFNJyvHqwPamnIHgzunKDS1g4srVglrnfE/5stGwvSux/9/knGAiojmkezZG557:jNAPPa0IHganKBr+IstG2Urj0VujpCEx
                                                              MD5:F84DCCCACE552F31C298D8E76D91F5F5
                                                              SHA1:FCB2C9E418570BAC3F462033120E85792FC1FACE
                                                              SHA-256:1634956FDE389345971C2C57E1EC844F33A40B846D7945D5BD8984CFD1017E2E
                                                              SHA-512:63B694C1B5C0F581E5239DFED0E31D87B604678E0E89BF5EDB0922394019F53CF1C337E3F2391ADA60F91497CC26F82DF35AA0C4E512AA2F0FC67059B02AC32E
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 Will Farrington <wcfarrington@gmail.com>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA.... Theme based on the style of the same name from pastie.caboo.se.-->..<style-scheme id="cobalt" _name="Cobalt" version="1.0">. <author>Will Farrington</author>. <_descr
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):7760
                                                              Entropy (8bit):4.598866607165661
                                                              Encrypted:false
                                                              SSDEEP:48:c2bFNJyvHqiaW/c1M/qvoIOI/btSFDuIv3MshutdBtUcfM/ycX7CM+k7sHwftvmk:/NAjaW/c1MluRfMKcX73+k7sHMtvT7Aw
                                                              MD5:B628E36E5B283CFA9A144D9BC20AF6C7
                                                              SHA1:CD246A25F940DCDFD3DB65A185389D7E1A679D85
                                                              SHA-256:343025A57585E2E361A44DBD1DA98D1822DAEC094266D692E9171E34F51864AD
                                                              SHA-512:74F0D363BCB5C33B613C715418EFA06500920F7033F4FC1D0F31E401DD9DA0C3D1B89AA21259790C81FB495FA7B4B413888D33FF58CA00EE7439998C0A3A2EF6
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 GtkSourceView team. Author: Yevgen Muntyan <muntyan@tamu.edu>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<style-scheme id="kate" _name="Kate" version="1.0">. <author>GtkSourceView team</author>. <_description>Color scheme used in the Kate text edit
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):5461
                                                              Entropy (8bit):4.5995288425836485
                                                              Encrypted:false
                                                              SSDEEP:48:cjNdFNJyvHqPtG0xhvp8+H2Hk/j0wb1sbUV5SfDADtGAaM1rD0YfiAgqAFf/ffFx:WTNAeG0Bb/j0u3/UFZ7NGbUB
                                                              MD5:76F4263D0B53019A0306CF00D2931404
                                                              SHA1:756E3CBB392D6F02EB867BF9A30A1EB7CB614650
                                                              SHA-256:8FB046A55E13C657DD9BD2A80AC09B4E400B9BDC2506C22B33411DBE94888615
                                                              SHA-512:42957CD5D1BBC74BDAF32919AE8E1431E4138A3285F40D4DE8BF77A4C3EF3F8901EFCB63647F2C2717A79DF17CD8BFCE7DE23ABE2C9BD832297746996CC3B26C
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2007 GtkSourceView team. Author: Paolo Borelli <pborelli@gnome.org>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->..<style-scheme id="oblivion" _name="Oblivion" version="1.0">.. <author>Paolo Borelli</author>. <_description>Dark color scheme using the Tango colo
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):3401
                                                              Entropy (8bit):4.54417605834984
                                                              Encrypted:false
                                                              SSDEEP:96:xNAeN9mABHYCojlCnuCJglVm49VxqnogbyFoArheLXn:xSkmABw4Ym4DxqoGyajb
                                                              MD5:11E2345777971F68DF18D8EFA2A95D38
                                                              SHA1:023DAC5CD32C514D521B3C0EEA4F9A341519A46B
                                                              SHA-256:5E738E82B5F0DB3B3A2F04BBEE31B6088AEA72CCED1CCD34AB7ED8C6BD556361
                                                              SHA-512:E1EA4F9618B948F5E7E22881A5ECEEDF062F230E297F98EBBFC537C4BCE584D6919DE46887E0C9C274C882169C630E1FF01702CE688623BA0E8CAD311C8D1AC6
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 Yevgen Muntyan <muntyan@tamu.edu>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<grammar xmlns="http://relaxng.org/ns/structure/1.0". datatypeLibrary="http://www.w3.org/2001/XMLSchema-datatypes">..<start>. <element name="style-scheme">. <att
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):5592
                                                              Entropy (8bit):4.589603429741462
                                                              Encrypted:false
                                                              SSDEEP:48:c2PMWFNJyvHqz584xhvp8+H2Hk/j0wb1sbUV5r2zZaM1E0YFtiOsrF0Bu4cvSg3u:XNAU5xBb/j0u3xdQ44r/O
                                                              MD5:E83BC7AD11ADE4B217E879E65BB88517
                                                              SHA1:7922B25F41000D2849A1A76EF744F2DAC0CE26D2
                                                              SHA-256:7F474589A106B40E96BCD2B73A8554FBC87EE677B62110C595E19D78AA1E95B0
                                                              SHA-512:B34E4ADCC82E1EC64C99993D99DA11F7FB40A62A3791972989CE1C6BAB767E22A9C078848AFF84A25C9DFD3559BB9C2E277D0E8800BC4E560553887EED537AD1
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="UTF-8"?>. .. Copyright (C) 2006-2007 GtkSourceView team. Author: Michael Monreal <michael.monreal@gmail.com>.. This library is free software; you can redistribute it and/or. modify it under the terms of the GNU Library General Public. License as published by the Free Software Foundation; either. version 2 of the License, or (at your option) any later version... This library is distributed in the hope that it will be useful,. but WITHOUT ANY WARRANTY; without even the implied warranty of. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU. Library General Public License for more details... You should have received a copy of the GNU Library General Public. License along with this library; if not, write to the. Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,. Boston, MA 02110-1301, USA...-->.<style-scheme id="tango" _name="Tango" version="1.0">. <author>Michael Monreal</author>. <_description>Color scheme using Tango color
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):100
                                                              Entropy (8bit):3.6821516450789775
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1MYLvLvvLvLZ0DF4LZNLMLLJ:aNWr1NmY/3/mZGM/J
                                                              MD5:E3562CCD62765D7D3002597F3C3C833B
                                                              SHA1:EB59BCC59AB992AC5FA719AC7EBF8CCF836CF5B1
                                                              SHA-256:B81BE2973EBE9D884F26D34872CD333CAAC4C28AEB60F147E09DFE9701ECDB59
                                                              SHA-512:3ED0BA132B5B4B0FC6B930AC52F911F782EDDC4A0ACBEB7214343CCC8E24CDB18D392BE8B392D84AC738BDED0B2834F6733E8F01EF8E6B853BEB7F210B2BFE35
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 1.0 1.0.0.6 0.0 1.0 1.0.0.0 0.9 0.0 1.0.0.0 0.0 0.0 1.0.0.4.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):106
                                                              Entropy (8bit):3.644696898026447
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1NLMLL6VGVGUhZ3GSVvVLZNLMVXQv:aNWr1NY/644U/HVvhM9Qv
                                                              MD5:79867A332CB1759E1775D387761CF852
                                                              SHA1:9DC65B3E2F97FE07F7A842169C5C791E32371BA1
                                                              SHA-256:3F6D6AA5F18406BCCC49006DB57D543AAD122593016BD3E6B8908604E14FC81E
                                                              SHA-512:201084E4555A64A058B0BCEC3BB3179E34BB0DC826FAE6B99FAF24E7D5D21CA1276C1ABD66A11F03EBFB863DE4B32A85B472DFDB71AFA9C559A9CA70FAD92F93
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.01 0.01 0.01 1.0.0.50 0.50 0.50 1.0.0.0 0.0 0.0 1.0..25.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):110
                                                              Entropy (8bit):3.840172487209101
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN5zVzULvL6VGVGUhZxVfULVvhZNLMVVSFv:aNWr1N4LT644U/ILFhM/SFv
                                                              MD5:0463EDF8B7157B56E586829BEE9C9E66
                                                              SHA1:71369E2FF1CA20EB4BE34C35B9DA85F692D92328
                                                              SHA-256:4FEACE58D14481A43BAB9DA0F96FA122F91E149C9BCE885F16F5EDAB4F977F84
                                                              SHA-512:22FC901C5E09EDD89CCDAB83EB81A8B3B48586D01CA1397566FC939140FD6494E8D89DFF2FA411247CE7BB0FC47B2CDE1FB7BAC8C7E5E74E8F2DB32D3DC9598A
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.02 0.02 0.02 1.0.0.01 0.01 0.01 1.0.0.4 0.4 0.4 1.0.0.0 0.0 0.0 1.0..078125.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):152
                                                              Entropy (8bit):4.260956733214682
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNYnceETaWniCU9BLFVLggNSvexZZNLMLLbvn:aNWr1NibwQCUHTV5M/Ln
                                                              MD5:847C64D20DCE377A8B04CD3CB28B3833
                                                              SHA1:065151919677EDC04164768EA29837B2C8FA7C3F
                                                              SHA-256:0CB4918977BB40B097A347C6093DF50FB625D5A0690A85A277CA690882834576
                                                              SHA-512:5E1670B088CCF07B7F91FC696BEA57B8B75A8A790FAAAE18BA88F7C49091AB2D6AFAB25BB66F0275CFF3E661268BD3025F6037199F08C07FFB31EF4B29033B02
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.329412 0.223529 0.027451 1.0.0.780392 0.568627 0.113725 1.0.0.992157 0.941176 0.807843 1.0.0.0 0.0 0.0 1.0.0.21794872.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):88
                                                              Entropy (8bit):4.020330150126378
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNLjb5VpvpN5V4VLNLMVW6n:aNWr1NiUZn
                                                              MD5:2E224DF6656F6D9F5951EC8C0BF4B410
                                                              SHA1:27D6EF798EF53C7C9854084E2628B474E856DDCD
                                                              SHA-256:0DFCFEDBBD047F9C38DCD5B3999B3613908C4ADDBB41769E5C6132599D44D748
                                                              SHA-512:62E3DA865ABC812EF62426920613D8ED48EFF0A8AAB42B8BCF0319B0C42A9A1B77792A69579E2837CEE03C34CD799F6841868CA6A658157FC50B5994176D5332
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.2 0.2 0.2.0.8 0.8 0.8.0.5 0.5 0.5.0.0 0.0 0.0 1.0..35.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):132
                                                              Entropy (8bit):4.2072421174441565
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNHWhVQWTjhRXdjCPDRhSTLkSVZZNLMLL/:aNWr1N2hVBTjhR8PDSTLJTM//
                                                              MD5:7891F84C415B025CF6D57F9ED7059467
                                                              SHA1:12270FB13AA9F0A55793863B41A0411D7F2D0C7F
                                                              SHA-256:583417898ECE9B6AB8E6B4B44A4B9624856B751A7CC87CE5A2F647E029614D9C
                                                              SHA-512:73A69C5B9372D440B6D9683E812A997B3695B839606C4ADECD7D407E0BD83F66F5C8D834AE51C4630CFA3744541037E61BF0BAADE4AB4168FD56B7109D88CD76
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.2125 0.1275 0.054 1.0.0.714 0.4284 0.18144 1.0.0.393548 0.271906 0.166721 1.0.0.0 0.0 0.0 1.0.0.2.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):118
                                                              Entropy (8bit):4.102460959153464
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNcsvsuLVvVLxVfULVvhwcSvLwcSvLwcSu5VLZNLMLLj:aNWr1NT/ILFhpSvVSvVSwM/j
                                                              MD5:D9C2782FE02B0E7625E7B69D27366998
                                                              SHA1:37915BB968F1B467E399AB3E2E244B5BFA7683D0
                                                              SHA-256:A840D580CCE41D0E3267FEBAC5AEB8FEC7BFA52ABEC0366E9E663626F27C2E21
                                                              SHA-512:5F7CC77507F5E4EE0F42A25D9F2BFC0FBA53DFA95F86F458CC51430C40E4DD38F62430F16A8CC60AB58177963B1632C898D085216DEB06A6291652F8769DBC46
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.25 0.25 0.25 1.0.0.4 0.4 0.4 1.0.0.774597 0.774597 0.774597 1.0.0.0 0.0 0.0 1.0.0.6.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):100
                                                              Entropy (8bit):3.9750108102672788
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNLja+h1oUSvL/jdEVvhZNLMVW6n:aNWr1Niwqt2FhMZn
                                                              MD5:680AEF1F735715A3DDA94AA668A4B25F
                                                              SHA1:3C6ECC45EF6857F97E1A5723BA8DE1F7C920029C
                                                              SHA-256:8111D68D32E63218C39F1A76983D24101EF1663171D927119BD291DF9CCA524F
                                                              SHA-512:7428FEC0222F1E5E57686338522267EEDF53A6CA780A87E50B45F0D0ADE483DA8D1893F30B3CCE3959A3AFE5B67BE41404D1D48B46F94C65398C195A17F7E8D2
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.2 0.2 0.3 1.0.0.8 0.9 1.0 1.0.0.2 0.2 0.4 1.0.0.0 0.0 0.0 1.0..35.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):135
                                                              Entropy (8bit):4.141656617603121
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNJEVh1QFYVLhdTXgdNET1hvLPMhjVZ5hZNLMLL2:aNWr1NJvFGhh7T1ZTM/hM/2
                                                              MD5:3F9ADF4D169B11A2F57FF1083F251433
                                                              SHA1:E54053DD0A788D1C1D9C5ED9339C71E4571C4A4B
                                                              SHA-256:3FF34A4B2F0691958BA8245B6851FD5888AA9DE877899E00672FEBADF9D2A43F
                                                              SHA-512:00C0FFE607C5573B607D4DA6FED958652ED946BAC118B404BFEBA79E67C67248993A9AE983082F536FA030C4562C6957B0CB8B1A4140F1CE231E710F1A3A8EFF
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.19125 0.0735 0.0225 1.0.0.7038 0.27048 0.0828 1.0.0.256777 0.137622 0.086014 1.0.0.0 0.0 0.0 1.0.0.1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):136
                                                              Entropy (8bit):4.037132329056418
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1chqvhZAcXWcFXWcsvVLYVSHCpVSHCpVSHSTZNLMVXQv:aNWr1NahUhacGAGBvhYQCpQCpQSTM9Qv
                                                              MD5:08CCF2E7E247E5A70402DB3F61BB6D0D
                                                              SHA1:E6903090F54E80FB57E86E8F7ABCC1C8AF9FA11B
                                                              SHA-256:167251926ACEC9E15A6750E495F023D5510CD347D994A53218131248C45A4C6E
                                                              SHA-512:423AD24ADE69004C1B917BB60938838A99523D82D9B6DD3C793FC36452D675348E1B62BF76D5FC5CA9A6CA80D1EE7C9582000BBD4544FDAEDF160B5764119E77
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.1 0.06 1.0.0.0 0.50980392 0.50980392 1.0.0.50196078 0.50196078 0.50196078 1.0.0.0 0.0 0.0 1.0..25.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):107
                                                              Entropy (8bit):3.8949478911747493
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1AVQ+VL/ULVNL3STvLZNLMVVSFv:aNWr1NW7c/iTTM/SFv
                                                              MD5:9677D65C48072A4B95BB26F9CCA949AC
                                                              SHA1:7BA1449913F8CA929545F8326F1D9EDDFAB6D824
                                                              SHA-256:C69188CBDB3E04CF0F5F3260299DD8D3AFA3132CB604C1C06C48B655F1781B7B
                                                              SHA-512:20FBE4AA1D9CFA947972D1310D62F9A673D50753B9FEEDDBEDEFC3088A4E105DAA3074A67A0EB919A5C1330AB1E92A1310D304366DEA4D01A0A8E77321E2E7E6
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.05 0.05 1.0.0.4 0.5 0.5 1.0.0.04 0.7 0.7 1.0.0.0 0.0 0.0 1.0..078125.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):130
                                                              Entropy (8bit):4.160356377300852
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNpVgS2FgQULLdRFVURXpPFUhvhdvX1uLFhZNLMLLj:aNWr1NpVXbQG7FVUR5PFYh1XeM/j
                                                              MD5:C0E3790466D9905FFDA597D4BE8DBB83
                                                              SHA1:A9378A6E43BD14322B6BE65E1D28FE9F1521F44D
                                                              SHA-256:5E017165CE8A119C6C99A5FE6B9656003FF267546D4495794970F254C89441FA
                                                              SHA-512:D69A39DDF7902B067B4C880E598BAC839639704231207479162167EB818BB8DB70CEA3A76014D6DA42CC4F84E011F0731478A7338FB478D728877E31EFC0EA4E
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0215 0.1745 0.0215 1.0.0.07568 0.61424 0.07568 1.0.0.633 0.727811 0.633 1.0.0.0 0.0 0.0 1.0.0.6.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):137
                                                              Entropy (8bit):4.2091222535596415
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNgXQCihzFULVNLORflFVrT7EFhJMqXDUZtLLZNLMLLJ:aNWr1NgXbIzuLT+eFh2iIZt/M/J
                                                              MD5:839FA2DF92CDF5C3167C024B4289CC92
                                                              SHA1:9100B2AE8BA7421238938BF5AD0FD523BE79FDD9
                                                              SHA-256:E59E79CE475AD7B86384B7C52D109A5A57945BAE6460C1D89F7BC4F58FC222CF
                                                              SHA-512:7090BA0C70B1306C65D8E53DBC1A94516A1E1CFF8DD8E1969F7B8A8DE62595BAB1070010358BBF2FD90DC87EB91A8756E8933B9B6362ED958D0BC5D35A0022FE
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.24725 0.1995 0.0745 1.0.0.75164 0.60648 0.22648 1.0.0.628281 0.555802 0.366065 1.0.0.0 0.0 0.0 1.0.0.4.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):104
                                                              Entropy (8bit):3.857253945645381
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1NLMLLkL/AGQQF4LZNLMVXQv:aNWr1NY/C/5QQGM9Qv
                                                              MD5:E5EF8A0F7F31E79D53A3FF72AF76C46D
                                                              SHA1:6F9180D98DA01A4AF8E0720EEF8D4F70AF97498B
                                                              SHA-256:DF66325329297256A024E446CFFD0604E298A133D7DCE453E6DE53097535080B
                                                              SHA-512:9ACBDADDFE4ED4D4F66B3C72F7B763BB56FAE33D3E15F202F507987B9EAAF04908FD1A2BB74B80F77EE917306ADAAFDFA9298B4E7D02413FE539F19682E6911B
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.1 0.35 0.1 1.0.0.45 0.55 0.45 1.0.0.0 0.0 0.0 1.0..25.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):107
                                                              Entropy (8bit):3.8720725243278
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1AVFULLBVvh3STBGZNLMVVSFv:aNWr1NWvU/BFhiT8M/SFv
                                                              MD5:F04ECC324C91835A58CDAE312CC3FBB3
                                                              SHA1:3EFBD1DBC0B07452D3568CA7027D1C1B21B45311
                                                              SHA-256:FFFA9B6475F15C8F12E1139347040E185E64C3489107F38D49AFA076FD0E4C32
                                                              SHA-512:A85722EDA4159C16F3F8BD817650C5F62EEE325FB640CBC37A42D70A59827A1906BC31A6B20F1A8683C1B9CE76EE415943A9634101B735C008CD0048D6E11A70
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.05 0.0 1.0.0.4 0.5 0.4 1.0.0.04 0.7 0.04 1.0.0.0 0.0 0.0 1.0..078125.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):126
                                                              Entropy (8bit):4.183861482790752
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN9LUw+VL0p0FWET1TTxTTxwZNLMLL2:aNWr1NpUww0p0d155wM/2
                                                              MD5:58DDBD05A6BD4F9138D0D9CB9B1AADB0
                                                              SHA1:BF3E812B22B63850523D53F90613CD0E719EE3DE
                                                              SHA-256:E7A401A3E8CA0578ABDBD4D0CDE8BD65C2DAFF4AA1725DB62A03692C340CADEE
                                                              SHA-512:6FE8972750DEB7A3BDF8BD5CC50F00DFAAD5D72EC3D42BBDD94A4518FDB2D43CB0FD41D3E304CEEC41BE758727E95CF52068F4E803DE727F28E55204AC037DBC
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.135 0.2225 0.1575 1.0.0.54 0.89 0.63 1.0.0.316228 0.316228 0.316228 1.0.0.0 0.0 0.0 1.0.0.1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):133
                                                              Entropy (8bit):4.183784927087676
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNBSu6TVTTAFULFVL+SQTUyvFU5VLpvLvTW1lqLZNLMLLo:aNWr1Nu50FU/oTvu/CwM/o
                                                              MD5:CA9BA2CBE51CFCD55F76797E9E87FFCC
                                                              SHA1:DD0EA970EBEEF496A71AC731CC5419571343775D
                                                              SHA-256:0E1E9A4F9A9A1DCB8F3E616151BFB625BC43E305A4AA97C538E072588DB4DBE0
                                                              SHA-512:0CF2E5A6443B2925F688C244FD29D0E219E2C4EBB730B0612FB7D767BC964A97ACA21761B0753BD12CE7FB35ADE628F4E047FE44D5B9B45441F8A0299A7919F5
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.05375 0.05 0.06625 1.0.0.18275 0.17 0.22525 1.0.0.332741 0.328634 0.346435 1.0.0.0 0.0 0.0 1.0.0.3.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):130
                                                              Entropy (8bit):4.1630155355592615
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNcpZvLXVZu5UXW9U1LM51LM505hZNLMLLdn:aNWr1NEZxZuKKUK5K505hM/d
                                                              MD5:242CBE018066C683C84E61D90866AE4B
                                                              SHA1:57F3D40BC617EDC0757A17EA81B7D9E581B74C66
                                                              SHA-256:9F0FEE790F0CCC971A78B78B105C8B7E2990BBD4B0AF157EE701F39A90606A12
                                                              SHA-512:C94586623CE09A3C723A5D13A23ED65D149170AEC5D75C7637FFDC281A3E995D54487F543446CCC55FD75FAF2077D25F36919AF7CDF2DECB1C24756EC9FED31A
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.25 0.20725 0.20725 1.0.1.0 0.829 0.829 1.0.0.296648 0.296648 0.296648 1.0.0.0 0.0 0.0 1.0.0.088.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):150
                                                              Entropy (8bit):4.222459957751247
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNFddXvhSjVwkBLFVLIQ60hjWMjWMAQ8ZZNLMLLecGvn:aNWr1NFHAj3TIQ60hjWgWjQwM/ecGvn
                                                              MD5:3A9B933F1380367EA38332E401CC8F99
                                                              SHA1:60AD6B2A128B22FB87441D75C1AF4F9C1C7D642E
                                                              SHA-256:56EF6C5E3732AA59ABD0140A7570B27C2A3EAA633D2875D05F1F1DE598CBAC49
                                                              SHA-512:8634A399D79FF13140ADB7BAEAAF869B88EB8247F26479FA7542CE9F87E3778A91DE02AF3B10829830C38F8E293126B6D1DDB0DC7ABF5583E1ABFA00AD083612
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.105882 0.058824 0.113725 1.0.0.427451 0.470588 0.541176 1.0.0.333333 0.333333 0.521569 1.0.0.0 0.0 0.0 1.0.0.076923.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):128
                                                              Entropy (8bit):4.186817826612881
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNc0L5pu5VLETHVDTwwcSvL2drjVVTEETZNLMLLj:aNWr1N/sETHRUpSvGdawM/j
                                                              MD5:95313A0312E0F34B2FCA7281D64437BE
                                                              SHA1:F7D2B83BBC713E8ED75F3D754823F87D8ACEC2F5
                                                              SHA-256:FF4A01541FE5072246104CCDF856318D2EDC897E651D9FA9ECC4DA3CACB06211
                                                              SHA-512:A74CF79261E2DC59426CAE248A65D3C2AACA765DAC60A941455E5A7622BD283D55296534D7AD6CAB6DE583E184A49C40E2D921BD2E7B4738561BE12AE103647F
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.25 0.148 0.06475 1.0.0.4 0.2368 0.1036 1.0.0.774597 0.458561 0.200621 1.0.0.0 0.0 0.0 1.0.0.6.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):134
                                                              Entropy (8bit):4.133243296968186
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNIQVLtXQLSQU5VLvHVJhVmLTOIQQSVcSTZNLMLLJ:aNWr1NIQVLeLSQGvHVJhVmLTdQaSTM/J
                                                              MD5:FF271BA08123E5141FCF50E77100BB7F
                                                              SHA1:0BED4919C86B83A3C776C7CBE8328A12F8EFF7F0
                                                              SHA-256:349832B8E36EF92163C0009FE6C9BB1ECAC1143462560704FFC876FF644E4722
                                                              SHA-512:5911A14B0494F29D88E5E4BB87359357AED2572ED0E607F1E75EFA0029C76AB644929F8CC6FF5B260C27DC8C65B5D9B5E4F7A0F850838619A6E2D7876136E0FE
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.2295 0.08825 0.0275 1.0.0.5508 0.2118 0.066 1.0.0.580594 0.223257 0.0695701 1.0.0.0 0.0 0.0 1.0.0.4.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):136
                                                              Entropy (8bit):4.203817269126771
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNgXQBXipQULLITRWLybTCfZxdVVAFhZNLMLLe:aNWr1NgX6i6U/ITRWObTCHuFhM/e
                                                              MD5:C0224EB189AA5AFA086DCD8180ADEE11
                                                              SHA1:726BECF53D0A5AA36490215B3DBF26618FCD4E1F
                                                              SHA-256:7C5D24D428CB90D23973333C3F8E9EFBE728AAEBCFCE1A5E7A03427F3D1F2B69
                                                              SHA-512:3028DF555517F1D1CF11506CEC5FFFB35AE9E9ADC450A68EEBED160CD8C605748A1D1A8E0BC041C231819726C07C2CDB169AED3A41E08A43D2FDC1476518B8BA
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.24725 0.2245 0.0645 1.0.0.34615 0.3143 0.0903 1.0.0.797357 0.723991 0.208006 1.0.0.0 0.0 0.0 1.0.0.65.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):100
                                                              Entropy (8bit):3.777822442392851
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1NLMLL6LMLLyLbLUZNLMVXQv:aNWr1NY/B/YMM9Qv
                                                              MD5:78C7315BD58038CD201FF4A9EBED0CD3
                                                              SHA1:E3D5A76E1FC7AB84EE836970385B17EC9F91F5D8
                                                              SHA-256:77E81571C62E1BFB80A23C7C05B267C547C576E0C58CCD16D64F009AB4809B0B
                                                              SHA-512:D4920F052FCE8547F035054D2EC9561CB4A6A8E3E89BE6C1CDC8A3E49622D5EDC6D805CDEB7B49E4903A9CA5639F7E370D4905804EBD597587B6B1F058F417F5
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.5 0.0 0.0 1.0.0.7 0.6 0.6 1.0.0.0 0.0 0.0 1.0..25.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):107
                                                              Entropy (8bit):3.8720725243278
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNShVFVLMLL4ULVvhyLBhVCZNLMVVSFv:aNWr1NShvq/ZLFhYMM/SFv
                                                              MD5:B4563CBB3A250E36D22F426CE34E6EFA
                                                              SHA1:8153E6A98750457C87DA1BF9D52322157EA2E511
                                                              SHA-256:EC0A65E3E43FCC60741722CF85B4B1DCC5D3A347DE17743FA5125D87044F1BA3
                                                              SHA-512:C7D0955813027DF3BEAFCE24D365959C0DF74D9C07903D2BD7259F54E7AD0E1699771E89E813AE6113AF5D6DD723E32D31575EF2BC5A13C15311548B91E8CD2A
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.05 0.0 0.0 1.0.0.5 0.4 0.4 1.0.0.7 0.04 0.04 1.0.0.0 0.0 0.0 1.0..078125.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):138
                                                              Entropy (8bit):4.175660217138283
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNmFzh+MmvVL8Xp1uTbEJfAJwZNLMLLj:aNWr1NRZ8516bERAaM/j
                                                              MD5:9A02EB5FE8CBF67988E71F2F6DFD0786
                                                              SHA1:F8D2C7F0FFE6F0070C42F13FE6FDB8ECD0C77212
                                                              SHA-256:01467C6EBFB90565296A9A8825E7C2196A3644EB153D8B33AD1A94FC47C08E97
                                                              SHA-512:AB9D71B31D12D6833CCE088CD47CC7DE833A969E139554F862468317A5BDEA3B1BD54C5F0312F78438837F5E6D1065F5066F29A5A25703D3A386E81852662478
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.1745 0.01175 0.01175 1.0.0.61424 0.04136 0.04136 1.0.0.727811 0.626959 0.626959 1.0.0.0 0.0 0.0 1.0.0.6.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):139
                                                              Entropy (8bit):4.127930249850105
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN9qAVLUvwvwuLTrTZNLMLLJ:aNWr1N9q+UvwvwwfM/J
                                                              MD5:9CBFEF9FB4E5958DC4C4797ABCB64AB5
                                                              SHA1:3A9DF3261245838CA5E8B7B44BBCD1678B139EDF
                                                              SHA-256:EE3EC48510CCD77EE36E4D30FDDCB142770EA145C183B1D875464C1B73A68775
                                                              SHA-512:71EF0D6D4C22696B4CD4EE9FBB7DC3EEBCFCE6ECD1914E0166B849D9A545D49F9D236E6972302DD1B574D3CF036387937EFD7FD8C400CADCD1327704D54BCA21
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.19225 0.19225 0.19225 1.0.0.50754 0.50754 0.50754 1.0.0.508273 0.508273 0.508273 1.0.0.0 0.0 0.0 1.0.0.4.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):131
                                                              Entropy (8bit):4.22316429183848
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNwL7LzFmNLfmYln4LbFXcvi5TuuLVZZNLMLL2:aNWr1N+7L0ftdGbtcaNzVZM/2
                                                              MD5:53593E7583271296C92B8D1ED9604996
                                                              SHA1:3D071D320E8018D511752BEC4093EE6B84C01B26
                                                              SHA-256:F328919831D115FE1500C783775141C5B722274043A3FFE7143E7FA4DC7A4ACB
                                                              SHA-512:C6C59B80875FA168DE48205CA6BC2A03CCA48FD386C39BE168B2FF98E97982791965163774FD362D4D4F4F408A9641254B95CEDA74E1996E25A46728325AEB82
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.1 0.18725 0.1745 1.0.0.396 0.74151 0.69102 1.0.0.297254 0.30829 0.306678 1.0.0.0 0.0 0.0 1.0.0.1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):100
                                                              Entropy (8bit):3.9750108102672788
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNKFVjrWFLFGXBqLZNLMVW6n:aNWr1Ne1WFxGCMZn
                                                              MD5:617A64265828442D6B1A03EAD0F587B7
                                                              SHA1:0F224B624B3B440886BDAB762AE01A66ABE1C0BB
                                                              SHA-256:17E9EDB77AA1C090B22B8B91529E436125D5D87BF9D0B3A075D1CD995086AE30
                                                              SHA-512:863B735F8E30FA5F5FB674709908F577EAFD0B73D40291B503337E9D2B4A8818E3B74E31CFA08B3785231BEF2AFF98FEF1ACBD29E5BA41FC699D466B638B4DE3
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.3 0.2 0.2 1.0.1.0 0.9 0.8 1.0.0.4 0.2 0.2 1.0.0.0 0.0 0.0 1.0..35.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):106
                                                              Entropy (8bit):3.774457705300799
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1NLMLL/GffVLyyVLZNLMVXQv:aNWr1NY//yPhM9Qv
                                                              MD5:2F657CB15A6383F504D2A1FD5FE6A089
                                                              SHA1:7D49BF72759E19C75E521E21ABB00C672081A7AA
                                                              SHA-256:03972B14B66369C37D7B57B2B85F83804919120CB3F1EE372B0635026F3E7E8C
                                                              SHA-512:21576D37A460447AF725B5A8002FB7B9C5C8C777EA4F22624187C2217B506C615A463AD08495B16516D95E806F8EF93B4F280F31C08DA0F452F8D32B94D9715C
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.55 0.55 0.55 1.0.0.70 0.70 0.70 1.0.0.0 0.0 0.0 1.0..25.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):107
                                                              Entropy (8bit):3.8642022701485206
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNShVQTVQ+VLtVMULVNLyLYvLZNLMVVSFv:aNWr1NShA7V/YYTM/SFv
                                                              MD5:AAF151DD690211427D9676421E33D456
                                                              SHA1:2CDC684730DAD3D0D457A667154D89038E7A21B4
                                                              SHA-256:EDF19AC9B9F6C9DADC59E33D597EC9B6A995BB0401AE8A55E8CF2437732A6EF1
                                                              SHA-512:767E74817CD6CB7E93D7F0E9C96D97BC31B2BD460F8F8D665E43473F9A226C861BD44C60AF8F61E2B914148CC65A74319B7A6362AC374ECF26D4ADDE6A9FD9EF
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.05 0.05 0.05 1.0.0.5 0.5 0.5 1.0.0.7 0.7 0.7 1.0.0.0 0.0 0.0 1.0..078125.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):103
                                                              Entropy (8bit):3.7275130767701317
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgN1NLMLLtVYLLZGSVvVLZNLMVXQv:aNWr1NY/Y/FVvhM9Qv
                                                              MD5:674A6E99B6895E1DC7AD10E72C53DED9
                                                              SHA1:45DABE4B297E3EE605C268FDC5FCFCB05A731045
                                                              SHA-256:25B10401718160234CF638E49C14088EF635AC66D90A062353671CA0BB9F7378
                                                              SHA-512:3AEDBCB6D393FCFBC359872613E7D12F59FF161EEE6E7F4EE74FB33181DA24EB601ED9AC7FD7C947C1E1C3D197595223C8A5F8F9D9030AF040E91C7BD6FDF5BB
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.0 0.0 0.0 1.0.0.5 0.5 0.0 1.0.0.60 0.60 0.50 1.0.0.0 0.0 0.0 1.0..25.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):107
                                                              Entropy (8bit):3.8949478911747493
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6GFMgNShVQTVFULLtVaVvhyLYBGZNLMVVSFv:aNWr1NShAvU/aFhYY8M/SFv
                                                              MD5:1FF1BE1F158EA862DA02332B0D66903A
                                                              SHA1:94A70F504240D2047FEC5E2D450CBB7D4880A88C
                                                              SHA-256:7E34E346DA362803FD0665604E5937CC775863F4EFCF5831F8186480F09FE91F
                                                              SHA-512:1E7BB9C98E28D01A69FC349F7B453179B5D8829BE61FA2222429A821A56E736CA5A588B86588564268C361693F5371591B77BCE417391D9AC136D894112E818B
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGLMaterial.0.05 0.05 0.0 1.0.0.5 0.5 0.4 1.0.0.7 0.7 0.04 1.0.0.0 0.0 0.0 1.0..078125.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):186
                                                              Entropy (8bit):3.817341498806536
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOF8gVLUUp+algVLWWRWCY1UF+VLQQQ5vUuUgVLSSsw01UVu:aNWFF8gCUpnlgAWRWQF+GQoRUgESsT1F
                                                              MD5:0B948A1F50508751F803DEEA6CD1545C
                                                              SHA1:400C901402FD2DBB755EAF6A93FEDADD083D58CE
                                                              SHA-256:75A0DBE25C6BEA6E734415342C537CA885CB2585B337C21D863AF1E08C593380
                                                              SHA-512:A14321B293449E6683D4BAFA71B30CEDA43CAAD9E3FAAE77D587AF7DF58B56603C5E93D6C9CC8957BD707E190FBB5E5D597DD5FBAA5BED2B4DF607540D16A026
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 1 1 1 1.0.111111 0 0 0 1.0.222222 1 1 1 1.0.333333 0 0 0 1.0.444444 1 1 1 1.0.555556 0 0 0 1.0.666667 1 1 1 1.0.777778 0 0 0 1.0.888889 1 1 1 1.1 0 0 0 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):284
                                                              Entropy (8bit):3.1630978519932453
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFFbXSfCc91mV4fAc916mF9GcF9Kx0fEcfwvu91Ufn:p9S6ceVnmFUcFSvu8f
                                                              MD5:A29972E344E7D76E3C7401365DE910DE
                                                              SHA1:D5BEC7786935F82773C633171534E7F78FA6BF81
                                                              SHA-256:2992343036EAE00444D1D89C67235A10B8E3D741EB1F45111842E75E8BF2860D
                                                              SHA-512:B253362178632F1D956E3B7839B9400016ABBAB77BF7037D36C4FF71FE18AD2C00B4AE3F588F41320E6F99E1CDF9F43396CA17CD99DF2365DFE2C09A4B49B588
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.09 0 0 0 1.0.11 1 1 1 1.0.19 1 1 1 1.0.21 0 0 0 1.0.29 0 0 0 1.0.31 1 1 1 1.0.39 1 1 1 1.0.41 0 0 0 1.0.49 0 0 0 1.0.51 1 1 1 1.0.59 1 1 1 1.0.61 0 0 0 1.0.69 0 0 0 1.0.71 1 1 1 1.0.79 1 1 1 1.0.81 0 0 0 1.0.89 0 0 0 1.0.91 1 1 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):345
                                                              Entropy (8bit):3.198553860573438
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFLIm9Vvm/CkiR8UbdcTFKVnhbylV+QIf000/:pLiP3sdcTQFhbylV+pI
                                                              MD5:B2B28CB23EBE8400642925E19401BEF4
                                                              SHA1:CC574FAC7721477BDC732FFAFF2136BCDC2C5BB7
                                                              SHA-256:4022683CB25E3AE12C1DE224C46B1753BC01FEBB3A31370129D5193A8C3DD0C3
                                                              SHA-512:D8C08E0F52D46C85A563936FDAE95BE67800CF87AB617216B91105214D7CEFCE7FD018405A900F159957B8DABE4583C9F71E7237C0A001F3CDDAB6EB70C48CD8
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.200000 0.388235 0.187535 0.009135 1.000000.0.300000 0.329000 0.319111 0.268771 1.000000.0.400000 0.222991 0.405319 0.490196 1.000000.0.600000 0.232616 0.617000 0.223354 1.000000.0.800000 0.925490 0.602476 0.853287 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):570
                                                              Entropy (8bit):3.4651482700891503
                                                              Encrypted:false
                                                              SSDEEP:12:pLeV/15Yj1GWATSMBhoZDcdT8AY8K9fg8DwwwxV:lu1g1BeSuoZghA8iDI
                                                              MD5:6C76200A6ACD3366B2BEE69D36F859AD
                                                              SHA1:F6A596E2CB2AC31DC1DEA8ED44030A47BC7F5DF1
                                                              SHA-256:88D73228F99AA5257691F771CBD5B2DBC7DBD9CF7E28584F3AF84F68D2C71163
                                                              SHA-512:9A2A6CBB63CDE4249F258F2A881F36B5120FEA1B4953E5F92C56B91BDD494C1F64E4BD715C09FE2A19E037BCC58B61A7CAD8A0FEACB01F5E74C1DB753C1F8EFB
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.053922 0.023529 0.054902 0.494118 1.000000.0.166667 0.023529 0.235294 0.360784 1.000000.0.279412 0.023529 0.352941 0.066667 1.000000.0.392157 0.025405 0.470000 0.025405 1.000000.0.504902 0.360784 0.705882 0.082353 1.000000.0.561275 0.589000 0.779000 0.057000 1.000000.0.617647 0.741176 0.729216 0.023529 1.000000.0.730392 0.741176 0.552941 0.023529 1.000000.0.843137 0.741176 0.400000 0.023529 1.000000.0.955882 0.741176 0.305882 0.023529 1.000000.1.000000 0.833333 0.833333 0.833333 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):62
                                                              Entropy (8bit):3.7933252882600437
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN11+n:aNWFFd+n
                                                              MD5:BC22C6C95473AB42E83D616BDF40CF43
                                                              SHA1:70033010F6E73454C9C2A1478DCD93A5A24B2F64
                                                              SHA-256:0BAFFFC8CEFF5B6454DF7466AE4C6E4990A9FC05CB694F9B8B91EC8548E38E0E
                                                              SHA-512:24CB4CC07EFE71584341C0FE2E5A78803338791F134BBEAC09A0EECD8258E8531A3922C63A56573D7F69389D1AF7EC601DB38AF8FFAA30455971F3C8EAD528EB
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0 0 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.796994443350909
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQ/ZT2VKUuvUfn:aNWFFK/A9uvUfn
                                                              MD5:0C16120043C1F0938D00B7155C50D6C1
                                                              SHA1:2BE8869940A581C4ABA647DB9D74B9AF3C06DDE6
                                                              SHA-256:CE9B309561802F80C07E4F3863A12D004E9BA9BE8099B993310328FC8F3A26CD
                                                              SHA-512:48E57874FF0B0E2414FD2D6D390127488D3D42A4D7E7239E63CC75AC069E560D67617C2500F13349C311DBC88B94B89A3DF148B1A24ED6891C2882263C906408
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 0 1 1.0.67 0 1 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.796994443350909
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQ/ZT2UvWn:aNWFFK/AUun
                                                              MD5:40ADE21C0F1B2AB34CC95798F3C04447
                                                              SHA1:C9A16567F2AA0AF12713AF70A880F7FB6895DD7D
                                                              SHA-256:E8FC30BC7EF70C2F7D87F7369201746D3A88EC752725BB95CE151B9AFA430F5A
                                                              SHA-512:839C8B68081898FE0FBD81A264053DDF9A0F1237159438CD0A023D5367E6CEDAC6F866B4AA15D657049E254B94D04E39CCD9710C509B845358FD0F06EDA385B8
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 0 1 1.0.67 1 0 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):97
                                                              Entropy (8bit):3.844532821859125
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQ/ZQF4SvSuAUuFVF2Ufn:aNWFFK/uRAUuFbfn
                                                              MD5:B9FBACB7C2E46870F3247B96A98A71B8
                                                              SHA1:1B8E8E8CC07FA855B43D179BBBE30DE4AF3F5F7C
                                                              SHA-256:4177C21673485593AB177227FEC77BE3EFEEE187A7BDEFF10F7001D7EADF7013
                                                              SHA-512:37C6F9B438EDD2D978FC89F7D4831019BECF2ADA7F387FC5900C1AC69DA44D3E4A3F416420D8D50FA3A5DF1C3680A6C968A8D226B680C39CE7F07B665ED403C7
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 0 1 1.0.5 0.67 0.67 0.67 1.0.67 1 1 0 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):172
                                                              Entropy (8bit):4.092073600910882
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNglmRXjVx1vBLXPgQnTcKSbYduToFVnVbXQGn:aNWFF1xjj3TYlY0TovFJn
                                                              MD5:A695B31F7BA7B05BF45D4377590DC577
                                                              SHA1:0794DB66F632F032C7821DD352143917CF462781
                                                              SHA-256:E7143E971D069512C23991E0F9891F953605C620AA531A9D7FC7B5E86DF0E811
                                                              SHA-512:E227606B4D6240C9860F30507CBAAA1A4C280F44951994F03E95EA42B5942C8DEA1C70FA7C9B73D162A1C3203CB41856EB6EF27F6B6D89B43F8E35F1F9EDF2B5
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.2 0.492424 0.3037 0.136994 1.0.4 0.74902 0.280947 0.117493 1.0.6 0.880909 0.563001 0.482738 1.0.8 1 0.855548 0.603922 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):300
                                                              Entropy (8bit):2.822714379319598
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOLFZVVV/ZVVV/ZVVV/6V7V/TVVV/ZUpU1jEY1hVVV/ZWYvoCVXvhVVV/Z3:aNWFLIA61jE/fCAvUdc+C3WvS/X000/
                                                              MD5:C3868791D36A12630C5445AD150AFF42
                                                              SHA1:DBADA8E417CEF9D328914DDC236BF785FCF8FD4D
                                                              SHA-256:6DF630F96BAD9CFDA7F577F97ED22E25E54D67B793E138C212BE91F821DEE509
                                                              SHA-512:87F8F4350AC1A7F67CA365C778F70DABF4B7C7269A23D7BFD2F0C3316BCEE5C0390E892B8D32F7AAC959E2B6F695B844F54E33733CDEA218B7A0AD37397B89EB
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.200000 0.000000 0.114118 0.221569 1.000000.0.400000 0.000000 0.365817 0.470000 1.000000.0.600000 0.000000 0.564000 0.438980 1.000000.0.800000 0.296904 0.800000 0.075200 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):441
                                                              Entropy (8bit):3.88975941172918
                                                              Encrypted:false
                                                              SSDEEP:12:p1SekieqYLUETUCxCBB74jCePZ4d6QVxoe+P+TdgwVVLn:rSDvZLUyZ0HQPZ4/se+P8NBn
                                                              MD5:8CB10FD3EF571460ECE375AC954E3EC6
                                                              SHA1:9D4671A05622757DBD7E158602DF6CC5FEA4DC06
                                                              SHA-256:64F5DB0B61F147F221BF8B8B4265C34DC9D2AC4191306D60FB17555F040A7DB0
                                                              SHA-512:D5E55FF36DADC9CFA7137408DC2014933E3F134AB241C51E8942BD91091D2DA1AA555959F2B24D834BAA99923AD8773F0FF833A563C4C39B08BCBAB2F4FF9079
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0 0.0196078 0.0196078 0.603922 1.0.0894632 0 0.141176 0.752941 1.0.17495 0 0.360784 0.835294 1.0.264414 0.00392157 0.635294 0.811765 1.0.355865 0 0.815686 0.65098 1.0.449304 0.00392157 0.827451 0.329412 1.0.544732 0.266667 0.839216 0 1.0.636183 0.615686 0.866667 0 1.0.727634 0.905882 0.886275 0 1.0.819085 0.960784 0.635294 0.00392157 1.0.916501 0.988235 0.356863 0 1.1 0.913725 0.054902 0.0392157 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):173
                                                              Entropy (8bit):4.051467566440636
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNDCRigTFnfeHx5lsFVL71LTl/FEzNYK292PfIn:aNWFF8wgTJsNsT71LxFEJL292PfIn
                                                              MD5:B1A009CF66182E810F7AE61CAF6EC767
                                                              SHA1:1D28181B943612473D26A8EE468A3B3F7EFEB758
                                                              SHA-256:3DC0DC2F4A4FAD27625C95297BAC3E0E7BE0FBC06479D5DBE9DFC5957431ABD0
                                                              SHA-512:1E569BDD420203D96559CAF988D44F05BC521EB008B3F4F82540F87C2159D1F8B083E1F9B2681267282395C1020048E707B3EF243E1D573E7990C090CF8AB91B
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.3 0.168223 0.27335 0.488636 1.0.5 0.196294 0.404327 0.606061 1.0.7 0.3388 0.673882 0.77 1.0.9 0.90909 0.909091 0.90909 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):465
                                                              Entropy (8bit):3.886483417870995
                                                              Encrypted:false
                                                              SSDEEP:12:p9FroabGSWD+1NVhnTCoj0NaiQNXS9gzJU8XI:qVSx1ThTC7NEiCJU8XI
                                                              MD5:25598B82B5F415BFEBECF9BA61086D72
                                                              SHA1:700EFDB3592C08A9455014A7A598BB4A897BE1D4
                                                              SHA-256:AC7F2D14F41493EC75299FF7C62896C87A0A3400974FBE38ECBA878716C7C7C9
                                                              SHA-512:C14F80239D75C26B4199ED1918B1542045C7B9F180AEEDAFEDDE8F0F32CCA3CF6F4956D7AE2ABF94E617A8E5AF81A54E16CA10A703F145133EEA9701D2BC5518
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.076923 0.43564 0.135294 0.5 1.0.153846 0.87128 0.270588 1 1.0.230769 0.93564 0.270588 0.729688 1.0.307692 1 0.270588 0.459377 1.0.384615 1 0.570934 0.364982 1.0.461538 1 0.87128 0.270588 1.0.538461 0.601604 0.906715 0.341219 1.0.615384 0.203209 0.942149 0.41185 1.0.692307 0.207756 0.695298 0.698082 1.0.76923 0.212303 0.448447 0.984314 1.0.846153 0.561152 0.679224 0.947157 1.0.923076 0.90909 0.909091 0.90909 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):345
                                                              Entropy (8bit):3.3989097364934953
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFLIE+sQLb/a7HwHlcqG1VVUkqCX+ZQDX000/:pLa7Lb/mHwH5+7qCuZR
                                                              MD5:FE28B726EAE1E6B4E2251FAE04A0F9AC
                                                              SHA1:5D1CEAB251DF1C73676C1CB4298DF583CAD317FF
                                                              SHA-256:F453C931793129AE6889B1372972C994EDF4E9323DB1F410042BCF0E1001979A
                                                              SHA-512:DACCB914F53E0C034933F28799C41606E19F89DDEED19F58C2FDD19DEC49C4AF29CF9347219824AB082A69C4882B8F6A7BA5C1D6D609AEC713B49BB4AF36F67D
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.249755 0.415686 0.039123 0.260631 1.000000.0.435847 0.893000 0.371488 0.371488 1.000000.0.670911 0.966000 0.742223 0.401856 1.000000.0.806072 0.764765 0.913000 0.551452 1.000000.0.903036 0.673834 0.826000 0.576548 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):133
                                                              Entropy (8bit):4.206210381070251
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQRWMFsTU2dKvVxiUdzKA5cUiUgn:aNWFFKRWVRwvziUJKyliUgn
                                                              MD5:3CA3CA3124A920A44C2A5F8076274FEF
                                                              SHA1:9BED4FD938AEAD0B36213841A31CE9519A58FC0F
                                                              SHA-256:83984DF033D75EFBE76384195256D9A1A3F23E28291BDA7540100174027604B0
                                                              SHA-512:3AFF5CABDB1EE44C3D0DBF78DEC5951602EE3B5C51EDC8D1E4BD266C2BCA5209423CF62E526AFEEDAA6F3D8603FC90182BFD51274F1EA9EDB68E2B7308D32F88
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.333333 0.345098 0.109804 0 1.0.666667 0.737255 0.501961 0 1.1 0.988235 0.988235 0.501961 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):50
                                                              Entropy (8bit):3.8337863204943647
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOF8gUVu:aNWFF8gUVu
                                                              MD5:8F24F926842C11D5D298CC32B92988A8
                                                              SHA1:390680D9FD08B2D1ED8CB7186E1D00E031A1370E
                                                              SHA-256:5623BE7CB7652CF7B999BF5B92C0497AD72EA1D9FA6D82B5C0D911A9006F5626
                                                              SHA-512:335A8F9D9DDD39FC70D55689DEB2EB68D6E60CBF7A3074F49900901B0EE24AF8EC4FA7350468F49C114DB2DFB517882BAB0F6286F04BC3BF0677A793DAC92B9E
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 1 1 1 1.1 0 0 0 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):62
                                                              Entropy (8bit):3.7933252882600437
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN18gUfn:aNWFFOfn
                                                              MD5:58758CEE22802A4F6748A0FE8D0382A3
                                                              SHA1:3EC80C49646B146C2771985F8A3EC2C9399AD5DC
                                                              SHA-256:D7BA75F9CF89AA87D1DFD7F70E4007A7D0E5876A21375C4487DE074DC62B03F3
                                                              SHA-512:93DE93393FFADAC327B516A6937AA042938A6BA9DE932DD1CB67DBD1D380C9D6D0BAB1A55576B5E3E930FA407BF36B6D8DDB51681FCB507D6EED712197438066
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0 1 0 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.796994443350909
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQCuV2VKUuvUfn:aNWFFKQ9uvUfn
                                                              MD5:1BB70CCD4244A9D7300EADA996E5E846
                                                              SHA1:AC8458A868BD9DD964AF37996DFC6BBD1D2D99CF
                                                              SHA-256:8544A9C076AF1AD206C6B857EFD6F5271C52DE354FD1C77E7DF9A6FAC7A32011
                                                              SHA-512:A0F4F27C6AF0D3C2F43C6EDFF7D484BAA6FBC97E11AF5D97EDDBD2FBBBA07F1D5F99B0E00200D1BB533272A3689E85FE95CF98EB36D5F137303208604EC374DD
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 1 0 1.0.67 0 1 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):750
                                                              Entropy (8bit):3.3736168090749636
                                                              Encrypted:false
                                                              SSDEEP:12:pLwoLqzuvhT4QiQiQ6Mnnnbar0ZhhhCglD9999eO4ILWyRYPgDD8V:lwoLIuZT4lle+gbhhfFIAbDG
                                                              MD5:15BF141499F35F8795C2BDE85D94AC81
                                                              SHA1:4EE29687F6FF6CBAF1508E5194E7F09CBF10A165
                                                              SHA-256:1B5D5A01BD875E632F880F51CA4731633C74204FE1BC5D077564A55589AEED5C
                                                              SHA-512:11748F1054898174D2D08E835D62EFD07EDDF1A9FFAB514E849ECFA601EAEED35C30E03809B484BE5B8CE11DD44FD14B31494A272CE020ACF0ACB3EC7C34D32F
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.066667 0.031063 0.031063 0.031063 1.000000.0.133333 0.062125 0.456471 0.062125 1.000000.0.200000 0.068565 0.486275 0.068565 1.000000.0.266667 0.124250 0.124250 0.124250 1.000000.0.333333 0.155313 0.155313 0.155313 1.000000.0.400000 0.081835 0.580392 0.081835 1.000000.0.466667 0.085706 0.607843 0.085706 1.000000.0.533333 0.248500 0.248500 0.248500 1.000000.0.600000 0.279563 0.279563 0.279563 1.000000.0.666667 0.098976 0.701961 0.098976 1.000000.0.733333 0.103400 0.733333 0.103400 1.000000.0.800000 0.372750 0.372750 0.372750 1.000000.0.866667 0.403813 0.403813 0.403813 1.000000.0.933333 0.116671 0.827451 0.116671 1.000000.1.000000 0.121094 0.858824 0.121094 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):97
                                                              Entropy (8bit):3.844532821859125
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQCuVM4SvSuAUvWn:aNWFFKuAUun
                                                              MD5:A61A9B1EBC4C4DF5B2C3FAA097E72027
                                                              SHA1:7CE104402E419F73BF6B8D99D74C0BD2082AE534
                                                              SHA-256:4E41207409E09B1BBE704E2B6F89337F87C4D9419B13A0D792DDD69675CF71DC
                                                              SHA-512:0867B787502676C306BF9588B508B4FBCE552D0E24FC37542DD2EE92B9C58642E94BD11E0A82F1A708D55AC305FB9BC063196B3DAF62307AD9ACD78FDC23AC36
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 1 0 1.0.5 0.67 0.67 0.67 1.0.67 1 0 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.796994443350909
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQCuV2UuFVF2Ufn:aNWFFKQUuFbfn
                                                              MD5:F258CAA1D6F9B8A5A72CF9EA6AE5B16B
                                                              SHA1:BCCD61D8D0899C351BE9C79DC2C0C3AA4C9B58BD
                                                              SHA-256:A32811E0E21E6CBED82917A37F96CA1AC51B67E36B2158643C4A6B5348454AA5
                                                              SHA-512:07BD8CF37E98F3254B20157D94E58D167256979C6E9513A5945BFB633608F9A913B4DC5EC5E024186723B2F0AA8265E53396EAF76044BF561237481281669F50
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 0 1 0 1.0.67 1 1 0 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):127
                                                              Entropy (8bit):4.249363251576693
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNXYUfIVp5wVKV+SoDzJTlWTW62Ufn:aNWFFqUfIVbZVQmTW6zfn
                                                              MD5:1536E23D3F8E8EA4F068567FD28BE0B1
                                                              SHA1:822838216EE63846EFE9D50DCCDEB7CEAF4AA09E
                                                              SHA-256:0F4D42E6AB91CDACDAB7D7BFCB7F80D454F1BC927BE996A8FFDF07EFADBD9155
                                                              SHA-512:AA8F31D4C8126F8CBA93A815628ECD172115368543FFABEA8487CF0D599ABE51C5267648F5ADC3292D7BEB5146A409A26FD75653BCDC6370F6D520AB41C32805
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.344671 0.658824 0.156863 0.0588235 1.0.687075 0.953506 0.759686 0.363821 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):345
                                                              Entropy (8bit):3.062623841957372
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFLIFVaVwmVN8WTDOy0K8QMSAXyGAt8f000/:pLeaVjKyyzEt8I
                                                              MD5:0BD556680A32A2C24DE580E4CDE19D59
                                                              SHA1:CC050DBF27F89420FDD1F48F873E1E10DDE22699
                                                              SHA-256:97917BB74407B052BF6E61BF2D9585D4226AFABD7490C0F155B452460C389A31
                                                              SHA-512:127B60D20D1E2FE468D87F379A1F74C82FAF8CF657306ADA4398906DDEC7504E3CCDC488CB480B3383ECBFA96D4159D0D4501B4D0826836401E9D58BE0331FD4
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.250000 0.010442 0.010442 0.380392 1.000000.0.375000 0.611000 0.200762 0.424466 1.000000.0.500000 1.000000 0.321569 0.321569 1.000000.0.625000 1.000000 0.585822 0.322000 1.000000.0.750000 1.000000 0.911834 0.423529 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):378
                                                              Entropy (8bit):3.4515320893769528
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFF/FSq3Fh8vEvsTVYbAcBboUTlLTFMUjUL/W1TZScuvnvVTHUZcc4KcBuuElv:pdJVqsUU9oUTlLPpZSJvVTHUZtrcpElv
                                                              MD5:79DAD2B301F6EAB877F0B50E78F96E59
                                                              SHA1:ADEF444DABCD2A95E3E71C2CC126DD8469112A39
                                                              SHA-256:0E9CC275475877EE1B3BB6B87D698CC9AE9FF7695D979E07275F34FD6E1CD7C2
                                                              SHA-512:153527A2B9952FA27B0E6AC436E64557E86C4242CC0A6A54A6C5F892F24987273DCF4AF4ED7533D9AA9D3E7C61DC7FBF3732CB5ABA81D99A1DA00DB4B5C14F27
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 1 1 0 1.0.006 1 1 0 1.0.007 0 0 0 1.0.195 0.2 0.2 0.2 1.0.196 0 1 1 1.0.204 0 1 1 1.0.205 0.2 0.2 0.2 1.0.395 0.4 0.4 0.4 1.0.396 0 1 0 1.0.404 0 1 0 1.0.405 0.4 0.4 0.4 1.0.595 0.6 0.6 0.6 1.0.596 1 0 1 1.0.604 1 0 1 1.0.605 0.6 0.6 0.6 1.0.795 0.8 0.8 0.8 1.0.796 1 0 0 1.0.804 1 0 0 1.0.805 0.8 0.8 0.8 1.0.993 1 1 1 1.0.994 0 0 1 1.1 0 0 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):345
                                                              Entropy (8bit):3.1005914472875205
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFLIfgVTW54RWEyq5ehUVLwmqBMG+mE6uX000/:pLjEEB9nRmD
                                                              MD5:FB8BBA6F58DEA8C1154A2B4354AB71A1
                                                              SHA1:5FFC6FAF9DC198587D86B00E8BD2DD0B7732A392
                                                              SHA-256:CC73CA73E27CDBAAB96A7F30BA163F95810457A6134574D0EE4789CC3FC53307
                                                              SHA-512:993D62D3DEDBC1E90CAFE8E0D9B065D6F29105A38AAB28CDBF6BDE06125D89E0C3AD56D98FD30517F10079387F201E638B8FF9CF457886E3F1938E1E6902BCC6
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.250000 0.069760 0.380392 0.028343 1.000000.0.500000 0.890196 0.844403 0.111711 1.000000.0.625000 0.987000 0.714125 0.209238 1.000000.0.750000 1.000000 0.523212 0.289000 1.000000.0.875000 1.000000 0.644500 0.644500 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):896
                                                              Entropy (8bit):3.7245588739554774
                                                              Encrypted:false
                                                              SSDEEP:24:RmkwezMOf5ZrjZkzRfD6dQOoby3Ld5clQpW9L:RtwgMOfj9kNfD6noS1pi
                                                              MD5:E962C0398DBC24C2FB393C902CE1BD18
                                                              SHA1:F2090022F053F09C250F6078C0DE3AA9A00DD303
                                                              SHA-256:046E42AC13C04F456DB440B629CCE066C67EBD871FDAACB4125989EC7527C40A
                                                              SHA-512:2635A3D4A7840371540640AA3061A0727418DF36A7FEF4908C5A80E80D0A991471FCB29E6734522D38B82188CE300FF0F4257F7656C515ED543C678CB5A1DBFE
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0 0 0.0313725 0.905882 1.0 0.112123 0.0722667 0.848722 1.0 0.19852 0.103777 0.804669 1.0 0.303304 0.141985 0.751263 1.0 0.395224 0.175509 0.704402 1.0 0.470588 0.202991 0.66598 1.0 0.540444 0.228473 0.630365 1.0 0.270222 0.129915 0.768124 1.0 0 0.0313725 0.905882 1.0.00229095 0 0.0313725 0.905882 1.0.0652921 0 0.172549 0.827451 1.0.119129 0 0.32549 0.678431 1.0.183276 0 0.498039 0.501961 1.0.233677 0 0.643137 0.356863 1.0.304696 0 0.839216 0.160784 1.0.369989 0.0705882 1 0 1.0.430699 0.513725 1 0 1.0.4937 0.964706 1 0 1.0.575029 1 0.741176 0 1.0.646048 1 0.529412 0 1.0.717068 1 0.298039 0 1.0.774341 1 0.121569 0 1.0.841924 1 0.137255 0.137255 1.0.899198 1 0.380392 0.380392 1.0.954181 1 0.396078 0.396078 1.1 1 0.396078 0.396078 1.1 0.781247 0.316289 0.507591 1.1 0.865812 0.347143 0.464485 1.1 0.919127 0.366583 0.437308 1.1 1 0.396078 0.396078 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):438
                                                              Entropy (8bit):3.9993823740111383
                                                              Encrypted:false
                                                              SSDEEP:6:aNW+FQEWkUFCQXrnFiSeC0dfcUtFv/+I9d2MOPvFVLQgH0UpucRLcx9prGzycUor:j9XrFRe1l3v/dgvFhQcbAek6zycU6
                                                              MD5:D0B39C78D3BE0F5B147BC5278680BEDA
                                                              SHA1:4F3578AE3AEF55FFB62C49F314F8C18F0CE52F8D
                                                              SHA-256:9EBCFDCD21E296660AE0E13918A2169926085C66768B6D9695AF6739257CFA82
                                                              SHA-512:596F7EF65ADA40E747948B0673A60E77A8DA8D50612AD4653A0CFC4BFD4831BC177CF658DFCF81A12834C3388FB979B4572AC8655568957D3FE2294FFFE7D2EE
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient..0 0.168627 0.0901961 0.133333 1..0.0874751 0.32549 0.152941 0.141176 1..0.178926 0.458824 0.231373 0.137255 1..0.270378 0.6 0.321569 0.141176 1..0.363817 0.72549 0.403922 0.145098 1..0.455268 0.858824 0.482353 0.180392 1..0.550696 1 0.576471 0.321569 1..0.640159 0.996078 0.654902 0.443137 1..0.735586 1 0.752941 0.584314 1..0.829026 1 0.827451 0.721569 1..0.916501 1 0.921569 0.854902 1..1 1 1 0.992157 1..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):255
                                                              Entropy (8bit):2.91201753603685
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOLFZTQovLV//ZVVV/6VsrTQovLWRVXFD//6Vc0VBdRmLVx6VnDVc5p5vD+:aNWFLgGw7GWRnDqK0mLOE8F00/
                                                              MD5:70B476689174A595A1A27C45B043D21A
                                                              SHA1:662166EDCCF8D847D1CC3BAFD973E2B0E3FEB0EF
                                                              SHA-256:4EF2E4833B2BC312488EBA0232CDA7763546E30A6CB58B5E3BC6D883CA11E017
                                                              SHA-512:B5E3C2E13B8B946DC21A7430EF2A4E7D9149498CA3A242A74D81A83D483B5030E221BF98C2CA5911C3760AF15955D94FD97ADE4198FF2E5CE932DA22731C58A6
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.654902 0.000000 0.000000 1.000000.0.250000 0.654902 0.342732 0.000000 1.000000.0.500000 1.000000 0.847059 0.000000 1.000000.0.750000 0.094507 0.886000 0.000000 1.000000.1.000000 0.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):79
                                                              Entropy (8bit):4.252981971098984
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN12RWsDRI7n:aNWFFwWsD67n
                                                              MD5:CB618646E789F17AB472A6347523DC1D
                                                              SHA1:0820D2F32511C942F50E3CE75D0545C22A0B8841
                                                              SHA-256:5A72A4137F31C7A45D57CA4A72A53252ECE938B4CC21DEA0F1739260F8D23C36
                                                              SHA-512:204CEFEFF1FC908A1D2A3F686585C20BACC3613C9CFCF4959BD9F54119E3FD9BF8D8F70445C609813BEF4B71B48083834D0661679928C11BAE391AB6B4676613
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0.36863 0.6902 0.45882 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):2208
                                                              Entropy (8bit):3.6816302749780236
                                                              Encrypted:false
                                                              SSDEEP:48:uHrnl8XdzCG1V1AyhsAj/HtZABNc2jE5MUN5jBYTYQrw:ujlloV6+TrAABMUNpks
                                                              MD5:7DB13E5CA7118E290279388F401D3DC4
                                                              SHA1:F7644FA123DE12CE0DC8FE1BC79EF0E7645EF81E
                                                              SHA-256:7B5E30467D69EF06F8234D2AD626A37C4AB37063AF0812A1D432186E36C19A4B
                                                              SHA-512:C52B2279B3065128482720A520F425AE60B0A965A4BC79A1280C1DB63E0C07A5BF47F2797FE386B8CA760726FA7BC9DAD94DBB84CCC97E29507C2FD989A0DAFF
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 1 1 1 1.0.0104167 1 1 1 1.0.0208333 0.956863 0.956863 0.968627 1.0.03125 0.894118 0.898039 0.92549 1.0.0520833 0.733333 0.741176 0.8 1.0.0729167 0.556863 0.568627 0.65098 1.0.0833333 0.494118 0.505882 0.580392 1.0.125 0.176471 0.172549 0.192157 1.0.145833 0.0470588 0.0470588 0.0392157 1.0.15625 0 0 0.00784314 1.0.166667 0 0 0.0117647 1.0.171875 0 0 0.0470588 1.0.182292 0.0117647 0.0352941 0.164706 1.0.192708 0.0666667 0.105882 0.286275 1.0.197917 0.0862745 0.129412 0.317647 1.0.208333 0.129412 0.176471 0.356863 1.0.239583 0.321569 0.352941 0.513725 1.0.255208 0.376471 0.423529 0.545098 1.0.265625 0.372549 0.458824 0.537255 1.0.270833 0.341176 0.47451 0.52549 1.0.28125 0.25098 0.486275 0.482353 1.0.296875 0.113725 0.486275 0.376471 1.0.3125 0.00784314 0.490196 0.278431 1.0.317708 0.117647 0.47451 0.254902 1.0.322917 0.141176 0.443137 0.223529 1.0.328125 0.207843 0.396078 0.196078 1.0.354167 0.784314 0.0862745 0.0627451 1.0.364583 0.94902 0.0235294 0.02745
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):74
                                                              Entropy (8bit):4.194893819417817
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN1cV0ROzn:aNWFFfQn
                                                              MD5:F1063F5E07CBBF25707FBE0E1FEF2546
                                                              SHA1:E0CA34EA0E2DE5443FA551A6DF2EF09A0DAC0598
                                                              SHA-256:EB57DCD4F29795A558D8C1B611AD2EDC73E37A07804A7AC04D94C588F77E41BD
                                                              SHA-512:096383768497527A7085B7B8F3580A67E09C537EBF090BF5301587768F89F56EAE9F53C4834D87FD08BAF16D018DFE647659B02DE591589A67522F107B9D5B3B
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 1 0.07843 0.62745 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):255
                                                              Entropy (8bit):3.1743148355000295
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOLFZVVV/ZVVV/ZVVV/6VsrWur/LM/VcDRcRXuRhcSNpXHcFSpDXWlUnhQW:aNWFLI/z/KOROJj35smhQVvLecX000/
                                                              MD5:F3437CB46C53C67EC974EFE035D1C1C1
                                                              SHA1:1FA9216A5B243D534C2EBB6B2F86D5F3DD53EBDF
                                                              SHA-256:34D95301E25CEA83C0D0B21A459C5B917EF0B491547B1D7F4A6F91ECC4B2FE16
                                                              SHA-512:1B8434DB34219A6A5A8FFD8F7F01AC2814C30527C5815E19EEE41A070FC307761B525A26A064CBBE1ECFB921AC4369A9E9FC756C04536FF9A1D2FB0A460BD1F4
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.250000 0.342401 0.066642 0.383000 1.000000.0.500000 0.494232 0.477970 0.823529 1.000000.0.750000 0.237372 0.614950 0.906000 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):140
                                                              Entropy (8bit):4.108775839650042
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN/TfS3PZGRuN1RWMiW5awTX4TFvVuhQdWvn:aNWFFq0oLRWouTFvM+don
                                                              MD5:5F9DA7BD539836D8660E90BF3B038564
                                                              SHA1:F0F4431AF559FAE69C3CFD6F9EEF58652D9BA76B
                                                              SHA-256:DD51D117EF74E37CBFA96301F0A4F739839F11CD805BCC58FCD2886D10D50B7F
                                                              SHA-512:3B87D4CA4ED815611C735A655A6F5B6E158DDE757C637F9426D430EEB1FFBD3D687F82D9EF4F165030850F0C121F309807BCA92C781622CBA491BC73CA933B10
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.166667 0.265412 0 0.564 1.0.333333 0.391234 0 0.831373 1.0.666667 0.764706 0 0 1.1 1 0.894118 0 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):50
                                                              Entropy (8bit):3.8337863204943647
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN7lv:aNWFFhlv
                                                              MD5:8DBAFC1BFDCB843955F2F48469F9FFAF
                                                              SHA1:F4B8D64C7566F0FD906B722E349E794A1334E714
                                                              SHA-256:89CEB646819C9E9931A692E2CD1D77BCDB712B8BA094866AD9CA35CC55F3DE67
                                                              SHA-512:C6034B3A1CAF5D4822A2BA8F0BA49BA5A015090882A1B3898A7CD11F015C2513C9EFF44606C7F55CB0A1081572871B61706548848A062F2986EB2E2D2EDC820E
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.1 0 0 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):50
                                                              Entropy (8bit):3.8337863204943647
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNRn:aNWFFL
                                                              MD5:EFB12B04A01E256BD4DDF57BE84A4B4C
                                                              SHA1:63BD38729D89CE013B5131D43FDB0D7A61A44D33
                                                              SHA-256:8CDEF294BD39FEE17398814AA0B91DB0D1A7068B66772CB714E29756EF581D63
                                                              SHA-512:EC2A2B6E5F5C17E31B432716D85F9BFB98E086A344A568A1A3C34D750FCB13F28101B91D8DBEF42BF41AC25BBA73CECA00910F2E30676F46F90666C7D31F2A3E
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.1 0 1 0 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):50
                                                              Entropy (8bit):3.8337863204943647
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNwv2:aNWFF22
                                                              MD5:C95975715B85EDC7B1F7AD008DE09B7D
                                                              SHA1:F54E645A63F4C03EC7BBFEB61A460858598F375E
                                                              SHA-256:EC7C57796B6316F426FD792C505EF3AC3DC9C05FF3124D4CA37666B932D5AE17
                                                              SHA-512:2ABB2FBE70D7686D5FBCFF0FF9020E85B696EA4E9F4EAF99A4A6E7EEB0DF968A975648E0ADB3A5159FB186D7314E92B516CE53EA0845A4205633F18C71709A63
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.1 1 0 0 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):150
                                                              Entropy (8bit):3.5908702681686764
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN7QKVdiFUFVF2VxjUuvVLQFcVxTQcVgVnd9Zd/AMVMU+n:aNWFFGKXiuF+ouvGFPd9LV+n
                                                              MD5:E7F2A9DC7DBB6C15CCEBBA13936BF6FE
                                                              SHA1:CB636E4D896DEDA7FB1DBD9ADA3CCB285BF98571
                                                              SHA-256:E10D7D0A599F14A41DEDB3B79430545BD69E7B9C984B64705AFD9B7882A3DD2A
                                                              SHA-512:47BF3833055E2E4274C7306A23F3D0EFFD0AB939E2CD1336E70DB718A8CAB02C316A350AF4D7DFBB666C72F74DD483AE480B14529ED7EEF53B6D48E2402C9A6F
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.125 1 0 0 1.0.25 1 1 0 1.0.375 0 1 1 1.0.5 1 0 1 1.0.625 0 1 0 1.0.75 0 0 1 1.0.875 0.5 0.5 0.5 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):88
                                                              Entropy (8bit):3.6949786416848402
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN8FVdn8gVnd9+n:aNWFFaVXd9+n
                                                              MD5:E530ACBA4ECCC17B770A713CC920FBA3
                                                              SHA1:43C4BAFF89E40540DEB674758B54D324B82BE33D
                                                              SHA-256:F78FC020A08306BC28F79E36F2106ACBB3C502437A9D68F1D0F71835210D50E2
                                                              SHA-512:FEE6F8C174E1728863BB1F270652DAC9D32F1DB480539FF67F3A407133D448C920EF849F68F8151499562636EAAB9C733BF5101202CF68B65E3606D7E65E8E78
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.25 1 0 0 1.0.5 0 1 0 1.0.75 0 0 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):62
                                                              Entropy (8bit):3.7933252882600437
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN1cVdzn:aNWFF0zn
                                                              MD5:2A8BCA981B92069F33CB84F403331011
                                                              SHA1:1D5938A57F750588312760244ADD7121B0D4E491
                                                              SHA-256:34DCDCB72EEB9EF536C9BA628ACB4D087D4D9947F8345FED052A008DCFE11E29
                                                              SHA-512:2321A39C1FF69C6BC847E325D297B51B9990B0B8752FA2EA470E7509C3EDBDE9D16DB06481068D0D40EADAA4003DD49BF19B197C4490341D1BBA99083E1C32E2
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 1 0 0 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):97
                                                              Entropy (8bit):3.844532821859125
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQOdn4SvSuAVKUuvUfn:aNWFFKOdPA9uvUfn
                                                              MD5:D303BD4AA9654CD7781021EC293A4B75
                                                              SHA1:BC5A7DD330C0CDAB91861DF4F464BE3432527E1A
                                                              SHA-256:370C0874823817DC31E96BBFAEBA2DBF10E04E9503FF54B922C375BDD79CB640
                                                              SHA-512:8182ED2620D7E51F2BCC6AC74B93D66C0DEA4F52F60EA41111FA2BE51A5D3554B02D614DB921AA47290A31EB828D5BE61D1AA5D37529D8E8A6FBAC211DDC72E7
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 1 0 0 1.0.5 0.67 0.67 0.67 1.0.67 0 1 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):930
                                                              Entropy (8bit):3.1629086411817533
                                                              Encrypted:false
                                                              SSDEEP:12:pLuNYrQKp4DmbC6Tho5QBvaLzcmH6ww6Dj/j/MmxP0RqUI9yWTQJfWRXi9JN3:l4YEKq6VoO5qQqrd0kUIrTQJfWFi9j3
                                                              MD5:F62DDDE1ACF44C92D5069CC1BC9144FB
                                                              SHA1:6B9E56A771B81C3A4AF46918F793B7E01E68373D
                                                              SHA-256:74D9422F23EB38AD24A29B0B4F54C6F30AB35E9A6195B7788F655CD427401CE9
                                                              SHA-512:877D11706BEFE9C6B85287AD792D687EFFCE719F4203FAA52B9471058DD97F3DBBA49D3F3FCE1E4ECC7FB32D545D75B9B981A2AC371CF4FFC40E072D3B613550
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.052632 0.030000 0.030000 0.030000 1.000000.0.105263 0.449804 0.060000 0.060000 1.000000.0.157895 0.483137 0.062808 0.062808 1.000000.0.210526 0.120000 0.120000 0.120000 1.000000.0.263158 0.150000 0.150000 0.150000 1.000000.0.315789 0.570588 0.076459 0.076459 1.000000.0.368421 0.603922 0.077302 0.077302 1.000000.0.421053 0.240000 0.240000 0.240000 1.000000.0.473684 0.270000 0.270000 0.270000 1.000000.0.526316 0.691373 0.092644 0.092644 1.000000.0.578947 0.721569 0.093804 0.093804 1.000000.0.631579 0.360000 0.360000 0.360000 1.000000.0.684211 0.390000 0.390000 0.390000 1.000000.0.736842 0.811765 0.108776 0.108776 1.000000.0.789474 0.843137 0.107922 0.107922 1.000000.0.842105 0.480000 0.480000 0.480000 1.000000.0.894737 0.510000 0.510000 0.510000 1.000000.0.947368 0.933333 0.119467 0.119467 1.000000.1.000000 0.959608 0.122830 0.122830 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.796994443350909
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQOd3UvWn:aNWFFKOd3Uun
                                                              MD5:30B9E40D4656DB715E8A7F4FF8D0FDE3
                                                              SHA1:11DFF628C9DC8748953210196D028D84D463C102
                                                              SHA-256:C2F963881BB03ED0ECB434541D4DD72AC1F2F730080D5467990D8092FC82A267
                                                              SHA-512:1295E60AC60A49566FA5419BD3CC765CCD0C8D4958CEFC58EE9F84D02513AE5FCFABAE6F9FE736F0968830FE5DEB423DD6770D4A469126FD53BCD68AC28B528A
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 1 0 0 1.0.67 1 0 1 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):76
                                                              Entropy (8bit):3.796994443350909
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNQOd3UuFVF2Ufn:aNWFFKOd3UuFbfn
                                                              MD5:0E012F2EC7887892556B2146743BA804
                                                              SHA1:C5577805D2E16FBD52244486EAF74D65C3EC2CF5
                                                              SHA-256:3DB69501FA37077100FA6F8B4B67D6C671381975F98E40B915421B66BBFDE52B
                                                              SHA-512:2DBBCE432DC86BB710929C9CDE72880215D3E4F5F4935CACFDCE85B0BF56AC10A7E039966B4D53D167CA0CCE46607B1EF62F76602900BDE6D4B5E024FD471DC9
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.33 1 0 0 1.0.67 1 1 0 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):345
                                                              Entropy (8bit):3.0258101180622283
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFLIt7RZUd7E3x2hVopgvmhFEc/V5vOzf000/:pL0PUdo3x2DkgvgEsoI
                                                              MD5:784D07EBBEC3CFCAF06843AE5A900D7B
                                                              SHA1:47D56AB15E376ABFBB2C734888520C64144CE898
                                                              SHA-256:A959A48258DD0FB051EA7F9A26A34FC1F5D7524450DF7619D5937CA1C88A946A
                                                              SHA-512:8C739F173F110727A203284C0A2C86790916E037D5F8E047997DFBD719F17FF77898D2DC5BD39FDF5BC2E47F78150DF8CDB2C86B554A40F3016BF97B98866FB5
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.286765 0.500000 0.266340 0.009804 1.000000.0.430147 0.785000 0.480598 0.005131 1.000000.0.573529 1.000000 0.652000 0.000000 1.000000.0.714052 1.000000 0.803444 0.268000 1.000000.0.854575 1.000000 1.000000 0.709804 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):300
                                                              Entropy (8bit):2.509202534320237
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOLFZVVV/ZVVV/ZVVV/6V0HVxZVVV/6VCV1RWM/dZVVV/ZVVV/6VX/VBVVK:aNWFLI6K0lWMMSEskFY/
                                                              MD5:7BACCE82C6A4CDC12E8C038BEA28E68F
                                                              SHA1:B421947C9FFE7E2446583998053FB12788312718
                                                              SHA-256:7A1756B0C151692504A2F492FEB13455C95FD75B92A22D60865717EAEE705597
                                                              SHA-512:DFFAA5EE8D3E8148996115E2A73F50F6865F4AC7781DB5DB6590BACB264A68ED5289A596E8ADCB5385598EE74D48769F276590C752184F2C4C0F4C6DBFA45BF6
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.325171 0.000000 0.000000 1.000000 1.000000.0.333333 0.000000 0.000000 0.000000 1.000000.0.666667 1.000000 0.000000 0.000000 1.000000.0.674829 0.000000 0.000000 0.000000 1.000000.1.000000 0.000000 1.000000 0.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):255
                                                              Entropy (8bit):3.2984013056067827
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOLFZVWsdvhTTdvgedXkrXQ/rXQ/rXcCcR8UDQ/BXdDv1K/VnDSBXFhKhC8:aNWFLQsjfnvkoCHUMnk/oBXTfT000/
                                                              MD5:1A9CA98DF44EC0A479C8A9388E4245C4
                                                              SHA1:4136DAF80756369207966C27CBBC539000BC9CFB
                                                              SHA-256:12505283C3CC96885B33663C8191628FE9B9992B94E878AE9BAE8E76309387D2
                                                              SHA-512:6E8E20075C079FD681CEC732E97C14B09F8790EB3C44203D255C8B2F9E2F094E36D89C07743CCF1E937893A4182744954B29A93BAAC8EAA3EABBF299EDFE7DF0
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.031318 0.031318 0.167843 1.000000.0.250000 0.250000 0.250000 0.295294 1.000000.0.500000 0.500000 0.285797 0.141000 1.000000.0.750000 0.729412 0.160185 0.414663 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):182
                                                              Entropy (8bit):4.154176131366005
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFNgglTVLIHyl4R4yl5TvXJ2hqAEPujvo3LuwXQuvGn:aNWFFpVVLAyCR4ynJ2AAEPuU3St5n
                                                              MD5:3A927C2278E0A77FE5022A77AC1C5C4F
                                                              SHA1:C0D7E252A55C46C7D88869496DA155B33220E2FC
                                                              SHA-256:E8A508516834C1F97B30A60F445C190186E7393D55FF822A948B83E251D0A27F
                                                              SHA-512:18D0E9C244C1118C0DEA1B2FA711DA39356E7D11CC552210CB002418347F289F91A2C09E2DD78EC1156A22FA2AA121419EA11DD662F9DE3B222BB38E7E5335FD
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.2 0.149112 0.160734 0.396078 1.0.4 0.294641 0.391785 0.466667 1.0.6 0.792157 0.476975 0.245413 1.0.8 0.988235 0.826425 0.333287 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):300
                                                              Entropy (8bit):3.4709209512680705
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFLbERKx1XMvgBRE8hk8WQsoqWZxcQF4VhV:pLbwKxWYBR1hk8ds/fQF4R
                                                              MD5:6D56657C005AF761AFE8554FD10C5B58
                                                              SHA1:20342C38E950565C8DD71CFDAEB8A610B7DB4CAB
                                                              SHA-256:F01BFC2F0BAADD43AD4CAE5A23A220D9DC8A8201DEE2A7EDD506236BAE7C5191
                                                              SHA-512:26593D991C56BFF1E0E2D762B87D3459C78B53625CD65F29BAD884B2019EBA8DE0233C20C59E9E348A8F7F4E2ED07D63CC1488134980CF239A9FA966CC448B01
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.048443 0.069416 0.494118 1.000000.0.200000 0.023529 0.505882 0.611765 1.000000.0.400000 0.060095 0.631000 0.126868 1.000000.0.600000 0.517000 0.503744 0.026513 1.000000.0.800000 0.631373 0.047059 0.054902 1.000000.1.000000 0.866000 0.833926 0.847672 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):407
                                                              Entropy (8bit):3.8947077666061567
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFFL5v7FhzXQXjLTFkL9I9Q1V3K7EHWDgeVkXrCZpTFlcP9VOdwAd6d5u:p7QX3TFkL9I96VW4QC78TFGP+Neu
                                                              MD5:06BB2CA1064303723E7B0BB391E44590
                                                              SHA1:65C89216BE012D062BC65AC5A24C2EB7B23F0A61
                                                              SHA-256:82A12F5C61F9C06AF4909416FBF8086A1842336E1F3409F2637663C3EEC42E88
                                                              SHA-512:AB5BF755700556A8326BBAEB0DFEE449906189FC5371D6597ACA5569F50E373E5B1571640A2367BAFA97A373B71AF9693AE0317D9314D0B56B6BECBC481C4547
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.090909 0.885 0.024681 0.017629 1.0.181818 1 0.541833 0.015936 1.0.272727 0.992157 0.952941 0.015686 1.0.363636 0.51164 0.833 0.173365 1.0.454545 0.243246 0.705 0.251491 1.0.545455 0.332048 0.775843 0.795 1.0.636364 0.019608 0.529412 0.819608 1.0.727273 0.015686 0.047059 0.619608 1.0.818182 0.388235 0.007843 0.678431 1.0.909091 0.533279 0.008162 0.536 1.1 0 0 0 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):416
                                                              Entropy (8bit):3.9158469336942496
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFF8gwiNLpBFa7FhNR1c4eS89uTX6owum9UeaeVkXrCZygUzPZ+z9VOdwAd6fY:p2UNyRdQR772B7QUzPQz+NxHa0z
                                                              MD5:194C2A1AF3A03D36467061A4A65D6D70
                                                              SHA1:A11346F912E5AD5DA50074CA07A0354C58E57D68
                                                              SHA-256:9EC257B20CB63467CA203B99E71BAF413C1C1B81BCA9B3F6B4080E1A6491AA85
                                                              SHA-512:2E0B9E30E4121D27F366A1DA00D53E8E543E6A0FB1237D96AEA5F5D3D62CAA7EB3F61DF1980181D73341B92E942AC8ED408E93B407421BE977A91C02EFB802C5
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 1 1 1 1.0.090909 0.940093 0.141772 0.135225 1.0.181818 1 0.534417 0 1.0.272727 0.875059 0.840787 0.022034 1.0.363636 0.496666 0.898024 0.0742046 1.0.454545 0.307927 0.782269 0.316396 1.0.545455 0.281147 0.741558 0.76144 1.0.636364 0.019608 0.529412 0.819608 1.0.727273 0.0775921 0.114046 0.778973 1.0.818182 0.388235 0.007843 0.678431 1.0.909091 0.664988 0.21297 0.667338 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):149
                                                              Entropy (8bit):4.123461419109132
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN9GiQadVpqU3gGFnWTh3TVXKUvVLjTFpQVcHVLQgIn:aNWFF7Z5qU3gGkTH5TFpQVc7In
                                                              MD5:27463FC9F8922E771DDB8022E72FA136
                                                              SHA1:F3EFCF7687432E54A88F912160042F9DD015AAE7
                                                              SHA-256:4B70170236D253A122B07B44A6CB1D25ED35172B0D4F5D2DCEF54E335382081E
                                                              SHA-512:582925A6F064D6D6C4BB46FB939D4AE0F0AC7D00DB43FECC3A37B351F63F2CA58BDCB7756511FB48D0FE8DFD377FFAD000B5B4E7489529F92ABCD3904F9D9BB1
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.25 0.059669 0.380392 0.293608 1.0.5 0.084395 0.65098 0.025529 1.0.75 0.758756 0.85098 0.560646 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):510
                                                              Entropy (8bit):3.906138701959893
                                                              Encrypted:false
                                                              SSDEEP:12:pnh3jcAsW0UlGlfXK0PYAc3DcTfOjeeUdleYQVhviTlgg2:Rh3sXlf6H3DcTfOpUenDviTQ
                                                              MD5:2740CF2954B44F145C6E14304CFC628A
                                                              SHA1:91DECC08659280476AB5E0F8410F947F27A4EBCF
                                                              SHA-256:DD60E36DF081E4BB04D410DCD187DDE4C4D28B8C417978C9B2D0D5CD53325C8F
                                                              SHA-512:B05A46CA139486EACFE33E18E28F7E48B8DE6EB919F786C03E4D3430F0C0B12F3F78482EED0B0BE308DEB42DECFFDDD4EEF6A16E75FF9BA4733474C70D44BBC0
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0.266667 0.00392157 0.329412 1.0.122137 0.278431 0.168627 0.482353 1.0.21374 0.247059 0.278431 0.537255 1.0.316794 0.196078 0.392157 0.556863 1.0.51145 0.121569 0.576471 0.54902 1.0.564885 0.117647 0.627451 0.533333 1.0.60687 0.137255 0.666667 0.513725 1.0.683206 0.231373 0.733333 0.458824 1.0.751908 0.364706 0.788235 0.384314 1.0.824427 0.537255 0.839216 0.278431 1.0.938931 0.839216 0.886275 0.0980392 1.0.969466 0.921569 0.898039 0.0980392 1.1 0.996078 0.905882 0.141176 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):196
                                                              Entropy (8bit):3.969405696039856
                                                              Encrypted:false
                                                              SSDEEP:6:aNWFFTcLFhX4vGyeYhBVCEQTLknbKQ292PfIn:pFgYGyeYhjCOb4sXI
                                                              MD5:468369D0B4E61D159885C46FE71BBBC5
                                                              SHA1:91940C376C78056B3FE3276738B64CDE1D3AB06B
                                                              SHA-256:348D14B372DD03C28CD002DAC61C8231209132797B9228FA9B93892D7AA69457
                                                              SHA-512:689B8E4DF7BE6E8BA408DEFDF069D1AD2210A6662A218837366E2B58BB6651568C00A406E0609484D3BC041F145A06639CF1E5BB56F322AEBDAB09BDBC06FBDA
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.25 0.484848 0.188417 0.266572 1.0.45 0.76 0.1824 0.1824 1.0.6 0.87 0.495587 0.1131 1.0.75 0.89 0.751788 0.1068 1.0.9 0.90909 0.909091 0.90909 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):392
                                                              Entropy (8bit):3.9929234868297327
                                                              Encrypted:false
                                                              SSDEEP:12:YXBh1axBUcnvmRxZvFhQXM6HrMjKRjjdF:YX31axBP+ZvTQc64KjdF
                                                              MD5:B1B0426262D3A7A4F71614ED6F1CDBD0
                                                              SHA1:286634AF4886D06CF4F5A99312B73494774473B4
                                                              SHA-256:CE84B8FF40FB14C3B1470B739F8A6547B74ECE0AA65EC8AD7F15CD215523D668
                                                              SHA-512:61E1D15FB43245EF57F6B28E977F3C311CB9DA8E9D94FFBE3179CD129AB6167A2EF4AF2BEB2956B4346B51C73790797A1261C34A0FA38F67086E3D6391AC0877
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient..0 0 0 0 1..0.0874751 0.278431 0.0196078 0 1..0.178926 0.545098 0.0784314 0 1..0.270378 0.756863 0.172549 0 1..0.363817 0.905882 0.290196 0 1..0.455268 0.988235 0.431373 0 1..0.550696 1 0.572549 0.00784314 1..0.640159 1 0.705882 0.0901961 1..0.735586 1 0.823529 0.239216 1..0.829026 1 0.917647 0.45098 1..0.916501 1 0.976471 0.705882 1..1 1 0.996078 0.984314 1..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):476
                                                              Entropy (8bit):3.974810094110253
                                                              Encrypted:false
                                                              SSDEEP:12:9dZ6cYTN1jsbYz3i223iDjKrGR6WOKSJHSM82v:9dZ6B1jsczy/iD2rGR6dkC
                                                              MD5:E1FC021D38BE9C01CAC7E074BD8DDDE7
                                                              SHA1:34FCBE1DA07354F48702C8175DEF0401EED451F3
                                                              SHA-256:48C48CDCA202E1060CF15C1699CF78C016C36986766B5D36DC5F20800185A80F
                                                              SHA-512:B297B49E9054565075E6216D5281F8BD5429C20C8A7B3A4F8FFC549AD9C4BA447319A32295B49547274EA52D2A4E25D1A04CA0A3F4F44BD3EAC87218CE0988E5
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient..0 0.498039 0 0.498039 1..0.0874751 0.294118 0.0431373 0.701961 1..0.178926 0.121569 0.168627 0.87451 1..0.270378 0.0196078 0.356863 0.976471 1..0.363817 0.00392157 0.568627 0.992157 1..0.457256 0.0745098 0.764706 0.921569 1..0.548708 0.231373 0.921569 0.764706 1..0.640159 0.427451 0.992157 0.568627 1..0.735586 0.639216 0.976471 0.356863 1..0.829026 0.823529 0.878431 0.172549 1..0.916501 0.94902 0.713725 0.0470588 1..1 0.996078 0.505882 0 1..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):481
                                                              Entropy (8bit):3.952028845762392
                                                              Encrypted:false
                                                              SSDEEP:12:m5VVz2tGsMeEA5ksddIUcRZTmzAFZ2joNKuTi:GVJcg0EUAj2jOKuO
                                                              MD5:157AC300882AE42E212D8FC53B339FC3
                                                              SHA1:994F714D2EA73729F578A63A6C085E9C2A1F3A69
                                                              SHA-256:8897415C008CCDB8B3A68C5DAA3C1774C1E032673A5081907E0D5746CD551606
                                                              SHA-512:F6E50C70808F29E8DA30B3861458B3E42361D2D9941B240ADBE50707FB81B36C3200CB19ED6086F6FD7536500A39C89A68ECDE6290A81458BFAB73A1A6131F15
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient..0 0.00392157 0.0431373 0.419608 1..0.0874751 0.0745098 0.121569 0.756863 1..0.178926 0.160784 0.286275 0.94902 1..0.270378 0.247059 0.52549 0.988235 1..0.363817 0.352941 0.788235 0.854902 1..0.455268 0.454902 0.980392 0.592157 1..0.550696 0.552941 0.988235 0.341176 1..0.640159 0.647059 0.8 0.145098 1..0.735586 0.733333 0.521569 0.0352941 1..0.829026 0.807843 0.290196 0 1..0.916501 0.909804 0.121569 0.00392157 1..1 0.996078 0.0509804 0.0156863 1..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):79
                                                              Entropy (8bit):4.137563606093125
                                                              Encrypted:false
                                                              SSDEEP:3:a3NW6XOFN1hmqau+n:aNWFF54n
                                                              MD5:049A47C1DFACFEB532F512B3860ACB4B
                                                              SHA1:D85517F652232E0DF88700246A5B6A6D414FB360
                                                              SHA-256:834DFF36D9ADF17C0EF66BE573AA25983F51F5517926C43B38ACDA56016F3BA9
                                                              SHA-512:B40BFEAE62CFA04B779879EA0BB31648D3B24F124E21C2EFBE3CE1D61D5EA6DB1EB448F019CAD09C8D3CCC576210466017B93683A75FEAD3EBE64EA3A30C46D8
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0 0 0 0 1.0.5 0.8314 0.71765 0.16471 1.1 1 1 1 1.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):750
                                                              Entropy (8bit):2.686202376735773
                                                              Encrypted:false
                                                              SSDEEP:12:pLEG9hzQ88xIh11E8C8yCjtRQKRZKVdJS8:lphc88xIh1W8C8jTQKRql
                                                              MD5:19407F5D39D1EE8FB23350B96F4817E6
                                                              SHA1:E6898FBE105FA2214B8AE73301D76D0F8487128E
                                                              SHA-256:C02D25F92C2AAA226D2829C77745D9B62E82525FD6D71086ABD84BF8D4A403CE
                                                              SHA-512:2F5FA200443BA7CE854B203B0A1C2BE7D99E5587070562E46E8618E23931FDB42CCF4272B7D6A19CACA3CB94EB948AAB0B79CCEC675514DEE815FB3BC175A1FD
                                                              Malicious:false
                                                              Preview:Gwyddion resource GwyGradient.0.000000 0.000000 0.000000 0.000000 1.000000.0.115573 0.148000 0.148000 0.148000 1.000000.0.125000 0.000000 0.000000 0.315294 1.000000.0.239961 0.000000 0.000000 0.503529 1.000000.0.250000 0.550196 0.000000 0.000000 1.000000.0.365328 0.752000 0.000000 0.000000 1.000000.0.375000 0.503000 0.000000 0.503000 1.000000.0.489716 0.752000 0.000000 0.752000 1.000000.0.500000 0.000000 0.597000 0.597000 1.000000.0.615083 0.000000 0.799000 0.799000 1.000000.0.625000 0.000000 0.705000 0.000000 1.000000.0.740451 0.000000 0.872549 0.000000 1.000000.0.750000 0.866187 0.872000 0.000000 1.000000.0.864838 0.993333 1.000000 0.000000 1.000000.0.875000 0.819000 0.819000 0.819000 1.000000.1.000000 1.000000 1.000000 1.000000 1.000000.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):4685
                                                              Entropy (8bit):7.932291880048192
                                                              Encrypted:false
                                                              SSDEEP:48:pq9KI1xHQH84CSkX4AekJuhJNGN+Z3KQxKV+cipBtBnZ3jjHcBaX+rA4QQlBmjJx:p+BhFX4ANJWP+Q3RBZkBaXsm9JslAvbt
                                                              MD5:B4A9022A46CDF62FC6442E887C60F22D
                                                              SHA1:5F0CB848C76D356D119E9E026CC674A6CCF4BC8E
                                                              SHA-256:AC932C398C24C18413106CAA060369BDAAEF4E37B478E71F0E82C04434D1A4A0
                                                              SHA-512:DAC4BB4ED012BA8A8CF52242DFDD0F3A19DA57AF2807122A49519DFD73D6C9A8F041565943F8CB886F289216D87E1832811FC984DED1747E6533BC593811AAB0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.......}......0......IDATx..].X...W.VQ#...J.1...........K^F.jd....m..(.....,..y.j..RQ!..=T...su.....*[......r..9..s.......~....%..uhCC@ ...."..@d ..O..W..;v,++.........4m.4V......LII.q."....?k.,V.........rrr.z.D....{...l..........cnnn.>.:.p...[[[==.._.]SS......u{...9w.\..9cee....nkhh..6L....~..J....f4//..;w.X[[..5.Y..S.woUU....>`Fy....;2.m-.....k...z.........={.............~..J.f.N....Z>..s....c^...w.XRR..d......]z..Q..\...XTT..:u.....L.8.....> ....9..<.>|....so...E,.BZZ.<..'On..k.#..G..<X..Kd..`+......................m.a.........G..I..rQ....0A\k........Q^.z5z........sq.../.A..|....<x..U.V..X....f.........###. .#F.........M.6..2.W.^MLm...Y...W.-B1P.ys..]jjjP..d....?.....B;B...|../.A..m./]MII......Y.q...............NNNF...s....k.k.....;L..}HHHiiiS:.........e.........,.`....0\..a@.>...........~..j.m....EFF..V...{....a..g...K.u...f...._....L....X.r../^t....#7o.....`.p.....,v.._..2.\../^............W...#$........5o..w.H}.}.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):5201
                                                              Entropy (8bit):7.943242006212645
                                                              Encrypted:false
                                                              SSDEEP:96:pfLOAIQfyf0ct+SnS5xLFQu7C3WBcObJmAfpXhVTruG64XCHDuRZ+Kt2JbTKc:VLOAIQfy/oSep17JBxbJ7fpxVTrukyH/
                                                              MD5:9D4A9BD5C1646EDA80F1936F6673097A
                                                              SHA1:8A7BAD985EAEB520D7ED4D42EB201B57221BE4FE
                                                              SHA-256:A47E9D2479A10100C4C71A3AD0A2ED477CDF5E33791D3B3ABA217D43D4D9A19C
                                                              SHA-512:07C14DC632D83FBBAEA8FF14434AE69E5E7BBF3502BE2F5FFFA3FF49F6DB11C95A0594D2149ECD1B672E11F9DF2702FE6DCA5875C208C2C7EE0FE890EDAD6CA1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.......}......0......IDATx..].X.Y...$...d).J..b......,3..jd.,1..\.......J..P#....e~...T......_..?......{..}..=.{.w9...<.}..|PB .J..5..@d .......@ 2(.iii.....D.Y...O__..R...EFFR......P555OO......Q.F....S...d.5k.|..g.x..5...'.;w..a^......^.r..={.............[.l.D....zCCCuu...$V....?~<5..A....s.... ##...'....X...vbb....<..;v.....-[...R...T.G..a...c...Ye..]6o.....0............{>|...Mbd@.Q{..._.NKK..L.2.i.w..E......-6.T..........(zyy...P...........-Z...E.f....i.......a...x....K.R[.2..0..?.....n.z..........gO.....Qcii....{..Yj:R.U.u.`......`.+W.TSS..?.VVV..F...k...w.&M.VQ.I[..<x@mW...\\\........_.e......;*===Y........*...D...Hx......w.............(P.W.*c..L...{+CDDD.V.N.>M}F.;DFFr3..2...J.........@0...2(....B.n.{.......@.I..M..l..\.3B..B...2..*.z7. z.%e.........{A, .......1m.=((..o..a..O........M.4y.......[.n.|.ry...'....../l...ZXX..7..AF1Cqq....1c.=c.>}.....v.={......=<<Z.j...B: ..!11QWW...E[[.....9;;......Q.F....A^...q
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):2452
                                                              Entropy (8bit):7.786385010050454
                                                              Encrypted:false
                                                              SSDEEP:48:vvOZqfGe1AQ9MPUXxdMQpkV74UzMK0QHcwl7FVbR2yexV4q+04cg2bU:+oOoMPUkOUZckN2bxVYNgQ
                                                              MD5:47E01F6FB5682A00DC1BCA8735450714
                                                              SHA1:4028D42210644A8A07719E250E32842A26ADA35E
                                                              SHA-256:5542022D7382E7AD394711D5D4449862246BF62208422FAABDF233AC702A1E40
                                                              SHA-512:BE1027F042700FE8237EE19D69E56363993BAD3EDBC6E6BCBCFB4FABDBFF616DA82D6F2DDA964B3B6ECFF820B5B6F014C6893C4B147CD7DA5CCE0E0466166FDD
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.......}......0.....[IDATx...H.....2.M.u.f.C.r.EEe..@7#.-... ..J...e.T(HE.VF..... ...n.D...6]..t.......mv..w.....=.wt...=.s^.y....n... .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .......>|.....x."..DGBB....5..........w..uss...f..**...B.@t.......7.bjjjdd.......b...r^.j....gggOO.L&;~.x?....D".7+..?---.......{.......744......B.......y......iSbb".1.../.}{VV...p.PQQ...C...NYY.yB@@.]....999...#*1...[1.......z..l..............b.V.Cee.T*-//...<x..1hV.4 .........f....7.....KP=..Z.....z..b.Vq......kq....(.Dr..%~}cc..;cbb....... .3.s<.F]]]AA...Y.F...C....... ......p..g.3.8........v..q..5. ...`..d....P8...b.3..xbP.T.......~..U.+.A......P(.n.J....yyy.O8.H.!((......,X.T*..p..:.....]...c<.."u...:--M..#^.."u.....g....p.....g....p..M.p.8...g..B.p.8...g........1....=...8D../s...*...)I7pGM"...2.8.......e.3Xq....'J@..~.W.{...* 'F.r_.......III.f......3.....M...=..{...7n.H.z......p.8..;....=...a.Qd.p...).%..mt..{...V.Zu.....D*
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 260 x 125, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):2480
                                                              Entropy (8bit):7.765230297602272
                                                              Encrypted:false
                                                              SSDEEP:48:rXC6nvJOYPqx/UOqlrlp1h83wtubO8yWRwb/oFJ:bC6vPy6OqdZtMzdg/oFJ
                                                              MD5:38B5BB6A0C925DCFA3DAF41A36432E14
                                                              SHA1:90A6AEB00FF6C7816AC1F0763E01900CDBF6D039
                                                              SHA-256:BD9D6C4FD962415EC57B120D381F9BFBC2F3D453A8EFC69FD185310DBC29A723
                                                              SHA-512:6E3C9E074D0BA275905E17C6CA9A45AA8C1226104AEC72D8CBB56B3D331478549ABC761A3F513695ADCCF111A46D0050347F81A67DE2D6F5507C3C2C80A31056
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.......}......0.....wIDATx..}HS]..}I3.MJ{Q[.Fd..EFe.Q.....AD..h.J%i!R...b ..Z.a....2.B1.wG.V.Kk.r..{~....>[./sw..~..=.;<o..=.6..F...a.&..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b..b...\.t..'.......C.@tDEE.3.........1...........j.....dmm-..DG__.L&.{7K&$$...`.`=......+33.............3.../(..H.0.f.S.777;::...=|....I.TRfOOOLL......... ....._!................f9...v...Z.......1.....jG.........2..www....F..2e....0\%P..D...;.x.`.m.T*.......?...k......2i.TVVzzz...S.=~...F.`...d2YVV.?S.R.Z.*??...........f.A..q.Q....G..O......;44..;x.d.=.uX?J.3..........o.........../.?~..L4{....i]]]AA.B.....<...!......>E....x..1.......R8...h.RiRR......Q..b.L..............p.8.x.i.&........p[[.g....."....ZZZX......g.3.T..m....H$p.8.H....%SRR.....p.....6.... .....1@..b...........h.$.S......>{.....08...b.3.. .8...b.3.. .8..A..xT..aP r.+A.C...@...;R..7w.$......{L.P...Aa..=b."C.pvv...p...tX.{.+`.....C......C........B...(q.p....0r.F.Y.n]rrrFF.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 260 x 125, 8-bit grayscale, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1769
                                                              Entropy (8bit):7.795029966382126
                                                              Encrypted:false
                                                              SSDEEP:48:XEPy9NyOH2vmrHBrZDlyMZRLAdldkLsbNsI8vtNo:AyVVplyETsuFC
                                                              MD5:26414314D6047E34CD2E596A7DC4163A
                                                              SHA1:78CA4B3FC192B3C21882EA9258350C9C2F462D60
                                                              SHA-256:985D19A5C20195E493528D75907591CEF09288EC4F7755545A1F55F2FC52E13A
                                                              SHA-512:4241CB82528808D0141AA259DE8AF269D46CE24B6E23932BA03DFBF4DF2653A1ABB160C12268D16E2F6BD4CE43FCA6D39DBF7D8BB7C1859230205D8416FE35FB
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.......}.....a9Bk....IDATx...{PTU.../.%_... J&..l.`,5E....`......X..".*KS....BMc...Q.......NZ......R.....?@Y...w..s..{.a..{.=.w~..b#..@...A ... ...@...A ... ...@xB... ...@..pg....P..W"..D....6h..!..z5V..B......dc....T...{.N(..;.^....;.ck...5.N..J..&..*........{.au.(..q...$SW..#.....,cQ.B.R......2...nI..&..l....+...M#.....C...PA.......|..]F....5.._.....aph.).u...j..C.+44.-Y..m........n.#.?qY<.aI..........L......v...3=oL.&G..p..g....s....n...v..]H.b....8+.$.{U..?&.Zh.....m....&..f......Hn}.\..$..+O..B.....`.9.....hX.r..]..UW..0.@..6....:....?.fd.C..K.......Z.0......a<...>K ...;..<.....7...;....^t..lw.\..h.*z.O...a.q,.:.._.@."p.1..v..K.....'.s<.....Z,.89X'.....|..w.n.x.g..v..n'......@ .~U...9^ .L..@......u?/...p....(L....s.l. ....Wd.?.X.h..-0......@.,...;..*.@7.%n..@.,..)O5...s,.&L...dQHy.......D[.a...&..y...G....B`..tY..#..>...c..>^?.m..EY.J_Xk......`g...xE.Y.?..3q....J,..C...y...^..Jb....v....).(..h(.M.`......&..Q....e...u.F`...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 260 x 125, 8-bit grayscale, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1711
                                                              Entropy (8bit):7.795099318203276
                                                              Encrypted:false
                                                              SSDEEP:24:utTIWyORXNBqvo6tetXkcslYgP/7SSJYh0lFsXDj2tCc25eFIszUBJmt28g398sI:GyOVNcZQLA/7SSJI0lyfi25ps4SAhI
                                                              MD5:F8BAEC8F20E965AE54C09ED029E540F3
                                                              SHA1:8BE204C99C5724584FB2FA8C2E4A4AA780AB023C
                                                              SHA-256:25E0FC4E7E01E0A67C1355773C4004DC3CAB33AF06181662AE699DF2B7180FEF
                                                              SHA-512:B774E2CC3783074A0256B545D7C72FB5076CBA5E47240E77FD015292B55F32A875D55CFD8FB2B9FB9404EF103AA568F5B46D18976DA16C794DA0DBE4EDD14539
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.......}.....a9Bk...vIDATx...{pLW.....F..I...D.L..U#2.hB.T....t.4.1.R.+..t..z4..g....L.H.A:Di+mH%...".fs..CR!/%.{......9.=...={.]P.!...@...A ... ...@...A ... .l..,'=yg\\TTTT\.....2-!.=..$.#jEG..%...S=..o.q.C...c..K.E..8........M......>7dR. ..F.s..|.!..lPu..{./K<./=ZD.?..4...n..YjB..2...F.....A.U.b.....7...k?r........:)(.l...1]...S..............4B~D{..O..IN/.5J....Wm.!o.=.t^...u\^...-...$.).....>...[O.h.^hs..XG..; =}].....c......^../...z..!..P;.].*..Ji.;..[......am.w^.j..N.6.P<...^i...M..7...p.....y...tMS8B..=.Y&6S......T2.i<.v;......"."\..0.O6k\....R.R:..p..9,..8.*.a..h....R~......}............]....?...b....`.,..~'.y.X.0.)..o............$E!,.. ....|w=y..@...".L1.aP1b...M.|..H. |.`B...|o.._....V).a.../..`.G.....Ve .k..rG.....5_....S..p...S,..5...'...:f[.......,...k..y].>E.F...Z...oM..v........n.<.Q........E.....cp.[gz8.?aM..;0."..%.c..~...VDx.x>G........L..B....T...?3.@...n;.......jhV>.p)...l..<3.....y*q..X.!M.|/..Y....8.....B.7.,.A.k
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1106
                                                              Entropy (8bit):7.762860438597511
                                                              Encrypted:false
                                                              SSDEEP:24:HaYU6MbRFh/eZ2QSMlRO3gqx2Ah7Hi2J9n2:6YERLEdRyhH7C2J92
                                                              MD5:C9E9B8D9B2631D30B49878F632EE3E1F
                                                              SHA1:CE5D81159210E277214B0862E2FCE5F87B6FDB80
                                                              SHA-256:DB2950963E74194171F541AFDF5BDD0016594468F827C38D04E17F543B7A17B2
                                                              SHA-512:09B35E7D4267746BE8FE9AAD610831E0D3D6B9F504EA43D50938E684EA1B08C7755F6E6D02373F72F4073BE74866851DB5475F4EF43FAB51B7A5DF51893B2A70
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..[l.U.....nw..wJ.l..*./5.'M.....Z..H..(..%Q.U.1>....i.TD!b.F.j...%.RJeKw.;3g.....]P..'..........9K...h..x<v..k.....wn..g~......l4.Mk..[..-..7.oM.&...s..............3,c;.[vS.emM.Le.O.-._^....s.|.4..b......2.V..W..u._mko....p]4n..+..8.q..6wY.d...C...N...H..V....[Z......`$Zo.D...qV.0.6.....g......\......g...l..b.1.qp....`.....S..u...^$..4..f.%.].75$..}0.5.O...ayz....%.zv`.>..%G....2.....C}&..{a.g...YY.x..h..0...`.Dy .3..G>.<..z...<..UU.i.._y{.F-..W.nK.rQ.z.c~IX.L.......G......z.=-*.3..@[g.q..".+...*.B......l....~..]....r%Y..<....Nh.>.Z.Z!(f.\..(......N.W...8.#.<......{@wH.}T....i..Z.L).(......s1..._.\..3.Cg.............z.P..!.Z..E]vg..9.6gU..2...=..b.8.....-V.*f.:..XXr.\...f.Z....5.d.....ogYv...............bo.m ..A.h..m.nm..P...WU])..N.I.l6.{.5....2..EV#.;.Q3..........v.&;L.Es'~.. .Cf.....6;ad.~,.+.....{.X.k`.U.`..%......Y...wSy]....D.5
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):250
                                                              Entropy (8bit):6.461832087016094
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwdshkx7z/VawvzN311tIbLz/pnoTm:6v/lhPZi+aWdKcdAwBNObHdDqUpFDdp
                                                              MD5:A2A3E7BD7705826D3FF143BB52DD3D9F
                                                              SHA1:07FE7162244E2B05E1586C101E9545A5FDDC9208
                                                              SHA-256:94DC37B9A2D954DEAFA5223892905B1E8B2D83B88ECDF1C6A94188B95D488595
                                                              SHA-512:3F927341922B54B27D3D4EA08A821D0FBFE098E35DE386E16F201C033EE09AACD81F75A6CB74E3809D95CF67CB1B1B0A66E418785A5EB583B101734F522D04C1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf........K.....F..Z4.,..a#+>@....k.`.j.ida\>.....q..',,,..Z.....,.......C..\.:0.`+...D..b.X@l2...."...At*"..o..q@_..E...5..T.U.K.M....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):223
                                                              Entropy (8bit):6.398799942519418
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcxaUjDvvV4H60iPQCu13ggp:6v/7saZxXtr0iPQz13L
                                                              MD5:1C743852FC14080A177242B560D837C3
                                                              SHA1:8D446967CA3D01D167619E0F86068FEE5BEF0569
                                                              SHA-256:57B68F1F27EF229A7FC05ED0CE6F68D3579D95F060D8F8640272A4C470111C80
                                                              SHA-512:61809D6A57914FD55CB20CBDE4865A183985D237D50343CEF09AB9D03C3489BBAF89703E34872920E51489C46BD80B0DC1CAFA4B17D712701C2CEE795F0F264E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....lIDATH.c...z.....r1H?...2.......N9dE..l..U...._^O..A||.,@V.".......`.x.qY..~.Y@.8.ME..h.."...4..h.Fk...b....%.........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):296
                                                              Entropy (8bit):6.746873141368636
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPUb+aWdKcvYi25Cw5pxk0JUnUkjM2xD5LUfdHitDbp:6v/7+aZx25d2PbDy0B
                                                              MD5:C6673C8207DD7A3BFDC899FD5A01C683
                                                              SHA1:F2F9C53A2431C86A4CD83353FA5CAE72C8667414
                                                              SHA-256:1B307B3D491DA1CDEF0436D386D65CD42893D0E300883DEC5D1B830FEB6FDC8A
                                                              SHA-512:3F67AD592DB9AECF1F63427A8ABF2D35F0D7CFDAC34180BCE370E4888DA1C2FE0556ABBCE33EE52FF6B8D909A82AD8CB1BF57745D3DFDEEF33AE1FC21A5F13E7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT(.c`..>..8./.h.8...?.w.%l...\.0.a9.X-6.*p{v...W...[.O!..1.X56.]..@X.p...A.._.`0%.xV1h.....l.)4b..B%./.#p.{......\..B..m.*<K...$Q,..3.....P..Q....._..........b..p.a)C&...).....U...^....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):549
                                                              Entropy (8bit):7.283369024087014
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZPQcT4lYTthdesj8LYShggLCBf8/AMyj/GdR6G4s69qN3Fz:HaQYTtVwL/zKMQSR6Gk9It
                                                              MD5:667D4AEE56471B8D1865DC64E9EDB5B0
                                                              SHA1:32CB65F26D5122463D577DB5C01DE6975B9092FD
                                                              SHA-256:4D2B4EBF08036D42A00AA94A5226C6816644A6BE7C5859CF20F71E413C6E0F5A
                                                              SHA-512:1928A6825EDD75E17F69527227F9DCD0BAD7DBF6EDA2BC4F5E8047566C9000CAC0A887B7E9A4EC7C281D06867FC6E178B70F6058EA5821F49C6C1DBDE41D5695
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..#....FX..5.h.R......'.>.....;fo._.>..N.$8...fdb...#..\|B...E.....1?.../...O..9.x0, ......Y.../...c...s7.......K.........FF.$E.33.zn^.?.V.........=.......n>.?{.>....N.......p...8XXX~.....}...[.^.......w....f?........j..Jj@....9.N[u...[...}.......O_..l.....&&.;..gff.w.6n.........w..........@..r...y........?v...u...#y...V6..gQ%W...^.W......K....cl.....3P..Z9_....M..7M\..Xo..-@C.s.........c.(..@......B.*$.j......qc.,.!......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):354
                                                              Entropy (8bit):6.795413594247034
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1w71S2BJImyidQmP/oQDqPEzl8MZh8OfkNbDA1KxVp:6v/7saZ1YBJc0zBvR8eh8OfkNIg5
                                                              MD5:D74E9E581C473BAE1DEF15699EB5AA2B
                                                              SHA1:513B78C0CC878F42597556B7A168F187806E7EA6
                                                              SHA-256:962D806D29BF95BA7DEFAD353523B296F0FAC02561C8C3EF27D7330934E6F642
                                                              SHA-512:046D7210A0FB0FBB19212A262CD0C2308574A8AD3A051335C3B63145676CCBFD365B2C0DCA4FD4D8B879E63452814F7019C856BF47691D4AC01326BA8CA6AD34
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` ....|.R..a.........b.ET...F.....I....7.+..4..]S...k`...`f.VL...@....qZ0..+&d.7._EJvW.b..<..+&d.|,i{>V..i`....!........f....X1.,...S..;..b.Ypq.9VL5.6.....L'/m.....J./...VT..<..S..s.:..S..1)\..S...h...V..:Dc.T."Aus..Z..l.@.P..g....:1G....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):863
                                                              Entropy (8bit):7.676585224606489
                                                              Encrypted:false
                                                              SSDEEP:24:Ha/jmJr9wOv/z5W5ib9A5OnVG17QHImdfbbNdm/:6bODv/wy9A5OnauxNA
                                                              MD5:F463432253A825303A05937804E13114
                                                              SHA1:C70E3D4C39C8920D6B66CAF8435DCC4A414D1444
                                                              SHA-256:C7ACF49F936E01C3758A4303D807B24F9E6B4D89B34F2DA3E4FFAED77F411BDA
                                                              SHA-512:D74ECD477651570AB0156F1DB49B5C2B88CC364FCBE3C18B33552FB2D2C7C6AB1035B35C5F9FD423E13668692F772ED2D85BF3E7BB52B2220A1E90A5B1559584
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...K.Q..gf..r...?.vUh..PICC4{.4(._ -Y/A..?..A....2....,..Z!*.L.!....H....].ec.9...2...su..;.~.{.{.]..[..G..q..6.. .c5OFf........>"...x@_x.|G...(.-tL..w.e.N.~.Ig.=.".N..~E.z.4d.>.E.Z.2d..BH%..#.h.%..2..,6..FT.."..7sV...YTEL .....r....d^...#t..HBD...Uj.r.......;M..D^S...r.G.. I3k...(r3....HZb. ..=.m....cp.........(.x..M^>...>U.N...E.[.fl.6.....JQ.3......PZV..e~..Rm...r[@....K%...^(..P.Fy.6.)l>.lP.&.7l....[P.5.\..v'.h-..Yf...*..F)."....@.....B........uP...'..$.h..-..X...N.o.\Q`x......{j.x".<..z..@h.....A....a<.I..........%.).;.F-...*.I..../...........x.]....JJr.\.M.$..z<h........r.JOYP..,.q.Q.C....(......p...}..IS,q..j......[..^.aN.P*zG..X.*J.W.;..~.Q.y.]0.]..x.(..0O..X.h...."...O.*.mq...E..u.oL...K.2.T.5~..Fr/..#....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):432
                                                              Entropy (8bit):7.022433406427089
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZy1iirqwEmIS7T4pEeQG0ZE/dh/2c:HaUiirqFm9sp/QV6hec
                                                              MD5:F1A38BFBC7C39AECCBA6BAAD013DD07B
                                                              SHA1:8DC318CC5D5AE6C4CD8A8FB13DBE6C42A97EEE63
                                                              SHA-256:2D996A5F900C566E37261B31530E756D3875F2CD48816116FB22F07DF43284DC
                                                              SHA-512:CBB562846167F21955CE749C3AFF63C4E07C138F3E2525E6D8688F0221BFB2FF334818B6DA27D5C4D70757FA66F578B432237E586DA49670FA9125FC72A530B4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....=IDATH.cd .0....}...1.........P..P6..f......A1...Z>p....bU(.......`...T.$^.......`.T."..".3.....Rr}..U......kA.@j....X....B(.7...Q..U.....p....6@...o.\.I..<.|..j..z.EJ. ......M..d3>0 ..i f.*Z...L.8......Q%..3...~<.4.,,,_@...T7g..Ta..Pe..........l.....<;......3.On..@....f.c`..g`.....@.I..\B...Z0...<.2....$f."....w^.O.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):391
                                                              Entropy (8bit):6.95337744772903
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc5sygba50UgvsOSpOCGkklVHuHcp0pzflxHXxY/kynWZzJ4xniH:6v/7saZ5BZysXR0V0C8aQzJ4xAJ9
                                                              MD5:9A19C446FC6AF7EC2801105DFD008566
                                                              SHA1:D0F53305204C064B3F7CB5227AA917BA3EC7C23B
                                                              SHA-256:A0B242B7DC424C14D376E5CEC3C796CADF15AEF497D02FB1E5ED7AD7311D0230
                                                              SHA-512:8208C9313F8A7B3D63E9E362BE44B447B21E25D6E282276715E4C5640F0C831875963A6D9779EE187D94188B6D2F3930764AA1C5542326442D55BF176CB045BB
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.....u@....B....hx...\ ..5x*.....@|..y.._..(.-../.4..........,(...$.B...D.(...@.+..B#y....i.H??...6..AKb_..T3#.M2....4c>Tb>.....n ^....X......`..dc.....2DP....C4....%...N...y....%.'/m..iM........!...v...7....R...E....6..w....3C..]S.6.....=...h..`..).3.]....v4-..hN...v.:....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):234
                                                              Entropy (8bit):6.296885754046096
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKctNi+rBauvV/B2keImuxqiutYVP9DJ/Wadp:6v/7saZtNdEuvV/BDebuxZrp9DAaz
                                                              MD5:B8E8F3379859A608CBA1D83F4BB34913
                                                              SHA1:BC48E687DAE012AFBF733DD7040E34F7D215438D
                                                              SHA-256:F3F6CA3CA21BC905917DF11ED0978874368D69A37D73489B9F6C20AF9E922544
                                                              SHA-512:DA739D664226DD094023795E1780BAE422BDC5B51692924068FCFA68842DA526C0A8A840C4C23839F4EB7EF12B9661528780BDE9E73B2F0DA01F125108DB53D1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....wIDATH.c`...`......@...yha8...........x$U.x$T..A..*.(?..<.m .. ....|.._..~r3..b..<.6.....<...<.f..L...L...Q.....'..`........Y......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):395
                                                              Entropy (8bit):7.057270124013177
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ1HQilxcm85iSf7n1e1ddbqIxobK35:HaTwGiiSDnccuobC
                                                              MD5:E932B31C319943E469549915D810AC12
                                                              SHA1:8B1B3B1B043EA60097356EFEE4E80352E07F0ED5
                                                              SHA-256:29F4AEF9D0D15012B8D146256380B01F10ED8035657EC6DF3035F992ACF9B8E3
                                                              SHA-512:AB75BCC508E35891D0117C93CBD7319331257AB93E7526E3A71B5D7167407A2CD513563AE14BC56D289EC078DE6BC6FD18C76F50DD94801ED655BAB1CA107398
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```.O+......p.v.&.j..........\.F[.:k.0,.k.r........VQ.` .EQ.....s..d...6...G...N.n."..d..0l.f).%x-.0..... K........9...e.M.5.1..'...|S..D3.G\.?2.G.n....6...m...c........@........n.....}..n=...>...=..1!.1........._....6........p.... ..."...!9.q@l.......k...........M.-...5../......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):395
                                                              Entropy (8bit):7.011693557019101
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ1HQ32pY9/tJLtZA8tU6GtbtFYnl1:HaTwGpYptVzArjtbtinz
                                                              MD5:D0A6B5057DC9BAACB71C9C19ED00B21C
                                                              SHA1:8D5FB4F80B314043BB45D207E3DC943C18DE42C0
                                                              SHA-256:F243BEE3488E45268B7F23AEA2F6E6103D5A3CD16D943C1E1CABE010B1200347
                                                              SHA-512:49B1C9D45C3BCE4129A72A50FFA2B152CC8B947CE7C5D117ED4325CB6C28920B2C932FF49DB7A2C0B6BD9C3FAD9E1A2427549A27FDD06CB11558909AE8A2934A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c.......@.......p.v.&.j..$X........`..h.4.n.Hc.|...;..b...^...`..H.......b#!.a..0....-..!,.....@|.%.).q.-... .YB. .a.E3...s._..@. j.c..N.8.a.. ...m.b$#...s...c.......f........Z.....M..(*x..313...f(.........a...f|..e0.K.+.e.1>..|A.K...8.&l...\8.H'&..h.l.......=.d....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):721
                                                              Entropy (8bit):7.448808390963381
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ9XDEnQVKj93V78dXY7k8qKDhSKGQ42MikNEZCuU0wgy5yhK+ATv:HawQVK53doF8qIGQ4M8EZTU0dyEhK+Ar
                                                              MD5:957773DC9D469F86A04E54E916592EC0
                                                              SHA1:8E39DC11495A21E663D5F8A5EA740243B398989D
                                                              SHA-256:83488EE535F319F9BAE4B6F93939FF59F1A87036A010E21185B1FC0BB6CA9E32
                                                              SHA-512:9371790EEF711449B7EB598D2DDCDCAAE4707A2A0721AB4014EA1E7818D6EAAC4EAC81D7624967428374CE22F8A7C3356DC11B53B8689A47E194E3BDEB51784D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....^IDATH.c`bb.....X........y....&.........w..G.A8.o=..I%..01...."................jj`>.?....b...(.......n.1.n.3....fdb.....?L.Y...m.,....?.+.X...Z........-T|1yA.3.._.,X..,..<."....v.%...7............. .9...v...(h...>.{.X\^.......[........C../..,n...g.S.".c..&..`..... >..zF..}3..w.|D..D..6v....a.....Y....<.....s..%P.b.).8....Ov$.7-.s.L.P,Hh^..W5..[.2....p.@|8...n.....=.....D..#..,n............(..8...CK....]..0.`|,.p...!..i;Q,.P....N.NY..KLF.......g`........`1..&.?...PR%..F$.......?.8.G C..d.....>#,..!.02..1\b.Q..)*...9...FV*......S;...-+w....Y.....GP,.......=..#+.....)..R00.~..f...........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):913
                                                              Entropy (8bit):7.677598234915074
                                                              Encrypted:false
                                                              SSDEEP:24:Ha3YvJK3Ww7NMWo9moWcVZ9YaRD/0A2UDeVAg7:6gWo98cnlRz2uc97
                                                              MD5:DC170FE8A09DD78D0EA4A5A0ED9EDFEB
                                                              SHA1:0A9ED3316315409A75ED2F91F1E661C6108D5204
                                                              SHA-256:085769601B961616FDFCFA94382B41C6164E4457FD09AA898C0BF645BCA4672C
                                                              SHA-512:27F31ED79CE0C4D555CF273A0B87E3615755C20AA9FE94B73113CFCF1B697B2B27965106F3D98F82BA174E0823C82AF3FA4BC19773E0717C449A4770C69DF5B4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..MHTQ.....4.{3.ot..0.Ll..hQ...F...*2ZIE.6E.....Q.}.a.fE.H..1.-...Rgt2.;3u.....%.9.......q.=...s...._./......%.....GAV..@b...]...2.Bd@..JY..$Q.V....31....UD.WU...A.....i...Z.FP...A.xJvX{.%%..n..3<...6.......d..s..!.@...(..R....K.....Wh..C..U.`..r.5z....UP.;{..#@.e.......I...e..t.z...A..<.(%..).....(.f2...rA....}..8@.^....N....@...(E;l.z.M7.:9..RU...;.u..r....M...{........r@[..w.l.8.Q...........U....OR.`....Z#.....G....1....?)i)K...p.<..T...Z......DD...T..|~...YH.(..:HnY.O..J...}8...m...{.K.d....l.g.4...U.jK\\'..CA.I...&..>....g..t'..{..d..b...|..~.n........e.....!....-..?I....p..eE.r.....d....0........]f... ...4...+H5.)...aR.Z....U...btY....B..p[J..s=.......3b......_..x.9......*.{..M.S.K.\fCL..L[8....."V....\.u.&....ela.......i..3..O...S.........]..=9jWg.P.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):361
                                                              Entropy (8bit):6.9821963636663495
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcNhkNRO83y5g1WAl4E5hgBL9LgQY2nfJA/NRk+fM1AL2UOVa1/1:6v/7saZzyXy5g1Z7UZg2nWDk+aRLVY1
                                                              MD5:EB9A5585C347526D179D4159B0908B02
                                                              SHA1:D796BD218C57007683415FC1284B55BD96E7FAAB
                                                              SHA-256:569427C23063A528A27D6A5CBA2F25CAA71BF0522FB2D8034E3C063D1B29DE4B
                                                              SHA-512:3C5777C5B18DA8472C88BB63BE6319BFD644AF162A256D8B0C3EAD4C74B1476E33799F703F5DA5424905BFD00CB6042A0CC1044D92437971EF06514503529CB4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`fa.....T...B.... .G........**X1H....A....E..@.!.....(....n..z......<.I.T.....g...{.B0..S....IYE.]...4......'63...r.. 5 ..'%.(..1)..8 &.P...f.EA......`R3#..R. t|...[.\.c.......O^...ny=....Pl... ..M-.....Q-.....H&:..M%DE2...b0.l...2ky1."....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):452
                                                              Entropy (8bit):7.285227731150245
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ894rjBvvyUKpQ+TQ1AMDTBlRs5Gogn:Haiy1naQ1Rpqlgn
                                                              MD5:AAEE78C672CA805E8857896226C2099C
                                                              SHA1:24EA344563F296A3903D3C1FD0073713112AB721
                                                              SHA-256:C2D7F3ABA3683D15944880A12DDF0F7D488300C2C5B6D84E04CF76ABAA3D0618
                                                              SHA-512:33A836A9A067B2F8CA72E24F61DC049C4DF19E0E115BE02E1D89B80EA75AF50BED69347BD1D42254C4553E69F64DC5B1E40E277CBF583DFF7BAAE3A3247247CF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....QIDATH....+.a....W.5...b...RJ.......de.G.;L..,l..[Q2.? V.f1.j&.,..T..s......:...>.y....G...D..Q.=..!NQ..@....y..Iw1...|..I.T.5=.O...g....q.c..p..r...O..J..F|z.A.0......`.G8..r.[.=..^d..u.........~...6............i.E.;F1.l...5%1..Oj.....h.x.......N.X..:...^+R..x.#.....[.2..|.....|\X/.......O..!.<2.....DG.......[.8....x6.......a.:J....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):177
                                                              Entropy (8bit):5.969137605937591
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPlT/Xtsjm6Kp0qRthwShLKOWGEVwks+RjaOWFgyqwgwDF0xJoqpu2l+:6v/lhPXK+aWdKclAjlWF3qeFutHYEap
                                                              MD5:C2154350B2BF58F4113638B8036172D5
                                                              SHA1:77FF707C980C6CFEC94B533C2600BA99B8261DC3
                                                              SHA-256:24FC0B2460761B1A9F0DAF5F15693DCD41DC4BA13A5415B120D8EF0FA0F67436
                                                              SHA-512:46CFBD4F33D7529E2C9EC2511DF22B35A1A6283C1063AFD60BF1B97B39D6209B1DD8526DDE73C1EC9477014FFE6EB50E4235664DCFFA870BD8B6CB662B2E7128
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............J~.s....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....>IDAT8.c`@...H@...&....@...j@U._.X...?....H..$....:....@.R....j.=.*.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1034
                                                              Entropy (8bit):7.734794645219255
                                                              Encrypted:false
                                                              SSDEEP:24:HapZ4JOeXbe0qxdEO7KCMfkKlgqG3G5Awul3kQ8:6f4JzC0qHMflvG3G5A93kP
                                                              MD5:E18AA31FF223148C443EBBC9DA889B8F
                                                              SHA1:A7D7A15076ABE042CFC6430D8920608C6EDCFAE5
                                                              SHA-256:16B6CA9329F1EA799A68EA0C21AAB50EB61F7A61CC23988D7976957D01D0A399
                                                              SHA-512:388E2A3582A9114FC83D43CBE1F00D528E4ACED37FC3F8DDA8921AEA3B3B64DEE30A3A3B93C1B366C47D35259927FDE6C866BCA0F7E37129398DFCF3B46C1AB9
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kHSa...s....,*C.4k......30..y..V..,K7*...C...nv...A"kv...fED...R.......Ns..z.7...y..sy.W"..b....\.r...W+^R..*.u.d......j..."C...O.3'Y...K..(:..Uw..........|.-K.]\..f.v.\.7...X..q.:...[p.7..0a..+.3Mh....8..lcrw..]..R...h..d^..E_.y....{....sWb.k.Z.G.4K.D...%.E...HeR..=.v.I.J.....7\mE.8w.jL...>....H_.......p4T?,.J..(U.3w.tmt.7.."06t...j..M..^.S2v..=.Wq.6./......}.B...b.|-I.....E..N..5 .4J0Vot.[..........9..<...v...h..t..e5[..{;....`h..C.....6.,.~.w.'.5.....^..Z.0&$.t.a.{.a. .6].."....D....w..~.Bh.\..v%...q..J...*2.S.I..T....G....i9.$...).1...[...gEBR..N.Y.N..%E.eQ.bX....... Q.....G}...P.....Y.........E3\.4.sf....{...K.m.$..u..rLG.......I.....yp.y?L...a...4-&......9.(.G3.Y..,.<..@....<P...?..z..p...\..x...M....!.....R...............v...;..x'..Vd.D.|.....T*...g...a/....)......m.w..?D. .^.....!..@N...K...W}....'.Fw.Y.sL..d.zu.-..!N.*....b..I..u>.|E."+.:..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):712
                                                              Entropy (8bit):7.613545467596214
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZrret62b25ynikW0NDsFqv3rZzflmpuYhrOx+kdeHvXdRmcv4K0Cf7:HapwfbQ0DWU9QpuDcHvXdRmcrT
                                                              MD5:4174969FDB24BA1C5D8DAC66C6C87414
                                                              SHA1:0A515C4A935F67A08E84B0974EFB1FDB5F2103F9
                                                              SHA-256:D22816398FED8A9F16C0B98CAF0BAADA6BE45BBD77D5ECF9059E5EBB3FFAA466
                                                              SHA-512:F925B53219120A373766F918B5BC5CB3C25B39030CE5F2DE8A5CD6C9605D814BCDDE8916F45036551D1D8B1ED0114340DFF5DA713160DCA863116435CC18B5B0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....UIDATH..KhSQ...E....<..D.".\.B...D7E"EP...B... .QPJ.... .q!hA..HU.....K.....o..p..h(q....9g.....8...H.....WC...(.R.~...Q..(....y...,..x..X.....0..^W....U8.. ..$..M..fa.l..>=.....$......z...N.:...J4(.68._....]...u_..p....p...#x..t.+_l..5m.......TB.><..R.......:..c*..%hWI...K........}..N..)w..5;[.@..j.P#.nb..*...*`V.[.U..ZF..].u. ...>...x<....L&W.'..................~:.cc.h#I.`....d.&0.H.&.....J...%9.....?...;F...O.G"..M@....s...".oVI6.c.......d.....Rl.....%0.Y....m.....o,.O.|.k.Y.)..h..Mv...e....=.k...!.;.....v1...*....0...._.O... g..k.J..4/..N........s...l.......C&....0....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):214
                                                              Entropy (8bit):6.121521703688993
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc5Ai/UyBSS5emlULuxeiyTp:6v/7saZ5RcyF5LUaxeiE
                                                              MD5:63B811B3D4BF104CC6BF409E0D6FDECB
                                                              SHA1:FD30B0A772DA243966AA8CC093DF89009689F5BB
                                                              SHA-256:234F565B79842D4A6411B68739CB6A390FDA675A2EFD0A517A33200B15A5FA12
                                                              SHA-512:C9B97F8730AEB6E1CC5FEDE1B2E9B71F285FCD73D156FF29EDFE0A406077519FE86A3C297BD0F7F92CD522E014D0097FF96A5BB3A3D8D2635CD57A623D7CDC55
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....cIDATH.c`@...wcb.8.&........d.pY.M-A.H...-....I."....."., %....4.......&-..e....=....F..h.,.-.....s..B.s.e....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):400
                                                              Entropy (8bit):7.016748459858045
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKctLwH/wF+1B16o7gUFyt0lPgF6g9bgApeHCbtnsO2RwdgE3uWVU:6v/7saZtMIFkTcUAWPSfsibtUOq4U
                                                              MD5:D89D713A14E737C662E4280229C1A74B
                                                              SHA1:08F537BC90EA5B765F8966A51BE64A2AE53FC872
                                                              SHA-256:5456BBD8BD1790A742D01A4229848418E3D2F923631177F07B3142784896C3D4
                                                              SHA-512:C4C079B8EF3B2553D0BFE8B7F076667DCBB19077B9A908E5A44A5D8C090E7B7BB5F0D79BC4644D23B82B09F315B5B635199424307B285ED9B867272095AE8640
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`aa......X@@.DC8 .,...r..]..>$qTIt...6.q9.n.6....X..X..`b....p.._p.'l..M1>K....8`bf....E0.1.0......8...3.....7.........`..7......|...".M.p...E.........Pb...n..TD.. .a..........YBq......./Z..Y.Q#.`..$....J$#[0....p.H.aHF.!"...g..B.`..\.....3..UTp.p..i.0.....y....G- ..Z7[.Jp.C...q....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):486
                                                              Entropy (8bit):7.170472697648373
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZW699qguNFVzmnyRDzZ0h1T/P2aGGFYnlgUM+:Hao6sVzm80hEakx
                                                              MD5:BAA6164F13FBA815DFC6627419F2AFEC
                                                              SHA1:5011DB35431AAC1B5C76046C753B7964AB5DA685
                                                              SHA-256:9D506E7E8D8AA813AEAC8427841A28AE2B858BDE208871B7CF113E4C52D3EE21
                                                              SHA-512:15AB7E68CED3F52FA91F1A1326C170239313A654921BAD68D1C18957D22AA8CDFF9151CBD6B6ADBE70CB6AF854E342A44CEAF4EA189239B532186A3C3ABAF2B4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....sIDATH.caff.........F&./, .w\......._@...@h.10..L.............TyX@.H1.........UU......,...&.n(...y..N..A-@......'....k..a...0....}...B.....0G6.......p.c......0....0.%.ha.?.d...z..d.].....Q#...A@...0}[E.(...w...b.......9..0.2l...K.=.P.......+.P4.U...a.s.@.........&..P.........fX..D.....(>@N-(a.'.`.s.>......d"B......4..>....vL..*i...F....q...j....(.).i...1.(U.......'~......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1238
                                                              Entropy (8bit):7.808915422534312
                                                              Encrypted:false
                                                              SSDEEP:24:HanXtZPcNqHGU4qPgpf0ZJImFt4MPJAqDRQGmoagfGxCy:6nXLqqHrNYoIEyMvVQxoarCy
                                                              MD5:92B9537C7ABAAB5654CD4841B8304A83
                                                              SHA1:D396624ECE2D994E1F7C65F284808C4C0A617CDA
                                                              SHA-256:150228E68DEE137D1FBD1D895FF70751D188D610050B350AC520351D61B93904
                                                              SHA-512:FD760A1B3723CCEE45E80E619867125AC7BDD5F1093515FCFB126212C1CB54E4430E0AB17A046659CFA2D1ECB709AE875F541E26AAA1B6EFC849D1478E5FE42D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....cIDATH..VkP.e...o.......q........b@"..9.#..*...(.....x.I.1C%.t...lr..~...4M..6...}.|....f..~g..=.<.y....G..-$[H..V.N...l8m.1_..6.h0j.U.U..:..j..3h..;..T!f!..T.$...b:o4.~.$./..S..o...7......O&.Kjsn96...........&:t~'.]...R.......nV.c...P.ZR..au..q.T.. H.....P...^..I..F..O..k{.k.ep5..$...J.<.i.-..w....{..z.s'...6@..O.J."a.v...wVSdl..?..v..I.+@....'..MK*.(<.F.G......a.3....-.W.A.s.iA.#....$%{.'.-I....D7f. .v.=.......0...R.\. .........[.)<.F.e.T.<.u.p."AR.P..........|....<..%D..X.....=.?..C.}x...p.D..O...'..i../z....\d...<f'h.VA#.u.T..2.D..t.....................{.]t..9..J..1...I.`.7.2..w.0.....3.u.{Xd....._.xR.F..I....D..et....|...^..J_.S...&.H..m..r.R.*J..X;...F.........J].....JASbj...~1..4p.....XuS1.}.R}..&...U.LD.Jw.s.B...$....h....c.U........H.bM.......E....U...v.).N..Y.2..9..@.`.hBw.....G.>....}...)#/....c)........WFV.=X.........K.<..M.....Y.{e.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):316
                                                              Entropy (8bit):6.791312583826091
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcTNJ2NRF48MqF85+ChfsHZmbFHMljGRZDdp:6v/7saZCNRFDL85JhEHaojGRlz
                                                              MD5:65E360571E63460B00426C87DF35113A
                                                              SHA1:CA09A029470CAE48D08FAECC1E06FE843F99FF59
                                                              SHA-256:221F074CACE52746BCD34A5E98F5656C485921D8579F10E43BC8F444C66A4C7E
                                                              SHA-512:E00693D4A619D07F74E7FA20D5099C71D76B3AF41DD8CCE64A3816AFFDDBE9049051104140DD8C4712765A1AA2DF1AB1C75EE708223D20AB0C70F1499F9865B8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` ...b......I....$.........8..5..c........AD....!..P,..bJ| ...X...tA..%6..b./...*4.g..>.*:H(......@....OH. .....3......r....Z`...E0..E.1.,.Jv...I..1.."....K[B..U.....Y@.B.8.Ql.M...V..q....&.v.jx......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):786
                                                              Entropy (8bit):7.514285909712526
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ4ZRY2VbLvZ8znm66wLcT/ayfgKjo6f6C6XC1FhTJHQZXGpxarRUKIpIYc:HaeVxQmRwLgayItUqC/hTF4ruhN5FWj9
                                                              MD5:7F4225C588D46DC3808075B735312610
                                                              SHA1:44C9C2855CFE398F7B85AEC33434192AFC7B3DE3
                                                              SHA-256:94DAEC623321502A1CBCCB2168B3FC471DFBE06322AE43CAE2446124B71E5F09
                                                              SHA-512:E9D676C318949D8B74F08633B4C0D9D7DC72CC30A9096C2786F1CCDC401D695F2B29A3C03C55F8754D5CB9CC2661FAF8F970D080DD7F80DE5060111B0E9CB562
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`@...C9g......A........r...........L...n.x0-..........YYw.rq~....... .....$..x.&.....A.p(n .......QiP}.\\\.,,,?a...g........W.740..8...=ruu.....G..yz....0|...'.|=...Z^..!...F.......<WHHh....u...?|....._.._..H....A8t.....Y......,(.5....z....Gcc...?._.......{...r.?...F9...L...|...o.>N...v%.....4.y....co~e.z.........=s/.g.|...}...w...8...??..U.w..`&r..y=f..s..;?j.w....=..<.}...i+...{............q$.H.9...PXk.....?...w..i...%..O=.......;::~...@T2E.p.t.'...=..c..?....#.H./(..La.j..:.."b,....r`..5.....T'..A(.A. ...8.../..}.lLD*j ....!...2..MET...H.i..R.N...F..L..pR.?.+bAl....sq..e.....b....l.~..I...o....a.3..?@=..}.\.../..b.......f...e.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):689
                                                              Entropy (8bit):7.574530374290251
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZnizlgDaH82JDYgnLI4hWaFC2HKnnCaIXPRVeYbd0AWWnvdHXWCSNB67PA:HahizlgDaH82iwF6CDX5UYbd0AJvdHXK
                                                              MD5:54E3DA1A498729DB27A2BF10AABCAF76
                                                              SHA1:DBF8D742769EE071AE7A85E79F95E46CDC29B759
                                                              SHA-256:D590BBDA450D7E69633384DD1B512E84EACA60F32A18A4E0C558518A9DB2DB6E
                                                              SHA-512:C22E57CFFB3F325BDE09DEE301B5B095B9012EAFD354622B4C327AEC5DFA556AF26888A01FECE033976FF0323B447F81324061C284158604E706F3EC5A5C8130
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....>IDATH...Y..Q......,..L. %JJ."$ERc.......7<My@.D."Q.&.VR...D....}.y93].~..'.n.v..~..{.=.g6.5../$...#0?.0./1.."....zlB."....d+...j./.NaK!..Y..E..b...2:D.h\....M.M.=...x...9..1.U8......k8....i-..y].@..aq.T.3*.?.p..S.. ...,nTh}p.....1)bc....>CR.. ..N.......m:vEG5Z.>.@..]K.W.@.U....&|.._k,-.]Slx.]M|...~b.f.N...K..........a}.......6?'6..c.1..l)...4...}".Q).s..-..."Z.;Z5....y}.[g.....@.F|@..G...Z.v_..U...x.-<.$...Q6j...B.M~}jg.....%...r1...O....}..-.5...Z~..@.......p#rW.d.w4............h..O.6:.k\b0...\.'.^......$.1|. ..b..?....I.Q.....2.Y.*..K.wD?....g~..o.p........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):654
                                                              Entropy (8bit):7.5246396249978655
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZsMb3rCXdR1/iuIQgv2YDAo/BWNeIkhkR4iLawLwaUp8rqbij/1:HayKOdR1j4v2eAo/INeARTLhUiebij/1
                                                              MD5:49CCDA35BACF3D49C1C208365F9EDA7E
                                                              SHA1:3C3FEACA3A8A97752B48794F84004558F6782FE4
                                                              SHA-256:E38F7304BD70D2B68D78ED098B3D570F465AE39C1681DF64A11045FC8B664706
                                                              SHA-512:3DEBDCE3FD946B90318C74ED6A40563E8248C507EC702196E12760ADEAB3043A18B0426380D994BDA770CF6315908610B5726BD494E7D2BCE73A96DEF9524765
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..OHUA.....2MB......B&..."!.E.iSm.t.R.`(Q.Z.m...=..... .."..MF`D... Mxh....Lr.{..[40..;.|sg........c...V.J.k5?..2.P...........g5O..@..Wf...<....&.b`.8.q..{...X....D..vm..."P*<.<.....@....+..6...o{.%...5h{.....h<.`{W|...=.."..._..l._.X..zac.7dC .`.=.....t..a....mPF-.'.#.;o.......U.1..3./..r..5.&`P.0.O.#a...&....N..h.>.NI..(...k3........D.......r..q.......g_...\....t..?.Ue.W.~.....g..}.E.@..;..W.w}.M+.V.. .2...@.....m7.P.+.V.....{.n)}.0..S..."v..........._............=.R>.@#0.G.....9....d.,/.v...|...V..........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1468
                                                              Entropy (8bit):7.782463629931873
                                                              Encrypted:false
                                                              SSDEEP:24:knpiJ2QS2Hv6E9h1e4rsV8j6GCh3sbWImFacV1eLnQ+DEzwWc7E59z41JI:CiJ7yE9hQ4rXY6lmpveLQnH9z4k
                                                              MD5:32F980D9976D4C4F0B4F9790A057B64E
                                                              SHA1:EC6BAB082550827366726F08D73179DFE845D7DF
                                                              SHA-256:8AE2D99ECBCED167A3A6F2619EBCE38CC2DFD3B5BB78212DB8BFA65DE0DD251F
                                                              SHA-512:33F5A73D344F86E8D25B7B3A18B6AD619272965DCDEC181DC345B20FCEABA651424CDCA654A4D909FE17EC709124CDF18AD349F7D99FC8014A47F9D533361DB4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....bKGD..............pHYs..;...;.........tIME.......B.....IIDATH..K..9....Uu..s..5i..MK(...6.-B..;.K... ... .........4IwN....^7.l.8=IgX.%o,...~........-.!.L......G?.'.=>.yzQ.g....w...{......_rrr...8...<..%g..#...-RE...W<x.SN..>:n.=A. ."F...W.%..Xr..O.=..Fg.....vv8.h.".ggS..2.........-;?......W%Q.0E....aL3.tc...j.3..?.UN...:{..vC.{!..1..n....g,/...sL.}L.... ......."%Xh.r>'{.......E..2l.tc.8..sK6.....;Ks.O..M3.DJ.H.....Z....9..rL. lv...q..D.%..q..S.3t6E...t@......b5..\]R..m=Q.B.....TR".6X...5xkPA..B.0DI.....-.V.yeXT.AS.7[..6N.8.1u...<()P....*..........R.s..d.[.X..uhm<@/.....c.'.V&.8%hvpFck.u..G....tAQd..H.v.1...X]RN.Y..Ls....E7..i.F{.w...P...u.............G....1..6...7.\e5..v$.$...9.%.S..st.....G...J.)..IQs.4.v#v.6.?..br...9.....g.....i...l..]. .....[A.}..6.eNVhn3K............gLG.\.-.s.F;`...^.&.z..9../(.F...>.[.3.e.3-,.v<.D.....=!.yI6...7.^L4B.v.!k....C..C.g.d1..4.m..~...X...d^Z&.e=......O....W.__p9.y53..Bv;......#....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):810
                                                              Entropy (8bit):7.624675630247123
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ6pMo17C5y7fjS7XLkEH1iICVOcaUYCr1dZYIAf0:HaiM67Iy7rSjBrTcaUZrUf0
                                                              MD5:7EF4A9E3931FE5E74093B5AD4FF425CD
                                                              SHA1:B72FB0DA6EDC04ED7EC79328A6FF52A3CD36439C
                                                              SHA-256:CAF33A8881B0BEC193AC1BFDDAAD20A459BA9BF03310A4FC4DC95E50B1662526
                                                              SHA-512:53B9C5F73D6DD45EA95C0C6BCB6EC2FA28B0FDBAA5BB6A3729D98946FED88C62B83629288F0356BDC1841CE3390A78E06BA02900694AE6081B56D70C04AB8799
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..Ih.a..'..5.$3.$bPp9..I........E."....QA..PT.....q..V.....d]....R.6.Kk..&M......RL.<.1.6.7....FQ...hd.....W....s.D.s. ...$....S...G.G0.8.K..\............\..A.....f... .2.........F.._nwp.v,.10...=............E...~.....l?........HN..91+.A.x..%._.g.mp.\.....g....x4....y7cV.....E..8..A..+.......Y..ze.\..T....H_/...*..Y.k.H.~.m|:..IJ!.g....`..{7v....Y). .H..k@;...P..T.1.Z.....D0X.gJD..;...<s..e.-.._.w.A0..A|....L3..$...^9i..G.q.{.......q..%/FYH.$.g9.rL. ......+:LGM.Q...M.\.......[........D.^.v...6..V......j.;yC.G...1....H....a.]......1.lp*.p.d.b.n...V]........W.t...T5y]..~....TH..x.I....w)(./....M^....E.&..,b{~vr..)....p.......L..wPILr=..+%.%..Q.lk1...ct.....(....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):190
                                                              Entropy (8bit):6.084337839265734
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwRshkxTDVQ4f6n3zfEQ4jmzAqsulk:6v/lhPZi+aWdKcRAU64SKazkq6xbp
                                                              MD5:95A4E320D9D3D8286913EDFA013C86F1
                                                              SHA1:6260D268ADE34FD4F6CAEEAB3280904C74059FC5
                                                              SHA-256:1A356C588CE0A9F60DC1EA052CAFD7BC9A8EA86C2171AC752ED810B125957DEB
                                                              SHA-512:46F822538DC6FA6328F36D0803BAC9DE9809044C5CDF3524A6900C3C909EAF64E4C124DBC72E02CD6F89C464261E7CFC11C184082871176C982C8A9716D8FB52
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....KIDATH.c`db..........'...6.6...ODc.E.-...B.......Q.F-..`.Q.F..C.F.Z.O.f...*...x$....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):766
                                                              Entropy (8bit):7.559452069599041
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZog+eu6trniXFwLtOF2YU5alMITk3s0C5c6neKj9YcgnX1bR5RLFvyKkEk:Haffrni1I4DMITk3s0C1nJScgFRLxvyN
                                                              MD5:65E5221042B3D6A197409FBEBD6FDBD7
                                                              SHA1:EFCC5A3F89D3DB224EF86AC1F029877F4DFCBB2B
                                                              SHA-256:FB7562D00A714EC795DEB429F585D9CC5531EDB351517316812162DEC3A27DF1
                                                              SHA-512:A832437E018CD8755F2C2A413E1F64CCEA7776C13F2DA4CDF3F5C2E2A1046EFD4AF4F8ADA834F49B3DFF7B45DCE2AA7ADD0CC8CDF2135E7853E643DC238530B5
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.._H.Q.... .....}..4.F7.1.?ta.EeP..^.UQ...B..).AD]........@.A...f...DR..T;=g<.....Z.<..}..;.?.po..4.5V....@..\.@...W.....C...q..C....j.o....4E..@5..8BS........n.d,.F.o.).%....;. ..9.Lg...w.........D.c@..k.'.b.OC.*@?d...?.2.h8.Ls. ..44.....q...Y...g?+\......k.L*.1...v...V1V....n....26..m..Z...\~.....>._.o3.lY...:.........3u5.w..E?.=.b..c.G....+. .........?'a.[e.K..0J.N7s..@....:M..~..:s.L...6hi..y.&G5....%.^_.........~..i...8..np.2............:.I\z....-...wb......e.g8.L.&X....3.....`.1~.n.......3.z..Xlj...r{ ....F..>....:..i. o.g6nTh.Yk......K.,;.......3o'...&....J...q..W2WVq........G.-h....@...I.....}.2.J....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):203
                                                              Entropy (8bit):6.132488327722438
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwCBxtlHFaOFowGsmTXXx/T30qbs8E:6v/lhPZi+aWdKc6hFzFo7DxT3RcSgVp
                                                              MD5:129CCB5B1D1D906A66C7C0C4D35517BC
                                                              SHA1:33F1CFCCC64217965726C9640BC5FAACA2D348AC
                                                              SHA-256:8F31881D29D52A152B6EE3C0064A8C75230EA1876FA1EC9B985616368BBAFBD0
                                                              SHA-512:F201A4C7D4B06674198DFDEB24DFBBC29F39EC2334B1C262BB8E441699BEAA49DA7F516F5D4D126F5CED9D9BCD51CBE8FDCD5F45ABFEB505469798E10BE1F937
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....XIDATH.c`...?.....wC.... ....a.:.......k$E..YDG..h4..T....@.Ql.........`....`p..=....m......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):535
                                                              Entropy (8bit):7.395960654127153
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZxdvAtmfpvNuahkzDGgFrKMM0opm9tL:HaEmfjuahkzKgFlM0oGtL
                                                              MD5:16149E4A047174835D6EF72F90E6F1F4
                                                              SHA1:90908C54F4579BA54E0AA839690A4B69A1EA569E
                                                              SHA-256:467EF6BDD23C2F8BD253468AEA3A711C2FC99B5DD4B4E48F5DC3C52F2201A01C
                                                              SHA-512:3543EEA908DC3BBBD4D94D6F8607867D377D2E4FB6794427F1F9B7EAA6485A119C793200556107613CFB3C1CC5477DAD5A58A994075A4A7D7C410E508CEC97D5
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..V1K.@........M.."$C.7\\..T...J)...Apu.....D...B...V.5_.wI.f...#...}w..V...;...t.....tr.a.X..j..%I.*..9.~h..aa........(....9.J...|........>..H0.-..q.J....L...1..<O^.w...k.F.8..i....1.E....A..9..IQ.K|<&>..[..X].1V.!Q....(..f.!.v:.....y.0..&...v.XP....<.....]......)...b........x.N/-..'....)QS..D...KTK..mz.tv./5....A.}.W.-...&Z.H...d0...+.,F..8.s..vmY...m...5H.m..W.kabM.\8B..n4ARue..7$j.....'...^..!Q.`/.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1065
                                                              Entropy (8bit):7.768185648410783
                                                              Encrypted:false
                                                              SSDEEP:24:HaTIObTYIO9jPpiEfYGMxIlnDIi4eYgQeAEhFBFtcOYGnE:6sBPRrMKlDIi4eN1Ljrc/GE
                                                              MD5:049193D11682B9BCB4882E04BAD6F212
                                                              SHA1:CD9F3607EAD93D5ACF81A6E23C0BBF437C530CC0
                                                              SHA-256:C74503CB1AEEDA2220C8ACE2AC7C917E30E1AB1C1E981947794AD787ADD82772
                                                              SHA-512:4F65F49EAA3F41493D54BE9C3D5B7F526651D253A014D314A507AD3E696B83AFA8540BB25CA589432DCE8CFFEDDCA82001365EF54ECB12D18A375094962B7223
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..mH.Q....S3_.l.\j......P...b."#(t.....iTT..F..0#...B...........4gc....|!.......$..v..}v..s./.......l.g...mjj.6./.6.h.m...u.j....DN....h..E......,.'.......r...N...KL.......A....&!..EE4........*.DGG.3.L.pn.MR.V...#...q.2.FFR..-.....L.O..G..sS.=...t]...uu./.vA#J...4.1.i.ng..|>_.1.....z.Z2.,.yma!.''.b.........V....7.mh.F......>;['d.....h8..X..,...+.P\......a..h4....N...q....G].*.9...n....~......j.2.(.......4..F... ..O.@..KX........!...?>N...k6._....D..<....;:&....7..m%.....b...E%%%$.JY F@.......x5Dx.4.......3.....o4..`zz...^ef.SS..0....r....lqp..fcb.|....V..+)).uZ..s?....7...@<...{...'.w.......O....._..dwg'96n..F...[.q..ms3..y`......H8q<%...#l...!zS\.s..m4.j.J...\0.G~l.....N'e..u.ju..-j...S,.P2.0...\.;..*..L1.....6lX.R.....\..I.Z=..9.".y.}..x...yy...._/).k`..XIx.:.....@.Q*#...}.p..S......;rs.x......GkkkY/....h.[........Aw.w.Y./#..x....t$....e2.U.\.......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1603
                                                              Entropy (8bit):7.8374788195207925
                                                              Encrypted:false
                                                              SSDEEP:24:Hanmr6UUQKuz/1J5CSXQaaJg7Srd9cx6PTIzYvajb1WYsBiH9gJnlgrNc:6n2WvurT5CbJg76lIz1hsBixi
                                                              MD5:7560F5AD9F56DAB28A0069979FA6A9F1
                                                              SHA1:7B152D8DB21EF7ADCE36175DE6136F830EF4652D
                                                              SHA-256:7B0E09520B108A41DBFB762A89E1B6E9C1614C3A33D9FFBADD9FD099FE4B8AE6
                                                              SHA-512:DB4029E07C4694FEE6BEC99E2672288F5D532281ACF05230E9DF95D6F988FFA2C4561D5F5741004FB640E412E40C3030584907114E74391DCCDC67D4AD613A32
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..yL.W...3.;..^,...(P.D.@Q.........U..1ib..l.x.......I56..6...bS(..R.@@Q...PaQ...{.f9.B../..M.N...~......).).$.....4.fQ..5Z.^.l..2.RyT..."C;...d..SR...sWK.....7..;e"..I.4.)M.V/A..,.Z...f6[...."-#S.....aS..p.9..^..G..fd-V....Z[..E.......F#.5=FJN.......1q......L....L#c....P.SQ....../6...9..3.@`.+sj4..~....C.8.1..'..]=....W.L.!zh,..{.m..v.c..H.k:`6G....t.L*s.!_.4b#a...]..3h.{f.@|..r.qD.E.....I..d...*.g%......TJ..FSI.........#5.(h...S[.<..@Wm...DuP$.#.C.............\...q.Qr.._9..?........m.....t.....6....1 .C..B.#.<.y|..:..<...o0?..V[H.......W.:.I.z......).M.Q..1....$|@._.(t.+....Y...T...R......+E../..FO...N..7.@"..71..U......*.0.... .8v......&.|.D.@{o....gK.v..s.*.mkclu.v..A..U500..7.....DQ.....%.m.....,.f..!!.W..i....9CD.A`(.h.#...Y.V.f.}..q..b...(.OJ...,..v..__S..E#.9..E...pr.. ..2mX.eI..BI@....k...f..t..I..%..<...a..B.....M....)..4R=..A x...p...OY
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1172
                                                              Entropy (8bit):7.759849502368421
                                                              Encrypted:false
                                                              SSDEEP:24:HasxqeyakJTQ4z4HvEEgNzUWnaZL88SYt2Ro8vCSjf3HU2j6VqGqwnDHT:6sxREmpgxU568SYt2pv30YFGqwDHT
                                                              MD5:3409761C84ED977BAA6BEEB20B5F585E
                                                              SHA1:16ACC8A18196DBDBDFBE54C387FBA77CA11D2F26
                                                              SHA-256:778B48EBEAD8CCC45F3B5ACE0D1F8787483A7945C6B3036E6D3039912BA0FD9E
                                                              SHA-512:51F4F68F881D593252F3786091864C84F9F0F1CC3E991A0F442012BA93D734D90DCC80244A82129ADDED38DCB1D1469DBFA0547FBD3D51B94FCDD8BBB4DD2374
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....!IDATH..Ol.d...'-l.6Z"4.$.j...+E*-;..[....\...... ..&@.S.q...!.....':q....l...m.m..Kb;q..;)...O.d..Ez.:R.{........Z....^|8N.H.sjul..HI6RE"...yT..._......rOOL9..N.(.......).j.]_<=...Q.....w.....nd|...Y.k.Y.@......Hdr..2..k@..].K...%..Q...m|..dSS.......E.`+...~D......Nme...Q.O..F.b.!X]....)8..Z.*...S.A...o.j.....g.|.9g..Z.....Ck.2.....$.b..E&(.p!.&.z...746.%.8..H..0.-...w..J^............+G.0}..SC}.z......>1.."I.J.....d.PJ..x,&...y.vL]rLs....S]V..{.;..X...tQ)...0.]H......X<...1\...........<Q..Uo.<..0....6..a..`.hd~'..-.`..E....b......NO.U...........,.XO.. s..n...>Z...(..,0Y5t.>.._GgG...7..|hP....0..........F.o...O.4.D._..z..k....'.'p"2."lY`2.,...sN...8&.9?..-O2.........4P.pv.d>..>]...?...|r_3,"..SQP.V..r.\.*..;.....c..X.b]........F.25.(.\`...h".fg....O.......0w.!.B.k65.e.F...?[..W!.u.k.J..R..nF#rX4.....Bt0^..._apt...k.."g.....7..............]..9..z.ob(%. ..]G&
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1145
                                                              Entropy (8bit):7.791035376643333
                                                              Encrypted:false
                                                              SSDEEP:24:HaxSAAS6+xnFi/WpCsW6SanVgXYOY3GHXbc/MrZ9:6xSe6+zi0W6S8VgIO4Mj
                                                              MD5:E662D82DD26AAA00CAB3D4F7AE5208F6
                                                              SHA1:6C6CEA9F1C501676F59E7D3CECC68B1195145255
                                                              SHA-256:D9F1B9C4B76E96097C7DF727279ECCCF336A5F256B12A11504EBA21538651AF4
                                                              SHA-512:C5DEEDAF9D8211A3CFFA3D96F383F6E53787F370C2EDABC19CCC5C00074B9918D87A4B3C49A124F56936F002C9495EB5CCD538F224DAEC276EBEF8565A5FD27B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.Vmh[U.~...I..%I...\....6['..@....aQ...CA.!."...V.....C...S.v.K1esS.X.Y:.6]]u.i.....k.fY....p.9..<.}...X..).....j'`e...om$.c....NvC-Ol...e`...s.M.A..$In.i:.......fRJ..h...,........qI....w..1k.X."[.....S..-.A...*.....V.P.F.c......*.50.H..?.8....+.%-.!cB...JkZ.B...d.6B...@.G...Y3...FbZ..^yY...'...1..<\r.......L..}....%..5.X...M../..<..9.8..a..'..|{..G./N...<...y..w=.)$...'..i.4_}k.Uo......E.S....@...9....H..^7.L].C...`.9....s.{.z-rK.au....E....QY6.J...3....{...S..8...._q...?.h..D...F.&.....l"M...dY..X....._._.&....f.u..M.S.Z...Y....R.Y'...]..;.....H...._....!."7.U..h...x."....8GB2.[.]$.>0IN...g.Mj.4...6.o.$.-*v..>..1U...aY.S.Wo.`C...U..|.D.y...a[to.:./..@ht$.].j.p.._.l......S...O.y..N..#}........-*zU...<%.[.'gw<.1.=..N....bX...../....:...d.3{.k*.;...'4<..8..2...U....h.... ...w.*b[h..].....'...WJ....2t. ..Mc...c..7I.....}...}....Mf."..4...Oz~.^
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1146
                                                              Entropy (8bit):7.786476294904737
                                                              Encrypted:false
                                                              SSDEEP:24:HahONJzBpQKhXBe1Opt5OdRTlxQFU19tIQf5cEz6n8O7HsZfUR2J:6hONVJhXBe1OpzOnlxQubqQf5cEz/OdI
                                                              MD5:3E78D4E415FF7A9F0AF99EED77C886D3
                                                              SHA1:7C6538ED3906C20C35944AEF525F3A737A97990F
                                                              SHA-256:3397B359E80B5B0B8ABC32F597747E396285B85248A47E7DAB205546DCF8AF63
                                                              SHA-512:3A6F2C5D0B44F1A1BDA60B0106B59536AFD653605E65374FC35F82A9BC59B3C198F1E78D59528A455C741A450152AAA537CD4DF1137A7D9AD3B16FC84E52D4B9
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kL.U..[.-...\[...e.e.,~.h.u.OK...-q.Q.....L..b........3......na.c.]+...Ba@e@y..<>..Y.F.*o.KOO....s..D...."G...d......#-g._.q!...F.P*..,...8~..0OV.I....).a.1.vl.........Fl.|..~g.t....\5RD......s(......3..U..W6..qd=.._v..8$)|....Z..\..j.n.....n.Xd....yO..X.;W%#....5.....-2v.....8..]...A..4z.tc.$..\.i.W...]GC.......FB..l.>.b C........2`2l...m#.{vo...3.q\..6u^..z....;.|...=......'j.8#......J .U1q...........3.......z]Fh.[s..m..$.}.)@Sp.F.|.eB|*......H.....P.3...K.\...o..~g.<.....\.x.S..uE.\........r.Y.$...P#o...!..%!..8O....t.U..t!l.....i......_.....L.>....`k:..%..Ov...Z...\J..$...9..e....R.r...W<).2l\...;Fl..A...1.X#L.'.[r&M7Z..[8..].M.Ha...\..."..T.rz.1&.....\x.^...&.........0.k^g...M.,.7.2.^..t.B.*..6...F;4... cZ.[.....1/..+..j.T.?4.....O..L..[R.......9..n.a....8S);.Zx.R...7...CSM24...ok..\D.@.@.o./.....lI..y.#...#..X..f#.......R.T..s...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):729
                                                              Entropy (8bit):7.6074646615829895
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZXu23k9jSQQZZnahvkIil5AsHLQqYiBNvbvniGCjvKMNqRc:HaVk9jm7wkNtM1inbvn9CjvKrc
                                                              MD5:EE92DF969C9E766AE6B7095CF45016E6
                                                              SHA1:4A0EA1E27D423F0944E0544BFAFAF1C58223FF36
                                                              SHA-256:75DD178B98DFF7A3410DD33653A7D7F50EDE2AA0A8D818C9B7FF1E6862532880
                                                              SHA-512:309B3D836776BEC778D5B8183AE4AF4292BD6F34B39B28493D2860EF21C48333CC7BD91C63CF0E072E6CE1FE3AA06A943B247A82DE7E87951C03AD886ECA7082
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH..Mh.Q..7j..V..n.C(..A..A.. .B.P.... ^.oJ...x.<x.bE.C...B..c........~E.;.6%..i'....M)}.c73....{...=|`......W.A......ka.~..T.=.]...<.../.V(. .(..w...va#t..-(A..n.&p..'......*...3+p..(iC..a.V.*`2b..}....A...ZA.A.V.E......C.{l.mU..+...A.r..e.h4........4|.....)......a....0..X..y..7.. Ej....S|.8..(......64.!..........$..9N...>.k....|.y_..J.fm..a...CS.f..Ip35.$....o;1.h..<...C.......x.8.....A5..G..=...[...^Wr9 C.Y...Q1r6....5i....i..=..x.3..a..*..D.^?|.Z....>Y1..0.*L .....9l......oc.-.;..4....:.J..<.i+...r.(j=WI-.O....."d...U..|.....\g5{...Y.6..fM2....l....._...$O....u.>..g.d`I../j...I.%.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):657
                                                              Entropy (8bit):7.3841004819796785
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZmosqrw3azT35SBMfWNeoe1s3n2EbYZWZca65WAV3K1SbET6:HaRUIT3gB4WNiwn2/adOK56
                                                              MD5:3839890848A28DE380925E6117CF6FB3
                                                              SHA1:4A8C8A8BF05F0A31F081EB06985A35F0596DE671
                                                              SHA-256:569F9EEBC1EA3954DAAC7538BFAE25F4F72A9E08570A315F5A35C8BA787BF62D
                                                              SHA-512:E75319508C5A753C47DD6E470B199F2935E3178F9722D90C51D9C40AEA319E4AA4290A4592C70E4C8C7F423D3E69864B6BD3F48AE360E04C3B8C953F16BE870A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..;...UT..iG...P_6........?..#P.c ..Tt...IIq..}....%.\..U..@.p8..(.~]CC.&..1L/......TU..,....pH+T.i$..d..45%14.m..*......16f.....tOQQ..w:.^..\.Y0..h..]X.8!....P..A.....a....A.w...... .......w..bs {.8U......M55i....u......lw(}|.........z..A...;(.af1...]+.u.K.&..k../H.r.h134Y...&.....22.@./.?....%y........i.......H..b-...P.FB.....1.....}P.. ..u,j.@.,..mh. ...zE.Y...$.@q.%.@..@}...[....c.t7..yA..UT.......~B.rr....H..7..X...0bt....2.6.....-....@.....l>..7`.S.dAc}=... ...C.. ..a...4.....4..X=......4.1..K..<...-...3N.5o%H....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):611
                                                              Entropy (8bit):7.4810435786950755
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZS7OvVSDolpVJKP/AUCufiWxhcT07r7IuwI3EZPLmDZG9EAlr422/N:HaM7OtSDOtUCuf1F7r7If6EviYEJ1
                                                              MD5:446A65D381142D651DE4D85B98962228
                                                              SHA1:9431379015F8E4D25B34431559D031138459FFA0
                                                              SHA-256:8901F209566425BC26486B34A71BAC3A6DE7F5FE2551350A8926F3009CA18D4A
                                                              SHA-512:C90DE1A23E28A7B23A57BB09F1D447529A1C4DCB162300F9FF71A6C4EEB2BB611786CFB7410589D000C6F45D9A8E74D2791B8F2C4C209C7F0C4B45B2F2473C4A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..T=O.A..X..v&.X....1.....Z.hb.....?..#PQ..J....h..&.Y.u.w....B.z....}3;..8...}..6.[6q...*x...DbS8.U......;..*G{)..Jv.*.Q.o...E..S.D...6.j..R..a$...z_....39(.A....^.x.n.`..'B....l....=.J.ym..hv.].u.#.pdg..27..dXtL.Z....=..x......F|h....B.E.p....-.m..E`m.P..v....59m.i.3AiEz9.u.+.:*..........oi..)...7...tNC/.Z.-..Ki..E.......(.g.Pb.L..u.P..S,...o...u....3.s.L.I...90.P..r...>.....y.Xu...........|...6..1.4......G.G...XuhsK%..:....Z..H......8.gq.........4..P...C.M:.,.y...>...F.T.k.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):300
                                                              Entropy (8bit):6.84897701377742
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcjAspigL9DyOwMrt1XvS2BFp:6v/7saZbigL9mOwMrt1XvnN
                                                              MD5:8D3BC3537980CA5185E0D68D64928E98
                                                              SHA1:F43275DC6C7BB095B9FBA2778C811B57CE770978
                                                              SHA-256:54D4423340634D65355A24450AD7A19E30986FF78B573F06F19F2BDCDB19AB07
                                                              SHA-512:F763C222CCA9459B55B0C22623F5EEE4B158389B7F09802A22886B26FCB31B3EAE8EF82F6D39F32DCE4FBC39E2633A3CACA5B2D92E8CCEEA29035F8E2794A13F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH....0...Qh`....... ......Cr.].....$K."......&.@.Z{....V..8.......d.......=o..=m^.!.,C.$XG..m..@./K..@...w'../.4..p.Ui..[DQ(.nYt...;.]..O.g..OpE........\..z.Sx.....j...3..Q..v.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):321
                                                              Entropy (8bit):6.8471270857138125
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1QeDn0HgLpmqvRXZcl2IQDREfpiPJZTp:6v/7saZK80HWpRRX62IcEfpS
                                                              MD5:42D102E2CFF494EB1AD7577BC251069C
                                                              SHA1:CDC8B8F5E65833EB29A5B09D150D2E8047861C70
                                                              SHA-256:7FA8044E5EC834405079D11D691B21872106C818A2A7168374CE7B1362FB2807
                                                              SHA-512:FB67B5CB9F24A097BE0FBB398CF400610EE17C4177800D4DCC57C3A1B803AD6DDFCF9F498E3A65B77AE15261488F8947E49A58A603ACB36C7E1C81E92C526D15
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.....0.E?t.L..@O....0C.0...)J...7X.!R.o;EJI.LY.....).....8....=.F.....L8..&.j...lB...2.>^....`..."..<.aA......2..U... M....B=..]n......z.zA3Y.7......M....2....{3.........NS..z.z^L}p......d7`.o.......d.]....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):676
                                                              Entropy (8bit):7.465661084230229
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZFUUHQGg1dXDBnfQjf7RZukye9okjTXrbtnnE6IDlPCItVAbh1BcHpgXc:NKavUPjdXV26kPokj7tnE6kl6qAbmgHM
                                                              MD5:9110D5D31B11E86091029E3121532EE7
                                                              SHA1:A4B0AABFBCCDAA7BF3FFFE045F75B57C3EF0BEB8
                                                              SHA-256:85646D81C6D18B8B200D29F851FF5A42723E6E742FB02BF55A35D8CB28D00D49
                                                              SHA-512:27A79395BD62293FE8C29988A010E64C8AB0CE35FC4DE76FB188920AE929A3EE5759AA3C1FCD76713C1F182F029D22CC1EF405BF5522B546CF28E8DECB983B83
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....1IDAT8.U1..P...6*...Z. .V..+.i..A{..k..U.b.w....KK..ll,.]..7..,)..Z.......M`..0o.7......:.%.....A......r..OD.#'.$. A.n1.T.....8....WDp..Yn...G.f..(j.3......t35.o3...*.........G.Wt<....v;.....&.f.A..|~..!.|>#.p8(..,..N.#.&.....1.(*...}.U*.r."-N..5bf.....r.A.LFI..`..f..(v>.G.M..oW#..h..R..x.P(. ....p...r.D.^.#.d.>.v..j.:..b....y.V.U.j..h40b2..#'..j......88...T*.ix: *.......r.9.s:.._,.....ba0.4...h.H...J..G.Qx...b.V.t:..^...jz...... .......n...m.... .......)...B....4....C.0..v...)........db.Z1..L.D>./.H@........~?t.......p8....r..l..v./.R_.;.....>.vN....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1239
                                                              Entropy (8bit):7.791857072030138
                                                              Encrypted:false
                                                              SSDEEP:24:HaSf2A5cmSStzzvHYCejTdxf61d6nzTkPeB0LlAr546di3m6:6SPQSt//Y/TXy1wzuy546Q3N
                                                              MD5:9DD2B2C779C67620E09F358C9013469F
                                                              SHA1:4A8AE8D6A857D6EA61DC03A464A303BFD1ED7B7B
                                                              SHA-256:CD1E9036A086270948F9D3F9081F40FB887327DCEE78811C4323C47AB5636E47
                                                              SHA-512:CF964CD583CEB87DC74EB1B94CE4DE837898454FCA5C0725A229A2A947E44DFEA089814AF16171F045719FB80F8FF0AE44ED56D23D2886FD35628D8FE4621FB9
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....dIDATH..klSe......a..vcc.v.....j.Q...t.*......11&...cP"!....jH.8.>..).....}..^..6.zY.9...................-f..:.MG...$.C.P..8.Y3...SArk=..`^...>L.J$...w..r.F.X..id..9...C<.4o...*$o%..'B@]...hW.....u........,c.U....]ql. .h....mh...\^.TZ..W.\U.6[n.r....C._....M.Vo.w....f.n.2...8:b..!,......T|..9..8&7Y..P...j..7.....K..R..G.xNr!i......#.Cd..HE...f..d@4Bf..TV%1....l...v...$(....7A..T..v.1..e.g0..N...B...<..4.*...(Z.....w...j#..AWO.....=.....qb.{\....Ea.....T........tV8).ao.z...gv....!.u.(=..;_ngT.8..>F.D_$.xD8....E.KJIb.P...IX.4.fG.8j.....-.Z...q....&..h.U..Xdj.z..r.Q8-....%#T...>..dV.._..G.V......b5.;+o..Y.S.=g.@4L...(.C..H.$...q+)$..v...;..3,f.j.B.nW...CA........p......x.4.=.....Ql.....Q|\.5..CW9.@...#...3Y.=.['..h..,.G+^LK.......yf.z...{`....S..np:...D...._ci.Y...3..Y.#....E>....#,..OL.....$..r..p..<G.1..~.......\..*\.(q..UX...2.e~.........n\.]...~d
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):450
                                                              Entropy (8bit):7.086382681459327
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcUiFyieEOjyFwcSkjjKUIHP4CgrxdHlvYrEqxOpsNC5vj5cxvM/:6v/7saZUiZOjewcSF7eHlgrF2sc59qq
                                                              MD5:626A62A06E8C84FB936F6FCCD0869041
                                                              SHA1:56CF9A1717E96BB7B13B40F1D6F7B89F61FFF124
                                                              SHA-256:CA2AE75215EC1F095A89A7EF480E43E3742979745CBD80C703FF0A884F6EC98E
                                                              SHA-512:46AF61687CA4A1B579842403EC07AACACF490BAAB2B2606C567DF2E404103AA82DB81BE7956F1288D5719C85BCF075FA531CEACE8300B9B0401ED636A30CDFA8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....OIDATH.c` .X.....1P.....$.....ex...)P..... ...|.....O....3#.;../ .....x7....4.....\.....EHq...0...@|..9p......A3.......&..u."4.L@........b....G...TAm.D....b.J#...?..<$.-@...W..z..7..F.. n....**.i..g...,..Z....82.'..`h..*..........;./..@\H.'.$..U.R`&._.....$....(....b.&r...X)E..P...r(.A.9..A..@...)q>._.V`..x!.-...}@....C............IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):733
                                                              Entropy (8bit):7.456549392815813
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZZkEWt+itIBlmYb15aU+kJVRg8iYuhZvCbbpVYNC3ZGT9GomlpYAz:Ha4Ew+WIB3CvkfRg8RuhZv3NUMT9Gokz
                                                              MD5:F5C451948DF5F40E9A1E74FA9FC920E0
                                                              SHA1:C5AAD00CDD801CD135794DC071CF4D8C98E7CBCD
                                                              SHA-256:ABC7842FFAB37A074EAE9C71292E0DABA4CDEFC3027F3463BDBB5B814091FCFF
                                                              SHA-512:15AD40EBF32CB3CB43741DACF78B24BFACAEBC0B78370DEE55F3BE8F970B08EACB6981CCA3817A92AD7EE060BBC61299E71B1B136D4D2F1511F992E9DC1918A0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....jIDATH.c`..`.bF0.J.......o...;.q...C.'/...^..l..o...~A.-h...$Xb........*...../.5..[..._........ KPt....mg..Y...+;.....W]l...l.......<..?...?.?.y.. ..(+..-.".R.n._.....p....]S..............+(..0....Kl...p..Yf."...'8u...Zt..l8.8.....jx....%...k...E<^.A...-U.nb...A...h._R..=4u.. ...#.,......'.....?.I.0....dZ..@..."......y..@../X...,.5......w..<......6..>.[ I%.4b..H-`.....E..@.... ...........X. .-..{u.8....a...V..L..F_.=X..y{..I.9...bK......*.K...Z..[@iw..@Ek.....'........1a.,.=p..............[\...u._....T...h.......q.. .z...?...[....P...6b.%T.>..Eh.6 ...g.U. K@>.....H.F..I.."..`|FR. ...X.~.a.Q....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):642
                                                              Entropy (8bit):7.341688074420382
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZp5AMieRoKdKnv0hPro7NVLIpCpsWksLss2k44hUH0hCZEP:Ha35iUuakBVL+YsWkHk44heEoi
                                                              MD5:619371FA5791AFD73C6F551CAC8283F3
                                                              SHA1:A03F3CBA0392B61AF93C90160312CB71D3A55AD2
                                                              SHA-256:3EDF4E0C4FA01F7867B1CE37BC800094364B376BCBAEC46D5DE401448D6CCDAC
                                                              SHA-512:86B33F6A4644E5E52E4AAE4261344ABCE70EC5BB79AA83D70389852C31F6682549106142D9049309E59BCEF88EEF1CEF55A975F1599545BFCCE1FE5F732BC880
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.L........RSs.a.YpSMM..if..e.....yVD.c.bsR.wedd..%.W.0.0+T.#...d.d.i...LD.".......2.3..7..9.........YX.......a.......`,%%._NN........JJJ..u..M.T._\R...H..311er.|......K..k6y..}.....E..*...r..MW'._{....s...........1....[.o.6.....\.l_.X..Q.gac...b...P...........b.......[........a...G..>...}....IGR......s..5..?. .W.v.Rd..8.X.6........6...k..Wmq._.. ..\.....&...F.9xX..-(F.%.Vv...e:...B,.YD.........j.c.`..4.gd.r2...Q..MEDa&f...a.?Az.|]B.U.....T31..+H-;..y -FlFc..EX,X..X,X....fF.W8.....iY\..0.*.UUo........#.*Cw,....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):619
                                                              Entropy (8bit):7.376649917179011
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZtFfo73Shm+OIlZ3EGgweW89YaMFWjCCt6S+9P0I0b/sF/WL:Hahfo73ShAID3EGeya0kSTB0IeA/WL
                                                              MD5:B0C092A6869976A6147F2AA15FC599B4
                                                              SHA1:98043849EB34E44286E0BF55B319FEE950FBB954
                                                              SHA-256:4BB6A2754559F012447A689DDAF91D9CDDC5CCCC679101D6663D78089C275E72
                                                              SHA-512:C2B95EBED1782B87DA6A697458A555E9BE99151EC336ED1BB290486BB264C70CD48B7B718A04BB7699A7793DE26BEF13AA3D52857DBB66F245C2ADE9974F0678
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.L.........V.{q.|..b....Am.X9.?....?yg..N>......2\....Y......o..'.......<,_...B)5.....bx..mWg.o....f.+..M..........\...x......-^..../_...r....8##.7 mE.7....O<...oo....n.k...,........B..%g......_........_~......[....e.../=W..q.7...VQ9....\n..I.QV........h......T..i....>PB`..........3.h.............`...n.! ((......O...D.......}....n?.[...U...O;...i./.-.......'.J._..j....II............)'...PydIva./.s).....;K.w..._...\.%M0........./.l.5..._.....$sXq.F..........[....W81..23.d.O...4=".......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):710
                                                              Entropy (8bit):7.545466302392075
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZdb9L6TsbsER0jpA0j902vsvY7J++9qfFcrinPL7ECr/XdIPLdJT4GKN+z:Ha7bJ6TQhRqpN02v+CqXECcL/KI
                                                              MD5:C6CC59A8EF2467937B0114EA55169E23
                                                              SHA1:EDF4A73A805440E7CF507EA4C88571D38C8A1558
                                                              SHA-256:14AF05E8ED91A7B4711A008B10EAF8EAC01A225E7D05E01BBFB92DBE97197B30
                                                              SHA-512:47375EDD11A410203CEB8394F7298F7EE4CF64BE8C9531B13ABF6C260E38B15163CF614023D9E569D1D522A40EAC283D62D9328BC58AE0C4B08360946E1C37A3
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....SIDATH.c`....H..b>.....V.^.?'/.S ....[302...V..f!..._B-.Y....g9'../_..?y...^..;Py. f%..f1........D9..........p.=0.X.s.`fa<.+.~.........j.O.5._...l8.Wmq....;_..4(.r......X...^......R..b0:.Y.%....>...}JF...Y...../.....9'..5..=.4..r0..e. ..K...._b.?s....N....\.....eAH.>(..".....H.f.- ....ek..2..}..A.t2013-..g;....RH.....Ym.. ..lw%.@d.......@..A.,.Y "..B@......m.?.`..F..K.,@."aX..q.vJT.H.D.Q!4.p.. n.R........,..1..@Wq..cM\$W.#y..d.h .....<8.. ).f.O. ...h2....h.....(*.1..lhQ.N.....E.).Xr.C/.8x.../..Ff..|"...-.`.5...v..<..?...m........Q.....bZT...$.......~...4.Z...H...............IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):734
                                                              Entropy (8bit):7.4827952110986455
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZNWACAKm/wJxEpNGQfN52iJOLGAfrTKLXJAsarm7GhWlYZF/aBif2SWJir:HaQEJHHD2iUVDKXx7GhWlYZWiuWr
                                                              MD5:3DB9E120D3C9888216166548D55C208C
                                                              SHA1:C3CDAE75FFE01A3512D8F916B4F88AA5DC43A082
                                                              SHA-256:06C3F27AFA7BF8DE5F2D62E3FD29A5796FD378CC3FF40D4066325B4AF7E6A8EB
                                                              SHA-512:1A33F8B5D6FA88CFCF9BE25206844D040F28827C4542DA49D68EA43DEC559438476E8D007E33228A0A6371732D561E2B414FB28E5A0BA84B6BE8009C83995C49
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....kIDATH.c`fa.......j6....>..C-.XPXP.....`......8//.....[....A..l.H...q.ow6#..n..+!...E..`Aj...**.o..@,..~[W.,v+)...L......b...."m.[_....v..b...8.Y...1..uu..S..P..\..ZZ.ou4Q...0..0..-.YBQ...L..h...V_....81...%..\..o~......Vv..[...d..$3..|..*.- ..........x..&9..X@...O.....`.E...+.|...&]\..d.6.<........:x......'U.}.-8p........^{..........n.'.... _....xA.x...Y.9.o........@C[.QC..e.b.v...@~{D.8....>CR........`..:....q|z....qV. ... ......V.......W.... !.f/.r........l`6..`..c..z."........fdd.........V....!..>@X.QX...ykv.....k.HH....G...9..b...X}.......3..........7.....M.. .z....../"&....`.....Z.....>.......lR.^.5......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):698
                                                              Entropy (8bit):7.518126295736683
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZd2dC4t4nyJ689VSwgT0w6sKj18zdZuYjCmu1glZzS7WItrOEp/pCRIvDV:Haf2A4inW94wFw6sKj2zpzS7WIZOEpxt
                                                              MD5:40F667F7B35CCEFD634C3E0153161E23
                                                              SHA1:9EE4D3791AB5821D8D88EDC9AF4A8FC3A6FAD6B4
                                                              SHA-256:92194B6A74270A2AB89B27C4E49AF9266E3CBAB1AE97A4446ED62575A0F5A8C9
                                                              SHA-512:5D7706958A75D44744DDD1347C9C1805DE15C57A116DDC7CE243764036F94A09D9DBA3A6226C08DF8A4627C0D1D59E2B6E1D9E3241DD93507EB60BB52FFB6879
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....GIDATH.c`..`fcZ...z...c..X..*._P.....@m..,D..M...j&.....,.Ls.8.......T...p..S.....q?P....y...$..v.-.7.3..'.../Y....l....)..A.e...............i; N..).?.6R...vW......?b-.U0..'...E.P.?'/.I>..k.k.q....=...%8..2...;y..?...j....E..]R........311-G7...3.A0.H7..".W.....4....... ..t....E9.Z...T..../.?..d.+7.....~..?,.........D..Y.(...0.z.+AK"...CC./`.b.n..w.S-..2._..(C.%dA.L...|...T./....h.q>Q..@~.0%.+^....D......\..x...x.db.....+.....O./Pe,.9.....;'....Ob..$iN4.o...t9.;.S...$...q.......[.\......M...G..n@...~1._@...+.`...$..E.] W...e....S.C.....wC.A4..P....dL.8....p.h...##]f;fw.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):398
                                                              Entropy (8bit):7.029883007598753
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcJmNmWnKItdok+1KByv1EkibfnaGkWv14FZDUJOicp:6v/7saZ4Nmkogyv1Ekib9kk1UD7iO
                                                              MD5:EB772D82CE1BA7AAD6D67A62D7883681
                                                              SHA1:319BD07610C4B2E7643C8EE00F6154F76FF08433
                                                              SHA-256:B714CFA1940D423CFBF61700CB440CEC3995FA97FF652BCDA7845EFFB94A93E1
                                                              SHA-512:5155A677B5FC067E6A66B43D18DDE1348EC7C7EAD7FD73AC2EABDDB0C086BAAB566B5678471071ED4F59A2FA02FA26E785DF52C2DED63893C08394E0FDC454AA
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.....0..#..+.,.......3.,.........5\..m(w.....k.Z`.m..0j$.._`........?9.#.!.Y.?^B. ~.@..PU"....|.Q......].s4\"."...S.m}...s...:W.y..;.........nS>.h....S....$..zE;./.Ig...h.@....y.45:.s..{..B.{..S..`..e9?..~.i.......$.)Z"<].s..8...".%#.h|..../p."...\....X.....kE...../.w.k...[....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):829
                                                              Entropy (8bit):7.632884519003374
                                                              Encrypted:false
                                                              SSDEEP:24:taR+f+NQzi51Chwe39FhvY3DcWWsY/tUnSxGGNYTqlz:wR+f+yz7wSnhwI+Sz
                                                              MD5:4BC18ECA2E9BDBEE05261132C2CDB835
                                                              SHA1:6CF8D44DD883763B6C7206F95484649FB2D512C7
                                                              SHA-256:CEBD547D1FBC6610732A168612A2B30EB14B724F5CB99EAF26DEFA09327C729A
                                                              SHA-512:B290CB4EF896D69AC3A866BE03CAA3F7EE7898FFF8A48903E3AD1CD495FABCDDE98697B6F567A44B534B1B5CC5A860CFBA14FDE0DD0A17BF66DD4980E2080927
                                                              Malicious:false
                                                              Preview:.PNG........IHDR................a....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.uS.k.@.~I&.&..n.............y..._..G.......<....".....E.'.z+.Em...l..$3.d.7)[..G&o..}.{......G.4..0.x,..q..........?.^O.z..i...BNJ! ..h.A......1M..|..2......{N<s..O..k.'.up.U ...RHO.....K.t.../}....l......~...;..:0..N....U....i.`V.YiZ....w.,=yp.r.K.V..k...Y.1....A..0....i@l{.......a.@t.,........i..(..........Z..%g{.g./..Y..1`q... .i.C....G.!K)p.g..!.B...`.r.Q......rL.#T....D.}H."`.!d*...$...9..#.t#...py.BdY.IYV.....@..R..h..."*....A.Gba.0.../.@P0l[..*...".d.t.[.1....'..m...u.2...4K..P...EZ..."........@...#Z_._...<.Q...2...b.U9...b.2x3....Z.Ir...N...=.se.1El....x^.P.).)j...HWJM..1{....._.=...8.nnkR`.Uk.}...5.R..<N....-.3..r.Q.vm.4.s..:...Y.]....q.#...#zA.pT...~..2..........q..2>L.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):615
                                                              Entropy (8bit):7.402133733424993
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZXaQ2wnzyklOWRG1joXT7W9VbC7M7mQlJLIpn5NMCcTD:HawLwneuOn1uWruo7LLYdcTD
                                                              MD5:9E4B760FAA85346B6DA85F8998C25C61
                                                              SHA1:7FF7DC78DFEA140ADB6485D91F53AFB6FD54CF29
                                                              SHA-256:DD74EE139078FD3A9773881E7D724FEB19B30EA1B8AF179E15ADC76B3F27CB86
                                                              SHA-512:2CCB78371580F3758776CAF8A1AE09267BECF3E527CE8918B0A2AFE0D035DAF9F03A0ED29E70FF7EE0525957BA81FEA6B6A75FEC15D12FA1FA65FEC2467DF7EF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`db.......j6...i.i.....u........4..o.~..K.}f...6...........\......O...(g......m[.B,.u......SW<._.....MO..,~@...So...._-...NB/A..=........t",.O.._.#.d...y.........../e.I..KN.....!v.\&_./c.M...N...1...........c...z+........dI...X-.p....5.1-P...j.I.....o`...`..y...^aZ n......8.y(0.`.`..w...j.b..u....x.....>R....8,...[..c.....N.Bp..*lA..=.M..c...;8#y..W..b.....pP....w2..LA.....]F...khWT ....+. .....d.....W\.M.....3.ZP........2..q..........[... l...\t..(..t.F(y.P..u....`[.g.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):613
                                                              Entropy (8bit):7.429512649476687
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZQAbB7f2Fa/Ye0MFrEgGxHLCVvqfCzaZSctfYqeRXYUPIizlz:Haq2B7f6ErEgGB4s2dRXz5
                                                              MD5:2CF489DD7D0B7213732A72A0D11F8C7F
                                                              SHA1:70AB89C395AE94C74C869389C412A65BC35ED7C3
                                                              SHA-256:045EB4C4EE8FDD6688BE60BDA92E5577990E131E9795A4E76AF5C909155F1A6E
                                                              SHA-512:41FDC8C3AAD2DCB9202CB6B7ABB87B21FC3603367B4C373159D29F5073AFC8E143766E1B4BB4715B7C37C903995A31E07257F9121A79206B781FE21309646073
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`db.......j6...i.i.....e.......+y...0../.a.. 6H.8.1X.Y...../m.._.../...1+]C...So..K.._.&.$..:....a..r..W..".....o.u..j!..a...-p.r.A..:...a...`.0,..8...yX.I.R..q...`..y.i.r....j1,.m...b.......u.......$.M..,......m9...'\..'\...... ...T....>...g.....*.|..C. l.....11>K|f...'l.=L........!.N\...tL.=g......V=Q@K0,..w.....Xq.G.C...3n.1H-H.....X|.>.....O..m{F.....;.."f...{_P....._.........daP......Z....%...+.A.6...'}....O.....{.......*....yk...|...U....~.#... .\..H..u2U*}Z7[...[._;.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):594
                                                              Entropy (8bit):7.382412668392323
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZUudAwhObscBhxH6STldk2u3+a+yVaGsfTJmA4wnn28kXb91:HahdThObscBTxkjnbAFfTUA4qbkXbb
                                                              MD5:3274DAF104B51719D762312A2DA79A70
                                                              SHA1:F4C6A2F0E6ED2D91DF4AC8DB0BD722E2D41A5B72
                                                              SHA-256:35DF664A90B9E28A0B37C17B7D34EB2E41E0B29EC42EBA4910EB6DAC2FA2CA4E
                                                              SHA-512:B22420283F5E6A3E5D074CB18DEFF89E5F5D62510954B60292A89827FB2751B51EA266DB563BA8F4005C54558853DD8E0BF36A681B1CD8AA317177325920C7E2
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```.OcL?.p.q.....l.X..~&...9....?#B.(e..l8..@....`zT.....s.=./....#1.?....2o9YX^....b..'+.d]......}...K.=o..%..NV....._...'..$|iwZ(?^...c....2....>.....Pzt.9...$_...8a.f.......X..Z."..f.bX.......?..L.F...l....ll.@I.R.@.PjT...R|<w.'.R....%...sg15........`Xp =2...,..30..bX.l.o.0.....4....eg[.-..i....H.:.4.....\l,....(. 5..gN.Z....x...7...(}.+..;P..*.H2<.......`A.OT}p"7..WS.6.(&..wU.;P...p. ..'..../%.n.(3.S..n/Gp..J..G3.h.@...].&G.......P&..[O.8.2.....i......"}......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):732
                                                              Entropy (8bit):7.433670846967776
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZPW1se1T3/khL3KX6R7t/7FrAH8KSjuTo2We+xd7/:HaHe1T3ch2Y/hXio2W/xd7/
                                                              MD5:1ACD907F486136B766107DC58D825A62
                                                              SHA1:B523F228DE06C410AB6078137B4C941E6E847516
                                                              SHA-256:25FDAE5A43DDB6E954AC9C423F2CA377CDC059091D3905B84DEC7223AF53AD45
                                                              SHA-512:C18058C770E8E6E16A9612A23F1D4DE5E4A4865A1E26DEC41F7B6F100D340237F9BA4137545B81A6EEEA128735F73C9066A505006B6EF32D5CDF9BA4B2023B12
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....iIDATH.c`fa.......j6....>Q...G..m.......{..AlB.....DY.2..............c..3........Z......}C.........,hx........[E.....v.@....d...&... 1./...........~......e.........$@............f .zJ..p.....\$=.q.uF n.....o...RB :...u.k2...9E`.ohi.?.`5......{..2P#6.N.........1"..s...._%.-G...-.....m}`.o...O....c`.?)............A....0WS.....6.d..].2....U...4.6........2..I.".0.....Y@......3...d .. .l8^.....a..u.....D*0.I(a.P.^..0<...1....::....H-......j....... .........^\.5.....Al...G..........tt.._........y...@ldK0,@.sgm...!......>b.0H.....b.4....._....<.......F....._p.....s...QA..W@i.Txy...x.9..B0..5["....*5.-..'.2>[......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):531
                                                              Entropy (8bit):7.374379882795916
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ7eBSKvggc9szTqYqkqUBHMhhdDb/KuaF:HaFISKHdzTJqUBqX/E
                                                              MD5:8C625FB2315C6025BA9D126A8CEA0885
                                                              SHA1:86C2682B9DA5FB996A4784013E60FB86CF4199D2
                                                              SHA-256:8E89A630AFCF89FFB0DCDFA7AD288A5803CEF9CD94888EF75D0701A734C4BD58
                                                              SHA-512:3871FE4B802F5C989EB1C3AF9B3E1E905E64B074C0D02B17E68C7077D4B7D18E0FFC2C3F6D9F78654B6CD957692B5F4D09285505DF39B09036DFC6AC51334D0B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...JBQ..?.&...,B3.z.I..5v...@h.+43.I#/`5.2.)4z...Y.i......`.^...{....0_v..x.z..............`/.1..v.......u..H........c.} ...L7....uq...6....|...{.kY...<.8aY.....v..f.g...CU#\.&.......y..p'....GJV...=a...,1...'..gk.E.g.Y..N4~.x.... .q....Z.o...-.......U...Iav...S3.%....Z..P?w.-..A...~.....b.....:.....^.]'......w`c..f.v[.c..............I.x0>....N....zKR...R.ki.STi.....z.n>..i1w#......H.*....../@,|.........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):641
                                                              Entropy (8bit):7.466226236806226
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ8e1YU3cWe+5IAp2Lzv0qN/pbej1T7M86i/YaVwdwJ:Haaemx+5IApEso/p6jyiXwdy
                                                              MD5:5E03CC16AAEA091DC7885D3D2BB28D62
                                                              SHA1:59DBD9A9255495A2B11324EDB36465F5C36ECB99
                                                              SHA-256:A67EB95B3D5EFCF3836C1D10E3151F9EF773B7334275BD5762AF222B20FF0BBE
                                                              SHA-512:A99DBEBCC3E03E0DF2B3409A40D178DC6AD9BEBA3BACA3DC9F09BC47C3ACD954D1ADD24B99A52059A9947944F5F5C9FFDCF7A55DE942F6698ACED2C6C7B746AC
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` ...q....q8......(.Ci.)S.]..+.}..U.U.`..`Z.- ^.h.....:..V....9XX.x.X..N...4.?..6&......v..<ll.D....>MYH..(....G. ...B..I.........q.@.?%...m!V...r.]s.R....\....n......@.....<0...Pjt%....0#DG..A*Y..&../w"<...|X....Z.,....LY.Af.mX.....Br-.aQ..O@......]j[P.`...W.Y......gX...i.....`...+.}...E6.. ..Y`"'.......dCp2...AM......day.O..b.(.Z.l..~/......k]......R.EV`.vl,,..B._(-...{a-..q....R.....|.................... .r...@^..V.c...Tp.2tGb..~..s.11eR+}^NV..R....`]q.T.,...f.(.Q...30...:F....(-K!.E.8..........V...3.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):634
                                                              Entropy (8bit):7.526327450209149
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZEuKezHzNywoo5tNsLHzkQqWFclJluYuoUv/IqyPp01:HaD/TgGNsL1vcleY7Uyp0
                                                              MD5:FE47A1F7263878951707B5EB502E8CC5
                                                              SHA1:A43BBE234311AB30FBF74EB9A5A1D5A7845E5F87
                                                              SHA-256:1874EBDE17D713FD1855830E3B8A2A403A2D5BD6F5905685D5F710DB03A9C422
                                                              SHA-512:4FE232572D15234F4D858DF1D5F728416131FD868F7A23AD052E64C3C9821E528BBDC94C0352FB7FD1B94D2C923FEA4CD9A6E471670227A6A487841B55B22E69
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V.N.A......E.0xB/B\..,....D.D..F..$.?P...*.5..`.&?..7L.....#.Jz...u..z..../A...Y.1a:3.... +t.q...3IZ..hr.E...$XC.=........t..#..J...l`..]..:\y..AQ......S%...B.^K.I....4..s;.4D.....K...']....>..h..m.._.H..........V+...>.......... .....W7D..I9....MV.N..2]..^x..w.........W.KJ....@...8K%.X.HX...]..3.....a.]4d.H..i..@,..E.O..</4..U.x..zP......L...bf..&.X..6U.Z..].....(\.".t...).8.R.>@PQo..b].........P.5(..b..J.a'.j.Z.E..N......q+....r._.t........a.+.r;y2QP.\..c..C.V.qap0.....A.j..kA..uA.o]...].......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):424
                                                              Entropy (8bit):7.018311873669045
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZIt/WbXS1NhHdH4/Alrta49N8TtImb1YG6VG8N:Ha28CzRF9lrta492aa56ku
                                                              MD5:E4F480DB14ABE5B68D7940CD6C1B148C
                                                              SHA1:D014044A4E744036E1769CAB2E8D43932A4CEEAF
                                                              SHA-256:2FD1ADF5914F936425F50FC6DF2AB96B5345D86FC7D211ED1A29FA1417588379
                                                              SHA-512:91936D1118A0BF6AFC0FC3997BFA44841D0B3AD5DD20780CC863049FE144F17414FCBB785C824482D989BD6320BA475F1427CFE1D0C9882F1BDC8E60B2A05B30
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....5IDATH.c`fa.......j6....>..C-.m.......{..Al.Z.2.............Q...kA.f.V.....c..$F.OpZ.r).. ...4..........AD.HFO..w...x..[.\....;.5._.?w.v0..I...A.N^...ny=...0K@.6.....U.. 6.%DY.r5.`CSK0..Ab 9..A.....1....\..<.`..\M.H>w.=.S.4...b.ap0.0.M.E.....j....... 6H...C...R..A.k..1......|..*..K.T.".- 5.I."r.).H.u...M.je......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):492
                                                              Entropy (8bit):7.219897003910568
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcLaRmNgSlzyIiRTJsDai4yO8RJnB9xKjfwGgoHyv/uouVR293w2:6v/7saZWW/G+a8OUnVKULiou4ASWk6TK
                                                              MD5:638944B7E75F6677279EA83C1795987B
                                                              SHA1:FB3E1A632C0BE4D87B068A37DD6B202F045428AF
                                                              SHA-256:B3272D237730CCFD00720835C0671D78E63B462EB7031A7C375E03BC518914DE
                                                              SHA-512:E51732065E3F59A1A420120B02C0D0AD88B38B7A3E9E0DFF8083FBAED5AC6105CF7126EBC72D5C4CE040CFDD8B02153D783A9F2DE1ADBC3263E53CFDA3EE35F1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....yIDATH.c`fa.......j6....>....kp.r......^.>T........S`.b.[.>...[.j(...*....v.@...^...c"...kv.@....o...1..P.@GaX.r-.......!Q`.b..\....h.....k... W..VV..c......X@. "'.I...dJ..0.~.......I.....p...>....hp..;..`%U.pj.jQ...LLL(.....Q1.<Qq.7k)P#...X-A..i.(.F.%.....+...?y.j0..)......U.}..........3..w...... 6N.@....d...>... 1\......-..c.....-...d...%... 1........$....`$.....*..n.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1232
                                                              Entropy (8bit):7.783721678283317
                                                              Encrypted:false
                                                              SSDEEP:24:Hap+fvIZSqNA2zLsumQ3zlVn9POyDulQJVzXxrjTMcy4vKy6rYugN7:6AwZSj2zLFv3nn9WyDul4JTMcy4x6rpi
                                                              MD5:4499540F1B0BFA87369A97CF8B8C5608
                                                              SHA1:55ADA1A3EC0F7173FED8D6D9905C2BF200A4E0E7
                                                              SHA-256:E4A0C51802F58C088F5B7A084859E59BBDE226DDE477203A933854C0A96D65D0
                                                              SHA-512:879FF35CA0A95A86D16145825163AFAFF5693D057248FDFA14BF7326A6528ED91BD590FEED83C383E20AE0401F704C6702EFDE6DFB3C44FDED849047D90E33CC
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....]IDATH.V.O.W.&....5.Ib..d.\2\.f..V..,...0....u..!.)...`.@....e0.ji..:*.JK.E.`...g..o ........9....<....m.{yya+OFF..bc!IK..?<.c<^.._....c.-.u...BB.[Q...50...#..{#........e`.=Z#&.......0..SBc@......CCaS.l.pWgCy]..%....M.....?.btfQX.7...%...T..R.+`v,x...}...^.."....q..x$.JCVA).}Za.......c.*.V.HS+f\....z'...HLJEh..........2P..-..V..}BbSP0..0.F.6..r .L...)......m.[.D!..eT.w..NF.;.Dk'&.(.cN7.....q....g.1..............DDE.....q..Z....0....0...................,[0T..K....y..6SR..U...R.@c\x.6&.i_..6cD... ....Z...}.m...1?^....v.....:.Ij*.....,........p)GB$............;-H=..O.O.BV.......tA T.............#....&..>.\.f......g..b.& ..Z........h.....'kA.h....2.8....}..p.e.6..*?.y..#.b..oD.>......ni..".du0./....H(U..3...D.W..-F....J$.uH..<..OB..$.5G.....r.T.[..b....l5a......N3.`...........l.e7....Z\.....j...../...~.Y2..BYm;.=....1.#.01.4.\....`..?J~L...5....&...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):430
                                                              Entropy (8bit):7.111129987047386
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ8WbkCdK+Uzjr5nGVd/Mlwc2UXt4W:HavkkO9i0yFg
                                                              MD5:90CDBCB74FC1D6A2F25EEC8D93F02964
                                                              SHA1:DD1F1679EBC535759C16A0E655C27172CBA1C999
                                                              SHA-256:B972A63743F9EF46CF7A114CABAAA20A4B6A6EC30C76D15AA95C62CDF5DBEDF6
                                                              SHA-512:AB13D2CCD06E02E595D115C57E22EBED865BDE89D7AF3E691C4BD5C3FE780A79AE88BF0FA48C066F4E1BA0159AB12A9E3BC062CD71F4E838F45C0E9278FF3C1D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....;IDATH.c`fa.......j6....>..C-.m.......{..Al\.N.|....-.../.. >A.@...^...c"... 1ljA.&e..w.... >^.@....QX..7$.....Y=.. .A. ...k.. W..VV..c....!.]..> .....W...T... .P..d.V.:.......z;...dY0y.j....l...X....-!...z...\.2X....Al......X......Fb..].g...x..;.,...4."F........>.Z.........$Y...o........F2A.(M.X-.%..Q.K?]..R....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):573
                                                              Entropy (8bit):7.405492291603919
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZwS4oPrIuDMZlt6tMXr9XsQmIwio6N8nphNB/:Ha9DIeMvUteHmIxo6Oj1
                                                              MD5:89E7C41B0D55FE4E934FC5FCA2E52EA9
                                                              SHA1:90365EDF8995E654948DA60770064120B188616A
                                                              SHA-256:80D8315EFEC2084DE5B737BD430D571966B10EF4AE70869A395731E601F5B0AA
                                                              SHA-512:A2AE086972352598EEB89AE7BC4749DB1760D1C9ABB9D6F11557BCF1930B499715372C369C9BF635E2682D2EAA2CEB2214C72D0173228A427DDA72634AF8001C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`...03|.R..1T.*.....j.^...........=.Y....@IH`.....l...+"...L.j>...J...O.r...u.j...iQp....(mM.....z.@..!.........X...1c."...31..|.f8.....RG.9>P.`a..<..?>...{.O2..#..G%..F..?..G..$..Ci..D...;I.......Z.in...%.h..8.j.....kA.....&.6.S....v.{b........V.9.......@..-.....NE.h...{..Z....Pf.S...h.....(-..I..T.m..}G....._A..%P.8)....?/..&hA.....6..r......9F.....0....HK..*.%.4.Z.67..h.3.as.<......2.........)....Xf.zX.s....{<.l..eD..G...5.=..A....Qn.C}e.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):719
                                                              Entropy (8bit):7.61984902090932
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZxsDJ4zve33jApRS6iGvv3wdN8vRP/hIm/LG2nrmT4+NqETDODYkRl7:Hav6gvIh6nvvgdy5P/hJ/S2r1ETDO57
                                                              MD5:408BC3470C7A9494E04A46C9CA712E52
                                                              SHA1:0BE20775BEF1B7D5C21584FC783120D9C5D2D64D
                                                              SHA-256:46DD35EE144F1D1DBC6108C88D2618FEFA12499781C75F02C9FA6D1790C7B20A
                                                              SHA-512:94627C0526905DD000EE0E358F29E6D0D5F3FA576FD9D46C2BD7B6657FA6AD3E26584335BC4357CB087740ACECF2A4B4652D4A49D2F877C92550B7547DEEE790
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....\IDATH..]H.Q..o.>..>..-.j.$=....DJ...$i...J(..(Z>(.TdDl..!k[m.....`....jh$>HQ`T.....6...^.1g.....{....u.BF..H..%....1.#..(.L....3r.9..../..q"?.?.D.....=....h.Dd....X......g87.$ .|.......Q....=.......k3....._<.Y...........A....R.._o...P...p.b..[WK...sE..ga.I5h_#..3.6.-...N.7.......D..Rv).yPX..x.a.Vl~...n.z.....&?.l...K..y.j..I(&M.k-.AO.0.U......I.1..o..K...J.PLZL.......<......x.<....;-..4S.../.....4.^.w~..b....W..<..k.%....&v..p...7{.!8...........JI.1.H.......6x...\.~...8UT..*<.v.K..l.*..........r..'!..#..PY..}...3P......Y2..6.9.ZIW........."......!j..^.X...F[.y..v..'...g....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):493
                                                              Entropy (8bit):7.338040208632571
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZtAdzaFoeTQmjxiQphKZGm7G3ccOY4:HaAdzDehjxiQpcGm2IY4
                                                              MD5:FB2A292E78AAA6EDAE419768C4B0D3B5
                                                              SHA1:34BE3FA1C63B0A5142722C64D8574D5B32BA5A26
                                                              SHA-256:F46AB9578EDB7B60DE27BE3BED49D6310B921D9A9B1BB684B06B1EEF12C405C7
                                                              SHA-512:50845213A4908FD3120337F8D3DF36EB18CA4A58D75FAD7A3A9CE641B2CD74EE1B2CDEE5392E6E6936FF639C7BF75888B29D774EBF17BB9676BDD95F64878A89
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....zIDATH..1K.P.....b....I....I7]...B.'.:XKq...T..f.)CQZ-..W.....v.&.l...=:.8...w.%D.$..B..!/[P...E.h4.....-.^)....3.)VX.)..[..o.hqi...Z.....St.......8...@...ST.M.m..9...^.WkR.T......T...M&.5Lj;7...Y.u...cW...Y....#.\..e&C.....0..h5...B"...C..}....]#8.`..Q...o..p....L.#.E...].....c.J.#...4..P.B/l..O-.<j.n.....ZY..Q.g.....]#8..g..6..Q+......(b..s...4.K..5.......q.f.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):574
                                                              Entropy (8bit):7.415864782969201
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZu1x2zRRRLc8nF1bh2SGg9VzKo/cjp028L6592kUg1LIvjJ7:Hag6zRRJc41Mbo/k0I2kUg1LmJ7
                                                              MD5:2EA51B3C1F5B39A83FB2DDA6E639094F
                                                              SHA1:4F91D35D241301B818415238EF38F5948646C218
                                                              SHA-256:1DD1FD88A04619F3D624C2B12379AFD7B476E4C09B8A684B2F9E631016963ED2
                                                              SHA-512:3C9FBB37CA3FEB84A5854840827C79DCCEF3E7B54E83659DF27C58FD6E2AD19FD4BBC7184B5E5405FEB56B731A4F3FADF8D630716AA21F58D2CC09CDDD0C9973
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.....S..m(....33O.cg....JB.....>g[.._....`jT.4V.X.?5.eWr........E.q...j..5.z.f.....*......,...C6..;<..s..<..cFw......FQ...T.#.....0.&".rU.9..q..|]......s.=.'....l...|P....|.#.z.-8...I.. ..d...E. .Ls.@-1.. . ...8.j.....kA.....&.6.-...8..aOl...6....:.x......A............=b.s-..wUh(3...O.. .......@....w...Lm...._.....L......Po..ty:..ac..*.H.....1..._.....DZ..Py(Y.)...!..@.........V........?\.l.Ny}...2#.........ag{|(#..?j.P\e.N...................IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1055
                                                              Entropy (8bit):7.724487431866351
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ35sxuWFyi432G7GBs/UFGe3r0/m8EnlbAWyHwPBgl8DexKkfVGz6IR64K:HaP0uWFxeUNFG+QcAWyHgB2xPMWIUmQ
                                                              MD5:D6FA8EF65E7A98C839098898B8DB9A29
                                                              SHA1:FBE0C6AE11ABA527F646E442F46578BDB6717D5B
                                                              SHA-256:D6F31D0C9C4F2C55A3ADEF59C57D73BFCCB77327BB9C9DD0BA603A2AC844C5A1
                                                              SHA-512:97AAFF326CBA0B94BD5371B724C7439BBA8D54E9948DF36FC1482F26ED04568A25A2BBDAEB9399F1E84941DF5127475104014B883C57167A516D7F9A43C77FBE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...OSg...3...e.so.f.~!.dx.AP.........8...A.....qc..2.......:....".....h......W.{..87XR.|............dddd$D.A%.3.~<.!...6...3.3..b.....G.....Z.....d.!..'.TSy..Z7@v.M...d........9..1....5.No.=.DQW.Sk..{.....k..4 .I.....D.4...c^vp.N.nK....Q..K.iKRbY..k...BZ.....Q .....o...p...$.-.4.tn...d.......U..:.."y..d.G.mP..T.Y.h.:.|.x*b..p..l.<./@v_e....M...{5....z)k..U.8t....F.".OV..i.a...Y.S.LN4...:;.{#.....4.."(w....[.........Nd.R..-[..g..*.7..}..z'..?.$..F.........~2.{.........K6..U.."........s(....bd.8.gW.P}3.7.Q5..oR3.' ..'. ......Q...'}..~.....@,.=1..|...>:......h..1!..29- ~.{..p!..t+6....K?..~.b{..r.N.X.....(.....2.1.....T...GL........V.B.H.Iv;._..y...bL..1J.t.).c...T........... ..y.....,.c. *[8(..qk...'y...$.'..N...Z....s.m..CUd..q.`..n.4.SB\...+....t.O...k)....Z....2.:........t.{8=...F...*.....$(m.. g*...+.\P.+..x..<o.}.K{K....X...IO.#z.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):697
                                                              Entropy (8bit):7.53325744462456
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZZNAtqmGh8QH8HbE0bGgk0WVpkkMdBXwYYkwxagjvhnteNNAEP8rSsM:NKarNPh8LbVk0WAkMdlYkMagjvXeUEEo
                                                              MD5:7FB2FA6CF1386EB4BCF192661D3D8DB6
                                                              SHA1:FBF94EC2510BE4E43A09187F86A200C42446454D
                                                              SHA-256:BE2DB4F1F3105E79DF4CE7FC1138B9FAAB60F35271B2DB7BCA4F4F73722171A6
                                                              SHA-512:8AF5323330B6A8A1A120EE7BFEF1D72D65E62D716A8733D15D6FFB9681CD0DEBCC016F0DAB94ECC52186B8412FFC2CD13129C049AD663BFF4F5100FE4A5CA05D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....FIDAT8.UO.aa..........$2#e.&.4e.,e...fAV...y5...46JJJv..N.,Lid...Ub.V..7.zs.Ko.;3'n..}...s.....O...!..N3.$.,.?.n.cBD.l>.{<...s.Z.j....HE.L. .......%x..f4.A.J..r9.b..h...>..}}..FA.v...U*.$.L&..n..B..g.j.|>.\..0.`0.d....6..........p8L.2.X.......jE\.\>...e.T.?.L8........q.O.&...4.....+,...|.....tN.S......8.z.F(......l6.h4.$.x<6..n...l6..t.8Q.^..`./p..J.R.Z..O..AeB....;..`.....L&..K$.N.C...P(.9.#.*...HH$........$F....Bp(.z......E..8E..j....D.......'....F.$..(...E...G.X.)f........R....f.m8..D"dAn."..5^w....2.....o..._U*..P*...Yggg....W./P.N....avg.F.7.o?[{..a......C....7.^....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):555
                                                              Entropy (8bit):7.444773704293754
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZD/0xASD/Ciha/9JIq96n7bJ/GyMyHPH+Jt:NKaN/DSzCiha/916BVRAt
                                                              MD5:C96D689AA6A82A88C361601BDABACB33
                                                              SHA1:E05E915E73CA26C585E873D4C6B31EE0C8121231
                                                              SHA-256:EA3F14D90D3FE8E330B0F226E1E2D392C81ECB1FE1C2FBC23F3B5311A4D1CD51
                                                              SHA-512:A30636A77B3D2EAF506111979CB97882A76C6A9EC6BB3899319CD60546C5CBFF90C6C75A72AABFB6A6EA005206231830A8E677ED81F71F4407DD669562EC9477
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..?k.@......(..".......\].....*8..N.,....\.....R$..E.!. *.8.......&...r.7w...}...'w....O.(....0.VI.g..f#.b.V...dF..G....;.N. ....t:.s..a .....'3.Xl<.+.q9Q..0...H$"...h4.......@.H.....).q.r.k..*.........<.,.0.R.....xT.P.j.Z....9)v&..7....v..P(../.V..r..x<`u:..m.\..P6...#Y.i..X,.Je.^k....."..y..[,..Gh.v.-.J&....l6.......{.j.R...n.>b..]..AX.-...q..}..j%.....f...M........].z.`....@.<2b6.n.K<*......f#.=2....G u.p8.#..~..e..a....u.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):523
                                                              Entropy (8bit):7.4247542434162215
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ1BGC6Ql8uWEaZW1y0g6T+stGNPQP6pIg3JPKv+d6V7:NKaTBV7l85ayIyp5d56V7
                                                              MD5:7F4EDCDC5912F3BFFE10111B1D74CF28
                                                              SHA1:FD161B08DF02E40811F150DF7494624EE9E7BE6E
                                                              SHA-256:9A6D18BA0217FF7A4CD17BE21ADEC9C5501F147F71F8CAD8B0016D1A7864EDE7
                                                              SHA-512:97A079DE59FC5E3CA643BE4635E4E9A1D97DE471536818910228609B7787A7599267D3F6ED8005A44A893D389265F340202A00ED12C705561D1C66C5B9C23A7D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..T-..@.-_....*.@.E"..". m......U'.$.._@5..A.kH......@...4w.-i ..t33.y..:...y.2xn.l.Y.m.7.....~?..|..d.B^X...*..\n6....`....}.a....R....}.&." 4M.y..h4.....c...t.t:..e.'....2..r.;..x.t].....N6...&..n.H$@.z.&...6.J*.Z.V...o<...S..].4..p$.)...*.B/.0...v.p[...F...^.o.[4.@)@.x.z...t:Er>....h(....W.U.)@. .u.'.N#.P(`..j.'..y.$..h(B0.q....W2.......5.........G./JiH{..L&..#......XxF(d..Q...%........Y.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1080
                                                              Entropy (8bit):7.760001011131461
                                                              Encrypted:false
                                                              SSDEEP:24:HakEv/VebOvVQDFrMnjBcs9/Oc707PYf5mouo352wu8AW0Z:6v3VPvVWFrsjBc40LYf40JOW0Z
                                                              MD5:693670B2FE6D65F4CB7BAE022A2528F4
                                                              SHA1:2BAC72188332BFBCB7F68772A2B7F03D5E03078E
                                                              SHA-256:AD52B061776B98857301D897C3CF8C0ECFB1240A6109FCFC9C425556A2FAE6FE
                                                              SHA-512:4A5297D3CCC42F7D5D5712950FD640997F6BA47802C5756E2E5C34716B734874894950735ACF576069AB78F55B046C20589947AEA966F1CD95671F691F08791D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q..gwfvfv...m.(...$...,.....=........eO.H..P.*.?hO3.+M..K....*..j...2.....s..s...9...E...(..-.e2W...j.h4..`.A.@.R.....L>~...L..F...z9.;.6jd8.r.E[OB..b....Jj...-...B.......G....9..0.#....B.....J6Pl..d_Va%.{V.5o...6x....[............._.e./[x^ i......l............NW;.._!...>...../h.h."9..H......*........z..^.[....<.}...}.x......}..`...8......t}......5......t..6.=....dDH.0...k.(.1.d....y.U6'....3.%0.d...n.6.'p.f.K..{1MiJ.:.1w..m..Uv./....v.h8...T......Q.v.[..1<.`.\.+...kHa..d....\r.*..b....]J.P....q........w&...f.wK,....=k...t.Aj.bK:y^....G"v.........A.D..!2r....K.4..W"vcF...w.!..|..E.>i.:I.'.....=.vC.H>.:..c.z.+..'.iD.._N......\....x.....\.."..j..)'..........S.:;A.s..B2[..?..1**..._dSp.;...Msc....v#qFf.........@....9....`.N9j...u..>&&....d.(..iF:....o.X.`..9c..b...E...Y....R.."...q/.....>.=.....nS.r....../$.7...........=::J.....X...;<&.|..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):314
                                                              Entropy (8bit):6.784929150611978
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKcd9F10rj77iGO3vndSX7pss5LQT4noC3EGMiWYWmOx8up:6v/7aKaZd9Fq377+vnwVsUVfHMi5Ox8c
                                                              MD5:807B340018C2B3159E533BE8265773BB
                                                              SHA1:3039E17C03CC775C98D2C55FD40D7790F288B5F4
                                                              SHA-256:B91575A2CEE1DB89C940165653B371BA08A9B52FD002BC870F74E4FA38A15FE0
                                                              SHA-512:C4AA7C69323178EBF4763D369CA70159C2DB2E2EC0415C90E20C9B09AD0BC4E59727F6D5934A1D3AE3D96091767A441ACC92CF2E49F0AEB49AAC70357E790A5D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..1..0.Es...)so...C%.......Z..R.qL...H!$...r.?...x}..`.V.......$..... (.@...A....A.9..i.C.pG.....6=.&..Z.L.;.\dP...b..].hl.8..-l.H|goFA....A.Sk.w.....Fia.....?.o#.Hwa..9.....).P..j..K}..C.<8".F....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):314
                                                              Entropy (8bit):6.721368144178752
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKcd9ONec1iJrRSwlJqGdulFDFj2fYRVMUtKGisoPZVp:6v/7aKaZd9HccJr02q/0f/HsoPh
                                                              MD5:22A148D6CB40FA988302C8F1073B14A8
                                                              SHA1:48CBE8FE474F031C104C96EF20115B163A35B1A1
                                                              SHA-256:5ACA3235F1AEF0B5713FEE3354495297EB76ED7A7C3FF43A31EE3E9CE8E1481D
                                                              SHA-512:8C0B8105F032FF4FE16C1CDC3E28B91E1CB48336853CC4C34C62FF5ABEB74F150A23F7CFEB3C05781B02AE942D13916C3D8F84C992D3D3AD982BF93E4D408217
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v.*....#.g....n.m.. BSjcc....c.. .z.. .=#.@..2P\.n.L....Ak+.{....".:4..N.........{z.`F.a..B@.o'N."d.....l.....Fv.._.\....5<).........Tm...H..............6...t4.."..I.l..............*..B..BV......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):401
                                                              Entropy (8bit):7.114487442979153
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZM32Toni6sJqwMU+evHuYBuucDNWEKerH:NKamRi6odvTuudEK0H
                                                              MD5:2D068C94CA482206EB6251538EF7688D
                                                              SHA1:E8D6446D6730AA24EAFDB89DB777C9682B8943C5
                                                              SHA-256:04752316A907E6B750F6FC163FC6FA957A70E0F3D5ED0614A9AD9DF75E6CDD9E
                                                              SHA-512:1068BA7445C02FE28E4F970BED96243185F263A792EF39B232D438F48E6F9E85FAD3243907CB479E327E04126A852DF816E8803E3854B9F61B84597DA8269392
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..=..@..9.,..3XQ{.c...#4..-..p6.h.....'..dY.!.......cf.CQo..</&.....T.......c..o...@z,.i..8n.........B..&I(.....(pFfD[...s:.Q8k..j./..{.=.#PY.A4.o.Y.!..,..@.6!1....ng3.g.O.3..%.R)..-l.........I.D.../J]=o..@.o..."#...d.b...M.._B.$H..Y)..\Wt.LeO...D\..l...h.X.4{.FG.\.v.....&...x.1..h....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):805
                                                              Entropy (8bit):7.635351047843189
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ9v3COOblIHYv935IN5WHiu6wrWjzFg5jFp/hKCjf8axlRdZR24:NKafHoD13Wz66xjzFImCdxlRlx
                                                              MD5:2D57C7CE9BD8D41BDFFAAC04292475FB
                                                              SHA1:B63ED926888CBD58BFFC083EEAE5FED7189606F2
                                                              SHA-256:34B1EA8F3C5D7861CAA6207D6BE751D6C44A9BB1FAB23706DE0589B3989FF197
                                                              SHA-512:B7642F676C7609A123BFC6729A322CD8926C40DC13CD09BE235722C9D2ACF9BA68EB9D43FB2E960D151ACC9B52F62D025AD72F634885B4B1B49E84D779BFE555
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..OHbQ...,..V.HQH.?......fd6..EC..00i..E..E..E.A......7......J.4M......8..|....L&..|.s..s.=.2.~......X,....\...vr...H$I>',.x<.hKK..;...$..F[[..x..1A.. ..R...`.rc#......L9#.L......K.....L.......I?...)..'.vw}.un.......S..1....V.hll..]...@7^.9AP.....T...dnoo...l6...Q.H..*..)...cP|q1..c.T..qJN.S*....3J....(.N.{.fS...&VV.D....}>.@ ..L&..-..VkE.-...&...t....H.?fn.....v:.......l6..>r8.Dc#l.J%.-.RQ.7..uuu.h4.|>.TC..~~C......<8...A......X,P.fs..>>>.0.0G...^..T.X,.DB,..2S..}zz....$....R.`.h4.........rF....vt...h.;.T.........y..B....Z]_...]...(.......R..Z......<...W.5..ea.$.]....Q.............0.......B..../,,..PEF.l0s8..?..........V...>M|>?.L.|.>..@ ......j.j_...z....A.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):864
                                                              Entropy (8bit):7.6639437363856935
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ7lnTXNCWJhGn/kG3vig5Oxmb+LDWt/g5H9vTMHEL9llPF2iNOK3oeOH7:NKaJlren/kCKkO9W+59Yov2yOneK
                                                              MD5:9F76954B5A93C40EA9B093ACED4781B8
                                                              SHA1:13706E9DB0399C8C3F86E9E63ED8D67A150E8B85
                                                              SHA-256:A3D485BB50745547D959028B354A1E60F3B8F840B35135F828E1E5F42840CEC9
                                                              SHA-512:38360EFA8297E4CF8F82AA198BF01265064FAA39683289C72880B23E126624E45704836DD1D80C7DE11DE4A151DF7C0F48727440AE919F8D1386EA93850ED5FA
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v.*....#.....:t..}....,...."""....`........}. .".gH...>ZXx...<5...N=#.`qQ..N...D.....CC.=yB........m..'...VQy.i.9....a...,ii.]..11.A.....P..)Q.}......[.}..)rp.RQ...........<..u..L.....i...." [XH..mU.W.Bds45.JJ...^.....e|..,%..@...jhh.........@.G.fIIu..............X[..........*&.h..& .eM.0*.TU.....zS]..........ee.......ATTkb.Y%..66.6m:.../!.y........;^W...G.^PR....p'L.`gm=KNn..T...0..ed :sml.........{{.(*..U...W999m..gKJ.Q......Dj.U....IK?9s.K`?..;.......2kkkSS..g...t...F?......n|.....N..n..s34.....x......n...{.Av......n...m...F.1y...?]......L..b...s.~.....#D............@.@..a.............EG..w..80q.....al.\F.NLl....%&..d.jk..Z(-......FT..r......pn..|..D~.....E@.[...a.......... ..eLQ..0."..2-ZnZ.....M...t(.g....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):993
                                                              Entropy (8bit):7.676951484144662
                                                              Encrypted:false
                                                              SSDEEP:24:NKaP+ZPR9CIhRgUHjuBRNU+hc1bXFPtThcTjal6+h6zyc+4y:nP+RR9bIguLNUec1bXFPBca8GEq4y
                                                              MD5:E2668B001588985B96C9C578E82F9A16
                                                              SHA1:68662EE176234B5BFB6748AED882B126A1769B6E
                                                              SHA-256:F3C9B45A5E7189968ED7AF834BDCF0DB0EC6C0E9A7C2146C223C314A3F71740E
                                                              SHA-512:B7FCD3F51C68F5748DE2C331489E1CFCC254B8D7B6ABFD3AC65728E3BFDB5DE168E87DA7A23653F97189E17FC169B882B403A23EF7A0FA0E647813BDC26B519E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....nIDAT8.UIH[Q....;...M......D.....+.P...jD.B....Y.... "...b....I]h.....O~..VL...=./%.......w....w.......S.1.[......^.o$....e.....J...8=....|.Px.z.}.....$...:;....hHH .....szj...eb......4..7.....y`.4SI..l.r.,&.1/.Nrj...HDn7!...\\,++c....ccp.**...o..."?.0....BCCCBB...-;;.6..r.L...om....@KK.b)//..joo....d...l$i....R......eeE.R..bYgg.`y...M.B...Z...0..B.dxx8.o....l....O.{W".....d`.......R.===.....W}..2...y..|0......q.\..B..`..AC=*.\Z..,.:....`......u9<....tvvF......=*...ddD.P......r....9==Mw.~S....t.M..D..Vaa!8.....mkk.............@..{{....#..t8.........C,.....~jW....T.\U*...B.....588x..I......!....a.^]M.Dtt4.333.B......u.\..JP0a.......0#..fknn.4%%..v{.Y.V6...T*u...W..<..{3.........BO+.JT...o.YA/.\.!\...yR....d.r..Mf>..9ollDFF.TSS.=(<M.H.XTT....F....}....iY.V744.#t."..B.......K".h...............b.Do...-........w1.rN.W..8...m..[.:......!........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):473
                                                              Entropy (8bit):7.259950302851813
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ6XtHPSVQg+q2yOdSRzqjNMWN7Le:NKai1a3+q2yzo9He
                                                              MD5:AA53F197A2A1238E53031A3170DD9218
                                                              SHA1:D4E4E2A3EBDCA1E7D30A34982116D03F67BD0F49
                                                              SHA-256:7FF9A825EFCF4158C788A7861B5298B40B35197C6CAAA3D6F5CF4EF1BFA7E152
                                                              SHA-512:7E9F5C853EE59CC7AE8624CAADABA5CA2938864B660D771C2B5388D8C157B2928478503531BF1BC9C7E3664F60F891E5C2C5E1865D9D1ABEFB79A88184E7E83F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDAT8..1..p......a..B.Bm..GppI?@.. ........Il."p.....LIh.......E4..w..]...@.._)...Ei..h.mT.Tt]?.N.F..T.U...Bz....v..@..(.....gA...z=R...4]*..0$.Z... .rA.'..f.,..x\.....4......Jt.I.......^.j..(.a..vK."...h.Z....v.....TU-..9$...a...C..N.4M.....1bYV.(..r!..|._).q.m.n..`.i.^7..<m8.3.c.X.q./.o..~.L&.Z..*..(v:.M.>....\.u]o4..E.,..ev.e..;...F_._..j.d......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):986
                                                              Entropy (8bit):7.664476910364052
                                                              Encrypted:false
                                                              SSDEEP:24:NKaCPO5SOn3ataq/81f+2/61+qdNJkEIf0HXajABD:nCWl3ataqMf+2/613XK/0HXae
                                                              MD5:BDCCC26C63565C3F7AC1440DAAB49D19
                                                              SHA1:FD9948EE8921B6B31A4C7437733187A567B170C4
                                                              SHA-256:C4AE5317ABEFAD97C516BB65B82AC6CF125653D890A8FFB34BE37E79095D66B6
                                                              SHA-512:94776D25077EFE80977F046F316E648D63B70E9A75EEEFAA90C0C6304ECE7AF17CB4DF2155AEF9814F6B9839B8215FB2542941579581282E8218C3CD8AB48175
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....gIDAT8.U}(.a.......y.l^.Hm3-...q....F..Jj^v(.G;.t...D(.#)..h..3.e[N....>.s..|{~.y./....|.#.t.?m..4_.+..r_}..H........9^..;........6..@g...t.........S.....@1.............@.{...mv.5.D......R///.......................I.......}R..........[EEEoo....;@......7x{{.7$$D.V.....`.Q.L.Z......PWWG.:...b..k..rrr.....'.J....7i4V...`@...o2.\.!....8.............I.).,+.YYY....GEEY,.G..@D*...4....JE!.........j..===.G.;.p.N.#..pgrr...%...& ...B!8B..{6...pt......,==.z.......4.....366..#n...%,].q.+9.............I...h4../.F.K.@L......W...KJ.5........b..jjj.........00...LG....E".L&3...o[*% n....k...}r2X.....d.TUUu......(.....?6RR....b.`...).H|}}......{.._.f...R(.....a0. ......0.tt`...W...........lmm..??....G..Q.%t.l.t.R..........G[577S.TtrQQQ..I.R.\.I.i[.........yy.t.B..PZZ....b$.....?4!OOO.....AAA===...SQpE|>...+..=2j...Q...P43...=...i...^0J.#......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):628
                                                              Entropy (8bit):7.420835398015451
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ1imbC5HMuCvsQfy3ppL4BCx7HXXFiCStYS7RDebuI7ufH45/N:NKafiWqsBCM0xzAYShebuDw51
                                                              MD5:83BE2CCAA86D59636DC435E046D80D34
                                                              SHA1:9E79B14484DDFB91DEEB3102A8434FD2B9486D87
                                                              SHA-256:F0A7C89C395D05B24BC6E623467C63E9D622C2E4F36F18A752A783B37E60D0D4
                                                              SHA-512:E8141D994366F7DFF8011E879898909D3F51DD64AADEF67C5A594B23ED5DB52447393CDA385FD8433D65C4E229A9C1B7F0E3E01109F98F118524280BE8005B8D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v..8yx.H....p..@...8.Y..f ......A,. 9FF.......AZ..D$.n.30...!5..x. zQ\..@Q2.(.A,!. .z...../9.!+}.....<++.m._........\..F.]]].....###!...w?..pz........=.....%6..........e............Ys..%6..{.T!((...`.L.<9''.(...F ..r....jPPP@..G............_`..g.. CKK.3P...R..\@V.3...8.d...a&H.A.?'*.._.T.... .a4k.,....DL....RO.>%*..........IHH...<y..k.}..y.......l%%%..I....m......P[[[555NNN.40......E===@Y^^.....@SSSUUU.....3.......7op.#QQQ.%.u..........-...y..y...y....:D=.l....4..........z..;.9.;;S....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):485
                                                              Entropy (8bit):7.287755682887798
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZH39xdGeZgokXp9RadGSJqlK+gQKNFUukbAY1BBkc:Hax1Tyok594wSJq0LUXff
                                                              MD5:2DEEF8D75069483C6938D90ED54E5915
                                                              SHA1:AAEAF07506F52D28699B8E08A80B912DD4FE4DF3
                                                              SHA-256:CD0364492E6D8CCC7D9F7C010109FAAA4209E89F1A81A475AC4BF1474D77F131
                                                              SHA-512:B73A3876BC2DB077AECD7183C3B1BBCDBC204404F47BFAAB28F677F5DF0CA03FFB1563A496769856157E480D19CF0EF611F520D4AE2247BDAC527E1585C00037
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....rIDATH....oL.....>W..M.~.<C...._i.t.(.D.`.......t1.D.6SU..h..Lm.].N..&..4.......p.....f...&..q...<C ......_....Cx..7. ..4q.{...8b....6.`..b._q.....g.g.x.W.q..#.h...X....h#..V..m...*>b.s.0.@....G..>.F...F.]..Ib..6|..X..^a.?.@.].3..x.@..M..&. .`8U<......E .x.=v...X.n.+X.-$.....l.4.+A....b...y}J>9-.O.....QT...b....+..c...NF'...N..L.*....Z!9zZ.d..%J.(Y.d.4.+A.....`..6.0....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):615
                                                              Entropy (8bit):7.493522472360833
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZXp9NWkENMuISGwgrprT3pAkq3KtSS0L2481z:NKaY1GwgrxZB1SS86z
                                                              MD5:1B0D3D27E658381D0EE4A03471B9B6B2
                                                              SHA1:2695953AC84F774608F89259A9C7FE9F726DD7C1
                                                              SHA-256:304A95FA52102AD85438BD787D8F987624147583B0217CE9A88ADEACCF2ACFDC
                                                              SHA-512:784F83D1735727F86D93F8E21F8B143CCD0877BEFB3597265749A844354E485F925D2C3680E1468E3333E10F56A1A117DE20E68ABBBB8CC15FD9D76AD4FA3B04
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.SMK.Q... ...5]......6..[.W-..P.@....Z..... j.."F\$.+.I..!wB...S/.......8.{........Y...,t..0..)...yk9EX....`@.....#.|.h.B!....,.."c.......1+..o..6.=.U......EN..[k.IE...o.lMQT..x..i....fQ,...5..r..1.66,....aT(..9SL&...k....~*.|...?.z0.d2H.T*.....h4.6.Qcm..F6.|M....Q2......=....!..Lx......Q..|...|.....F!..j.<...l..y...r..V.....*.$.....+....D(f.DQ$...."....0:...o?.H..f..w:......A...:......D"A.B.I..#...n.K'x...#:A..t.N...~....p8.x/....a..>..ql.|..^-.}l_9BUU.+.....i.f..... .QU......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):851
                                                              Entropy (8bit):7.592368176556942
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ1nSeXaEu7xD+up53sQBpStE3s1xka2PuXAQad9azNDFpnD2qL5tKbVtl:NKaLzXaEudiCNS8szDAQa/G1DHeoi3
                                                              MD5:FA956F1A722FFB5D96710094E8D510FF
                                                              SHA1:DB54EE566CBE4045DDAF78F98BF648DC3B6C2013
                                                              SHA-256:177D3183B5C677C5A6E3308DD4B8846DFDE8154D25DCEA61C50807EF432ED457
                                                              SHA-512:13FCDA8618266DF5228395EC6F8CCC2BBFED32E613F3DCF1BCDCF056E1975393CE2F44AEA3FAFF5B8E39DF75103DBED1CA656D9DBB55A2C598EB8D926747A6B9
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...MHbQ.._I....?....c..Q"..i#n..j.6.(\.sQD02...a\.(.e..f..."...E.)-.J.2.ox..2.A.s...9.s..........D..L...yaW\d........G...CR-//.........K...b`` ??...uww.KYY...Z.^XX.?#i"r.. ..............vuu....6...............b............&..J..D.......'A...zUU...V............Y777KA....9...Tl.....0....".,--.....Ur.z....l6.Z\\L.......D.BVVVjjj8...566.yr..LNN..W*..B.T@.........E..E.T..!.).@ ........|..........@..C..`.....}...-..f.488(m...$..........Laa!.@.i.......tJ_.C.Q]f........F......;....{...D.MLL...S.....K.###yyy.%...A(......H.....2.@Y.......B.?.Q?.}}}. ....U......#...h$..(..i4..T1..`W.........%S.h.......X,...T...M&....0g.P(^.w...?ZZZ......2...nzz.b..JCCC....?~..6/....v........q...xzz.z||...........{..<../?e.......{......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):611
                                                              Entropy (8bit):7.381981068805649
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZOvGkAZd9ySe77yxJCJjH/FZTFxtD87UCWxsks9:NKaaGV9ydaxIJjfPTFxtQ7DWxske
                                                              MD5:A6180E3C24B9C22B27B63C6AEC01B45F
                                                              SHA1:5331930AD50DF8F1871AA0E6C212AB41C13A6E41
                                                              SHA-256:B78549B89540C61655CE5777848B6CA5F2CEBB5DA4E71783D6A0B9F107F6BA72
                                                              SHA-512:0DB4227A51D3016BC7327AEF978EDF1C634B8B7B806836E0312ED6CD5AD5BAE5EF0E8E78FB5380A9BCD31BFE4DC70D08B7A3C644433A5D39801E357FA57DC24B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.cp.v.$......"@q. ....={......7...2...........=C.O.<...gcc...<z..3.@..f...`dd.....@sqy..A666@...'.....+V. '..}.t.''.O.....*....1h.-@Q;;; ....@...2.A.v...k.............=....:..K....r...."ooo...k!\777 w...@..wYXXXYY.2HFF.(z.6T.......................;......9r.(......;;;33.c...h.n......?...............RvMM.P(11.9.O.0...qq.........B...h....e....Q....._.:t..b..+@...4...v.z{{....X....O.........{F..3.......?.......g......N..l...V5[..V__.....$..V...r9._.yM/...8......9....X,....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):718
                                                              Entropy (8bit):7.57373170308176
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZVWu4GkCDzCsgwe6NJXfINhjYlEN3wrhpKN40X7ODNfQ3mgCLajSlzgHc:NKa/WuBbSsFe6bgNhs+lq6LX8NfQ3mbn
                                                              MD5:DD2A12F20833DD086DFCADB2E1AABFBC
                                                              SHA1:57255E0D800E248FDD20D91CB40CC7EAB7FE1CA8
                                                              SHA-256:787365ECA2AAD7E65D6D9AD02039E3311011801267B0942DBCCA3BE1FEA6E430
                                                              SHA-512:36E9D49CD3A31E4428D8F2C92A66CEBA516BEBD62AE16A59EC7DEA6A85E664B0AE475F2B2C6C7B0E196168186059EE703D86864EFACB5B21E198D0D7568C8977
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....[IDAT8.UO..a.'....H.Cl........(..E9h..`m+..D\...\..H\f..0..q..=......2.3.d.v.....{~...z..{........P._Y.^..so!.S.,.n...D.Z.E..O..v.....8..x.f..m.s...Q.RY.zuu.\D.6.....ZK.I.=::.n4.7.....Y..B.P..^...........<...5.L......9(..+......s5&.?....V..P.x\...d.......R..l......... ..~ .(..{...fP.t:...@w<.K$...Rk{.u:..R...d..ju>....h.V..V*..r.\.^_...{zz.`.X.....b...Md.h4..d2`4....[.....tv.l&s.1..!..F.'....d2..b....`0....!...9..J.F..L...J...l.E.....*...1.N.....r...#........@.D...www.:<.)..8.........N..M .D"..SS.......<jk..\._f...h4v...vk/.R^.c......2.....?;;c..KE*.zr.k...c....{.. .....__....~......?B'......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):660
                                                              Entropy (8bit):7.487874226621958
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZVAK4P3gx4QREhQS/+2c5yPScNhFV4Q05cgBNxRzHtgWX6/xz:NKa/Aj36HRCZc5ylh74S4/RzHXe
                                                              MD5:74F875662E65E7AF52EC157D5089C563
                                                              SHA1:5B4034DE6733C742CF7624DB0639B4C73D824CF8
                                                              SHA-256:8AE60E1D38A47D941B714CFED351BE466B3E3EE314CC8B5D11B030141952511B
                                                              SHA-512:F01042DFCFB45DA3F9F3FE6C0D7AFF9891E727C351C7C959D8FF994E89031F7973424CF5CFC1B1131B9D00DB8A0FBBA15522C70BFEFB07C922D219F5BFCC24AA
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....!IDAT8.cp.v.*....#.g.....A......n...$.GE...T......a.7....rSE.6..WRz...3........!.....TU.. Y).^*,...K.]..........w..._..H...300...x....ZL.......>P......$''..b... {{{......4....`.:.:. x......7o..!}..q.ziii.t......?.>..Z.j.P=0....NK.bg......}`..&.\..(.T3..:MP......qq.tp]Y...2$Y....A...!R{UU.....Pt...{.......[...YY..4..e...AEE.qjj.......'7l.PZ.`.d..-,,.d.".p.4iEH..];u.(./..s..AFF.k.w......_.4.d`&.. ....,.r..$.`N".<....j.o.Z..f....J....@m...7N...?...S[...W.....VGE.QR...I/...,. ..4.......@.L....I8$...d.>:........@..}..g.O.....s........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):643
                                                              Entropy (8bit):7.480465914810552
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZFU97Kxp0H+ub868kN826ZTjoviqY/qVLrjYJ5Ta8zo2lQWl7:NKaTU60H1868d9joSyJfYJlaCLP1
                                                              MD5:8F0A3E1C69420112A8B9A5E16266D75B
                                                              SHA1:D23BFD6EA53F6E37DA64FC75630282012B6B0823
                                                              SHA-256:6722E529B14E2B1535D8410335F1BB7C47A58EA6D159DAF5CC9D3E6DB56FDD01
                                                              SHA-512:DC4FA2A0E12BEAA4FA34D1190C12BDCC651091E7D6E68AB46CCA279D1BB8F8A2D4B9A9A064208D6474C4E0A3BE15BDC6AA46DA551C93D5E4011ACD5F9606D846
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..?.ia....R.1.l.;0..a.,&..2.K.LJ.1q.n.{..p'2.D2.....@....o.s_.W.s.=.<'....|..P.......|.......(...*...EI..v.}y.|>......t>....X.....O&.. .t:E"...c....%...v.gA.{u:......W.....Y*.f.....Gt...z](.t:..."D./......S.o..$.N..j.....&.....jI$..z..s.`0.x<H.....O.......j%..r..\.^....H$.B(....n....>.p...u.\.0....q.ud.J.j...xd.B...0....M&S2.......e0...U.TW.../......V.j..(B.....6..v.. e.4..m.t:-..x..f3...f...F...H(.2..b.......f.HxXl..uu.\.....L&3...@.....Cgo..D"!..'.....t.^_,.O.r8.*.Jr..#....LFm4..B..V*..M.."......o.._...+..4:....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1124
                                                              Entropy (8bit):7.695799649655058
                                                              Encrypted:false
                                                              SSDEEP:24:NKafNd/+lwL9BhhL9tTGBQ+v90hFTgMPRvzPVy0T/c:nl5Bhh9pB1TTVvzdy0Tk
                                                              MD5:793FBBC1B6A023311972D56E9B65B751
                                                              SHA1:79EA32112C777BE797D88B3F678B736249696565
                                                              SHA-256:4B7EDBC9DDCA89D277143E84690C043639C21E1707381838F0E0C33CCF10FCE3
                                                              SHA-512:134659E779B738C020EC57A0B702574AE0B8E14C42D8BCCD795F39E93F21E181BE7ED2F3E0ED96D77CF83938AD60ED68431455B8623B80D18039AEB2D7D7C170
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..YO.W..}.B....\pQ..#."-...)b'..a). ...5.P.bl.T../..\..JU.V..#..m157i..8M*V........C..8.7]>.Ks.....[......+..>........?}#.O.P..v.a........;::2..---J.......A.R...,--.4..q....%.HJJJH..............|........o<.,...x...5......Gnn.XMMMX..`0.......?..!c.I3Qn`.b..K..t:E 8{<...l.......A.~4sF1.$;.O.8.xrJ.Mf.R..........F.......G..Z.bg...?.QM_.WWW<...b.X~~~aa!r....n..{.i....h.....@....../--..OP\.<.....2..}.4..d..xo_.V..[..@.@.....t$@....2.(sB..<..!j.o.....`".-.......t..(.F|.#.....s.D.)f....u..!R.......N......Q..xQ'g..<k.....n.@.....|k..Bh..L.....a.1.5.=......c6[.....[t.d...mooO.Q....Q[[..GbqQ...D._7.p..V..%J........r.d.Ao.....2t..._WW..z.....4*u125;;K..\h(D.......Z.d2......[.....n.K...zp..5."..!...-7[...q>.C...&..&..gq......\.QEE.J;..}....'?.../.q.`.h.......z{.Y-..6{.(..T..moo....k.S.br..ol6...../.F.m.6...e...K.U....ZYY..2uww.d....>.........j.Z.. ...i........u.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1122
                                                              Entropy (8bit):7.744597577510679
                                                              Encrypted:false
                                                              SSDEEP:24:NKaGdleKuX/r5iHUhbXs6oPk5t47C5TC6FKRIeDi7mL+Zk81:n0fU/roHUhjFH47yTlneDi7mSZk81
                                                              MD5:41F9CA64544CBC78D910C5859776EB1F
                                                              SHA1:ED50839BB9A9E0163ABD62607035F73F23002179
                                                              SHA-256:7F8A325E13B5C36EA2AD0E13E860F072D5E5246D44758B3750E0153316E2AB79
                                                              SHA-512:1222110B06DD2C988EFD5150F3D56839EF26F16B39E19FEC71170D6231832F4B21E12198F310F3F4D275D0B468317AAD6B994299431725EB462B12929F02F24D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...OZW..I.1...'...K4./.9h;..g.....X_(f.5..!..2......ef[T".!u.8|.....>..F/...\........C.....~.{..\.|.........9.~C...1..$...b.i.......<....z....M*.666655.d......e...._.rrr..AYYY4..............bL......ol>u....x......e..Vk~~>X---..E..TTT|6...."....Q.&.....L....a.......kzz.l6.2.d6..CQ.a~..%.g..V..H.kkk.~..Z.........q..8@1:...|...:......D"..........b....p..,(...a#HR)Q......(.....P^^n2?...9.... "L...$....J...;...zQ._.n*.B2;.t...$. ..f.....U..].....%.^...J.1....-.,.!.[f....m.H..S.......n..A..-...dwTWW.&.x...-...u..C.\j.!.,B.a&_..:...."..V6.L..8Q..@D.5fv..Q.>E.ggg&(..uuu.....@*;ne.t......~...a.....y.><<\\\.!'t.xRT...$M..."408....r.2....(d.RTjnn.J..2..zs.T?..uu:]$..4.....c.b..;.2.FG...~.a(.....n{mm-..w.y ...)..V.o+.o-..}XUU...Q...........W3.@.......p.`.s..-S..K.(h.OJd.n.....F..s*.B,...dBA...x..Q.a.rA..r...n...}.VWWqy.......D...<.p|QQQss.\.W......<m.Hs5Iyocc.>....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1110
                                                              Entropy (8bit):7.74470888827379
                                                              Encrypted:false
                                                              SSDEEP:24:NKahYvsE+ZScsGdj3+dASuXETYYVSr63iGYHV:nevsE+Z7Vj3+dEETfVSr63i/HV
                                                              MD5:69B272E8E1083CD45E542DE16F75BD08
                                                              SHA1:42E188086C45DA6AEC1B7DD707E9960446F0AF97
                                                              SHA-256:458795F436359E7C95FE00F29A4AF65F5823FC952C77F979F901DEE9EB0800EE
                                                              SHA-512:1377EA697694DAE2CAE2C86150938E2A2FB69237190123EDCB3795A1549502EC77C308478B9226A372D74F92F5831058DD06C110C66CAB6E394C3307ADB0B4F7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...OZW..y.1...'...K4./.9h;....0...Zc}..U.N.....0@+.R3..mQ.4..m..M7."]..36ui..\..u.{/0.....s.9.s..s.. .8..?..'...|yl..q..5".d2..fc........4i...F....M..766655)........h4..8......Deee.H...t~~........1./....x....2.......@ ........`...`...NWQQq{....QQ&.c"Q&.5....b.2......n.;77....i........D.....$.9...F.\.......O.......TVV..........+...Y..W..j`...'...@.X.........M....."#..f....o.m..D.@......r.....A'.%.fH.........j.Zjz*...~D.W.7.r!...f.0.b;T..cf.....Uj.$......@....34...a.Q4..zt..L...(ZYY.hgw7. .,PJ..U]]-.........z..J......yG.X..)..H.L.A.He........r..9A!....A.S.wvvf.h.....'.d.wC.L^...(...I.a[.......E$...K..H(^.............y.0.N.P."Rsss.4Q......o.wF............/V-~tMY....../......z{mm-./r.Hwo.cJ.r..;Jo.K*..TUU.jG4.......'..=.......-...(...?..j..v.J@A.|P..qegg.l6#k..".R).X,.....@.......s...+..........shh...W".........]TT...T*.Z-.B.X.M...').nll ...p,..p....k2..bq
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 32 x 32, 8-bit colormap, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):657
                                                              Entropy (8bit):7.309095706915046
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7snWuEHT+E7c3c8BysPpDE37hekuxNER/P9q3+mpiav3p+/a8mqi:hnci6oc8B5pDE3tekeNM/P9A+mp1BH
                                                              MD5:A3AFA72C0D4B0924E8C5728ECA8FEA3C
                                                              SHA1:DC6A712205AFC34748AB86CABE304DC936823328
                                                              SHA-256:5148C375DF089315451A3EE3691F6773712D43F005DF0C31191CA3D852940455
                                                              SHA-512:42A6E3C4CF6454D520AE7802717E75FF3A6DAF6E47418556D0F626F7E10B5AB15492E0F239BC334522EF8D3BCB3895ABBF903A6649DAF970A411DDA6A018AABE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR... ... .....D......KPLTE.3..3..33....f.....33....3...3.f3....f..f3.33.....3..3f....f3...3.3.f.f.3........IDATx.S..0..cg!.0...._Z).....8$......{...f.0X.{.....%..lf|..%B6k(.s.....U.*...."vn..X..-X.+.bw..+X........z.........../..gg....fqX].d.....A.P..M~.E....~.;5.._...:.....#.l.r...d.&.......l..H.".W.8.,..f].Y.[f'}A<.O"...-......x....I...:.z....7.jE..Z0...T..=......n.\"E.M..T.M../.,i..kP.d2.y.oE.....FK...3...0.;..>.....J.&....5.]YE.G..y`t,@.%... .3X..>.IK%S....N..ZB.Ud...$........zM]r$S.-...+.}..]....VCC..&...`#.....8m..m.8..]*...uTM.j^.....".f......d...p...._.,.e.I...[..XJl[\7..{.....}..............IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 60 x 60, 8-bit colormap, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):2267
                                                              Entropy (8bit):7.881694929189102
                                                              Encrypted:false
                                                              SSDEEP:48:mwMgXc66itTkY4WZDeA3tM6wNAju7a5iAg73Faxf2HSDrPgIXBTubVALV:h96iBzdKIMjNAC7aAxVwWSDrP/TubKLV
                                                              MD5:F546D38F79F365A25D25DCF368659993
                                                              SHA1:5171F5E47F17F8CAAAC88136BC84F19521BA4C9D
                                                              SHA-256:3B32D6E3719136CB5B949F11600BCAB6B3E757F86507BB366129A9167E7958F8
                                                              SHA-512:ADF8919B58851F7DCD9642306A1A0941F8C13433EC810E3CF10E186A930A88A67283DD6D2443352360093F553304CAE1419049E58BFFDFFB00A892849DEB56E8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR...<...<......")@...`PLTE`.....s...... ...........1....."..3.....C..2../..H..X..>..B..K..^..k..X..y..m..z................U.Q...6IDATx.=.....A.K..F.........=..Lw+I*U....R|.z.K._..0$...h.\.Ik.s.........sr..TLC^?:.N..h.u......./.....w21.<O:.....Q.u..7...K..^I.8../.........m...x.T....b..c.....]r.....D$A."....4.5.V..a....DZ..z..lg:.Kr......RJG..>.......M.!.@.|...X...dj.M.b.....x...&..y..!O..$j.."5YM....:.#.."gn...S*...:.s&o.m.r .. g(.......H.8?....`[c.....'O..J].f......c.....K*...8S3@..^.DSF.....@M[Fm..S.G.o.zo.>......).!*.u..)..>./.9...Cc...z.g\.ey......kcJ....!..?....5Ig..p....|...z...;..f..4..t...M.P. .g..T......r...}...Cj5.D%H;8S77..l.\s.78...@....s:c.1`...*..t..'.w....................5Ad...*5."]...Z.~..S.@.....G'y.#.z.....Z..:...@...i.|.....u.S..:!.*p...P;.9...4.Be.E.ZG..-.....c..:b.(....g.=rR<..o$..q.f......m.........4...#...b... ....C..j...5*ts....,BcQ.W.1X.U.......E..9Y.J.1..<.y...e.S.^...7.s.Z.CX..y...,..5.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):240
                                                              Entropy (8bit):6.542858130603722
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPW/sj+aWdKcnASF6oBgB6+cs57kvZGe0Hv4gfK4dp:6v/7uk3aZfFRNImZGepmz
                                                              MD5:F93C1E09DC0859289D652FF5E64F9B7B
                                                              SHA1:45B1899CF21E0744AFC9303C391996555E889405
                                                              SHA-256:C20798AB61B591F83DD6CF5DA97BE1C2A0B45ADB7ACF8C8A91186E62BFD1D2FF
                                                              SHA-512:02F1640F5FA5A99D7ADE18211461793EA3B1F4358B3AA8F57BC6F07C8BEB6BA71249DF17B713919E4A1E674B8AC4664BD98B9F2CE29CB8F466E686163A9D4237
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............V.W....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....}IDAT8.c```.O......F.". ..A.A.\;..}?w..._..3..=`6.....6.,.............M...M.......7....X.v......Ez....(L...A.@.../.X>$.......gR.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 18 x 18, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):282
                                                              Entropy (8bit):6.749845265114627
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPi3sj+aWdKc9E66EFcDvUOL454DPBcZaLp:6v/7aOaZ9XPFEvBWOPBWal
                                                              MD5:6315C61A230ACB18ADABCF018A342F0D
                                                              SHA1:D94D92C8560D0FC391A96AB7887B828610A3B0A2
                                                              SHA-256:03E217B1EB5E03E2917DA62134DEB0D3E5D7316148A23364B8CD42089BF99A28
                                                              SHA-512:B56DDE8172AE74D106649550AFEB51ADF862447C7C89A45822F7BE23800AB338B0F8722743717F50BDD31AA8816B302154FC1E46D3FA4F714EC7C6B34774AA13
                                                              Malicious:false
                                                              Preview:.PNG........IHDR...............F.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT(S}...A.F..(. $$.8A.8z@cP.B...@`h......q. >.B..9.q...}.E!.,...6&.......U..Ml<P.:.[7u1....4.t....7?....+.s..W.-lS;.......C...@.F.LQ.....E.wM..j.F..5....@y.(.7W...........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):650
                                                              Entropy (8bit):7.525427473885113
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZBfrOPSV4jo+HvWCzb7gYwbhcS9j5c5CooDLbWwE7FAYy:HaMSwpfHgVhco6yDLbMWYy
                                                              MD5:32B5AF351BD79608E0B57A7AF52AF882
                                                              SHA1:AB99613C540A1F58DE446F462DAD45B615B900F1
                                                              SHA-256:FF9A453714CD54E0697FB29C3BCFB00ADA60E703AC533D174D3B3AB24E03E045
                                                              SHA-512:22B99255E587800F17D3CF09F01B24C3E0653370EEBDCA8C4B9244E6853E3A76F57FE9677226FB39D07E2DC5747C8E223FADBEEEC47D333CB385D20165855FDF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...M.Oa....0...z.#5...F.FJ1.!.K4...H,.B6..b...[...P.4a1..c.."Y........al........9.9.a.6hp..d.<..d...........]j..557....Mk........#.f.F.gc&...-.(..l.ZL...v{e...l........#7k~x!`(v....4....R.B.......1)'P..tc.......Q.f..c\.q...?....B......q.o.S...4.^<G].^..............k...h.[.....q.g.._.6...<.;!..C..?../8........H=..$.&I....AD...Q...bTI{...Ab...p3..W.......&N.&..".Ax.wt.W......`l~2M.-y....Akt..(..Hq.V..i....&Dj.1#...]Q4...?..$9...3.......V+...9.S..%.0.E.N.....#........$..?y.6.K...cn.6G..*..4IN.C.?.o.'v.U3......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):584
                                                              Entropy (8bit):7.443760110402973
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZot2v4QU1zBv7P9dLUgZbpWupPzNw6mxZH/08t1P007:HaW24hlB7VGgVsup5wF5/08te07
                                                              MD5:C3C3A26EF1B07274D60A2E4C4A4B6B5C
                                                              SHA1:F025C2014A32F582E7CA6292A9B1112F30850BB0
                                                              SHA-256:1A1E6244841FA12D283D584871FE4CF9EBB5894FD0C1F01D0BE6DC466E6670B8
                                                              SHA-512:88CABC63789DE2217B56FDDBE0A417CAC3A2322141C0D061D9AC7A3486E0A6943B9D9F6E47C198D75AB7999751828EE526CB62DB2BC28F76389F076588D97C74
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH....K.a....&......m5.dB.D..*..HHT4D......A-.$T..A \...B.eI.Dp:...{........y..|x..a.Xs.e......{U.UjN.$.b1x.^.,.[+(..p.\*..w~...fS...x.7...h.....A@.T.l.Dn.....r.W...5.].a...-"...+...9... .2.k@.G.%...... .N..8.<.Q..3...om....,.~?.v....dRwF...S....T*..e.*......?..h...S..\...*.d2.....4......H..C.P...A...m...M+.....)f.X.......&.. ...a.?y(.L...x...N......N.\}.u..`....br..o../.G...X.@...w.\.b....GO..bZ@.w......s...................%k..V..H...7rh........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):209
                                                              Entropy (8bit):6.261838814231255
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcFNyLk1p0sWwIOQdReJljp:6v/7saZbyL5s8RkJlN
                                                              MD5:6CA3B19B68C7FA450B3362F5B0FF8414
                                                              SHA1:BCFC66DD1CC0A4E15C1BDC102174417657A5176F
                                                              SHA-256:233240163DB2E1D94FDF069A93BD627EBB2C105A17BC80AEEA26E776D1D5B707
                                                              SHA-512:D8A6761172F7F70589BDAA7C8E59CAEDAA69B81BACD690C7D897E6A2DCB49B267B20B82881B0F22F10E51AD387273B9DB660EDD57251AAD7C04EEABBEA63AC34
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....^IDATH.c`bf.......j6....n4.P.F-...\.........UTH.A........$c.>.,.....@.F}0.Q....Z>.yiJ..........>-.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):723
                                                              Entropy (8bit):7.57625040753958
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ1N+upwspJ8n2ecPXE91cj5K8D1p1wOij5qJaDV+s0cC2nLDpC5qucjm0Q:Ha5nwspJacj5nDn1e8aDV9DIQVwyGx
                                                              MD5:B4C9FE6E0A3AA30C04C87C7B003602F5
                                                              SHA1:6144B19A3E30264167C13C09C13E27C62BEDA708
                                                              SHA-256:5650E680DCF29C4D1648FDAA45A3AD06720A263E3191068D2B32F3518EB9FD73
                                                              SHA-512:BDA82471C4118DCEDD91415D27543DB21FF075196337653C53C5424011BDF18E08FA126958532D95BDCA9E4130E71810AD1A453D0C6428707ADF78BC6118A5DC
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....`IDATH..]HTA.......]+M,4.....%...*....1.*..$.@.(z..|...."..."$J...QD_....PYAl.z..]........:...9.?g.g...<.:...... 7m./.......Gk^.&7.o&*.r....`.(.....E.c=.p.1.L.k.E^f....D.O...L...eKV.,...A..3.....h!Ql.&[ij.E..M.....n%n....FL?..<..Uf.H.$..MDC&=.:.`r8..{.5..>.-.J.T.".....!.U.^.n..iq..M.-..TI.sC.n...~.i.O....X~.%............MU9..C...-.......Ql1...c.... ..$3.2.4x..`......d&|........:...(b......s..{...$_.y.....}.m`Y>..n..h.2........t#pQ..!...A...Jf8.O...`.7..p..(9F../.....W.Q..t.p.......t...(....lE<.$...pA...%T.....;.m.....'T.iY.T........z./......!.........l.5.@.0....xY..g.fk.:.P...y.C....}....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):250
                                                              Entropy (8bit):6.638352218274784
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPUb+aWdKcdAsmIcTHjwMaMLHilHDpup:6v/7+aZd4IcTDwMaMJ
                                                              MD5:56790C420677CE6C7CFCFC7B2EC2CB28
                                                              SHA1:674393C84C23CC6CEEF18C97E50C2F0C3E4914DC
                                                              SHA-256:AF67E464FD386CE8085A0D030E02AE5EA79BBD369D209783E4B831E76849478A
                                                              SHA-512:42E46FB28F9CFBC4ABFA9A2B617EA5457E0AD9A039096E6441BB93E5EE0B6C0424137422B25668CBA7FD8E8453E15476CD8E7BC214DAB1B033EA84558E88866D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT(...!R.....7...!.L^.d.F3y..m....L6.&...F.......|.`......1.."..$...w.t..j..V."....+.A|......N..Q..U..M|..~.Nu+.Y...z.q....i.<'. 3.;..8....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1017
                                                              Entropy (8bit):7.719031051833791
                                                              Encrypted:false
                                                              SSDEEP:24:Ha7eE4xJQFF5pGcn0y0BTO+CbelXhy7iJiIfmLKGlq4:67eLrY0cnV0BSJbe5hy7iJF63lz
                                                              MD5:140858A57C162A09569D9591A6F1D2C4
                                                              SHA1:F26E7BAA9C7F6347AFC25747901F5077E860D4DF
                                                              SHA-256:026C5F82D05EC1C6DA5E6D0A14C9DCDE4D92593CDBB1A1696ADF0B3F0AAC27C0
                                                              SHA-512:F7856C3E0608C3FDE4A9807EF7C471B2AAB7B76E31E768F2F7CA90C84BEA80A601691E10F87745F7196981F7F66C235B34B2D1740A61F525FF1CB701B78EC8A9
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U.K.a........:.I97)..'.9]..X.R...Fh......A...%+.@.D.De~.>..].U.....}...^..4'.>p.s.s...;.../.I5I.J. %...1$J.<..%U....y.A%j..l./....*.0..e.*.>....L.i..[<$.2.;...].s,...^..........g..6...v.|Z.9.JY.w..X..>..N=`..#.r....bu.C*A.._..Zo... ..3,.q..j.e.7t..v.a....2..P...pHJ......(..R.!.2..5.$..7..%.A........|.....(1..N..@Hh..V. \F6ppt.bj.) ht.d3........7..EB..S........9.,1...r..[]...Ko..Bp2...rn......7.l....D.q.p.4.,..c.F7dv....c......00.}..5...R.h+.>........$A..(S.R.j...>...B.V.\.K4.'r.n......4..W...`<....+...,FA..m.m.` ...0....o...j....Oa.#.C.\O.PfP.....*.b..(a.M......\!M.?.......c..t3.?.....{T../.W.......AK..c..:uRZ.....Z&?.y..-..zl.C...2S.]...Y......%X.,..0...K...%..n:...........4..~.6X|p..cB.d7.....$t(.2GBh*.:..e.I......@.J.......P.....;.........~nD~|..e=...'7K.'.Z...?J..3...K..2~..o..^X..(l 7[</.#.t....5e.H.;b.v0&h..>rq/.?.,c`...V.G..D.../p..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):290
                                                              Entropy (8bit):6.656455341947266
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1NIzrdlOuVxJUqKxxnz0l6+PY5zbBh4WGp:6v/7saZ1NAckxJ6xnz0A5bBh4Wk
                                                              MD5:118770F7532B07D3952A4F23352A1640
                                                              SHA1:05A0C13874E6FF9918B02FC67B5334CE79A897FD
                                                              SHA-256:D2D51C0920A4C2B93BB1F2EA0B15D4590229F55CDBE13F97A921D0D8CAE7C99D
                                                              SHA-512:811A1A117CFC8973B4F5F33F635A86E0C174A0336640B44CEDA00B4A0E6AF44AA8B49109D2C81E626C71255F4312F56D198C1224E86215E824325F7B6E8255A2
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATHK..A.. ...?....r..K..(.2..)56.|.BB.#...cL...K...h..\.yiv\.=w..............2w.....J.....q[..n..p[....k.........7....yhG.1.3nk@.m...7.Q|.7u....^..M.......@$L.i=.........1..w....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1237
                                                              Entropy (8bit):7.77646665153383
                                                              Encrypted:false
                                                              SSDEEP:24:HaF9PPLwE8RO6J7QMCO/LioxcAxJ0laMKb8VZRVkmV2EqlfRRuVCuaFU/:6vzwEuJUM8AxZbqV2EqdPw/
                                                              MD5:1FC020764D36C7C31E71716E635EBCBA
                                                              SHA1:CF3F930D66EADF8712271DEF957162420702D244
                                                              SHA-256:8082BA775B8545275BC71BEC7A07A323F8B0C2400ED160C960D539199DE3EBCB
                                                              SHA-512:26260EEE077587A872B03E5582593A8EF0664F16504306CC28A76BD82837F5A362064DB3209AE6AF1773394A099162CB74CA3FCAA34690C690A87509CD2EBC7A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....bIDATHK...SSW....B..~k.!,.d7.).H..U .....4.B."KX"..!,a.aMD$..eW..R.[..*T..S...7g....P;|xf2.}s.{...;.u..[,......Y.Y.:..E,..o.....8F.-3.~4m..b.W../..,..]..4...7.Uu.zCb.s>....{....~..-......Cb.....(._...$...I...8.~1..p.f.Q....~Z"...#F.......`.M.Dh"......KH..a..$B..#X....e$.G.$Y.M:.i...,......_.3...E..s.&9..+......Q...KHl_Cv.....T%z......Rt.......?P..-.S..r$9..V.....o.!.u...o.f.F..;..m`...W3;Io7.Uz......\.,Btw.....;.....6.c......H.....M.?{....(..DsT&..Io?.5/.;#....T..0x.4n..IF...A.W.6...I{7P..-!.....>7?..7rJ.Q. Gqn+=F...7...qG7T.gB.]E23.....1..{W../P...M...%&O...'..nO.\.".V-@,.....vs.g.e]...~ ....M....:...9t<..z...3......V..OM.0}.....h..SAj...2./Q....r..9..%.a..............3k4.rh...c.|7.5..j......^a...AIZxU.m.`..Cr.OL,...#=*..Y".....u......l4.!...|...^.X;.....3.h...{.|...a(.,%=*..)...,,.>.......?.^.4.!2......]...nY!+........8....if.u..c..0.<.f1cl.w......?.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):659
                                                              Entropy (8bit):7.517554215764761
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZbnZUpXS04gdT+HiOZxAVMgstoKQfFdQFFWJF6maCFP5SWDQgdV6kpU7:HaIpX3aHinvstoZlzl5OS6kc
                                                              MD5:F77CD33941835B968DF2C90B4BFF4186
                                                              SHA1:35D64B698CB6EBA7739287CE27601B34D32BB648
                                                              SHA-256:B79B756B866DC4B5F5037B993A0669294D5DBB48BA8A3BC74B49EEBFAC05F885
                                                              SHA-512:65212BAF8CE9D5B920C0FCFC1F03281C72E686C3D88E57C45B8D86E39AF9B89D89978304FB82C039A95994BEC5D2A8C997DDF4014B70104D5451E6375E6054EE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.... IDATH...K#A.._B@.A..A..X..r......B.Z+.P.P8......m..*.kN....BP..G.a3...l.ds;ow.8.E.<.dw..........A.;......MW..kc......"f..C.#.....-f.7g.......~mB............N..}.L....h.<....D.YOE...h..l.P.g.x+zz?.... .f.../..n.j...........K..q...$.O.Vv.......Wp.....~..i.E.8)..::.*.....TRt.3;$..Sx..k.....m.0.y..q<....4....<...#J.3..Z%H...#...'...n....0.[..bM..)B...V>..SCt`:-.....piY.....x?.w..R.Q...?...KJ.=I....A"hM.+`C.._.3....}..^.b.?...x.......B..).U.H.9C....N..U..8.Q..Z.......\.....'....&.C..J...2\. ......p,.......4....,../...Lq?..-............IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):870
                                                              Entropy (8bit):7.67200330665294
                                                              Encrypted:false
                                                              SSDEEP:24:HaHPLV4xv0J1q7aRI6kmlkHUeJsk7ghDPLc:6HSOJ1m4IvmlCUeSk0Bjc
                                                              MD5:AFD4610DA6393A115F4CBAFE8F3DF682
                                                              SHA1:60A1B348B5DBFE3A513EF55BE3F42A475C28ECA5
                                                              SHA-256:7FD6E7508D3A0C48F3BE40951E5B5A3CAC710FFBC636B34BBC22083BD50C2E31
                                                              SHA-512:83E3F15C5D17DC4DEDF7D995B92BEDB461D037C2CBAD9E74582369D5F67E3CC2EEDF3686B5CB516042ACCE34E42C5698B11983C73CA27AF21BC89C4A828461C7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...KH.q..?........,.4%..D..RA..K.N.!.....5......]....D.E.=.....iR.>Zgvf:l...P!.2..........I.#..T.C....X.>.....R.d.l.gX......g..."...7..@j.|p.S.H...,..n..K.......J.....r.k...r.y.R.p.]0)..9....!.... .|.*S.H...p.o.....6?...*..A.C..n..N../...w..W..@JI..MA..4.*L..L..../.bt.......e(.1'..A6x.*.We.&.?....3C...ce....nf....R...X.....s..wjJ.\;..U63......5W(...|......4W..S...q......(X..<.e....y.r....{A..6s..~T...72....-...^..V.b..a:......y.0..o.-..tC[+=.F.|.I..ECKp......T........@..-iQ.HT.....Y...M....vW..\.y..B5..U~T.D,../....xzF..p.......r...^....rH...:.G.x34A..(..a.]....Z@\3.xe....U...XA.R....8.?L.v$....B...Z.fp:EK....%R.w!....0-..8w.'y?..w#.L...A.....,/79.....y~.'.N....#..g-.jps...6.?.......h...^x.~..i..A.".il.o......\.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1156
                                                              Entropy (8bit):7.777950812326851
                                                              Encrypted:false
                                                              SSDEEP:24:HaeTPKmVZYBRhgbi7Ha7l8teZoeOUYduJzhDihgCLheB6Y7mv:6oPvVZGLa7l+eZocYdipihlmK
                                                              MD5:6327AD1155D27DC14AA190A9093686D7
                                                              SHA1:A6EB221B98DC56E427BC162EC53A4CE52BDDA9DC
                                                              SHA-256:1969339528585083FC6CFA694913BB7694640FD277E82FDE837C12C9B51D0D80
                                                              SHA-512:EC46CA35554DAAF363B8123F65F8828C03179376C5BFBD39CE3D6FE22752BF580A57884A8FB3C9178F3989CE667E0EBD86BC5EFAC9D55447E0A3906CEDDF0548
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U{L[e....{K'....4..be]xU6TJ).x...x..N.6.D..F%.W|.%..d.d..^.m......0c .......EW.P......V@Y..%'..._...yT...aX.....Y..'....).z.|S-.%Q.h]...n...@...l.3.UAzJt@.9.b...b....4:......F.........9&....O..W.`.V...G..\'D..:........[z?,...C..d'.D.u.V....'$?to.,.t}Z...O..+._....3..[..A.q.nhZ.T...Z!.....). .!..%.....g.e.....[.=..$#I...XJQ.iZU........3.......[..9..0..Go....A...I.(..L.:l..Qwk1m.>.m...8<CS7C%"w.....g&.T..Y.../..$.6._8..:.a....`II..Y\...^q..<..f.1...1.......!......n.l.N.B.$.'p..E....Y...........^...M7..z?......k.fDlE...d..Z...R....Os..p.a..g.@#q'C.qD.....r..t.xN..5..a..FR3...#y......[.%...............9..A.W.x.1....UQ.#...bQ...._.3I.M]..N..a.cb..m....6....vu...sOAm].....,Z..g...\r..........2x.l.4`.$H^.".4c.`..-.3.}C<x....b8z..Z.. .f.f............L7.gg>4.s.m....:..3.....0..ld......N.'....K...b..bT...p.*h;Z.{..`..v8x..'/T..>7.R.ou:`CK..Zf..cB#...$...=
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):531
                                                              Entropy (8bit):7.3285789129552406
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ7ZNXiDnAaUsECLZUsL2uBwVfb/CkvfgpThO0x:HaFZNo7/tbLLwVjVvgzx
                                                              MD5:2D5E4D0268B968430FDED70E0C5D5CF3
                                                              SHA1:D71A9138FBF82F629ED3A0DEF78DBE3517AC3170
                                                              SHA-256:E28B85C25EEA6EDD302C2A5A3700356AE0094047DB86DEC3578BA3C4AA8BA0B3
                                                              SHA-512:68F4A60CF016BD880B6D5CD9E57F4A71C3DAD8D38168D2300F6262364651B6D2F99A1ADEAAA948464D0CF602227AAC924879BDF59725E173558B08B6ECD264B6
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c...$G.v32..'.@.......-,......?yyy.z...ibAqq...........nA...M}}..........c..B1,.......P.v.1..I ...?@...Y..%...tA".M .......].H....e..? ~.$......0..v..w.E%D.>...'....-...k2.J..c0#.o.....X..C...6.@^...J..w.....]Pu.....{.G.Y.F!.A(.u..t.;......k".......;.......r.....W.]..jH...@}c..[...%)......x.....*.....ik;..../((....66{H-.1,.........^.:9]..^WW.?YG.b.\..mTWW....idee.KMM.KN.DT..li.....1.,.al.!1.../@.*..H....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):235
                                                              Entropy (8bit):6.441444203662517
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1XHhCDOgRMsyHvTaMtXFc3/0up:6v/7saZ1XHhoesqvT40c
                                                              MD5:BA344FC149BD007EAD91CAE0F0CDD150
                                                              SHA1:22B94A568AEE26A2F19EB6EDF3BD25A919E0327D
                                                              SHA-256:88A8F0798A54EBE64D1E9B52C6A620783DEAB93C9F99F9C192BD5BAC8DFE7FBD
                                                              SHA-512:B68DA315C1C983DC218F26373513953921DC7A303BF8DAAEFA43966C6999CC1E2C3DF54A0CD2E3AB6060A495820AE4D88A5903E32CAFB8EE73A687E8910B57B2
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....xIDATH.c`bb..........3.......>....ZD...13.....E4.`..~..pp.._p.&....y.i.....h.....i....4....Li........i.GKS."..5...-../...G......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1148
                                                              Entropy (8bit):7.7962229428423075
                                                              Encrypted:false
                                                              SSDEEP:24:raeTIXp57oJTC8qaI1Pn8mFB/GSsnUHjqAHiHnD4TO7kn1qE:2eT6p5shVryP/F8Z9VD0OQ1T
                                                              MD5:002F8AA5E6487BFAB769EAB17E1AD381
                                                              SHA1:E55094B347339932837AE346237A09A18A28B467
                                                              SHA-256:EA3A2A23DC13D85A38E1C8142DAF6C38A6FA9AEA1D35B70FA3BC7BBA229DE1A6
                                                              SHA-512:3954E35860364EC10D216457D9023ABA7D8B1F627FD59074CDC53371BF6B05E36F6819074E34A737F8B77F287472FB846C526815F2E7A7E3A7490D3E228136D8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.....................pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..mL.U....-...i..%.)...[....P...k..!.......xQ...1.,3~.%.h..1q.....u...F....x.}4...{o..[...$On...9..9.....%.L46V.....F.h..$<.{......r.......9.M.R.....X16.|C47A4..h<..{5X...{..|+...A.&@.4...G .GQ[..._..7..`.a..'..X1h.]....r.. ...m.....,..A.D.qv73Z...X...t..w?..N..g.`....[...: :N..wB"y........#..:%)..`l.N.\..s2...'.Xt6.F.9A.=.O.@&..U.......HVD...JI.:...."GLt8Z..sJ..x.c.r...-M.+&...P..2.mG.#.e....`..HP\..*e.^|!.M..av...S....a...~D...?u....~..=.(,.....!D.s}.D.*.#....`:.Q. GZ.....c.:-=......~........b;.:.a.U.)p...3....g8.y.....AX..E.<..(.Ip..n.x^.....(.I......&...`o.....6.....n+RS...^<..0..k.......m...=..h.S...d.GmyXQ......[.Ou..m......5c...+:....6s\.+>.....{...YO._.L..f....\.....W..qbcE.D..5..{.R...-..p.W.S.....b..4o.#r...).........>.,..u..nK...T~...OI..k..../%............&..........0.|..........7..X;.7.+.....P6....n..............q.l..tq8.I"..g2
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):991
                                                              Entropy (8bit):7.682924149319847
                                                              Encrypted:false
                                                              SSDEEP:24:ra+QE3Wrr33ebPUNIEv0d5PjZrhi70avrNzLZ4Prj5DzG83zv:2Trr3SPU2U0drrUxJGXRzh3zv
                                                              MD5:C07FCA4C320B5EC4430B70E71ED74278
                                                              SHA1:076E6CAF7166255128329886A94CFE78AC8468CE
                                                              SHA-256:ED0B60F7B41A49BD2D3244AA4ABCF6B4119FE5E812617255A2734A7DFA966E3D
                                                              SHA-512:BB478600DEA79AF8F1CCA936529F404FF2306EB52B7BFED1B44D39BE45A3F6A9C993AE835B688A7A24BD2EC0A7261DC3FA0AB8DF0132DF67E3838785EC749D0A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.....................pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....lIDAT8.m..oMA.....T.Z.~W..EbA.$D$~$V........X..H...H,,$$.b.FB...$..V._.O.3s.9s....|....|.3.)..\..gua...FZ...;....V?.Hw.....s...b.m.{.(!..K3?;.`,.,...Ds4`tt..k..).{o...C.*... D.i..z8...".....^..=.2T.i.^.y......,...;C..#Af.v.j..P..*.;W...!. ..(..H.........N...$......L.g..oh.......P.....{!O.......0V_|E.,..8*E..l..!0.V..?.|.-Ad,D...l4N*........W....P.e..(.8...d.V.....kBX2k.|.U......c.(..K..6.h...7..t~].6g.`.i.........*.~n.....jq.{..=...GJ...L...Z%.]....,D..H[..c&.7...e.P)`.E.r....Y....+}E.K..-.9L.b0..r.......`..v.Ia.s.VT.)A...V.2|X..}V..I.....r... EL.C>..8&..pt.T.c..O5.WY..!VF.tH..x(.I..m.,..K....?..dC.W..xP.|(xUB9b....'...j2...7t.xX....A......<......h..\....x.i..-i.'....[.;V7...i>.k....?E.6.O`......l....$.t..k.q..A..pf=}D...CZ.<.TNM......HM.E.O.K.....vj..........N6....l...+.z&.....r.J...n.-h.Zh..-F..C..>.L.4..w......Z.e.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):900
                                                              Entropy (8bit):7.673850601276888
                                                              Encrypted:false
                                                              SSDEEP:24:rauKrjsoCd/SrmyCEioFT8u3Aww5E4Fy+:2HjQYkNodk5E6y+
                                                              MD5:8393CCCC2CBB476579353FACCFD27301
                                                              SHA1:93977C721973326E4DF51C02ED49F7DBA34056D7
                                                              SHA-256:850928AF483CB7777B661BFB39F7404F32DA374E64F2C95E1382E389389901E7
                                                              SHA-512:2A34C3397D6725BE7AE6FFC568E40EF03F6CFFB1951511AE6CDDA843BC6393468BC79E7A23DFCDB69911A6A46301C631FE237ABDD9EBBD688250BAE4254FC9B8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.....................pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.}.OH.A..3.o..e...4..0..Q.C...W....u.R...[.V.DT...._...Z.K]..H:..<.|>wgw...]Mm.....g~..f9.i....../..r.O....O.wG117..3..T....%.q....'..H$.....g.k.J..`..E..g.q.".W...|..B2y.$9..k....]d:...,.e..H..;...<.e..+.N..r..pP.).>. |h.?..mS.ZHq.%..3.S...U..V..v.&(a,e<^3a3..`6......N..U....l@.I.H.$5u..H...(C."J.......>...r..^.Qa.T...ys:.6..f6.uW.qM]y.-.....V4\..XI.lm2.6l.Q.(...hLB&..?mCM....6.mT..&`.....ku5....s.9JY..4.g..P.I..7".32o^S]..Yk...e.h..\#.(...P...y..\.Vq..da....J.K.~.."x..B.2/.P.......PV..RT#.Z*......e....{w.0# .g_A..E$'...|.}.......#.R. WE..cX...X.!.......!E.}^.V).%..W..u....=.h...bU%U}..6\}P..pO.b.%.....s.......^......f.M..`..&..}..A/O/..B..C)...Q..BH(..L..'.|.X?..C.ug.F.I7....|..>.....<#.$Yk.Y...+~.+.`."@..A'...`b.D>.#..$.N.}?~..n.lsa..Z.....CD....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):363
                                                              Entropy (8bit):6.930901404804559
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcZinYcYiLTlK9W2sLkwlhd8dDh1Tqs8aQ8oLOs5yiwfDO/1DJkg:6v/7saZZinTRTl48Ld8dXQEsuY1ZN
                                                              MD5:E717D3ACE4F3A4CC0F19F0F16AD77C9B
                                                              SHA1:6D57E2D8F7AE675CF02280039AA1E8CEB86309F6
                                                              SHA-256:7692948887AAAA9C26069968CCEE53499AC5995EFB651DBB0AFD1FA98721B331
                                                              SHA-512:46670EB321694455A525CDEA50DB6CAACF20966F03BBC4600733C1EDEC4C60BA0402D506642EF4E8AE342A53204274C8E33DE227D5E70662BFE894294EA79355
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```....i...1..?^...}.....U.._...y ._.......U......m.,.....=j.H........\X.@....E-...j.......r..`..#...[..'fdd.....o.......]aL.Vd "...b]...F ....@<..yhe.8./..@..@C...7.x3.....N n..@.....H....%...`f.L..........C...+F@...h.an....[...D.1..a....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):335
                                                              Entropy (8bit):6.7357667016278135
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc+Aw68zIyo7kKoXYrKHJ/ooUinLoheHUZrp:6v/7saZ+A1EIEK1k/cicgHUv
                                                              MD5:532FF39D96824E846B94267CEADFB2D1
                                                              SHA1:96D8BE5BB519EF062D58F502BE22220E5BB1E565
                                                              SHA-256:BCFB8AF5F2A65943901077D905295D35DBF2AE06F2F62BE926D3D33957E103A9
                                                              SHA-512:AD087A5C1E50E454D9FBAA2F93246E026063B629E9153FD519EEEA46176870843C2708FD2162AC7E7AC8E7C152554699A5F67E1A5FCC00C19868677F7EFFF47E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..d.3 .......`.X ......o.bi.x0._.._.b%r-.........PK..q.....? 6$.W@..e...s ....H.I.........Pv.48...7..CS...\..=Pv....... ...7..G ~FN...b.$.6..B]..|PZ......5S.34n@....ki..Y.X.J........!....c.C...F...........G||.&9.!....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):340
                                                              Entropy (8bit):6.7888357277761395
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc7N3SXsnkhkoTozQWnfJk7kKoXWc/OA3m+RGmdANp:6v/7saZt8kz3fakKlQOAWu7S
                                                              MD5:0CB0F22816427F3201F4CA37CC705DC4
                                                              SHA1:55FBFC7E90D13EE02AC42351557F6E8D8A2B0475
                                                              SHA-256:C5108D1F42D88E3A9E5CD68EB8B74FC3D13E26EDF22B1285D10505ECBBF7ECC7
                                                              SHA-512:3F3AAFE715120E9743CD7BE582759450CFC5832888E444721934CA840FD213BFD614A02D1446498F6D5046408304BA04A7EAB5E64195EB77607C27FA6B37A873
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```...7...h.*.n.2....>.x......h.D ..-}@W.d.x;....m@,......P.@.Dn.m..eP.W..j...8..........W@..e...s ....H.I.........Pv.48...7..CS...\..=Pv....... ...7..G ~..(..@..]...@..u9..Ai. ...".,*..q....@\K........+.F-...p...B|.........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):232
                                                              Entropy (8bit):6.293423098250012
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcvfGSFegwRcxvqTMFS1p:6v/7saZZKhq8
                                                              MD5:C6BFC7B72C718727C2BF87766F7800B8
                                                              SHA1:B122ACD8D0AF84A9D8980B3A5F48F2DC3A306009
                                                              SHA-256:D74FA6B34AF3618EBA78F301727878259A53F8990D6E6297D6E07E183B93C296
                                                              SHA-512:CEC41C876F4347C45377193D6C96319BC4BDC7204472B61E40DF99963920B2659E65B9C906EB97472064974B5194B88333923EFFD81C06687E14208550AC44F6
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....uIDATH.c`db.......j6...i.I.UTP0.uP..H..S..$Y@.&.Y@. "..X@.<j.., 7..d.,..]....`.....V.....X@. .~9...n.z..=......-...M.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):246
                                                              Entropy (8bit):6.474495464903845
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcZwaRmNNhAYPY17ipmvMgl2dEPUTPK2Vp:6v/7saZZ1WNBQSgkdLTPK27
                                                              MD5:7E3565468855774742364E5DD622C024
                                                              SHA1:9E45BE9B0AB3D4DB30458C075D90469279C8CC62
                                                              SHA-256:8D758CB95C80536B88655C8BC8E9C818F7E5AB0CF79C7048345932F833AD1435
                                                              SHA-512:5188EB71C722CFF934A7AA1EF497BF7DB88B22AE683175032311B9A4EE3B3C07288BC166A66D11605D4632F84A6BEBC7072658F3B8BC2A60E75B033431B06073
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`fa.......j6....>..o....P...H.0..2.-........X...)...- ......J....AD.H..DY@I8...h.D.(.)*.I.3t........ ".. 6.)....h.l...RKgPMZ.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):387
                                                              Entropy (8bit):6.929897289976686
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc9sQjOUzQuYHAPNQfKXaXWXJbZP1pwlzFh6CbMM+eY7TWEkmysh:6v/7saZ9rjOUUFHprmbd1YphLbJhAD6s
                                                              MD5:BBB4B37870F6A541867E9110D055B888
                                                              SHA1:AEB373F055D745985DEFA4CB29FD483808A7650D
                                                              SHA-256:A75E8CBE29277EC6CCAEB0227EFB80EADEBDF550B91AFA4AFE11084385EC325F
                                                              SHA-512:547FEFC1586854F815784852252C38EB275AE37A8D1D94123D09877BCB0F160635F44DC5484BD5D3A9BE2DEFA620A16F4A8859085C08D964091D1C8D5E777246
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf........C4..~.$...4.8.Y./........M].G.. ...E..0......v.".....>..D#.t..Y$a|..G2,Ba...p.].g^.....E.......d .x....rr...,,,..Z.../>< ..|E..|.<`...s....01....;\. ...S.\.o.......).$.../.( .....f.(S!.....y;._.a.a...9....0F$c...#.q...@\.X0L,.wn?F..e>.Y@NQA...\$.v.cS..r.t~....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):184
                                                              Entropy (8bit):5.914742316746099
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl9vt3lKm6Kp0qRthwShLKOWGEVwfZ3lI9Vpqqpqc6Z8By2JPSdp:6v/lhPa+aWdKcfZ3Brc9Byu6dp
                                                              MD5:E583A3AF6887154119FF083B97CE6588
                                                              SHA1:6AD434AEA5E009878008E6526E9C8506D02F897D
                                                              SHA-256:0A5B85EC82E5967D3EE4616C9A78D5575FF8B58F673ADA6D591767FF0EB22AEF
                                                              SHA-512:B4B444340C5463423360CC46882FC44E9230E5EAA6352DE1AACB141FB6E3EA4B76110AEE3C0385827A732B7CB790C2E679D36B1A644506172A9944416C16DA2A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR................a....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....EIDAT8.c`fb......`ZT....0.O|.F....C.n`..N..`.........0...".@Y..,.,.*...RC.e.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):217
                                                              Entropy (8bit):6.353147907859688
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc9hkozcySr4le3S769Tp:6v/7saZDRYbosS7A
                                                              MD5:F08FEDDD543516EAE3F7B62C9D83BAC3
                                                              SHA1:272ED041DA4380BC804873AF98DDB04B92A13CC0
                                                              SHA-256:2EA354C977EFDD92D0EE9405C2C6A6C7C64F3AB387A3C028B96378EC3EA286D8
                                                              SHA-512:47617D22B303F8DDCE683645CD1F4374AFC06FAFC1611EB9B75CBC565A54722EB96747CA65DE6D938817BB1C2055C8C948402C983B66ECFC4CD08BB2E75916E2
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH.c`fb.........e..L.j.a..R...1.. . .&.]Uq7.....ZY....C..P.0..V...O.H.....h4.....T4...N*R..Z@.f..@.:..<.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):246
                                                              Entropy (8bit):6.52071577801275
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcZwaShtwDzoAn+N7NbqU74mLl/Vp:6v/7saZZoEDnuNbv57
                                                              MD5:CAD897172B1FBB2D28F561100E7A7324
                                                              SHA1:7041424F657C2FBAFB5F80D0F836F5333AFEDF3D
                                                              SHA-256:363643F1ECB47F52893B5B3A900531272D07779830F5E2E9F0B770D72D487C42
                                                              SHA-512:605A567675C5A00CCDC4BFC89C02CE47E59EFC240FDD07F98636ACCFC43EFCE3FC6DE68A1311F72B7E5610F68E88CC94CF6055895E6A2537AF6266ED32CF99C1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.cP..Z........E5.0L.....1....T..J0.B.......]..}....c]..n..8....A.T..g$i"9.p...........%..4.....3.".o..a.6..Rv....u5....8.....7.OA......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):674
                                                              Entropy (8bit):7.4988813850995175
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZJjFKLsJxU5iYxSnez99FtYkViljHxjAMxmt8uuYO56tiSz:Ha/oLsJxxMSnez4kEPkMk8pYO56tiI
                                                              MD5:EDACBF218BAA4FEA8ED05033B79B143E
                                                              SHA1:E1FF7FE0F851501FED10115C7A84E3A5EA5C9890
                                                              SHA-256:51D47712D9CC1ED869FF435A4CF371C270E56A4F1FA6E229A45C839D5A1B21BF
                                                              SHA-512:44E7875D147AF1B6BE38C69BA422FBF38F5775B637EA2FCFD73DD2CD66A094A0796B747676228FFF69EF28892EBBE6573DDF8220D6BAB135D56A952E8AD6EABA
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<..../IDATH.c`........D..L......................d.Fn6.%..,..U...O...0-..w$.._....f.;...`Zd.....P..Q&.\u -.......P...p...wv../@...5\FPP.@Z.rb.E..=..r..Q..Q.j8.v...]I......$G.?....[...8;.l.Qqt1.L&...Z-...cx..jG..D...`z..j...........V..2...Q...vSU....`..N..S...S..`j..(-.......p_.[..$=2.....lO..........B}.ha8.. .3..A.....+n6.........mA....>..C."".EU...}..D....\L.2..%'..PjT/<'....67;...]...J...QJ;`.UB..A......4R....*XJI.......0^.....\\...l_..!9x.8'.9.Z.h{......uu....CiQ..4.......V.(.M.u.g.P..3xgR..ge.......:.........?..A`S.)..!&....3"...M&....2.e.1d.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):541
                                                              Entropy (8bit):7.443697536656715
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZL0OLP/kHWULBku6CwxDgtVReWwoBDJq7f4t8qF99:NKah0fLFsa/JwcDJq7+pN
                                                              MD5:A475B0E24EDFCB5F56F605AAC8A368C9
                                                              SHA1:E915BC9E44218F1944183040F26622629C5C6669
                                                              SHA-256:8C940165559EDD3C72DEC3259EDCE529B6BB3BA4E8F52C1AD891D2CEFDE11628
                                                              SHA-512:0FEA7AA3D3D00C40FBDD62ABDFCE72EEF93939590BD1469AE34EB15F01440ED52C2C8B947B58EACED86CD418CB04BBDDFE70A39C48FCCDC756B4BFCA8E4D0324
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E..@..Rm-.%.9..g..^.3.de.. .=)....=)......._.p....?.....A.2"........i..no..7......$|.E..Y[..{..?!.....)8.J..4..1.@...;...c1....I.........=..../o\.O"p..jt.A1.MK}.Y...o.y..(.)...q.?.....(.Y.h}....n.X.b...K.0.....(.].=...]..$!.b....+./.j.U.<u4P.jp.q..&.....s..A{S".DE...C.AW..`I....;./ ..o.6.....|...My...i......H^rqZ....cPV\...x..,.Z.l...hc...o.N`Z.z...;..{ej/....Z`..z9.......3&qqp(IJ....t.O....k.Y..^....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):578
                                                              Entropy (8bit):7.38626092430479
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZVF6PQlsbsrMM1Pfbds98uvw2FKcxAS28dkc:Ha0PR9M1PfbIAKKcxTj
                                                              MD5:69B9DBE4EEDCD554CAD12943EE58547F
                                                              SHA1:1D63EBA859CC3C088E30598751F18D59FFBDABAF
                                                              SHA-256:CFA5EE1FDDF0C36165B79C14F4510B03C0F753AC3C1EDD6361943D85190B41CE
                                                              SHA-512:FDE3DBC8A64632CA695500FA3488DFB3BD018501318D18E25F477E3DFF9E357703A6306B864DBE51D7590F2518ABAAE60CF5F85D2D9A2C2769BD209B4A456D4C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..@..{.7;.3.&..I.zs..EG..P.J..1.Y..10..L..:..uvn....a>.w$......VA.-'..... R.f.de..+!...0\x....}I..m...D....2QST......X../.N...k.....V7..d...K.}v..1.i.....r...I....q.5.'.].........4+..t.v...vf.).`.0...d.0,.fc{.J..Z..R."0,...=1.*..N.(....;..a.............`.0......d.}.....(.....?/;.zl.4L...(.Ez...Y..,`.bcy...D...1~8s2.Z.N......X.D.k]!X..,P.E..q...E.....~.J....|..*.AE11...*...DJ.....`.....7.........#8B..G..j0J......(yP>......D.r.......`..F..3........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):290
                                                              Entropy (8bit):6.61847269335982
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1N92z4Hs1gtH93Oof2h83Yltmox1bg8DsENp:6v/7saZ1N9ess16H93p+qoltmSu8Dsw
                                                              MD5:04E012CD1CE292FC0FD10CCC0E34D3F8
                                                              SHA1:0F4F564426001D9D3D6FB3C81C88BBB9D774CEDF
                                                              SHA-256:3B16633A3BB07E09FFE90B76BC9A51D89EF319FAA2B79C89DB5DB3CED7A6A3F7
                                                              SHA-512:F3AFB9551A60D7D74104A520B83953BD47F9C858C36AC63C88A217C8A6ABCC89B1033BEC625DFDDD1C4584A41D638DA3DC6F14412F119BD479D559A89035D0B2
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf.....T..G...~.d...x.8.Y.[2-..A|......;....c.%U-...~.@4M-.E2z.S-.i.L.aN^...dFff..DY.R...,.1.D[....w.yUp...(..d...HS.@rX- .4%..bS.L.M-.E2z...d.- 7..Z0j....T$.4...!..S.l.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):927
                                                              Entropy (8bit):7.674600493975985
                                                              Encrypted:false
                                                              SSDEEP:24:HaofdY7h6daHwKlYXMU2fSXaj3XFfGRRtP:6oFC60QKYcU2aoFqRtP
                                                              MD5:67A41061A03844FBDC9E0A33F1731E5C
                                                              SHA1:375D0CFE90F3C1FDB2AFAB06DDEC6A2678F7BAC2
                                                              SHA-256:49E4CFD6C8D5DE852AB88A34137348253E7B915813E41B17D0A5BD4D8A26C010
                                                              SHA-512:8D630BC7D80F899C053D4DFB9FC86A80E67C9C76E2248CB751E3829265DDEDA26F5E791071941D7C7DDD188A32925ECB11F38E5462B0DDDC1DCBDD96B79185C4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....,IDATH.TkHSa......ls+77.5B,#.b.n..(.L..V.E.....$..F.d.p...h^"...A3).2. 3.b..k,Mc..s.fts.W....]..<.{.......ai.ZA.s....ad(d4NZ.#.JA...4......(\.tXp..Rhb.Q.X8.0."n.....Y."....-...D.#....d...FP...B..#...D..$.........1UA}..L.]"....Fyp.;...b<....G.rX....Q?...F..f.......!.=..`%B^.!.[2=.......ZhU4....AF.tH*...8,......y.G...............|..M..,...]j..zL..T..}'.Y...1:.v .{..6.../".O-.,...F#F.LH...._~7.."A.&..v..$..n.A.49..5D}U..+..G...D.:..x..-.r1.K#....c.b9.....b.-.O....}...D.2....%.A.9=!(X+..d.K.",.=.v|..!f(..E.v...(...]N.....h'E.(.>...L..V..X....+.m.:G2$...p..K.t/.^/..F.I.N.."^..I#.MJ(d.7..3.z..x.J..x.p.LB.G....i).Q._+[.Ve$.g...r.`6.0.y..wk.s.jL7.....e......TWW...34.b. .j.........9.@.D"..j5*++1.}...!.V.#.^.....f.GN...2g.mc.....nF . ...*.}.H.9x...:.....^...m.m..Z4...[..V.v|....o.`.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):259
                                                              Entropy (8bit):6.636436356860917
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKcBIusgGTFm7Laho++6jwh9lbQzq8llbp:6v/7aKaZBCm7mhRSQd1
                                                              MD5:B22301F43B6332418B119E9F0A76944F
                                                              SHA1:E1C64D59C00A14A2B4B67463FBFDB385A9BE7654
                                                              SHA-256:3D3BBBB58E40420981ECAB1361A0B78068775F723EB684950D4D3C78A5D9A5B6
                                                              SHA-512:FE206A529F48ECFF5FD1C27FD9E4D2D183EDA2143270F2F8385830CAE7C6E2D3C432CC31DEC4528044378166755D4062A3D04C5486D69FAB9964B68C8C992085
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E..0.....nf0.....2.\."..J0....{..0.2........MD......C......=.....f...@O`1..a..I2.g`.];.......5...0.............e..D..%.,yFVQK!....lmZv......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):541
                                                              Entropy (8bit):7.443697536656715
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZL0OLP/kHWULBku6CwxDgtVReWwoBDJq7f4t8qF99:NKah0fLFsa/JwcDJq7+pN
                                                              MD5:A475B0E24EDFCB5F56F605AAC8A368C9
                                                              SHA1:E915BC9E44218F1944183040F26622629C5C6669
                                                              SHA-256:8C940165559EDD3C72DEC3259EDCE529B6BB3BA4E8F52C1AD891D2CEFDE11628
                                                              SHA-512:0FEA7AA3D3D00C40FBDD62ABDFCE72EEF93939590BD1469AE34EB15F01440ED52C2C8B947B58EACED86CD418CB04BBDDFE70A39C48FCCDC756B4BFCA8E4D0324
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E..@..Rm-.%.9..g..^.3.de.. .=)....=)......._.p....?.....A.2"........i..no..7......$|.E..Y[..{..?!.....)8.J..4..1.@...;...c1....I.........=..../o\.O"p..jt.A1.MK}.Y...o.y..(.)...q.?.....(.Y.h}....n.X.b...K.0.....(.].=...]..$!.b....+./.j.U.<u4P.jp.q..&.....s..A{S".DE...C.AW..`I....;./ ..o.6.....|...My...i......H^rqZ....cPV\...x..,.Z.l...hc...o.N`Z.z...;..{ej/....Z`..z9.......3&qqp(IJ....t.O....k.Y..^....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):268
                                                              Entropy (8bit):6.55143743125411
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcDN92z4Hs1gtH93SeQj6fr5EbEn8up:6v/7saZ3ess16H93Rfx9
                                                              MD5:0B4A6BCF1B7F3B6DB8D479908582E1A1
                                                              SHA1:1371B68733E1B9238969509D051E98717952C730
                                                              SHA-256:0F72CD8EF488DCA7BF8FFEFDF3DAF0C72C46EF6989769C8A5A03C56A7BE77E37
                                                              SHA-512:928427CA6A9ADBD7B1C9F1EFE0EEEC0AAA2ED37BCCFA85D799538278EAB90AF3EC777CA6FA2836C77AF224D2151FAC4E794CA2A7BB8036A3D6D01C5863B6D829
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf.....T..G...~.d...x.8.Y.[2-..A|......;....c.%U-...~.@4M-.E2z.S-.i.L.a..$LRfdb.L.. 5...$c./......q........c...)%> *....r#.h..M....Z...-..*M..?.8...|....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):931
                                                              Entropy (8bit):7.727893120799397
                                                              Encrypted:false
                                                              SSDEEP:24:Haf2bWSbQLIFlACUuYXGGIc3Xde/TvAg0SkrdRJXiGs9:6ua8VFlvUuYWGbcA3zdRJSGs9
                                                              MD5:D1FAF83DDD2D3DB762FA66400F3AD981
                                                              SHA1:529CFFBE0C1A8EBC5D08FB666C9ABE78B8A3C483
                                                              SHA-256:56797304D5F0D0FAB060096CF9684BD68E08A983A23B1CADB6D70FCAE1029742
                                                              SHA-512:777836FD29AA3E76006E1F5392ADD5FE9025776564E3924D513737D001EE6A721D5A65BD0C46F53CDDA9444798BAF10FF8567093D3B645755DD8160CA986D8EF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....0IDATH..kHSa...\7w..P[.;j^J.9.a^..K.tSC.9.)..d...).R..B&.2. -1..~....o.%*2.n.>.g.9#..|....}y...y........$..yBb.=.9..p.h....&....p..t...h.#`.Aa.,H..o...>./.`.].f'..%......[.S..."i.p@.e.~..3...iq.^}j.+.......s$..p&.8^.#..4Pdn~..).W.xiy.F'z..u>\...Y.t&.........$.U..*.A.6.z.o..!h.)_........r1P'..f.Z5.hT e...!b].Uq*......A..UG..DB..<Rlh....T.[\..b..UVx.$......".....T..\.0.....6...,`$....c...<.......No.M.7.A.f.(<..T.'..';....6.z.;.R..k+=..(..........j4.}...<.9..PJ...l..U........,....$......D...h...oOv..c.(?......P......R.Zy.J[n&.)r.M.9.c...J.N..co?/.k.. q..l.<.S..$D=...~.."C....a....v.Z.7ZM.pUQqqdH...[.H.flr.....,..........{...!.Q}E..F...!.S\..j...rG..}e.$.U.M.......1.].{...`7.( ......~y..|G.X.V..:2.#B.-.C.......".V..Q [.&e......,_S.D.O......n}.......3;.u^."......t..7.7......o.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):844
                                                              Entropy (8bit):7.651683816838416
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZ05zJr10O0TpWcALKtj/CS3jhLDEbcsAJAXaVINYntL1ceBSk3:NKaOj1+pWRKtjaAh6c7JzISLTBSC
                                                              MD5:AF9938CC5C47683D03024554D510C1D8
                                                              SHA1:11807D39596C39B63B63C513B6346ABA558AE509
                                                              SHA-256:BBA9239D1064EE1818FFC0BF018ED6C106BEAE2C94A8B1050E69AE775AFD24B9
                                                              SHA-512:AE556984C55CEACFBB82B7A309B08339350EC10E61362D0FBD27C33EA850D1098C4863458D013CD921A23850317C0A7DA9257084FFC00848B73E2683AD946D7F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8..E<.........n.$. ..Y..H#.&.D.k...$...bb.?/...7.....b.........................@....'%"..D....I~..O?.......s.v...p3q..4."`P... ....@.....^.........;....p...D..my....4he....`[[....g...+}...x8.n..)...y;.4...*4.......W...6.4......,.q.T.d.1..N.:./.S....A.i.!..8..............0M...j.%.k......".|.]..t...QI.4Sb:L...tdE......xS...8....$..XC..k.k)!*.U.`y.`....".....A.Av.V..k.mC..i:..`Or..Y....P_......3..U.....Q..8L...jw..05...;...''...$$8."|.yh.O.:..32b......$.Z.......q....\.....7...........k......P....j.'..........6;)..h...H...M..<....?...7ndgf.hk.:....bP..yVj.....? +?.Q..Rlg.L.P.....L..tp..iKSS;5e.Y ....W.^..,.....]I. ..4........3..j...m......#.{IB8.....G;6..............).5..8.~....P.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):584
                                                              Entropy (8bit):7.460976541370829
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZot4eYqeQtNBKXEyEz/dL8tvTIme4Dx2qt:HaWWeYPuZMbfD9t
                                                              MD5:15D67DD421614AD563290995033F8030
                                                              SHA1:F39B51333F47A30E5FFB22A2C2537FE5F6C7CB40
                                                              SHA-256:5F94F9076DC29D0B24F82F9944B399C5F367BC5513FCF585BD4B16074C296706
                                                              SHA-512:4556A751AC8B7136036D5346CC21AA7911A1DDEAF1F98F50C11D86E16DE4E0F4EFB35CD435885952BD0E2A3764AAB10CAFEFAA7A0F368D1DE95D59CE0BD9D5E9
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V1n.0..F.T.S0.;tb.....W`$.J.....bhQ.^.R.VL41.8M......il..,}........qV...j5r.&..../....:?<"].{?Q.u...0`.F.,.U....m[..-#@H*...~'...Z...GE..le..v.|.'>{....|..:......4M.K........|....l....A@.F.j........wA..5g..9'.q2.z.N.1)WA.~....4..h.....o..mJ..Q..Cb......r..J..by..........V..|........C.o.}.&...D...x+E...........:..A.S.2... ..q.R.S].\..z.B.!.6.J.lHF$...D...$...$<.(a.E...a,.c...Txi6.|k.n6....V.U.\.d.r-...r-L.I..G..&Hp#.Of:../Ht.G..-..eA..kR....-^.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):270
                                                              Entropy (8bit):6.599121404178277
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcBwfjGJCeTM1wiKluu+yWzUdreh9p:6v/7saZB8jGJC6NuByWzUwh
                                                              MD5:967FAF10AB12D968716D34FD3BCC6168
                                                              SHA1:44BF9DA02D56B2FCF2C05D78D2D7583D67C515B3
                                                              SHA-256:DCB5F641EB8233FF5C299505FEAC8DF71DDC2DF0A5B548992BEAE62FB9375EF4
                                                              SHA-512:3720324825059029AB51127D27941E478E2736A0B1A5F096DEC23D20C9A55579572A098A116C28B045FC4EC07378F4DF8D663E478ACBF09208561986BAA59E5D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c066^..........abD.;0..P..........@.vq0.- +..s......5p.....a.... .....x|.... qb-.6s........b..TD.8.y$30...|.W$......XY..KE..H......`.G.{,.p........441'.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):441
                                                              Entropy (8bit):7.2750299273531365
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZAyz2F+MOOhUGIE9lNpSVrQGGMGW89el6TMKoaKM8r7:NKa+MlOCrEvssGGMGF9Q659J83
                                                              MD5:1450E62C558441714F6E7887140E37F9
                                                              SHA1:C2C79EDD0DF8AE8C442377CE8B78C930E1F4E724
                                                              SHA-256:DF0481CB1F675A387C2606FF2934EE1CBE8B24D65D7BEF40977043430A378E35
                                                              SHA-512:399EF31428A325461A37BAF70C8A28BA90955335DA95175286E339EB8A6F7A213BC0C72E4E80094EEC687805B8C0E0086B2991ED7FF874F4A5FE2202DB81A3AE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....FIDAT8.c.O.000.L.".......AT.........g...9..5d.&...l..+S......U.K..........yg.......4EBHpn.'\....K:<..2(7*...4..?/..1...A.p....A@....`.O..7..b:.M.G....0(.........[+..0...s{b(~.>~....A. mu.....M.c.4e......M.....3.T.p.?...AwV,..AD...o]}. ,...../.....g.M.7.....k.....t....T)....e.W.^.TW]...S`..65...&..=D.!^f...l..A.@.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):416
                                                              Entropy (8bit):7.146883608164431
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZEsyy6mc4Z4IM3q5BpkhXCbU3bRVfK9B:Hagy6B64xMfQ3ffK9B
                                                              MD5:89F6F48F4BB08E3170EB9D304CA802D4
                                                              SHA1:B8D4ECDAABE86B0F381FAC4D679F96A72725ED38
                                                              SHA-256:CBFC0CEEDB309625E78DDE53F6A3F70FDA0010A54A3E67B7ED926CF4D899991F
                                                              SHA-512:CFE72FC2BB2D4289F4D28E3184AD297EBED8088ED1E463C5CB6FFC580999474ADA93711B1658DAD6A716389E1810BEC1E58491CCB4F3BF36068215AAA7E3EF65
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....-IDATH.c`... ....2......+.Q ....J..nr...$....};U.?...u0-...........j.R.h..3|gR.CiQ9T3....c......7.........0.....9.P.. K..}.YJ.0.N...6..<...].2\iOJT.,.A4..|V..<.M.%wS.pE..0..T.sP..........j....P..9().R.()V.[tR.p..0..p...)UL.v.nls..g.`...j.z05:.9.A....?...yyk.|....oObD.-*.NP...<.l.Z.N...o.......Teo1&....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):321
                                                              Entropy (8bit):6.821435526019302
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1LzcySZCZv86JcuGQvGNJb7zypnKQwCsD7gbp:6v/7saZtYcWuGQvGjmpKlp7g1
                                                              MD5:4D9C01A44F7F8FFFF2B10337F45D3914
                                                              SHA1:8A42628DD2FEDE09E629F10EFE2A38142D44EAF6
                                                              SHA-256:450510A3A26DC0D4E4B53BDC7FB3F0F3AFA2CCC6D52C908FBC624945DB868284
                                                              SHA-512:9119D76D4AB12EDB2CEF0367C653BD9B03B98ED8F546FBB2BAA97FE2ACFB7BDED31BF992CB387C9B7FDC18D8B95C2D203A3FD9CC23C362EB0CB00B11C7DB047E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`fb.........e..L.j.a..R...1.. . .&.]Uq7.....ZY....`.^v..0o.m..c..$G.. .n-........a...1........H... 65-.HE.HF.`.E2).[.;Q.E=....zJ.HE..#.....R.zJ..,"...".l..I~ ..#.W..""#...b.Y.5....4/.....T.&*.......:6..a.}....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):391
                                                              Entropy (8bit):7.143478711342228
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ5ButDAu3Pcbc5F8bDWbPOKM4cJxN:HaQtDxt8XavcTN
                                                              MD5:6239C6F5999FEFF7AE9F5927F4C2A7D9
                                                              SHA1:C2213B812A16F5FFFEB6CA99232C32A454FE3899
                                                              SHA-256:B16D267E954EB0F966B92451979672374907C78D47455C72E5A0B5F4F0C5E6F7
                                                              SHA-512:01DE90742460659B548710460670B8E0D2BEE4A73F373829DBD47BFBB37F4A316A45162C55D7ACADAC4F3DBA5747AED227EF7D70736D740DE8E1E88F0BB2A737
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..V;..0.5.......1q...10!.....4.312...CQ..u."..*J....l:y...x\.|..**.5r.w"I...G....o.|f.qH.".E..W7Y......$I`..<...b....d.....d.`..0.f`.7...h8Sx..W=...f>U..;........0.......%..k?..}.*.....4....J...p...R..).^...=.......@M..2...u...u.\$Q.y.M....T..9kL.........x..Q..F..Q....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1239
                                                              Entropy (8bit):7.832004468327275
                                                              Encrypted:false
                                                              SSDEEP:24:HaKOAg4wwlCCnguCG6ix+qJFOmsLjZzrN941Uw+l2JX4tXHY/rFMFz:6KjCNlG6Y+qJ4HZX41Uw+wJXKXOrFMd
                                                              MD5:CF4B6951FE123AE03E02ED33F473E3D6
                                                              SHA1:5A62ACD07018D0CC72015FA1856F5BCB323D4D44
                                                              SHA-256:71290249E192C85E9F0C75648E87B21964BE256818C4E570BF37B97D542DF862
                                                              SHA-512:9542A3684FE39439F71DC41662862BEB3F8531AAA62EE65DAD30F5B7574DE08E23631BF202AA206DAD044DE8138999E8598F70846F09BABEEA9395F309BF3389
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....dIDATH..{L[u....}...>..-P..=y....Dp8.2.c.J6.+...8....hfD.'s.....04c.TM..fdY41N.F]..8 .0..x.m ......'i.9.s......."../.'.=v.>....rib.K#...Dz.........y...a..!....Q..lV.u.tkL'tu).<[,.4t.J.,.Z..@.._.......U.d_............%...f.k...=...j.\~=..........c....U.h.....a.~?T_6._...^|2}....p..K.*X....H5.u..w...J/p.qvmC'..Mm.2...8. ....nZ*p....,;.q.MT....d......$.\...@(.E.}...=...r...J.-T,3.>+.R... ....*....oO......E.@.n.N.....E....Y.J....6........;.F..B....k..#..C6....>w........-.~.,.[.U12.f....4.=.".(.+.........<.....F5.j.*..?......A.A...~......9..-..$..GT.*.#...KQC.,U...c.2..7..x+.K...|....z.S*.k\....*.b..#....'H....x...0.W...p......Q..l...{}...J~V.c.c...XIQN......zF.<%w..5.J.T2..!..dY....6.f"py.>.T?.?.x..+....w....e`.E..V.z........7...oNK..)../.f...s....$....dy.]3H..sL..XDa.#+U.....+H...#.R.,C..j.x..<..~.,s..y.V.]..*...U......AW.(.^;.__.7..`1j..z~..J5.<)..Y...M.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1278
                                                              Entropy (8bit):7.730830042212621
                                                              Encrypted:false
                                                              SSDEEP:24:NKaB9LrOJHWj16XJ2SDf1ApR9dqs7hONxqU38NXkn/RMis4pFuaTNKKsN1B:nB9LY+1UJApRPixqUMNXknpzs4pUa8Ki
                                                              MD5:64B58FA6866A112021A70761B448A33F
                                                              SHA1:1A1CA94680AAF18B6B03179389BC4DC4EA90B6CB
                                                              SHA-256:7274BCFA312DD4C702DE853410A39AF1E80C74979BD6DB18BA90BC8DF428A9E2
                                                              SHA-512:5F72397203D6B42265961616BDE78A01DFF9CB6FCFBEEAA9D4A13CA6920C2BBAF7D84CDF309B6F52CE5061CF57484640B4DEBC164DB6481DF3A7AAC1DC84056B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c8...2.?......&..^.`km*'%.i.wW/../..3.q.....v^z.k.^.=x`.d...(#../G4S.O..u+/.KG...7...../...q.0.d..........?~......<'..I..!.......p_......Z.E.YE.x'..}...d..4...`..........C...^RWW''..k..azJ.k./...)...f1@l;Z..dg.#/+.................K...)J..../..n;.s...;.r._'.y......'.p..TEY.._....>.v......8.w..%.............t.6v...Fzj.....M.......8Xn,..........4..t..A.O..k..n....._........;.t.T.CU..\[.)...z... k.......A..........$.....h...+V.....4..LlB...}M..r._>.?^..n..PWm.{W/CLY.`.....7.$D.f...M..i.!..k...52z..k...~%"A.M....H.../...>I!...&.........PuY.m5"@.LK.r.5......xt..e$...A..........q..?..f;0....,}.Sn.)..II.s_.p...~.vX:.O...5...._....|y..........E.YoL.....'......U.`a.x.....Sf.11-..!2b......T...L.>.E~.(.6I..-^.xq.....}.I.'.M9{..0?...?H.y....'..(..0....%.(.0..f.g....5. U).s.......+.3.H..*.s....3..s.$E.dD.+.y5T.}.p.8..Az....=......)....-U@.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):195
                                                              Entropy (8bit):6.071182236715599
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKcRwXgki8IEVk4xGQq5i9N0Vp:6v/7aKaZRAO4AQq5OO7
                                                              MD5:B3D900409BE71A73D4401B8BDDEEC205
                                                              SHA1:6C2B714DE75ED0595839C4511BFB34BA559CD423
                                                              SHA-256:85328D65160BC64B2D4AF369887DA922A28748E02DD881DC2EC7689FA2533243
                                                              SHA-512:E6FD5BAA3DC9756354C5E6AC4FC1FBF8F36A82DE873050F3CF2B6BFA4423BD0353A5DDB4A479E03B0679C7E1D927B675A189D7B412A5C9046EEA79EA9A8ED5C0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....PIDAT8.c8..E..0j....rr0....k!...p.\.i.b.P.?..h.0.(J.A@...A..6.c.....p.`>.-!.. .Q.h=.J......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):193
                                                              Entropy (8bit):6.056973920208479
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc1hkop55C0lBPbogFcw5p:6v/7saZrH5w0LPbVFcw3
                                                              MD5:FE117A6CCC528E8BA952B1A686A5E65B
                                                              SHA1:B046E3D5550A4920EF14378CEF4BCE9A58ED49A0
                                                              SHA-256:ABCE8A2DCD4CA8AB3927BDB5B5909AF7871973940F06F7A2304525E67891002A
                                                              SHA-512:D8D1DA15269156815E4B2900DCA0BCC9DBFE194A4241F70070F8180A913797A702217BDC7D65141FD4EF3C36A3227E0349E000313C1D1D9610E8436D7DAB4B9A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....NIDATH.c`..#.031~.R.A.`ZT..............`.....hXR.......h4.Qn..."..C.....`$...a9.".*d....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):319
                                                              Entropy (8bit):6.715977842662184
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcRRyuo93Yo5WrlggRe2SPGbXzR5WNAraOhvNbp:6v/7saZRkR9ohpmMD3W+2kvN1
                                                              MD5:5576B053262674F22AF8229411C372C4
                                                              SHA1:373EB33E71C99918A014A4E8D922D075A5208304
                                                              SHA-256:E25F814ECB172936ADE7B23FC8C68C419354A1D7F93CA929AFF52793B85D3D48
                                                              SHA-512:7AF459616F440D6C9A145D9612715C48A31F57C01BA1D00C6EB516F74B1C6B1B73FE37852502CA03BC4DF0D345CB3A1379FB16EAF8403EFF743AE80921355FF7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..#.033}.R.o..... >..#.5.'..k...0.R....t.7..............D.#....qn.`M.v.`.Ab.N.`..'{.K..G..}Yi.p.Xb.?...E...h......0.Wd[.......a1.`..../..[$..D$Y......E4........K....F..T-*@..%...O........h.R. .{....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):197
                                                              Entropy (8bit):5.991426632099323
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwIsNGAY+vavfxmIP60lsyb4z10QU+:6v/lhPZi+aWdKcRNqx5C0lBy+BDksqp
                                                              MD5:B48D9E2D512C4AD569877C57F24E795E
                                                              SHA1:EF002CDE02528AFCA9714813AF01FC46F6063C17
                                                              SHA-256:B811B92907ED6414F5C62FE3448BB903CF977DE03CD4F13DF54F9F066135438C
                                                              SHA-512:3B0FA476830E82883FD2E268FF40B3985399FCA150BA92B432A815D21B68365CD0DFC3C0BED1D6D69B159BA2F4553508676F6E3793F456B43395DC4902F3D7F1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....RIDATH.c`.......-.R.A.`ZT..............`..8..Q..qC.8.......T4.S.3..gJ.j...1........ai.k....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):374
                                                              Entropy (8bit):6.920188451872822
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcVgOtsCtnhjvo5OWZsqVIHN+r0cRh2m16tC0Ud86OppDp:6v/7saZKGtnJDWZ5VIHNXcRgQ1t+6OpH
                                                              MD5:84BFCCF763A8BB0FBE20169067D84B09
                                                              SHA1:E09CDDB1DE8CE8857D2D35DC6020FEC01AE8E87A
                                                              SHA-256:38BA8EBBB5D1A8CD7A2AD3B20D6009FB400F238202FB92EF91B70DCD65413983
                                                              SHA-512:D3A20F7556FDAF09F31B0B1029DB1042CB3350236844BD7EF7FC776E18825EE8CCA4B7511D288A02722B4DAFD2C0BE1C1B22ED64BA4DB32BC954ACC082B42D60
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.'`ff.........`.&F........@.....O-...v..}.?#..`Z..w.T.1............ CQ,...h...B...8 .).X..1.@..ZP0.d..p.&d.......A.l.I.L.......P..c..."..`aN.....o*......b.>.SQ...I>HD.N.R..q.M..HET...FX..p".`..,.YB.p.N.&s....v.zi..[.......j.B.`.......#E....3][*.[..f..S.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):935
                                                              Entropy (8bit):7.693438365611039
                                                              Encrypted:false
                                                              SSDEEP:24:HavzMoXz/9nHBU9JgwYAEubEEYMtWsO49m:6vNz/rUDTYAltW3r
                                                              MD5:2046B3E74D8FCE0065DA8DE0DDA394E2
                                                              SHA1:DFD45E6425B88109C7DE5CF622450F084F611999
                                                              SHA-256:A646C35F0D6EA0E7A815F81E1D5E13DA45CB3C58D20A3837EFBEDF6F74328FD5
                                                              SHA-512:3FE4C6C1B2992C338C05E507C0D6FCAE7F7C21B4702547914A77BD184A5A94A063D0895C6AF3E611AD259AFBEF9E8C44239B3848E21037F1164C140AFD440574
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....4IDATH...O.Q....po..(L..A0....... ,U.h.`R|@......bBL\.....gI.%P..>..7j$j..x.m...m.Y.......s.=g8.X..8.y.......v45.1..hx...b...*.ql..N...b..}}....lC=.....:..G..jV..q...z.Qo/}...\..|..\.........?..G.PS.P..l...!G..Br.B`.F!.....vlC.... .C.....AaA>.P.Y.!.....0V....|3.&..>......t.......1..P....0N.'.G....c.Y5.....v...^Ur>,..k....G.c..+...vl.....".;...,..).%.v.^..x.e.~/..B.A.f..I.n..Y$.H@...?.6.5..p.(5....ja%.]t,tP......~...~l....){\C.....C......., .} .P$....h}T.%.$.....&..._w`.AB..E..7.T....A../...."7Y...Vv..MZZ[...o_..E+;Y....m..."..........1o. <#.~7._...I...%XwL.......|0..TX.i..Oeq1l.;.F.M&.k....kK.=.b.(..N..W..~R.# !.........."+..3.$\..9^. @D...uR.s..p...!4.J..g....`.|...U.I..BsS..9VP...`..\]....9.,..p......6..z...[..d..(....jYzz@....o..4V|.M?..6...,.>r...e2.T*.f...".J........... .>D....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):272
                                                              Entropy (8bit):6.58332324360963
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcHwaShtwDzoAn+NTJGuFU9yWygzea/xp:6v/7saZIEDnEGuFU9yWnCa/f
                                                              MD5:ECC2A36D953FAEDFF0520E75F15D664C
                                                              SHA1:C1BA9ACFDD0FF7AED0D2C4F8075957143186E166
                                                              SHA-256:FB4999D575DAB9E9131E50ED92E5A346E27505E4A4A2AD6C65677B9D9B6E7B10
                                                              SHA-512:CB6BCE517A62C8F65EE3D33F50C5CAD5CA157EF3EA1B60222F098A3779CA25C18E8A72748678557D6E401ABB4AED0ADEE9A33B39471AD3CF523D8BC58E466046
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.cP..Z........E5.0L.....1....T..J0.B.......]..}....7Gxz..y-.#..lb.,.j.H#.......$N,xu.........b..TD.8.y$30031~.W$......XY..KE..H......`.G.{,.p.........&..v.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):949
                                                              Entropy (8bit):7.671578907093583
                                                              Encrypted:false
                                                              SSDEEP:24:Ha/1APoDV2O+WxjsE14mDrQuXSwc4XHIji5:6/aQDV2q4mDLXoji5
                                                              MD5:5E5A90047BAD90E4B5F924EAB7D26B3A
                                                              SHA1:1E16A010DFF27183563D5C2B0B6A792B7F9AC953
                                                              SHA-256:4B92FEF6453D501C6B43FD8209CDBC5833D2D0DE6A2E35F918D39E163BD658E5
                                                              SHA-512:BB891B7AC7EA6899D43FFABE0A5F9E6A7BA18A3B9932D9B0D0C6BAF4CB1DEC0C2CF1C36BCC6CD2B5EA56ACE45C52F4734C031F710D608215CD60B0890B1A9406
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....BIDATH..U]H.Q..Y-6qJ#.B....zP.@.G..,G..&S.V..h..Y....PF..00A."E..+?..si.....ps..so..............=.s....E....r(44t..b.8..5$$d..x.C7.L.....v...L&......A~.#.AT'.v...Z]./..MPYYY..R..{. .t.V...F..s...h..g....B....'5.!<...E.v:i...,l6.........`..8.V.KI&.^SR.N.111...W..z..`..:/....T0(...Q.*LNNn....F.ddd..^....S.u.5.o.~.A.ji.. .....I@.....\...V.{_*...|..|.....`W__.........d.....8.....X.H${7..6,...6jL<..I.u......=W...z...I.si........Q5.o..J..d2s...-...z.~...oU......o (...W*...K|...3.v.l&#X.:.6.L.iB.K..X......,...l{{;`..6.. ...:Ei.y..=...W.Z..Z.....Kpp......oo.....W.67;.G..........(.....x<SBB......N*.czz...u.z.wGFF..:@.*....QJ.%...Y..Xe{..u...t]AJJ..xo.Q....pb.#.....h...V...]]]...D.KJ...8.z..._..h4f.l6J@.7!0.U....b..=h_Jo@..e... ....sh../...||.n..!m.Hmm.;,,.S &.......z.U..S.=k._l...Q...HD.Q..1......'.T.uwl1.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):320
                                                              Entropy (8bit):6.7386073527126475
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcXwUrRVwY/wL/UcoDNZROpXhyk8LJHBhcsOtp:6v/7saZnV//wWDxOdhykkF5OD
                                                              MD5:8F12468990C7CF9F1BDF01646BE26397
                                                              SHA1:55D8C141961E1B018F25C37EBF64332DAE383255
                                                              SHA-256:BB980C3DEF78983FD8EB816697A5A1FDDF4D822C755B822FB226E5B916AFDFE2
                                                              SHA-512:428894BDB348577055F5771A6B2A500CF34A0C87D1F8A96099C96DB8A3683B8BBC4DE56966D9EE90DCCF53551C3B81ED4C435F53E797F16DE6FFCD6976733BB4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.....g`af..U...........wcbd5.6.k8.z..c...>.(.(..........JE.UT.@.4.S..` ...X....TME .s..H...q...s......US.-55%.......E...T.3...A..W....{...TIE...,.YH...h.JJ.4).......?...JQA.........TmUPR.....o.....3....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):217
                                                              Entropy (8bit):6.324278495387383
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc9hkp7N8gmWrLbdLWcDwsPnup:6v/7saZDy7LmKb4cdPc
                                                              MD5:BE8FAFE61D456CFC208BFCA0A862B8E9
                                                              SHA1:0A85BE5B2A12B19E9035B05C655205D9D348E5F8
                                                              SHA-256:4E93C1ADB41F70CA15A5B72132675CD9A47ED9E317AB6C272A61634FD4EFCF38
                                                              SHA-512:2D90A6C82048CB6093BB8C2B5230E651CAAAF88C0E6E317BB49C7EA88854AC914A44E1414CC56D5DF44D0AC33D750B61B2D6B021560CDD218E57EEAFFA439A4D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH.c`bf........K.....F..Z4j....m..c9.7]...srq..OXXX>...d.....0..Z0.- T\..".> .OF-..`.[.-r.j....3....F......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):675
                                                              Entropy (8bit):7.487089357496866
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZA2zZruIqT9WkDChSRfWHro3nh+dfxcTIMN9EesbMGS8B3uNqRb3sRyt2c:HaJ1qUkDCEWHM3nh+RkIIiekMGS8lRL/
                                                              MD5:2AE495C822BCB8DEFF2E7E591D9B1408
                                                              SHA1:80C6DB987F51C9B28885E67234D6C4A21C91D1BA
                                                              SHA-256:65F9977F672A9F92F621B3490E74F5C21E822B094FDFC69808299CA72D4E8274
                                                              SHA-512:CB12CF5F42AAF383A525D89428C086D5E5A472E618ED27969CABD0366BB569662232083ED9B56CFEEDDB4BA85D42047F2D11AA1D48E256920F86C9FF3C64B8AD
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....0IDATH.c`@......9yYo.r2...fy...z.....(..@.`a.b......!V.w.....K..g....a..<H.';..W.n..@..$...Z.@.k.Z...;....w...$......G.....o..l..O.Z.I1._..K.&...[].[.)....wP0..u.V..j......-rNQ.....P.+..S/..g~..l...$......PX.I.7..z.....sm..}d......-....A../.Y...9....8..cbe.......e.v..y.l...3.$*...........!8S..S.0.~....."....`P.%%.........'..N~.oni....9..o..../.....^...o...?...)...4+;S..7.2j....R@....P....&.@9 ..b.+AIw../...@....b.j.A...r.. ...@,C..d.z6..l ..h...Q!H..>.......?..=....,....$.....V|[E.+.Zb.5.......\.`.....j.Q%.#y..d.L.d..+.rA3.F.3.,\...E.U.;.}TH.-.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):783
                                                              Entropy (8bit):7.655849766017428
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZk2Y6EaDV8kzfvUvncAHjiHvS6GPolQ7guQOrpVUoM053uKEMqkmjD6mI+:Ha627DXUvnViBGPEQ7fXrwoFVgDlV
                                                              MD5:C2D47B2BB3A5598A6A2FEFDB8E68AE89
                                                              SHA1:54CDCC3937445AA88BA7545BE25CADFD024E0538
                                                              SHA-256:0545197DDC7D4AA252E60E5E2E98140DC0371F08DCB2B9311D96AE82719C6B9D
                                                              SHA-512:D40C64A5E9A34E53F68F20EA0BC1F35C560C2AAD1D93F711899C6892E4E869CD1687E806F1A584BF2BA1AF23E9A9B2EBFF4BF3D64FC38ADCE639B9CA6DE3F40B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..]HSa....x..tmV.Q.....6M.+.L%....."....... ("".&"..$....>.........m6..yW.....}..... "..A...W....|C~K...q.E$wI.D......I"....[..~f.)...).......;..|A..b....Y.....L..<.....^8.Y.4.R.*bc.NV.R.O...B....J....)..YK:..\...N.4..T.x.....%.J.......].E.......%y..+8.....3..\...|....lE..]7=..9..A..p..`63.>....!U.G....t>V.3.p(.....O.%...+....0\ON.......1Y.L..:X.2>.1V..%..H.Vq...,......Y1....f..e.8T..'Z....a.0zV,..0.pgXp|...=_.-]..c.....{Y...Mh..M.V..L..G(..........r.L........&...v2d...2I.,.}...U..ggB...(.:g........x... T..p{.........(../.{.HE.p.........Oc?..1........d....m..o.;I.T&.U.l]o..=nD..q7...b{.6.1.z..*?Op..&..~K...4...?$..4.J4....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):787
                                                              Entropy (8bit):7.49484754631625
                                                              Encrypted:false
                                                              SSDEEP:24:HaTRuoG58HRW+vkPYMH2XA5MfhOI6yPYKJMEwFw:6TRIWkgMWiIkyP3MPi
                                                              MD5:F7B53ABD5EB6261BEE04321A7E68C758
                                                              SHA1:3F35DB614AFE45C7B96A51E26BA35201FF49E625
                                                              SHA-256:2570EA19B4BFC9ABB18D0440CB80ED350EA1B185CFDA14F809810EEEA3444643
                                                              SHA-512:BA3BC9B30F1350367487C0DF5D8D0D4C5B79F28AF38127771337A66C664754600891948EB833AB17A2B4CDCE06D2F1835C8C61BFA8EED727172B59AB7547363A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..f ...@\...P.....A6.WA..X...A..j..G....6.bu(6...A..4.x.......?2..A..@..".8....[E..3@,.., .G.+..........^........X.q....,......lw.G.>.:.X....b!",.......6.7...[.Y..$....i..4.2.a.H..(.....u..Zl......E..0...H..g...8.A........U~.E+.G..L.Y...cXpKU..2.b.'3..3."....Z.k......../Y ._X.../.u.....@...0114K..I.f5.#E......pe...]...<...H......J..XC..;,.P"....Hfff..Qd..o......c>np>x.R..9..@......7..q.~g!..^....|...6DX`..-.l..!v._p......KH....ph1....2F..T....0.$&.......Tj......wP..P... N.'.|........u...Kq......W#....lw...Y.`.b........:({..kB...X.T..r>pNR.Z......n.....8_.....[.I..).C.ZaI..|.....p..*.@......!.px..2<..t"...K.....|...UX....,.... N........#.@.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):563
                                                              Entropy (8bit):7.3034711187336825
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZtHQiw7TI0um7XvYRuwPvUi/cE5ltl+zlzgbBp1qyc:HaLw9KMXvouwvZkzlKpk
                                                              MD5:FEC3D3FEE393C9106C2576E7C5F40E56
                                                              SHA1:66B4FE505B1D701FEE65AF63A98CD48532ADB51F
                                                              SHA-256:54AC3F4A78A40E68A1643E47FE69E36D69A98446F9F1B744941267AC4883393E
                                                              SHA-512:B6DE7342F4146F7837F713FA6E5652085AFDA804C52DB8B42227471F8C757631462A45F960B95875F33C64CCC44E2CEAEC821B8FDA0A92F4D2E939DE9D5B9204
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..f ...@\...P.....A&..@..X...C.j.j..G.....b](....A....P..4.x.........P.9P........sP6..@....**(.j..d.q8...x.....1...6 ."..k n.b.$,....`-...a..T-.....`/..,...C......,@W;H-.......@....+.H.c..[.,`.b^o....v.....e0..A8...?./.u.H.c.z$[p.~.......NI..X9..a$S<. 'SFv.......`..[.d$.......yl.....[.eo......np...M....:..72...E...P.q...&...n...9.m..r0.#..cacj....l8....:..f...6.bu(6F/..Y._.J.(..!....S...Q...h.$...lGJ.dY@. X\S..V8..x.Lj...>.*ehG~.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):380
                                                              Entropy (8bit):7.104571499447948
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc0CoGJrw9UETD2RoyCgIjkkUaI5cnGlRJB4DwiR3Crp:6v/7saZ0r4U2EORrIjvHIPlR74j3CF
                                                              MD5:942A1B12946890EC1F254F5C16AA84E2
                                                              SHA1:1A029C0872D7E8673AAE26E55ABD8482BE83D9FD
                                                              SHA-256:10E821F3C10BB5939920EF7C3E910CBD34875E91983F27634B6D67D08433A6E7
                                                              SHA-512:92BF7418E7657C96BFD714BC4E2423412DD9341EFE1715EF3B6E22795056459A30A1FE8A236F896A6FF9D56733D8E1B30A2B2197A76D663F6DCC1CF912A2A2F4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.....@.F...XC@=x.).....V...`...d.F<Y..x..8..aw1......8.!....,m"#.D....2.$68.....m.#.....C...A.(}"..IT.O.........{..@..".....y...^"8.].A...1ly.TO).\..KP..SP?.P.....[.P7...a....%;..K...1u..1....3..L..D0...&X.3.....{]GD.D..D....q.l..G"P#.:..T.e...?.0.)+/.!...!?:....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):384
                                                              Entropy (8bit):7.126131615252493
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcIiFea91Iyfjtrujbu+V/GBGCAtQa/hq+pEvBxZTJbp:6v/7saZIzc1IyB6jQiloZJxZD
                                                              MD5:AEEE1D1310D3E0EE92F15CC40EF48204
                                                              SHA1:D844B95E8B9725E4564B26E5D8632662AAB32CCC
                                                              SHA-256:0A082A032FC90AD3C5CF5DD6C8E8F8F8B4821A2FA78A19AE08612E80F7E714E3
                                                              SHA-512:8E7CA6695205B3E5AB20A49FE254DF4F4BEA464F6D4C92F0ADA7135C453DF83BFEB755D58FEFD3574EE62DF1D9A179A463E9CD699A55E25DD0C5B3B0184A92AE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..;..@...&..3.....>.!^A=..v*.3.[y.5V....q.u6...fv.P.|.f...1.z.,]"'.DZ.O...F.....H...{k.s'|.cb.b.....O.X...Q.Z...W._=.....%.H.{b. ..;..D......... .5...VYs.z..zg./P.76...4........9....mSN.....`Jl%..c.&X.3...a....:"z r..6...........@.`...Y..?.."P...9.+.'....i}..Q......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1028
                                                              Entropy (8bit):7.7483677316269395
                                                              Encrypted:false
                                                              SSDEEP:24:Ha7n+6cf3q5Uz0RKqYFwj6e0QgZ3VVc0p5PDyX5H2AHIHYVl:6boPaUz0RhWW6+C3jpPGZJ5
                                                              MD5:96EF1FD77C06C7DBF9B2D863791038C3
                                                              SHA1:15D2ADA362B0AFB6DF07206E13725F5A9CF17737
                                                              SHA-256:DE28E2521485EB29D1AA48715D84CCDA96EFB862E09E81453B3BD7145D0B1CA2
                                                              SHA-512:A584CF8AD0AD8BA52AFDD45FEADB391C96CF671B2EF6E51D4D9F4A8D6A30958108F94FDDA12FE3D93BAD1CFE3BE08AF1BA5C215375CCF3910AE3B7E507EC3614
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U.KTQ...{o.7...I.R.C.\s.D....5..4j.. %d.bh.e..KV.@.D.De~.>..-...@..1.f_...y..f....ys..{.....E^&.j..P. .i../J.s<..%U....y.A#..[.6...<.*T......}.X~.}f......ym..<..cl..<.=qg...|ZS.,..I|Eg..6HzY...i.&@.e..9.c...4.?.....aU......._#h;.+.V.*.:..w.e7.1kM.,.....7L..T....LTa.....7.q....K)v.(C.hJ.....A..t.%..k.YI..&%g.yQO=3.Pb.c..2...D...A..lp...iM...3....&.3.3.Ro......J.....1r.Yl..i._...K/.e....x8.)....N......7.."...F...6.,..U. ..0.j..+.s..Z..;...T.}^.P.7BY.....3.......H|..W..>1.]..D.....#@ R.N4.'r.n.....e:.W..^`<.q...B..&(...M...............,......f.Z..l..zJ.2.J.I.n*..b/.......`...4.+.......1....a*.L.......|.*...v.%..6..-...\..i.....2..,.7n...c...b........$@..^..J..,..0...K....z.n:...~`....h..J.....8.....n.D.$.I.P.d...Trt`%.."I.F<....+..B......5...M...@...T..eE.F..G.\.Siq{:..E.Mk......c&....4'3...........f...o...a6...7iw.vl.c.....#....#.2..@.,.\
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):205
                                                              Entropy (8bit):6.257560642821402
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwAshkxTO9flBnE/UC+7mXdM0+gT8u:6v/lhPZi+aWdKcJhkQlVG+pzMIkSVH6p
                                                              MD5:43D9FCE3B598A39578EDE7FBCD8C2C5B
                                                              SHA1:6C41E83F9645A6E4EADED5054F51F93C4524AE97
                                                              SHA-256:6914DD1C36CDD5F00F03427C6685D588CE62152C17EAB556BE7CEFEF9677B9D7
                                                              SHA-512:7A329D2D2D9C4FA3047C0DCCDB5D1B3827EFD29195330B41AD66C5F37603C4A39960E49215A0CEA1A134A58B97251CDDD1F3B23FD6901CF35432493108707B29
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....ZIDATH.c`..XX.?....b.~........P.F-....K.L.L.."/.7A..UP.../&...Q.....LD(.....`.@...B.h.4..h?2..W.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):948
                                                              Entropy (8bit):7.721333434767267
                                                              Encrypted:false
                                                              SSDEEP:24:HaaoLtShDfN1zlO+itP+b1xJcZ80FUe6fT4pFINjTku9:63tQfN10+++reW287
                                                              MD5:425BFF7A104C29C2D231390A3D9FB26C
                                                              SHA1:4632BF2A4BEEF3EB6DD67015E0429AEAE0CEDCA0
                                                              SHA-256:B836166F15CD27E8FB651972FB864FC5438CEC61B5AE550DEBA9E93949FF20E2
                                                              SHA-512:BD57363AFB78B2C5748E59EECD42CB893B0BF192CA7A9342E2B6B84CE1CE690FB12D7E829DB50E1E4B0316A6F2237CAD33FD95B20EBCC0B8AF17AAC41724E4E0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....AIDATH..]H.Q..g...g..f..Jj...Q...R~.$e(..H......f.ZQ.&.aI...C...}heP.DVB..`A=...l....m\g....qg......8.3......~..;qN.%...Gs.6_.~.......}]..s...0.t.W..KV.k...{....s...`..%.,.cl...... .A...V.....!%%E&--..N'...BVV..\.X...l.U..tG..T.S.Ii...{..JQ....L&S...c....z.7@...n..!.0.......^..>...z)..z...*...az..gb.6W..0.P.@.../E....}pf..............<....A.H94.-.....b...qu.._.=$.x;.N..F..P.q.......?...l..2A.E.&.Xd..;{.4...4.f.P..6'$..).d..H...oLo.Sz.@.....S.dT.&......g..!.^X.%.C...dJ......W&..Z..........^ E..EQ.X"........M.&.{q...A......h.{..f....38W.Z.(.t....h...Fr.R.+.t.k.t.....!cJ..:Z.(..x..#3.........N.E).,.s.J..H..c.*D.r..UA....U.......7.....#.Q..P..N%......y...|...O../.k.>....I..5._...lO@....Y9...;;....h.I...E.&.V....1...I..7.M.43...U]."8|."x....?...X.y.Y.#.E...;<.%B..f.#+bVu...(.jS..*..=...{~.e...........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):857
                                                              Entropy (8bit):7.630473976778439
                                                              Encrypted:false
                                                              SSDEEP:24:HaCVfKyBM5dm5/wsnqEy0CMbFfzkp+4Oz:6SKndm5/w8ZyeQA4Oz
                                                              MD5:0D3F4D375AD1B906C63CA0F093267E53
                                                              SHA1:9919C2EEB6DC5A0FE8A8A0E763E956EB66BBD792
                                                              SHA-256:5AB0D91E9EBD6DDCEF21369EA6C9608B5C6BD653BF1EADE0987C74187B5F7424
                                                              SHA-512:471B9DF61A1420AA02267BE6B0DA58B9C21634229AF87B7504691744E45EAF6A021DA750A4E09C692DA923018763EB25AB8E200700A6BF14E6FF59161C737D47
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..[H.Q...>;..8....../.Y.B.......Y...@0.H..-IT.A/....YQ...../.>XP...4......i;n..t.c.\...... ...5o.......P5e....i..8.q.$<o.&.........M..k]..Y.!.".....e....W.W@V.....qJ[_..M.gL..#....p........).....0..>....9.........yg..z.....Ihy.a.X..e.I.j3.Z....:....E).3.H..o.E..E......:.....Jh.&.....n...\n^..1.......+.=t..Ew....P.)..PHx..0.1D?d.3.../.W....n.;........p.............^..)...7......!..w...*.[......J'2.n.^...-...{.Ig.f....rW..e.s........6..=..%m/..j.DQ...n?.y.E.....gd......\..6R.,..h@.H...bciG.((D&..aqoH:g....%y...k.,_&.b....7..".*(\_... ...Q*..%U....8...F..S.I..,.&.y....]:..]K.&P..S..c.,.w..8h.0.`..A.DI.Y.5.....-..l..0..Ot.....N6.J...wH/rY....._.j.....=8^d5.f&EY....Mq7..,..`....+b*..q..%%..Q.......(.._........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):493
                                                              Entropy (8bit):7.205985693009607
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZwShtc/+l9/yLKZrL/4SZG5lNz2BnK5ddA6z9:Ha+Sht5/y2ZwsG5lNyBnK5/Pz9
                                                              MD5:07843EF7E80593C221689266D6676BA3
                                                              SHA1:4F0CFDF7817013367E9CD73FD9870249BC040D89
                                                              SHA-256:C6AD5C20777850004432E290DD8F560FB2E51151F61DF1CD23C07D2B62541888
                                                              SHA-512:3E617E2977C3E241161FBE2E17390EBD18DFDA8023CC1C9425E3024E036AA0C9141C174781E0570E85EFADB674326686D10D8E371253E353AC412EB84336151B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....zIDATH.c`....$.17.....v..G@Z..j..B....q.|eba*..Z..e....o../......e.PL..j..._........n........5P....+}.Eh.p...../=...tZ.....1.............R..i..E.g.....t..]7.._p......W....@5.0......p(...N..S.f..zm....k..EX..\....^.kw..q.....{...D(.f.d..Tg.R...E.......;.]-..}...@.z.+X.0...,....Z...4./../...D$..mAx.!.H&A-......M|e..K.$.E....9..RA-BS@..0.3.cbe..Z.&.....v$.._q=......AT..N.V....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):316
                                                              Entropy (8bit):6.748312662816778
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcTN5UDMoT4n5OVx1VUblpkoRVaSwRqdDLuLhf82Sd2bp:6v/7saZvUQU4OnYkkVXBLapBS6
                                                              MD5:E8D6922C81904BBABB10D14D8A57C12C
                                                              SHA1:3B34130618CED92238F34B57B23EFE6F2FB7930E
                                                              SHA-256:6921904E251128C114C01113751F480AF3565A29A03F72093B04BDF88E9ECAC2
                                                              SHA-512:5EE9CF922E266626982D9B93D018E3423A0BB85C342E1F0B4FCFC06F6829065349E07A10CDE3D7F25548048FE5B3EDFF7D50084C7CF20029844EC334E4032788
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`af...............]..i..]..&...X......p.f...@.O..H..Q.p\q..f.A ....>..~...fbf../.@...q).&.P...;...R...p./...........*(j.).... ..)j.yF...Y..[...0M.@.x.hR..8- .....[@s........q@...."Y.).l.Z..V.Z....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):221
                                                              Entropy (8bit):6.280963957721208
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPa+aWdKcZRyUGhuoj5hdtAXhWMVd7vCkup:6v/7maZzrol/tzi7vC1
                                                              MD5:6D33BDE9EAB5EC01735868D53E567EDD
                                                              SHA1:B3756107D2DC9398DB176E7159C3FA163B82F6AA
                                                              SHA-256:D4D78A0859368D0F0094477E89B70524B0C3DDB9CE586E61105BC33A73B91FA9
                                                              SHA-512:A97E614A430E9CC50E5C92997338FB5E4CD84E8BE45144705BC4D20EBF47F32F1324DA309C047C9B84D81A5608D4BFECAE2D3F29879A8CDC0F8AEA1D71DB2D3E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR................a....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....jIDAT8.cd..0..g .!G3.......%%%....I.\\\...pQ'..A:...`..b.R.b..|.`.u....(...U......'..(g.....@, .0j......ob....,....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):303
                                                              Entropy (8bit):6.811158010147474
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcFbh4VAU5ronCWkncWHVyUitTAkrCjp:6v/7saZFNFU5roCHncWHQw
                                                              MD5:50ABF9F4EB57CEB2BB19742556CC75FE
                                                              SHA1:B64231B070E61708C5EE7B02151AC965A37BFFC8
                                                              SHA-256:0E232D8BABE6C89D38517B1E8D0A1DC976FCBCE44FF3B08A0D7C160E8B41A611
                                                              SHA-512:EF54C26C304EB5F8228545DA2E9BAD45B47271E2E56490FBEDE53AA8D9FDBE2FD9811198638D4C60148EC63951D2513292C1A2E079EB6952D0C8B546D146CAA4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..A..0.E...6Q.FJ.M..z......UK.+;.......<.|.....`...wB.q8c...,J).!6!...s.x.'..>?E.....*.Q....5.C.j.U..Oi.)cxzu>*.L..X..uH...|M......<.....a.....^..,...>..H......E..@[.....c..9x.).+...-.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):782
                                                              Entropy (8bit):7.651813728098983
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ5mqk1bYTFUsFYDT03zmzYbvwUHoRq3ysLVnwz7y5AeCpSsnSZ/S:HamB1b2GSm4oUHd5LFe7IzGBnSNS
                                                              MD5:3A9F7E8B21AAF44AD7DA8DBF60D28AE6
                                                              SHA1:721CF85B2FACD931503324939FE9B5BF615EFBDD
                                                              SHA-256:FEA1D1B9CB56ED7BA0AE0331D217D470E48F8B97155A3AEA13BA244371CCEBCF
                                                              SHA-512:804E1BC6581F4052396E8EAF4363C8860CC5F9994257663F3609AD89C196287387A6B10A704B4E3A62CB08E00A61D85505FDEFD462A4F40169224D8B1F04E167
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V;H#Q..l$.....C.B.T.].D.Pd.@..*`.......U....B,l\a-d5.6!.#.|&.5.I&.$3...{..i .....!o...s...q._...(7.gTh...;.ss.x...\.).<...E88.lC8}...>.......vv.H...b.g...tuu5...m....T."...9...jEooo.g).@../n...[*.."..L$02....$..@R|....!...ln.?0..n....v.u........x..J...9..I&....px.....D.q...E..UP..H..3..[..J6.D^R.u$......}.T..Ji..#.&&..?5...p....\."+.., 4=....Z71...VN.p...D"..Y$..d......n...8.$E......z7..@.)2._......*yt~...b.NWw....6......O.MMU.....e.x...G.-w.*..E..H...,...v.[Zd&............x,..V...Z...`5.g....... .*uT}...{<...1k....X,.y'<v..$....y|u....;V........./.Y\I...Ur:.J*...n.....h4..y.n".....x..f.......5t....s.u.....w[|.y.A{..........]VeC.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1068
                                                              Entropy (8bit):7.723136693175827
                                                              Encrypted:false
                                                              SSDEEP:24:Hat1Q4l+I2VAWWeYQyjIT2DsKW3Uy5lzTIzx/sX:6zsIgAHeYQycT2YKWzzExsX
                                                              MD5:B68B881F1E8AC2097FC7A5E393DB085D
                                                              SHA1:A2A50912D650D39689013A601AA752BFED1C807B
                                                              SHA-256:459130B6B99407E3DB65E8B1E31F980F8BDF458707EB6DF07197E374B9838A6D
                                                              SHA-512:61C2EE031F8838239193113EBE186DB7951C10694DAB471F84E5E1FB28986858CE1ADBCB4E7D4CDD6D23260D1FAB977B0CC3B235FB77902D775C4229E13573CC
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..{LSW.......mo.n..H[E[-....L..`.......@.9......1.......>..D.q...#>...8..-.......R.".z.or.......<..S..".H.............=@...b.......H,...Y..O..kD..L>P.,>...w....#.......a0.ca^..fg.......P.*.}.....Q2....4=...{.`Dt..~....J.W..?.a..Cb....bS.H.1U0.s#.m#.w..Q....w.].w..H.w...e.....?U....0[.`....|4.~:.Y9d..F..:?-<<<:...X..S....!A.7....yX....Uk......BF....@.x+.....)Y<..`P.....xg..|uZ.i....g....o........9..Y'....S......]:..\......9.....p...*...."@..2.F.bi.).*......P=..T...v.jL.2Adv..z(.,6l]...K...F....L.F.....l.)=xt/v.....mC.^F.,.6..Z.W.$.4d..J...Kr.C...zI.Nv.H......`...C.....B......'.......,..f#3g.(.....]..]..N..?...CE....I.DQ....=.$.F.x...(U.Fj....U..-..u..-..$7..O.C.Q.......[.R....V.W..\;..X..4....}l.......k..X......W...K..!5}.k........-.../...BM&Cs...H.J..n<....@..7GnWa...m$..C.....63.........J.0.y..c..../^6....^.....lm&WD.../H.m<.j.....[s..[S.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):695
                                                              Entropy (8bit):7.5150265960205465
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZZehKR04ZPYqCKwHMaBHL6e3B03YBfQD0y3S6Rj3tKZcGs9haSXJu94Em9:HanehKRvYqCKqMKLSISwt6xMZcX4SZue
                                                              MD5:CA3E44222B9766B67C7032C701541C4D
                                                              SHA1:7DFADAF1CA802996014D4B68B7EA15DC91BA86B2
                                                              SHA-256:A768847285C61E24492527347D16752B090D021B873E82F8E62852D2B3768201
                                                              SHA-512:27B66CFB9405EE6BE97E0AACB5A8EAC7ABE1A18C6A5431BE422B315F177EDF5F419FE7CBD6A09002F9A3DF83E8386EEF7CC7F35EB40E86B7DE90A481097070B2
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....DIDATH..K..`..{A..-.....pY.Y....X...s......+.o..ftE.q..a...r.F.E....m.qh.|..JJ[.:.&'m...|..9...O.8w.="'...ui.."....d...:.r........wn.....f.|^..B..;.TJ.N..X,J.|.l..d2)1h2.......'..[.DBf..R(..r..`q.....x\ak...,..*.....nD...3I...7N...B....d.`@2..A^....U.[e.$...)..h42 ..Z....g.A:D..E.....|.....}..vY..d.jU....l.......=7....4M[....s...M.EO..q.._."...SBI.(.Y..Z...6.k.S...E.`...........dTs\*.N.j0...g.P;....H.y~.D3..s\.p<..z.*...<..|..A..A........].V[v.p8d~......5..q...M.iTqJ.T.Tdl..`~..h.`C..F.. @..a....";=.p."...,....".M..x..G:.V...Z..".M..H...}...*......j...}...g.^....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1033
                                                              Entropy (8bit):7.7289281772419995
                                                              Encrypted:false
                                                              SSDEEP:24:Hac265nejCUtL5ApkBex2mEl4HKVkRPN9XsRVb:6c265nemajleTFvYb
                                                              MD5:D17EE1A0BEA19747C5D4B1203C073824
                                                              SHA1:AB4C65A20AC7370A4E799A89358278054003F7C3
                                                              SHA-256:31157DEC6F9FDECB468CDFBDE069389E7CD05C5A91714D700B3FAEBA937E68D9
                                                              SHA-512:A1AA13656A1BB952AA6B46060704FE0A3DB5EDE5AC830A9F7D3AB10E4936F78D14AF969501D8826DA22A566FD25A86E133E924EA0463C441CF5961226C253277
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..iP.Q..-w.....Q)uo...{c...i".Q.1..S..,.2......)dIc...4.(k..1v...9w...............s..y.......Z.M5$?.?..h..G@.p...Z...GQ....B)..w{.b.....c...}0B..H....>..g.F.......WQ.)F.Y..Qq.0..*@..0z...M..A....X\.....q..-.[.&.m..........c&.......=08.....R..N..Mv....g.2....GwA.a#.`m.J..../...( |..R.....@.V.....9'.Y93..g....^WQ......8<y}.I.6....>F[SR.....g'.{R.(y.....;$....c.RT..@..1...b...<......y.GN.@..XT0..\].."$...uF.).i.)....?..h........!=.....)..ni.'J.R...............2.....WO3....q..$..b..b.O...R.h....bu!......N[..,rt.q..Y&q......\[^\...F..^Kn..........c..uL"])]qs.....I..}"5.%...^..1.I.p...zwF{...x...w..=jP..H.W]..1x.....!..t..9..."..!95..a..(....w..F.ma~........It.5_..M.....g....[.}.....M.........lU*.`d.Q.k.CM..F....4L.`Of.OK.q...y hjJ.h...h.wl....H....,..d2sc-.tlS75...m=.....D........}`;22.7...}hzLD.M....>....L. :.I.o......y?.O.N.....|"E..`.9.`...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):944
                                                              Entropy (8bit):7.668014193939864
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZZSL/ONx//yNDxTKCT7SKGzbG5Tm2Ixl7GN0mzOrQa3oI7YA0rgQ1PGX5k:HaVNJ6Vx1fKXAaHaeR8A5Va1
                                                              MD5:8D8287DF128380B33EDB3E936FAAA0FE
                                                              SHA1:2B6656DCBA9D15DEF203509E29359479BFD3D1CC
                                                              SHA-256:6BE276730352E48EA9E17175D8C98C93698B43266BB7970AC3C6D2545984CCA4
                                                              SHA-512:31568BD60961AEA47B422AB43D0E21C861EE63EBC103A26C2AA9330414C7B6A05FD8E993618FF2EBD17B5A1BFD4F76810CCA109AA7B235B56462DC708B6ECCED
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....=IDATH.c`..P.,.....a$5...3k.+.......O...f kj..y...j.R..n...RaJ.....I.,.u.P..U#.M.VW...u..B..-0q.~3mO..kw...*...U.3..I.b..U..0.V.1.`..=+..@!F..E.e4.N.*...a)u....<..,.2R....(......d..<......+[...t....R....|.D.xm.Y.m...pb...,.o..bE.....d.i.s.".....?$U..J..~......o._B..".86.CCC..u.?.>P._.@.,....YR...'.....M^i^aQ.>..E.c:...eh..T.;.-le5.....>.-../.%...p[[cI.{..v..#H....LNX..TR..k."....b.%.y.0.VK`ot..?.D5...[1,P..mI....;....~tyI%.".+.......,...4.;....b.JW;..x..(r.cX.c..|...f...E.y...3..:.~.4....&@...H.IH.............Wa.~..j....z....6S...b.....<b..x..k.?............#m..(.|..L.3{..$V.|......'.._R......W..t.$......Z.EX....&#{......D...P..#..@A#......5....s..R.j .e.2`....W:...p.'....i.9i}........K.......E^_J...7.Q.Du.t,.../..._..]QK*....;.=.....W....})C.......+..Y..ppp`....:B..t.....Z41....a.>......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):999
                                                              Entropy (8bit):7.694173553938531
                                                              Encrypted:false
                                                              SSDEEP:24:HaPWeQ3JUXIhlatMhCyZzJspDBmqsrvxRBfc+3MsEG9:6PWn3JUX64zOstBurbBfzf9
                                                              MD5:4619092A7260C7F51747222F3BDFAB43
                                                              SHA1:D98F8E033900BE101DAB04208777D6B9FDD8C659
                                                              SHA-256:373365068B3BA4FB7DB26EAD65FBE3180F1E6DFC3E087824506096FE29E1F3A7
                                                              SHA-512:AEBA06D1900DC789AEE602483AECD3E93BBC0DDAD835722C3D6569613F1C2960FA5313288A992468CBCE071BDF23DDB78C72BE647DB556B2374BB15D59F272E6
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....tIDATH..kv.0..GO.6....Iv..t..D7.Uu)m...~.w$.....s.m.w.%9..8...}.........H..R.%[ddrK*.$.".$....7z..{.....'..m...y.{.....I28u..8l.u..j.....xF....q.LN....8fi..t..`.W......SM...P[.0..i9a..%qU..G.K....0@I.m.....j;.w.....y.[56.B..(F..h.5...]......sZ.. .H.x...x.d.V.!..r*LP@.J..0..........K...*.+..u5\W3#%'...S.&X..5.3............y.. BZ|....a. ...kB..f.ng...*...L......|.w3ef...th.W.....y!)"...;.87X.3ae.......5... .-U.Z...:&..A.>r...;..._...%.........\B..e.=.GKK............"..gv...cH........0....(..&\..k.+.....G\..`..g..@7.K...d.q..n.-.7.....MjM.v)n-....m.0X:Z......;.(..-./.vH.g..w..j.....:[8.1>...2../...,..4.nya&8'..{....O...r...3...=....?..bz./...n8}....6?.X$wh.....'.......D.......p..)y.........h....?..C+.....32..,....7r..hK....Vwi.h.....K..v.WJ...e8...~...c[....5.f.J.....vg*..S..t<...;.....p....0..{:@.......//t...}.z...M...g..O.....?..X.~.X.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):461
                                                              Entropy (8bit):7.3045672023
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc3K+zrl8jloF/gt+SI7WdZbbHYWlzVgaXK7aXT6AeVPtHrKSp:6v/7saZdzryhgK+h0ZbLrVXwaDBetUY
                                                              MD5:3BD32856BC8F30E088208C05B216A6EC
                                                              SHA1:93A32CF8AEB1D2FB850967D5F380B471FCA832F3
                                                              SHA-256:B8D77227BBCF02BAF84E8EE462DD86E0FB34D54D16B6275BB46674211106CDCE
                                                              SHA-512:314D6B5836264900BCA2269267E5A6422CC3912719F360DF9B648906F39AEB225D637B65CE85DE140D7E21DA74A409F355A4ACE8AB764F7BA6B6E943CBD957B6
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....ZIDATH.c`..C.p.q".....'.C ...j...Y...8......#.... ....QD..s......T.....``...sc/.../O.......7...v....0..3..5|K.v.w..6...`<.p2.&.j.9...`.V.D9.Y..+.|........._.......;.5a....G..?.D>.Z00a.`~....s.....,....t...}a`.H..j....9S.............W....0..[]Q.b.D.Z. ..z;w.-!M......U...h"E-.0.%=m.....\.i"E-f......=..&R..&V.l`.~.(#..IQK..^..(....!MV3yC4.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):592
                                                              Entropy (8bit):7.376149039173553
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZmAkgt1baar2Rw78gzNChUdSk7geWqLWlNA8RAtiWlU:HaMApA40ASkceW+Wlqg3
                                                              MD5:DDEA67A9E977BBAFD6EA78A66B82DE4E
                                                              SHA1:3A5122F2E773F28D8A59690891C32D2AF9E3A20F
                                                              SHA-256:C8A46A765B5AE7E29E77634F03B3B1627D22D0123D2EF0DF424F12AF794A1B20
                                                              SHA-512:4CC9F78F6DFD6ED23A1490985C0C0EA182159BA614B9F9E6A8D9475FFF2B7029013DA6F62350DBF7460B1950781BB064ECA0BE597A4CC172D957FD53129B3464
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.D@..k....y.m.3.?...P.....q;..Sb03.7.........e4..313.G.... ..2....]....m..kw../_...&B.f.\r-...?. ........8...f.N.,....p.N.a....M,([.....M,.a.!v.%d..F.f{<.h.K.,H'.. ....8-...Y...9I.`+Hsh.>N.2g[#.@<..].../p....5.... ..!(."Y..O.....@..P..c.C.X.(...f......K....._NG...VW\.....v.v..D N...b......t.5...KX.-\f.2.S.N..5;.f..t......].@....<..O@..!0u.6.qQ..0....,....H....$.&...h..c0`..5$ ..6@.....x7..../%.....T..;<..A..5...eP.. >......}.X.....d|..C.*._..^...<dI.H.1....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):217
                                                              Entropy (8bit):6.31276163977255
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc9hkNRsogA8It2fgmTq0dd8l+Cp:6v/7saZDys8P7iq0w
                                                              MD5:24267F3CE2653D103E81458E77E6FA15
                                                              SHA1:ACAD2F526F754A51221AEC8042FC5B6EDED8C23C
                                                              SHA-256:878D97DC9D9BE8F04DA58805193465920C60C91D7F0754BE680B153964975C4B
                                                              SHA-512:DD7A5D097053A76F8D7AFA7956D72F97FF1A3376ED3BE73C74CAE80F8C77D70FA4DCF41B6B54CF2752110EF28A605FFC9DC73096AF30884B9EEB4C5BD9E19AAD
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....fIDATH.c`fa........K......Y.j.H.....?....U...0....."N.Z@...5phZ./...T."l.5.3.r......T."Bq2Z....J.5.l\48.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1579
                                                              Entropy (8bit):7.8497345876928
                                                              Encrypted:false
                                                              SSDEEP:24:HaJlLpXMTG0MX6rLINwUiOJQsrEA8XwFP2QGGdzmBVpAxCjyqAGXmsJGGit:6TLiyZX+INwfaQsQApp2QAkx83rgGit
                                                              MD5:B762940F74DAB1162C586807D8150FEC
                                                              SHA1:0912019A43D7374B9E83534555F7140DEC526092
                                                              SHA-256:82155FC7C44B836396B99852AE6D446DF464137F067F1B5253EAC0AE2952C125
                                                              SHA-512:5B7626B093E193BED30EF5E21FC981FE0E0EBBE759322D2CFA76E15A05CA154C7010EFF9BBA9277CD0E5E10608EF7676D971E73E27E15D1B74D9090375A5909B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATHK.V{P.h...........#K......[*..C.v..l....)RI.6IVJ$..(Rll.&*F..U.........;.v.......9.w..|......7.>.xn5L.l..|..s5........'..._...,.3....z.F.l....1.s.|5O.[..`....r%f.....c`~Mm.,.v...../b..*.i....Z.XI9j.6`w.~....4u.Pw..*..!1%...'./u....1..w...ap.)2r.q...Sf..f.7!...J.~3..UJL.g.... ..o.G....YZ..y.....`<.|...k......~L....1R....Q..b...?.bK.4.V...Wp..a.=C`X".......k..l~.a/.D......vg7f..Q.......0.....}...@..G8~..........!..U..!..f1.."......G......C....-tS.._......4M6`..%4..1.h=...Bpd...i...."3%.....g...N.8...!>.......c.y....d.C.c.......Nvg.>.........h[.2.V..U.....MEnQ=.9.,.U.bE:.tmwA....`.Z..t..G.O.C...N.2....k..|R..X.1{..gC.<...(....\.k).xu..S*.P...V8f.@.6.R.L...#..-.k.S..H|.B"O...:..fv.....3X.y.@..6..=..o..<......w`..,.,.........).1{...tW.,.+E4K..}.C.ev...d.....n.........v.....w.j...MB..x..-FFFH..p.+&.z.=....}.4.Hs.J ..:..~@U..oF.[._.I.....^.......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1702
                                                              Entropy (8bit):7.831845141466342
                                                              Encrypted:false
                                                              SSDEEP:24:N/6T3KvVHpr7ie0siKZ6ohLufCaKlphxdT03fHRYoweZ4eXIsavzKJW+e8ZUe9+d:N/6TqdHsKZzhLwzwTOfxL3ZIebBw5h/
                                                              MD5:2294265BB983FD86C56EA524A9357D12
                                                              SHA1:CCADEED98C5A439FBDC42188C23AD354589DB531
                                                              SHA-256:739D291EF57C30D4FD1C366944C6411FD2AD7BF1AC3693B8E6E0A5A362474485
                                                              SHA-512:49C16F40954D7CA2346E2172161F1DB23AB94DA07656A4AA014F61F5FA9A534D83D35F88AB103265BC8AC0A6AD7A62ABC2E10F6B3465A2019E71A98366466D3C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....bKGD.......C......pHYs.................tIME.....&.@h.(...3IDATH...o............k.w...q..I.!2.#...i.D.z...H....E..&.U...g.E[5J.J...UCJZ..i.Bpi..b.....zm..~.....XK.......{....#....i..R.Oz...C.1..;..0n.....0.Yp.1.8.t.Rb.-t........\....>C.^........5?.F.....OL>....u...{+..>...G..._.....T..r.>.u...).>.&{........A@..x.>4U..O?..C.19...../.....p..k8)..?....E.....'w.jm...~....h.8...J ..D.(..)bH$.p....n...e......'_......U....p...~...|.k..o.>J...o.,.....-~....!............w......8..#4...q-AH.Q.Ja.L....[@.[@.%1A..#..&...e.....~...L.vP.c.9~..yu=..#.l.*Yc...8..%.j..@<..`}t.U.t...QE.\$.w_|.oN|.UU.u.EQ..n..[.,.E..AF?1../>.k.8.".;.....s..6D7b(a..4<.-.q.N_e./..pv.....8.]d[....x...ps......WQD.W.{dB..[$B.$.4=Z.v`..w.M=w.I..H@v.5.a...Y.S\JQ..f..S.4}z..>.[.?...*f:@].....".ID3.6.H.itQ'jx...nO.Q.7...2..D...Sh..mX^...u...jR.,.5..D.g.....z.ew...@J....D..Lz....;I..8/....^..;..l.\.:.....td.......59.D)....E@@.oayUn..z...2....p..xv32s/
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):813
                                                              Entropy (8bit):7.570851377012235
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ+pex3qmzm307SBeG0dCg1khFHc97DoKzToJp6mhCrnEULj6I5HUk5dY/H:HaEpex6Pf0cg+THcKkrEujdR5dYYob
                                                              MD5:D2913DD5413A13A5CB10E993AC64426F
                                                              SHA1:FE3E9A7032816A8452B2FA988CBEC2C72D275F8C
                                                              SHA-256:14A7034A005483F6D117C3D94BF2E24757BB952ED27F0E89E5F40B0F2933DEC3
                                                              SHA-512:4B978EE27AB239876D3E8968B9C27220DCF76ABD2C81DB020F4C89EB892CFA3351906A1DF8876687F9A6AAFF46D3570636760AAB9304E0BE21875983B91ABC71
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..U[HTQ.]g.2.l...?..H+.@.bbPZ.D.GT.=>...#.(...~%?....%{X.......G....|.;...3..3.0..as..p.:g.}.1.K.|.(2.FK-...BR..9..+.FG.6?..&.d......3..\HH...h...Fk:Z..$..#....|.<.N.{D.x..J.HNa]:..t....r........:..'.E..X.B..U.$......;...@.4.<n&..!..]..A..u.)Se.Xa...Q(.......,o...loytX.g.@.zOO.I..r.1P.C, v.rr.....d..o6..8......f.o....X6..HD*.r..F{.........].'=..g....M.]..s...m.....Ec9.V..(.O.j.P.3....p.)..g....;#$...B.......L.........6...<c..<....$q....... q......?H..c...x=..B.......D#.)@.A.lOi.....7.B.B...h......jF..yP..@../;.r...o......42Ms......'..j....=.......;...@.V.)...0.....5o!.N.....N..3....z.{.o0P. .....x.Z..7..O4...R(.!}.....I/2.|....fXg........*NDA.2.....3........ m....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):783
                                                              Entropy (8bit):7.616588971497248
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZk2ap253F5TDXhWIoM3Vxcg8OHuUWbDTQSkP3rvdOeZW/P24bHD/G6+WBs:Ha62fBDVD80ut0TvdO9e4bK/ESWev
                                                              MD5:5C5B218ABED182BE649512368F4FF08E
                                                              SHA1:33033ABDDDB14E7624CEE395C142E29C477E094D
                                                              SHA-256:16F38A29AC2DC8179AE843233DE80BBE0950351FFB1FD6AC8878D349EA6C768E
                                                              SHA-512:5BA196BAF1019FD5E55B0976BE45080D5DFC61DC0172AF81CA3053A7361D0F43C3AA22F2DAA9262A3A378FB9876BF11EDD86BD939FBE75DCCD609F0554025596
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...h.a...vwnV..8?oM...M.N..aa.(...n.....u...H$+E.!.W..d..?.D...j)a...g..z..m..S..<..}......9..[...>.g..........U..@.@.p..."....."..#.v.(W....m3u.'..p\......Q..b. }......N..2..=...&....W@.P.eE.+.[....L.:H.h.e7.pA&....k../S...2/^.%a'>....yNUs.l...t.T............5.}L.:.Rp.|..B_..;Ua...i. iE..Y..mn...SV|qK..I.'.........W...G0.6i.W..*K....8Fh..i.(...~.H.M....h..g..o@,....5....\.P.....s...*.+[...%....3...n.x...-..6..1..Iv5..../.>..l.N...A..P./..tSX_b.A..,O.U.s8...H.b....V..w..`..I.....l<....Q"..I1..m).5......`........b3.X`..M\..&.Rl.."...r. ..?.b........^x..d..p&b.y.b.......e.....j.^.Q.7E.v..:".[..g9")...s.3..2a9}......].}.....b...8k*.........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):295
                                                              Entropy (8bit):6.649884229559437
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcJi3qZKdWqGEN6seCVeBQUhV0lluLDu+FVp:6v/7saZJiaZ8WqK6DULQTq7
                                                              MD5:7DEA69F7FEFF54901AA4540DE3A26B90
                                                              SHA1:2B3C12117160BBD00BF4E49273CF1BC6D4ECC27C
                                                              SHA-256:4E199E512497192685EE27FC9A8210A071D6D6E249DB3AB52517750512F79EF1
                                                              SHA-512:708D8F178A6EE4277BBEBFEF2872643FEFA022B211EC642AFD6A2181E4D5DB7D22ABDB7C359585AC0AC42A2750D312DA34CFB83ADF976F0E464E49F9EDF64FB1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```..../...c."....../.@.h..........81.c....a..\.S.....8|.. m.C.L.. .d.V.b..,...jX.d...- .t`..].!.L...d[@(.........8.....0...%.<.L.....8.'U,.a0j.Qh........:.(.........O...d=.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):848
                                                              Entropy (8bit):7.5568178818775165
                                                              Encrypted:false
                                                              SSDEEP:24:HaUhtqUkvbWR9gSDNJ4Ii6o+JATBve2nFc:6U3qZv9QNiJ+CFXFc
                                                              MD5:22D1F372BADE3CD19D8D4EA5449195B7
                                                              SHA1:FD728C6D03F4AF1206EE5691556EAD13FB778DDE
                                                              SHA-256:81B45BCDF9A18AA38373AE2EF09237F4317CC2D1A136B3830E67D664F0E0D54B
                                                              SHA-512:D7DF2E7DFCA76337A5136DE629AB1F00AD056A8BAF486E340CC0DB6BC443B19EEFE73094B7DB9D11788EAA59E786E6D1008BD454F5B142F74F28EB78021E8172
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`@.1&6.K...s.......@..$o...l~ >......a).U...S..WuM...'........3..bFF..@.'.f..q....E..!.....|.?...M.x..'...3.[4...'.5......Y88\.....p.....G0[.3.-.p....l|". ...40.q.....i..D3s.."..x8...es.._df.... .s....@H.;#3.~........8.%I@..+...Xz..9...p8A..B...........+|...+.*...h......8.....;ZH..Fd..a..7........TG..\.%..!IT@r6.p.... .C@b............p Pefa=&.m....-..@>..U@l..*f6......X.8..H..P............[ll.QPq. ....vI...I.....o9..].(......"r.A..W..o\..?;.....n .#.Dff.p$n"4c!...Fq.._ .%..@>p&..,lkX.Z@L vD.?Fh.-g...B...xr02~.6.......s...P....M!!1wh..Z........cP......Q....d.kD.....w.H.......Id[ ..=.d...o.O.u.?.?._n%..)v.......A.........J.G/... G...c...,....@l",,......X.#..i...l.$A...!*...i........p\..1...3................IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):438
                                                              Entropy (8bit):7.1454922264990035
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ0WACAKm/wJxEpNGQfN52iJOLGAfQKTcVqymTpc:HadEJHHD2iUVjTpc
                                                              MD5:369657CAC8AB19A28E26CD10B1ABFD70
                                                              SHA1:B3D69E623B18466DE0F6A4DBF224D250483B92AC
                                                              SHA-256:38380C649ADEFD2939965D573B2639BBE7363CCDEF8AE7697C5D80A7A5E9D903
                                                              SHA-512:C38C52AA86B056532FDDB53B2D301D84416D456A1B5EC4E788DDD10C0EC4C225392EC350FD252D8BB98A834CCF5860EFC37A278B8EF68E044F2DD5BAA9BF292F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....CIDATH.c`fa.......j6....>..C-.XPXP.....`......8//.....[....A..l.H...q.ow6#..n..+!...E..`Aj...**.o..@,..~[W.,v+)...L......b...."m.[_....v..b...8.Y...1..uu..S..P..\..ZZ.ou4Q...0..0..-.YBQ...L..h...V_....81...%..\..o~......Vv..[...d..$3..|..*.- ..........x..&9..X@...O(...|B..D..., %.Pd.1..2...O(.."+$.,.|..Q.)...l..>..-...$..5.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):819
                                                              Entropy (8bit):7.635704166545616
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZVNX17b62WALbzsH0RH70oMGAqr24t/IxQXyhFsM7Km8xu0xeikxGM5cFV:HaZXdBfsH0RH75gqr3OXQMQEi+GucS4
                                                              MD5:428FF2A8E1C428A65F0238A67D626687
                                                              SHA1:EA6C3107060FEC615AE9E57B6F6B9D2795D58850
                                                              SHA-256:F73BD8D903AD6E5CFD440990BE8207CEBB21DB01E7C6F9EC502B022F990088C9
                                                              SHA-512:510EC7DF27C6C5CDFA6EB156E68DF2CDB312D966581069A3CF272B48875AB3C6C36749A0CF9FFBA5294DFFB60BAD7AF9FC3E79B388E79F85D44C22233EA21E52
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...[H.Q..pk7kwg.......zIE"K)(..nP.].@B..I...M2.....B&Q..[PA.C..m-$..n....[D....?.-,..(..~.a.......DD..Q......:x&L..p.gX:.....,.u0..@=........U.....\.w.'..._..t&;(a-...~..S!....,.F>....)......D~.5..a...Xz..~........pY7.(mG.....:..|......5..8....,/.....rh.F8....^../...d.{%..R...P#...P.d..,.y....^Q?..dA../....Q..wZ..l..._.Q..P.z(.(....].....e..0G.....5)H...ZxI.8jcyd.=.p....|.7Tp....,.L.\..1.5...ZB.....K....X.$...[.v./..J.e.n..h.......H..*.......>...5..`.6..B.zz...(.m..v.R..M.}.x.A.0....#."ifOF...&xI7Z.8.2xY.e*&...2..#.......4..=p.|.L._..KZ..$o.b[...fu.K..5_..7.,.....-.._.OI.#....#3UK..#..L....s%.H..&..?ey..3..Y..........#....v...._9....1..>90.|O.#.vh..;...7..I.....4~.............IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):955
                                                              Entropy (8bit):7.678938775213358
                                                              Encrypted:false
                                                              SSDEEP:24:HaGdg7vCEGoK1SWXMBOkzv1G1rurCE2whDbgy2c:6Gd6CEdK0Wur12vzkDbt2c
                                                              MD5:5E161199F7BF3EC697D7454803E16A45
                                                              SHA1:780FCD972CD6C76EF4EA111C60612E547604B5FD
                                                              SHA-256:AD716CDED42D9358C2FD198499BF5A4FB67E73680CC9DB0A29CBB9E8249B7F13
                                                              SHA-512:394AF75C35EC53B7F8A7C0FBF4F701069C08C02A1120C9112E442EB3B1D0DA8440B4E7EED00A0233EF26902B4AAFBBE54CD6306E7CFB8945BCB22DFB7FD03BFB
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....HIDATH...{L.a....9u..2Vs....EM..LCE..J.bn.njQaS...J.+...m.iki.........G1.E....i;k.F.x...g.....s.......q...6..]`..C7|.y.. .....a...o6...w.h.........2..j.q].bw..%Lcf.\..[.../b.h.......1.<K...`.6...........?......C.dY=....W....s....q...I0......K..........p...x...#A..P.I$.....ld...)p....)..._.v\.W...7[....:./.7...R..7R..|..y.Z...Z....c..(.L$5......H......(..F:|u.....B........V.\SA.."....w......\..A.5.(.l............S.O.X...56...L.@$7hO).J........w.Sn]4.).N.7|hO.+.. ...}..];ie.....!t..A*x.0.............mHd.......#...4.t.r.4M....O..j.."...I(.....vXY%.+.GA...3m.\`..`.`B./%..........V...D...{.....t..`..:!.I]^.T..r.....d.E.x......L....;,.....6.....~47.698H....0.M./r.........H...t.Z.oM.....R~....3V...........7.Y[.MwZb.pN.D..!......3..?....=od...yP..x......?.]...r..Q.`r.[M3..[.....".f.....[KK.*OO....~.pm`o.#.,....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):852
                                                              Entropy (8bit):7.6502777375247275
                                                              Encrypted:false
                                                              SSDEEP:24:HaZqVMMxXARkEAOAlE8K6kFdztpFTS85Q9JUCOa:6ZqedRkEAOAOB3xppScQ9Wfa
                                                              MD5:1682448020FAFC44AD2698704BD978F1
                                                              SHA1:C943E219766FD441EEA7130FDCD8E4370ED80841
                                                              SHA-256:E5D4E6E6D637E9ED03E552C0D0D7F1DD88E13F0C0276DC77717B9DE13F8D16C5
                                                              SHA-512:233387F10B15A929AD3C487594299729F3903A8B3BF2AE0A0D22358A9F6F21D70F20060336DE1D820E9FE2670DA58A7B2572DCD7196174DC45C493F7C7EB3F66
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q....7.0."...gh..aj.+..%i*....(ERI1...,.>..E.~...7.n&...,I..2$.!.....l..;...~....?.<....Tj..rA.R...%K.\....E......8..@:x.dZ.I..+z.(.6Q.fL)1..,:%....@#8."x.w.l.'.zo...n.n.9ij.r.:a.m..l...(.W.....4>.'.V..L~..`........A...s..t[<.;..............A~X.\:...5.#..a#A......O..w..5u.g...W.w)....+[="......1...`.(^..5......e.h.3.."{N.s..#...D..<...=Ox.?..T...-...dGN.!Bs ....,r.s.z.Q.>/P..`..,.USp|.^....._D....c..Do..{.,Z.....DK...H.......i(:a(.*.o=.,$l.......n.<_I.G.Q&2.v....C.b.......m....L...H...qqa.....`2...^..5..[..........;.f.....)z...S..A.f%.0..X..V..|.l&cL....Va.8...g./b.....3.~........q..t....MC.F..,..6..$...?.GE.dE)g..b.eI.E F.N......e.t..g.r.Wdp.e.......\..A..a3...`...Q./..\...k.........P].8....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1272
                                                              Entropy (8bit):7.805905219435155
                                                              Encrypted:false
                                                              SSDEEP:24:Har/vpjaC4G94qhbPSSBR5hoBJFVKVtWcrCkgbeH5vQ5q6IOSU7HWPXJz29LK:67vpfLuqhbPSmsBvVoYcjgbeHQIOSih0
                                                              MD5:07316DCEC4B7A791703D32A63F60C99D
                                                              SHA1:FD5BA289BA923C76479B382449F01217FA298D6A
                                                              SHA-256:8419CE5D7CADAA7D5170ADDCE1A6E1A53E738D504E9EFEAB63B3EAFB60EA41B2
                                                              SHA-512:B1D8C3AFDBEE5E3CC78044731B69DFD70B46006CA78A9CD125A7F28776A237C695BF042F4B8F7C0008518EA44DCA612A155AC47AF5252EF302BD8A3552B937C6
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V{L.e.?|..].wn...Jp.4n.`h.$..)...A...........Lf&.r.&t...$.T.L(3.....-.Z......P>=...........>.sy...{^.j...~(TXX..(....(.j.KMQ~......5..f....n-.J...5IA..W.p..~..Z-...u[..85..G..E....].. .6..$k.U..].}.p.?.....t......N.bV.+"..e.....~..5.............k..b.....=i.U..j...QOT...T2Tw.BT.u....s..TgT.'dF..8R.G.^...[...H(.8.,!....^M_^..y..\.'.".).]xe].:0.Ly.....J-....{g....;....VJch..Tc|~1s.3l[.?Z..S.../7.."..d?.@..w.Z......+...........u...f.....3[....'...6../..f.]........o..@..q....C.^.9J...{#.....]..u..5....8...lO.......L....-.....|\.p...< N.........Q.*i|..}[.EM. (.....Y'.)i...}. ......z..f..#.....U...<.z........Th.j;..n......PoVF...... .*.x?.X...n+,M..pG.. j..C.Y.i~E.z..^n]..H..X.....s..O....I...F.......<#.....|=Z......7...%>?x......8n. ....G.G,.Dxo.............V.E..c.D.>i....[.5Q..O..x..8.......3.^s.....rh.z.v6o W|o*..+Y.s.....>,.."....Cb~A......h..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1210
                                                              Entropy (8bit):7.797403183791096
                                                              Encrypted:false
                                                              SSDEEP:24:Ha54P/JCe7IcvpUGodv2vbAIXc3/Ccsqr8FT7v4//X4LYpe+ttyq:6mJL7IcvOXAJ22RtvAcA
                                                              MD5:353CCC7351B2B66BD405D3068C1D73FE
                                                              SHA1:A06894386C79A7C50DBBD6A3A16C5AAD561536B1
                                                              SHA-256:5EE98476395C8980E580D8E65E738AA5045F8D94C789FE5CCF5ECF05C3A807E5
                                                              SHA-512:BB3B02D59CD6B4B6A138A67AB66E6FF450A9F1BA47BCBEE579F8026BC8B0AF6998BE7DBAD21D93BA3D5BD5206B5914D8C34A85A704DA5F89284EEEDAAEB70717
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....GIDATH..V}L[U.o..{}}.X....s6.c....S..U.lP6'C.3&:...cl.. f.h..E..8...&......N.\.&..4.9.RZ:...{.j.2...nr.{....9...}*....$Kz.k...tK.?.-.3z.8..\+...$..LQ....I..O.?.qigS1.w<...<..y. .l.1Q..+...H.v...8;;.......&X...0.S.|t.e......../....@...P?p.<./..6q..P'q...iii....S.....m..M.....^...O....N(.\.e....;W!.g...t...O.G........j.Q.....#_7.....<...5.W4F&.i._x....!^.OQ..r./.U.......Y.:Gs.A.Zu1.~8..n.Y?..h...._.IY. ..h.k....tHg..U]YQ.Uw/.^......e.F....[~.9....C%.:+!.kCh.Y...l.M...sEI..{.HJ-G .......N.K....w.....d._7>..%.'...&.!.C.....8.....M...v....%.YrFN....Q.p........#....D.YI#.x... .B.".d..2..h"..15........,t.....;...E....DP..<.D..(...i.xz...*.,.h.x..H..Sj....w....J....@.C;...5.[.@.E..-?...%.#.<.!.B..s'.4q.m.x.T..qg..Y...Q.W.?A...W.wB.@.BP...{.1@....usAd}Ik.w&.Bk...0.X..2...pJ.-|k.iZ....L.`.u....y......{V...{.*...AV5A...9...`h.z..7.f"b..[.......4:..$.Yb.."....>.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):616
                                                              Entropy (8bit):7.443433882018433
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZI0EdQ+P2zuqZnT4FutCrxGxgILodO2JUN:Ha25m+P6uinPgxGxPoQ2JUN
                                                              MD5:0A28DA391C0B41F44D9DB40A89730F46
                                                              SHA1:0E8564EE9D1AEF4698C74B050A93339A1D1BE081
                                                              SHA-256:88D3B02C5BB1E488833F260CA1AD60BE75530622F5059C004BE5D67DB12536ED
                                                              SHA-512:073C4ED98726FD034ED92EB327AB483133A8EEAC0A732F6EFBC85388449A27C5BBE34229C595CC85B104326E17476CF032041192AB200603C56798EBCE8B94D8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`.i...C9yX.s..bag......(......?.c0...K....7m3....{V..........[........P.H...\,'5..;6...s..[....D.$[.....S..+S.7..._....G..?e...|".X.~P.Dn..\_._..n....d._..._8.YW...X....Q.^.m....wz..h2......(,M............W.....f.......2.x....V.o..DM..4m.?.,.i7....z...."X.....\....]Dm.jm#...,pJT.....Im...b.....A.!aA...C.n4.v#.e....Y...r..O.........M....g.......RG..x...~r...=...o.../.@.....l.....(.&EVN.....(.d|...VvfPnV.F\..K..sm..............Y....8..-../(.....)....X4Ogfe....h...8.J.N...........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):660
                                                              Entropy (8bit):7.505490499073369
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZVAqFBVJX2RFsYI1Rw2VYatgFfLAgxQ7IE96gE92Az:Ha/AYwXQRw2VNgS37IoLI
                                                              MD5:6BFC1F0ED58680ACF33DEBF613A57148
                                                              SHA1:56E760AEC70ED7D8C65124554ED80C706BB5D2CC
                                                              SHA-256:902BF9B0AF9DD955E2DF20181FF175CE06599738767DE91218B1BF2555F1BAF5
                                                              SHA-512:5DE9C029350EB4231CFD56D8F7A722B5D94508029BA1FF27EFD8FFD95D1A4566DBDA270247669C5590E88ED6305104E65EFECA3462A2F78F46FB9E03840F3B2C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....!IDATH.c`.N.............Y.>q....a]....b.r-.`eg.q............W.........6...i....#........S9P=3Y.,8].v...n.........N../X.._FK..;7.^..6R..'r..].._....'.<..E+...Vou..b&....y!.."..@.........g..o.%...s.~..P3!(.s2...1...%E./......b...?.,.[d...O@1.jZ......r....... .4...`...:..l.......7us$...J=......N...l....r5...{.~...P..`J......O.T...z......rf...h.l...q2Y..s.......d.? ....b...I...{.[...s........B....yIw..m..o.../.{.....q....r.......b.`..?.....l1........<....@.\..;.......}..(cN.T.,..Dd...-...+.....9...+.'.JfV.?,.L.....8.....%..V.....Se....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):377
                                                              Entropy (8bit):6.927103825066419
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcrrcOaeSUEz25zWlletybKidVPzMk7d0WvMlnn/vRsOAdMoPUj6:6v/7saZ/ciSUEzmzWlkLiDzMk7d1M9ni
                                                              MD5:7A3A02A08C59BE3F7C4329CB10D8B19E
                                                              SHA1:AF608974F496CAFB45D338E7312415297716E310
                                                              SHA-256:CB59BB21593B4679AEF82AA2B4C7886AD746B913683E033075D5D537D774A182
                                                              SHA-512:950221A7BFCE6A317364133D330477823C4737A74FA6C782319C5BDCCC25D0E5CCA795FAA7305A8A165FA4D365B24FE056E58531DBF1F429494595386BCFE86A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf....@...f.........^w.......... .....$...Hc..7.0H..K.0........``.%C.s.wc...\.<.\...[.).&.@..'.....9I.%...(S?..-A. .(....S(OE.Dez....a....3...E... ,$..P..-\.1..z.j(...D....`.....> ..l.S=..a...>.....l.A..).ar..R.-.y..$508.@......hn...".N..hM...Af......O-Z.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):613
                                                              Entropy (8bit):7.485960849218955
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ44oFSt+MvaJrWSBNbVFrI6oULDPXJKC7VfBv7UDN1Hmz:HaloFe+HJrbl33PXECRfBv7UDNEz
                                                              MD5:116E10C815F01EC18503E5EDA39F2B42
                                                              SHA1:C72F96CFFE84F253DD1573F4B00902E389EBD42C
                                                              SHA-256:633F0472936E4434F95DC7D417B84F4A7ABE9B96AF16488FE8C430A6B441DF6B
                                                              SHA-512:B4F4EE1A34B171A3A011E728615D08078140602D1D8D582A7C37E050363BF093990B0C96F68B643A103C7248BF239A10D70B117408031C2B5462D4B8BF79D791
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..?hTA.......8H....),SK."Z..M.b.B..)..D.S..W\).I<.-,R..C....y/.......s..C..............A.(...R..~.j.+.#.[._.$..........S...x......@x..gL..u.8T..<).>.>.c...Q?..7.^...H.(.c...E..J..b..R.$v..s...s#.1...w..z...0....<m`......9._....<.a8.@......,.ZL.l.....#..........0......i......F.p.C.#.NBA.p....B#....5<.Y.....N....d..m..j......$....v.....v..I..i..[k....Z.#.I.d..G..."..5..{....H..... ..v.....<....4.q.{p0..S~.....E1..I.&)r.....z.1iBN@p.t....9.c.^. B.......u.x..~...._....-31.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):577
                                                              Entropy (8bit):7.3423909253899
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZzxpD9vUVXvuX3uFswJC0psrx6+Y/YIGLum1BSwZM2dUUlN:HaxD9vYvuY0+1/YIG4wB2U7
                                                              MD5:A721568DE444D543B710252AA03D748B
                                                              SHA1:D8BD4BE2E84740150C3F558C4AF008D846FDFF32
                                                              SHA-256:C7889C62624E70A97AF8F9FA35EB1396FF134FB3DA8D2C52B88CABCCD0C035DC
                                                              SHA-512:DF6593C262D51F49EEDA0BA4B32BB814B1A5C27E845C1B3C4BA7CDD82051E14086CCF23D002987427503D3B03F1B1324D75EFBAB1C13174AA7BFD3EAF3F23FA7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`@...wcb.8....0.Y@..XX..X..ie.../..n!..L.L.D...ex,.b.`..>.....9.X.233GS.."...g..;.x...=....X...a.....J...l\,....~m.:......5.\.8m...6N.%...."F ^.SW........ek..Wnr..gdd....(.d.....;..7....^..`.#..~~..K............;..[@J*......|..e@..8.H.. ...K...o..O}.DDD.......*`2."-.....D..5._p....n?....5..,.M....._q........v.R-..3.##..11..+/...p(...N..|..h..lIQQ.V..k.........mw.g.......b....G.O..yz...]......O.d.+..U.....~..i.-.s...ZV8.._e.X...'..@"-.~&.Q....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):206
                                                              Entropy (8bit):6.246485617263056
                                                              Encrypted:false
                                                              SSDEEP:3:yionv//thPl5ljcDm6Kp0qRthwShLKOWGEVwBsUXp/m9ywb0fx/pE44XjWdVXK7M:6v/lhPZi+aWdKcB7RmNQZ7RdVa2N2up
                                                              MD5:1BB90612C945D71E39B134FD84989B70
                                                              SHA1:7B694DDF126D09551CF17BD776EE68F8F54242AB
                                                              SHA-256:6D153ECA03C5A8EB2E0A86A7A7E5C59BBFB0C70C6346FBCCB5B9CAFC43D90394
                                                              SHA-512:0F40A021A59847C1A6601CC993164B6CEB0F1490235FFF7766CF569AEBCF215F092E5C887D0E022F50358AF97677B0A8E7FA788D7D38B9F02764B88644E15EEC
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....[IDATH.c`fa.......j6....>..C-b...Bx.,....A4.-.$....F#.......`dF2.AK'....O4&+.h......."Z7[.....'.@....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 18 x 18, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):545
                                                              Entropy (8bit):7.462798362030968
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7uk3aZ7BMOFiSe2BCZ6hdxdIjbIqzuRJYSa16/LVqSWq6I:MaVBtS20YPb1IFGJW/I
                                                              MD5:0F089C5C3D8F200201814E0EB4C3F459
                                                              SHA1:63ABAC882C2DB38D101E23AF193F6D4F43473AEA
                                                              SHA-256:353DA4B34D653159DF2EC1FC2D5CBC8CF7641FC7732927E6F5D7CA90A2053A8E
                                                              SHA-512:90CE0E0F141C5A88F868913B11E1CDFA0FD23C7EE53F40CEBD7BC5F003E51665B0BA3C1B2346836187C0DD7A3CCF086B4757ADA23A02ECA573E87A7DAE50C0A0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............V.W....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...+.Q......a..t....66$..;eXP..R.l..$Y.RRR...%J)C.k&b..y.......S...9...........e.j..W,#Q.........2.o.g.9...Ng....hH..1.........a.I_B.x&...z.ySR.....F..~6..p...@a;nXQ...Ah3CY...~<.Ej.0..d..)..5Z}.,....b.*.X.N.........(~:HNN<LJ..o (..@l...X..O....P...W..p..u.98.r'.?>......./.d.c..j.._.Z./{te.hh.%.0f1.....y....d.M..'^.P...Aq...^=:...or......6./..C|.8.5..JS..;(.......}q KM.."&..O'.t...~\.L^^..f.c|_>..7.7.A7A....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):307
                                                              Entropy (8bit):6.663616187019764
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPXK+aWdKcRWGTNxsApmjrFStcKVqdDH2h5BKwlYXPDYQ/bp:6v/7maZRWGNxsAIjGcmC2hdYfDYQ1
                                                              MD5:FCABE0FE5FB6AB4D1BC770E86AD12CF6
                                                              SHA1:867239C44A4BBF506A46B03E8ABF757A7C037D5D
                                                              SHA-256:3D5D9F419FA612706668AE59A2584F565C984DB6ADDB38BC7FE00C7DC62B59EE
                                                              SHA-512:B8BFD5793B9EA21237A90951CE2964EFB76A0AF2B67B1D1DE101F32DD2C4533D4C0E3F58DBE74ACF2BD0CBD35973C9D6879828953B15A9D2014C8429C1D751CE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............J~.s....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c`....!I............@9P....?C=q. ZP...C.X..x?.L/G.2...p..B..4./ .%>@...-%^9/.{..3.5......v...aL.L.w...p.W..X.-.(x...E....>...A...`..z..C....q.W....A..$...=.QK..!K.{.w`H.....v..,)......9.F......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1279
                                                              Entropy (8bit):7.7728133290999475
                                                              Encrypted:false
                                                              SSDEEP:24:Hagth1pJkSNT3ozc6+HhciZMoKhHydxHKNJiQfMmUqvG3b8aMJthT+M/6tVP:60Rh30c62hlShHyxHaiQeqs8aS6b
                                                              MD5:F4B99D3B08ABCE65385AF2311B6AF205
                                                              SHA1:0BB77AA406DE198E1E7CCC244E2782C2A99636FC
                                                              SHA-256:1DF75926F2E4805278B1182EDB75A121543EAED317E25F76A758EE4BE6A2CA6B
                                                              SHA-512:4BE3CD59A4F807773ECBC8B2F7BDE70D5FBEE235189702BC26E2252B5E520AEC11D81EE6BFB6654A448CFEE8DBE7A1E5EF614984EFE8C4D75AF6C021F99A82B6
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UKo.E...}.z.&.u@.....$.. .R$...K!...8!"b......._ ...0......$..$.-..$...W.....!...vw..uUW}.....}...z*..|..*...<.]......^v.....6..N.`'T^.-...$.,.!.=H.!H....w...?.....`....MG....6C.B....$I!.F..CH.}...h.@z7...;.....`..E..._q.v.js.9.C....(U.$9...9Fp..{..K...n_n.............f..n...=..V.`...U.0S..4Z`..j3`U.\.*u...r..O.1'..^..V...7*...2K$.z..i..i..p.ctV......;u.v........K{.....Z.|.6...I..,<....].G..s..!h.A+f..4.....;....hf.l..x.P....C2..di2...8.N~...2....F...E....ywB.8........p...........[7.X..c...6..f......M....cJ.Q4i.tY.). ) ...`.O.g(G.......O?.Y.w.<....(AdI%..^.C?.a,s.?..)....<....6...ux...E.c...Oj....."$.3.F.$..(-...h_.J..'SxP".*.y!#...R.i......t.........$.."I..@..$.V.Q..q.S<..n.....2.....C..~`H...y.E.?..GD.&*.0.)..\&..i`..e.Js.2=;...Q...0...k=.&...#.0M.)*...#o.].4....9..n.j".4..(...-.....v..iM.......g....t.$...D...........$.....8EL..h.ipR.o'j.~..j..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):990
                                                              Entropy (8bit):7.65551415416186
                                                              Encrypted:false
                                                              SSDEEP:24:HajFLtp3/M8CuDffgrBaaMOwBb8ZjYUPOA3e82:6jF/0mgrBfMO6bW3WAz2
                                                              MD5:3E6D7FA4522E07F8192A81502ADD5A53
                                                              SHA1:9884B12F9817BDB8336949275B83990E58902BF4
                                                              SHA-256:C6B55C49D45991902846062F9E4F1E2C0D62FB94B1A561C64869DDE6795CF2E4
                                                              SHA-512:A97D047F82592BC9EE66E9A96CEEB37601F730AFEDCB7F6E927B2A325435FBC0435A4B7F22CBE7DEA302828BC06693CC224B6CDC2B785C4D6F487AC21C29ED1B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....kIDATH..mH.Q..9.jj..2..Va/.........F.d"...t. ..^|.!..C.\.a....(...*....,..D.|A..9..%*{.....>....>../omm..b.....zz.^+o/.....f&`.ZI....&......r......................o.0..=.yz....noWW.TVVBNN.$&&.J...\.z....*JJJ.@YY...v..B.c.......B...n.YYY/x....L.......p...T*..@LL....@}}=ttt..........4Pa..fc.EEE$.pK...u... (..Mp\\.444......0...:.......:9F(............EX.....b...(.Jhoo..wb.}.9..a....ZV...n...wGKK.....=//....~`M.~...f..hnnf...t.x.>....."..}...&.......mmm....B....VVV...j6o0......8.4....~..h4..w.*...As....i...... .?...r.....d.r..M....fs...:G....w.y..b.pbC@..X.H$...ann.zzz.<"".\..P.u.....J......a:,......V..F#.}~..N.pS......N..=B...T..Z...8....,p....4_.....6.........R.<2N.^..)7.$.>33.f.'A...Q.p8...7..&....X..[..=..821..+........Q"[M.U..7%....A>#;.L.<Ah.;y[.... ........4...N........V..9...p...-....E.r..*..9(H..*..q.../....3\..?.E.{...a.._........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):361
                                                              Entropy (8bit):7.136545221158386
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcNhk/eXTFt+0bT32NHeVrSNjPseqgdVp:6v/7saZzOeXpt+0brBVrSVp/
                                                              MD5:E66957D87199382D40D1B3AC2030DD36
                                                              SHA1:F325D0E8E6F917870C6347A23E00BD4790C57F21
                                                              SHA-256:3EFA6A5D9F7B5F09B9FB0DB45EC34D615C80BF1D9F3AECE3BFFD79DDA460DDCE
                                                              SHA-512:15BB2D84A28242A97CB427C85172BF95C105E02763F293F1805507FAD55447A6713BB7BAACB04D74D738D48749E7556DF15D7BAD1FDB04D2B8445EB6F2760931
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...M..0...A..Kt.S.....!A/..zSt.:.'.<..<mk..Iq.yx@.....Q.^..B .x6..t.R......4....=..0@.g.G...*......9.....&d.{y .[.Z.w:...X........!0.,.k..+.;.]...QL.(B..B.U....`m.O..Ef..6b..cM....'..).D..+\.A.w u<.........E.%$...&...sqk .C..UT.5.....}...0......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):306
                                                              Entropy (8bit):6.779836965175441
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKclwiLM2sv05l2rJJsXFT0l4T3ZI1c3HIhLXHqb25XK5dp:6v/7saZlRl40FT0lw3eoQY254z
                                                              MD5:8E64E50CCAC92FC093AA628D8112F8EE
                                                              SHA1:10915949A8961D422913911BA06526558261753F
                                                              SHA-256:E6B37820393C225CC6F6AFA6E1A219BC77AE141C3D7752504361E23396590513
                                                              SHA-512:9DA167F55DE5CF1B13A689761CC1592DAE76B4DD63B22ED91BF8AAB4BEC55C9FDF7F289B5A7C4115B8CE67674EBCD100E93482964B1E3ECA6036309404C46B81
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```x...i.A..../_......^...C-...s.....'\.g.}...l.,l..p.c..m.m0.Y..Q.......<...P\E.@5...:8.f6.a.2..>.F...........-@.*...0..M..Y,.l.......W...[.e..`S......9.X...%..\...Bn...[@......x.(.f....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):316
                                                              Entropy (8bit):6.818936178614701
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcTN30YmdwJb5Lg+F/M9Twluxdyh5NBGUfYup:6v/7saZFtVLgYixdyDNHfYc
                                                              MD5:0ACCFBB75443E54C4878CD76EDFF0D15
                                                              SHA1:937E5DBEA628B6E0D0B3E6C791C3EE915AF298E4
                                                              SHA-256:A8023BFB133FA556C06693FFD28F06B34291D0DF793A93AF19624F42D78E13D9
                                                              SHA-512:D19DC1E6816F18978A3B6C1F8032CA3A0327CC90A0F6B3348C2A203658BE6D9AC607024AF5F1EA9C31C6CE026351217A43CFF6D1A9CE00C211B11CD594C4FE6C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```...S...PR,...;.}L}.X..>c...8U|...n.Fg....P16ZYP..|@\J+....j[p..}....Z..."-`.b5 .'......K........l.../..g..{r-...7..'.Z...f..'2P6Hl...)2x.U+...P9.k4..2..`.R..B1,..R........W..*d.>y..K...9..]."...&.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):262
                                                              Entropy (8bit):6.584171654438013
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcJAg7vsGDI1xhQxdskJ4VUyXKvgJBawDqp:6v/7saZJfs8rdr4VUeegnvDA
                                                              MD5:413E95B3CAC7DB03B6E40323FBC18D98
                                                              SHA1:876667A7EE4327D386AA64040532A1E6DCBDBCAE
                                                              SHA-256:5AA196E1F2735BD69C4385AAE15D962D42338CD4AF33986D9EE2FE77875CEEF1
                                                              SHA-512:42C341F2CC135AEC25A9C5F59FBD1BB151F0378557C9EA0F45662CE692364DA240E70E99A7CF84863CEFCEBC6A85EEEA2BC41606E1E9A883023B71628DA91D34
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..^...g.%... ..1P.(.....$.jw.....Qn..9.,.).........l..I...}@.....j.,.....d..Z.C}....\..r&"........w.AD-Cq...a..|@.C.Y...*M......P........N..VSZ......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):993
                                                              Entropy (8bit):7.688663120600708
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZps37hqnMk2Rx4FKY9o1GF3S0a7S6Va13TRm1EaKzAmWP3PU0tTZcxX3cm:HaIW9IY9o1o/a7Szd2pbPU0t9cx8b+d
                                                              MD5:391040BE857029A0BB882CB51DFFA521
                                                              SHA1:AD3038BEBC151F7A7613835C41B4063B2F376EE9
                                                              SHA-256:5A2E899C9786B7E9FA9F1E06BD49404A0B36FF29500D05FD0C55F990026A8319
                                                              SHA-512:095683084D980049DBED2500B0C2FB7FCADB76DECB4D5202A67FB9F2B4363CCEB7CFB2CF3B69CC7E6235E6E1142C3AB9FA80FF69F2C14D6AF98ADF874A93893F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....nIDATH.VmHSQ.^z..^w.;..$%.5G..i~....B$..L..a...fF~e(...eZ....4E.S.v...V.a.0..c.F{;..]f..y..s......}.;...s...O..a. ..:.!...a.o......!...m~.9.e....,..%....V.8...........I =.x.)....E..;/..."1.)........G.J..'....r..a..0.T....... .8..8.a76..e.MJ.......N..K..AH...I.E...!.....S)....eQ9..M...{......P!.s....\`._./.}....WKX.xj:..).D..S.=..Z{.......c......h.O:.....A[.......[%.F *G}......M.&&..j.9ray..TQ..kg...wp...?.hz..P.v.?(:....a...f.e...A8.5....a...h.CAn....} .....F..N8NLW...J....T......u...6RE...$..x..UA1.v{.....n7........Gf...A...K.n.=.......6.g....".)B..'..\|iy......Gp...60....\.]n.a.b..$.H^b\.Db:.'.c../b..@ ..............T.~...b........X,@.............eI%../.6...r/r.$..^...[..o.{.&.0..._... I.|7.h.%.7....!Pt....f.B>..4.@.._..3..`g'....".$...8L|...&..S|>..Un..a.Jq%.![x........i...mw.w..*D......^L9vS...Q..B...K.......o.o._..s.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):411
                                                              Entropy (8bit):7.242398236393612
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7+aZTasVcx36DtL4a6g/dhwV7rDoRjuKblWw6N:FadasVum9ju2WNN
                                                              MD5:FE0F7DF9971E48C19D8FEA372734E52D
                                                              SHA1:E60F5AA29E2D442BF66A595DE9939570D0D9755E
                                                              SHA-256:D2D12E525510C4F1F4E307925C7ECC406DD2F987945D936EBF59B088E807659E
                                                              SHA-512:D60AFC0E757C906BB3549900042B068C11743AD5AADBE990DE9366DB3E4430D3612D3C04F39C82329CEAD2849339A15E29AA6C04D3C3AD0FEFEC1A5EC4982B47
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....(IDAT(....K......C.$"....!..Z\........"..p.]...%..A.."....."T....)....z.P.K.<.Jn.(""V<.I.#.?.4m..1M.E.:l...ni.T<.E1...EE......M.9c.:..I.DD./.}..0.bYDl...N.p.m...u.....5.h...eU.n].Q1.@..1e.;;.....o.E\2"...0...u..X...qA..X......y.f.'k...q.U.Q.......8..?..s\.]......n..es>.UW..7_Rx.W.5.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 20 x 20, 8-bit gray+alpha, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):407
                                                              Entropy (8bit):7.178780035130412
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPUb+aWdKcEsFn+U/CrAP50JC4/N+FI3/l3Jmhe8tgO2dEJIobw/89y114OP:6v/7+aZBcmWBJZsIvlZmgUbw/sy118Y
                                                              MD5:727803547B9D498B078729DBB656D2B5
                                                              SHA1:1A542DD567C5804764C9A11F16557B7CA1AA9DEC
                                                              SHA-256:FEF7AFF7C54E323D86718B4B1C66920E69D2B42E53F114FB1629161F840FED10
                                                              SHA-512:DBC33E83F3932A5B9AA0FE4174E600E934C652633DB6EEADA0CE285B5E1AC8EDEFE363366669236C1BEE31243F382B009B50B212A42A0F99014A69110027CFA7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............'......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....$IDAT(...?H........!.......Ehr....%H0.$...hp..1......[.%*...."B...#<._.y.|G..{Z*..........M.[...DlY..."........Q.Sz.v.=.......L..G]....f....i8..F.].s..cA.;...M.T.-.'}...i..8`...U<.2....f._.pS.G..4..3f...t4&..5.}.u..3J....qYI.k..Wu......"6.Z....6.].DCD...]}...Q.T.._I.u{...S....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):485
                                                              Entropy (8bit):7.338671748313559
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZAt7iUNbC2AE9kqYfILAAdRi07YXuqlXFDq:NKa+tRNe2X9kq/LAAdRi+qlXJq
                                                              MD5:0B139E6D98EA7664969D538AE9F30173
                                                              SHA1:4AD439ADB97A2BF953662B19E8F15E2DC986D758
                                                              SHA-256:AA926C6838263FFE0045CD7209D930DB09BE7822EAFA0C429C92FB8ABBCE4211
                                                              SHA-512:824EB79F7B63F4C1690F32E66FE17174FE3E523BAAF60783E0FF94D0C920C19B12419027BC4A039D81CFAC470B18206E66833E6EA5EC2BC995888093B2763FB1
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....rIDAT8...M.1.D/ AB...%..*.(.>H.*H...H.@BH@p..`<..#AX..g.gwg.,.4.n5..z.}wq.}}.g'6..d.K....|;>.\..6.W.:.`B.......Zk.."......Y$....q....0..,l.,d.....$.....*..%...n.$/...Z".J.;.......,.'M.r...w...HBP\......&.Lg&..u$8.V(U........ls..e.\w.45....u../(..R..]n\.nQ(....(k.D..)..XPDA...3..T=w....3.....]...m..Q....N.2.q4j..*.qHF.m;#%2..;;.:.(k....%\.v...^{...?.....e....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1424
                                                              Entropy (8bit):7.817369567859558
                                                              Encrypted:false
                                                              SSDEEP:24:NKaJbYqc0xTBTFi2TY7vVYFR+Y40kmhp7LwZZRY//NAl25MH:nuqc0xTVm7xL0kU7j//Nx5MH
                                                              MD5:187C609F9439FEA205DD9BDDCABB7D71
                                                              SHA1:CC07D2BEE876ABDE4FAFD2B2C27D28B68978A46E
                                                              SHA-256:A873EF621E5A4466809EE2E8ABFDCB063DEF0FDD965A129FFAC83A57F817755D
                                                              SHA-512:CFBEB4DEBFAF9494CDC971FDF51750A1D2C852AD2976E0A9587083DE21B79DD93AC5CE63905125D6970EE144FC1DD74344AA6BC86A27604039EC6AE7EF13C57E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8....W.y..93H..Q.Zo.B..Pi.d7d-f...Rh.1e.a4d.I3.....n].J!.0...7.i.s~.....{.....}..y._...I.;x..Z.T.. .e.....os..I.R.n/..mI.."[nq'.H....l#Y....9.,.\.fw.D,.Y:b.n...P.4k.{K.z.r...%..H.m:.ua...\..3WZ...'..E_..z........y~e..Lo=.."..G.(....D..........+..t.0nX.Z..M..[&...v?.&s...,...........\..9.U.{..`E.......?.a..=.d%.v.......u.G......^=..xm....,.W=..'....PWCr..Y....#..C.O.qo.).H.r...A....SF.]d.p(+.QAU.....G.BZ.;...0.h.n>.`.%...fW.r|}q..<...E.+.Z..........h.8E..8..S3.......|.......o..M;.q.6..W.?..@.-.>;5SY..MUi..+#''...N....+.&W..Y}...VZ....P...]S.....cQ.F.._<.g5..H....(.#A...t.........L/.3Rq.*.....f.J....:..1.>).<!.U....d......\.*.'1.....\.G.0.A8.}..@m).nz..E.....5.k...g.j+EA.,......z...E...4....[v.....%..4..Crc..6..b..<..p.n./.2...I.......k......@......lE....ZS.'.....=Q..%...g...A.$;..:>..wJ...E....p}g..J1>.;.p....oR.Y._Y..o..x.sOk.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1352
                                                              Entropy (8bit):7.808495374579655
                                                              Encrypted:false
                                                              SSDEEP:24:NKa8/xBij4z0AYjpTpZ6SLfI0TQn+8twOHe9auP3k0QaPwF2E8z5:nKxC+kVTjI0TQ1twOEPf9zDz5
                                                              MD5:57353E3C3926BD8F1A7F0E7CFD99B59E
                                                              SHA1:ABF39C3A16C8662712825D01F9859DAECC47BE17
                                                              SHA-256:C1ACEBFD14631115E0B05904BDB8EDF3895684E75EAE41E68CAD60FA47E10AC6
                                                              SHA-512:3087E0D4D3382259241ECE160E8DF4ADCB6EA608D41785D20732D73E2832E8205D1F51D2107289507F9D487D894DF74E07A9B004A0C8FA80A28A4AF61B08A845
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8O.Tko.E.....Y{..q..y8nh.Z*.".._...w>....P...*.R.....).Ij;.........t......{.9WQ..C.~W4LJ.....~.m..Hd.9...Z.h...(.-u.`.M..tTC...w.....f>.aO..(....f./....z.dYF.*....tUg.T,qjh,..x......j.F.r.D.P..X !..VV.(.B..K%...Ql.......f..Wl.1..-.w.3.F...9.8...1..r.`7.<.('.#.|..g.'.q......_.N..$&.P.&.1..Z+j..S.p...!..,r...k..t..R>.$.D.r.1...!2.....M..L.....3...u....T^%.Gb.e...P~....0z..3:..5...g%A....@+ FQ.".........*9...D0B@.W\...I..3...~........;.q:...L....4..a.f....O%...r....|[%...L4..aT.Q*.......@.~..1#.....#.f.qT.)eKY#H..t..3j.A....$........]&...F....F.nv.3..(..w....e.*$"M.8.|...H.-......]..F.B,......q..R.&gO/0.k.F..w.*.T].........B.9P....q.;.....z.%P.dZ*e....A9.0..'..v..^....7..j.;sAB.n..Jv9.|..":.;.^.2.g...5.E0e.Y.......V>Z.,}x6...u..l...4.y.Ar.....W~...A'....V.&.j.....0UM....twy....~..YK.l.......g..r....$S.s.<R....6...Z.._5...?,..Z...c......n,...:H.r.4}....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1414
                                                              Entropy (8bit):7.804249307631032
                                                              Encrypted:false
                                                              SSDEEP:24:NKa/b6wxzZ+sZUT+kvUaRLfQfxyHz5EshfRnWKTOEDpzpFOZzwqCK3OqYRv:n/HKT+kv5JfQfIHzXhkKhpzpkZzw7uOX
                                                              MD5:34A70EAABFC6A8BF981949C8BD860240
                                                              SHA1:FBB6AC1B11169A365D871D99D6657A6347CF75FA
                                                              SHA-256:20B2C5C9CF8EE17B25816897BA20A57A60571248ADBE38E71561C10E47A8E8E0
                                                              SHA-512:6946500E625AC25059F389887ED34C5779C13B7B5DEAF92B5924A9245F8277D831D58450E3F699FE7F85D93562C249CEF0C1BBFF344278096778C780652AC89E
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...SSW..M^....-HX.l.I...R..:.HE.....A..qi.m-.c].S.E.J.V.(Z.T.....{eS.k._.........y..r.....}.&.....m..G>a.cO!.m....DeY.?.>....P..,.5#-ylW.0...d......'f.8...p.R.`E.......=..S..-.".U~D.y-G...b?(8.#5.Yf......r....@...g........uG4M....t..!.)..[f.&.)..a.c.`'b:...g2..XF.Mq.O..).j-.4.o....e.o.W..0R..`U...C.+..g.9L.......j..BMC.....P....w...BT....i9.,.....^.Du.......V ..?u.. j...[7.(....Z..,..N.....a.....{.Jc=.|.....t}w.^<...gzn..j.O.>.h...#..p.N..........W}=+.Q.;..".#..1....;.....4.1.,F..O..."a.]..ZhE4(.'..L...o..(gzn2.......5.)PT....B(P....cG..............._..Kj...m;.r.....!G.p\..`..yF.Q.-..........I...~..T>!..N..m;..c.rb,.....P....A..x... !..4.}bF.'.+.c.c.........D.5.5.|D.........aNEaSs..2..o.1...o..(..@Dhf..p.W.....-...l..;.Z.X..+g..j..rp..[l.[!%M9,...D.... P.$.#.w......+SD{..qW.x\[`}.N...B.F..T..4..F.p............,h.n-.."....b.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1166
                                                              Entropy (8bit):7.797797851076832
                                                              Encrypted:false
                                                              SSDEEP:24:NKafiuEtcDXDP7WjWiLp05HZVF9YyWIJEJF1F1b0m8N:na1czj7uWUp05nLYyOJLF1QB
                                                              MD5:046AEA9AB7057E55745762FAA010E10B
                                                              SHA1:A91FA64199894B1CA4F292A9BB576BDF486C60F4
                                                              SHA-256:CC403C513AC0AF447371E2F553FF3FF348C8BECFB99BE81A3FEFD996EB398EF3
                                                              SHA-512:3D9C639003604D4C8AFD5523C5B3E272685FAA8073C415A69063B0F35AF4E4C400D8EF6C7BC9D9D2C90A902A1003D465409883B41C781A8F2B4F0C7489D364CB
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..{PTU....w..]vy.....$)........eWL........G..LZI*..........1..`.l..."B..pD............3g...9..{|.?.......4!.h..&.|:^).,..QYj..l.a.D9.=s.=..$.{..u......)......]{s...e......Y...>......77..Ws.B.q,........M ..X..6.....5.b.......#...O..H...e... ..1..0....:w...X..o.K....h.!'.....yv.".4S."......s.;.M...A..&....@k"...e.b.L.[.c...@....g.[+,I.sk.m..''[.6..<i(:..T...w_...2...s....%.|~..D.O..u/y:O:N.....p_/.Q"ldz4%\.'M.W..w.^Dz$Y....3T...p..,.d.......Y.%.....^...n.9.tKY:b...x...Q...Yb..z..vP..*.#}.t.....DN0..C.M.l.....;....g..O=..8~....R...[.K...dAM.n...=......k...}Wj.>.<...m..k.....[........m{u24.{VK.tW.....Q...>.oyD.?V..f.lW.GK.e[..O.!.....9+.KV2.L..'.u.......%..].v....4...h...`G....).N(M..P..X....2.baL<.P#[.._VN...FA.Y...U.LD.../.#.j..a&.l.V...."...<QF.@.u..(y.Fzy..rS,OiY.n....'f.{../.p]u6..{v..i].w<#....J..z~...<7..G.....y..i.....{...1..W#....44.<\
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):940
                                                              Entropy (8bit):7.698059274671223
                                                              Encrypted:false
                                                              SSDEEP:24:NKayTTWBJJBYcqUXXBqCLpy4eoK/Y+wUfBYo3MaN+hYdhqxaZQtU:n5vJB5q6Xk/3wifBY9KdMcAU
                                                              MD5:88456D52FA5CE2113ECA03F1E2CB7A97
                                                              SHA1:AF86942112096F87D3572D3FC1B23A701BD685C6
                                                              SHA-256:2DDB6497DB20C2FDEB867B42AF780058D976B22786099C77282D2D6916017423
                                                              SHA-512:4C156B3AFB3DF5A2A5E339465ABABBD7BDE255AE9167898B748DCCC17B630BB4A632B4D7461572D4C0997D3755BECD38983FAF2947F98D15BB50C6ECBDB50F77
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....9IDAT8.c`."Xo,.......*.@.iMQ?nL.._.((.&D.p.6.A.Z.d..m5...g].B.A.LD.T.."...$ .%\..A@..XDWO....o..4...|........_K.(eg.~zc..[..F...D....d.`...G...:..\...T[..H.k\......E..qa6n.z*. k2..gx)m.W.n.f.Q3A..s..l.~.!....=...*....5..YKn....g..033...-...LE.15WO....S.U!.@..!M...b..m$.XIl....12<..._......5._..D.K......W....y~...A@.....1.b.";..V.7.B^o......sn..[...~.........z........y.A.E9..?o...lP....W.~=..A._.,H.....aK(0....X.c.-....\..|%..8.[.P..u.D6..n..'*..... . .&.S.$W. .."...."..vs....d....z|~......P......k.g.....,5....).}j.............O..\.../.j6:.gt*..N......jk...... .....~...t1...F...v..KyZHC..5...........`...^..<....:.r.q..........q...i..z.J.uz(..'l.....CU..Z.j..7.x..p..V#..8.P`"...5..R....WTZ...%.9.t..TW..a..]..n.....xS...+UOW....K|...g..o.0.,...@5..;[]..g`.....b\....^..........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1271
                                                              Entropy (8bit):7.806469024341951
                                                              Encrypted:false
                                                              SSDEEP:24:NKaHXAnYeAJvDXw4NaxsqugTF5/Zd8nFE6xM1sjHjeRcSA7:nHg2JvDX7AsqR55rSF1XHSRcl7
                                                              MD5:14920E906B09626149CEF38E4BCE82A6
                                                              SHA1:9FC903C48025F9F9BDB3A0351AAF6B89196F2787
                                                              SHA-256:AABB8ECB201696CE2DE4B71BD5A6ADC9DC87458D61A26B001388F1B924A6891C
                                                              SHA-512:E9782A18827F09D62B7755F77982779701C025C64A5C018B6F5C4BF7A9D3BA22523F91DE69B21C1CBDDDE98CEF69762EDC0F5091008D266D7A91592D15BFBF7B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8O.TklSe..iOo..:7V....[.s...@.:@A......Q.d&.@B.. .x!1H....A.-.?...,...tc..-.........~z..9.9-.../Mz..>..>..~..]|..A....R.W..s?.2..9j*SE.0.J.*.N.d...h.,... ...Nu F........(KH....c._....D(1..L.V....l:....^.Nvp..W.>.E'....T..B.2..d..H.x..+.J.....V.S.z...$.d.B.....n..l...u|./B.<),.7.>......R..Y./W..-.$..s...B.8>6.G...-.f..).....%. .F.u}>vr.........".....k:8C....c.?.N"8..&...^.-..w...I...s...b.~w.sfi..h......~.#..7....#O....x..@.@.....R>..7..k.1("YA....,....d>..).cD.[........|..........-5.......Ha......lO.V.2m.E..T.........Z.J.M...cb.o........D..r.wy..O.=...1JE...wU.NU.S..g..0.P..)[.PLjJ..A..7-.;....sb.?..]....$]...M....v.x.'.@...D....@...Ed.....m.....a2...3F..X...-.Z.C..c.......X.F/1....tg...G......?}."q.{.M!.N6..l...v.dq...<.[......([@.B...E..g..-.v/v}T-...M...8.5..Z.*\............[{n].4....><)..]ba...y...#..r.K;.....~w1.".........#.l..hQ:..H+.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1246
                                                              Entropy (8bit):7.7774242762524946
                                                              Encrypted:false
                                                              SSDEEP:24:NKav6spIR70nXxKVBdJCYjREcHaPUWO12ajMKMvQu1+80CAC:nCPNsXxKVzJCeRZHaPA12sMPMCAC
                                                              MD5:B6C4F1B8069156D45626FEB88F39735B
                                                              SHA1:261D95B451131A13BBE7F1C3DB7E4D43B792F656
                                                              SHA-256:F683C94984865C1D450DB960F5B0D329F228B9F2A16C8DE8C8B7518E757DCB90
                                                              SHA-512:B4463288C0C76A320E8CA279FDABB8FB82CD490C0FC32EFD9F1F8BA9D7295E1A33413B8764FBB238F6A4B3A01F492DC3E07EB1FC4E5143024AE084039C1DBF64
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....kIDAT8.T{PTe....e.e..]X..1.Lyh....h.ZX3Y...fSS0..,.|. .i..,I.h..1|T#.X.%d5.P...1,.l........\...|......BBn.....&.Jt.L.+...Y.0eQ.*=....=N.0A}...XD.".".''o..b..L.4.....,.r...k.J...m.......LB.M.9r&#J.A.K.?C)".%#...(.}.z.....+/U.7.Fo..8.....Q..K$A._ncI/.."...."..._.+..yQGEj..Cq..]...R...A.I.@..g.H.K..s.sYCg...9........M..D...p..e..3..`..|..>...^...V..mv....\|fm...Q.0..p`g..#..24.d........C...........y.f.....u,.A...?.02.......8.o.I..t.hw.{.368.......=.l..}*..ix`..S.$z.E<Y`......'....q.......5.,E...S..[aH+.....k.2....?[=.5z..+{s..ru....C.....].]......+l..t...k{j.?J...c..2...1.&..FA.a.;....)CgK....-.].yg.B#...4...u.@.....Zj...*.=..ua..Z.4....u..s...........4..:).l0.R...JG%\_.....}'..(9]...,,.8L./b..Q.k.a,....Bu..~..........F`!J.Uff.{-@g.kC.LSGe.`..Uc....z.G.....V;v...L...k.H+K.\..4._...6.%.v.l>..F.....o.^.....YG..*t.......Dj..sNI..xV.sh..i..;.....W.....r
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1178
                                                              Entropy (8bit):7.804844334364623
                                                              Encrypted:false
                                                              SSDEEP:24:NKayvtbsVHLp4VV8k9q2m/FtmZRKRZR1IzrmRoLxEimgqEY:ncbs4z8aPm9tu8LIzra4OlEY
                                                              MD5:86D892E71AC4015A288433E03EC49AA9
                                                              SHA1:B326E43693B4A716916C5D6B5DEC30699A1B72ED
                                                              SHA-256:30774B36A38FBCF8BF0E51CBD9F569B52EC43534F0A8E218F2ADE6F01E3258FD
                                                              SHA-512:B15F69930C0ACA543AC037E6423F71119A156E2EFEC80976B57616D641BCEEEA3A1D45D81B14EC7A90D3299D11AD33D58E3EDA98AA661D48DC4F9F19AF4F0FBD
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....'IDAT8..Tkl.U..........Z.>....%.(h.@..QyX...h(...(.`P.hP......5H....4E...JK+.R..R..i.m...;./..;..?9?&w.9.........<....N..L.C......c.g.....H...|..:..P..6~...[u..C..}.....n..=0%.....V.@..iJ..u..8f.C.........M.*.<..)F.zJ%n.]0P..@.S,.8,G..r....G2......H...n....9.....z8.j.i...n.}5WBE.27IdO.LF.wu.pD...[...5...&Z..=O.....#.P......].....u%3e.."Q..':.r...<..hCQ..yf}.%.S...g....U.a.+....YE...I:P..#...q..v>Q...1.3..r4..m..4.,!:z.!..zT..:.st...2...IE.....H[..1.....B;.LL'.....$u.........M..e...O..LL.*.i.%u.Cc.......h.F"..4.t.M.>p.4!.w..Xp.v..cb...Z5.-hb...K:..D@.~5....L.'...*..<+K.}]..s...M.CGk.P 0.fV....E.,`......skW.FS...g.........S.\....o..........=.}....E."3.5_.."....T...-.0M.._tY..N.y...P.d...J...]f.I;........-..0.B.U.....Z.@.....t?...r......0...M.......W.P$.........2.8......P..._..q....5&..E.&x^..b.....!OR,4.X..M...........C4.%{....T.....a..M.n...M_?.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1212
                                                              Entropy (8bit):7.789728112228107
                                                              Encrypted:false
                                                              SSDEEP:24:NKatGDvzVjgvDNFp/N+SD6I5E7TmNMnkxZ5CV4OgaOZVXHVaEuwz58c:n4zVa7ptt5SBnoZdOZOE/I9
                                                              MD5:7768E97229175F79AE6BDFF0EC911338
                                                              SHA1:7D95E4851E50B5338FAFCA037BB1F6284A6E1D78
                                                              SHA-256:99E5E32140E254CAD6365529E4D9E75A368E02A90BAA8F60E47D3E89CB92CCEF
                                                              SHA-512:A72DA1002E0DE0F5B58CBDFD7A02B6BCD4BEF7F782C4B58EDEF745F77C5E7FC8E084AC81B152DEC2DE7C3AC29B4B023D130D272F26FA13EF77C7348DCD52B608
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....IIDAT8.T{LSg./..Z...R.f<...1E..8...S...&..!l.e.Y....L.i...:...**.'.@./..a,.R..@.......e...?n.......w.....f.....j..>...#.+S@cQ...4z^T.U..4....p...2...T.....C...#..I......]8`F..F..p..L..1..7.U...t.B.+...X.u)......B;>\.o.....I]..:..W...#.6.u..x..ak.u..E.^...Lj.3.../......j.*Y....g@....j...:S.}.^.@..S...t.|m3na.;......y.....){...........G....e.aa.7..K.n..[P..Me...7:....tu..5=...>.O^L.z.....<. ......2..s...F...%?%.R\..Uw.j.......].5VT...m...@..M>..x.H..@).5.Jv..*o.8.*..."..E.QT.2.......j&..CR....v.>~I.......+.e.;....DGJ_bB...2{.X...;....|.bPuq\T..E7..........)3.....?3&.....1....i...I.....x.K....e./...Tr........O.i.........(2Y.Ho.-1.l.nn}"......#S..iz....y....aS..{...b..v..s..._tn..J.....o.o.r...a...AcF......+].....n. /.....r.........>./.!.#....%$.Pk.?.t...7....'...&.@E..C.!"._O.....w...%9..N..3..8...'..K"....5f..!l.K'....An./3K..Hg......C....E0qZ
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):382
                                                              Entropy (8bit):7.091139352072596
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKcudu2H9s7veHV4vP6bAP4bfzrn2zOhR6/N061gI1pgjRg5h0Ic:6v/7aKaZu/ds7FKb3vhR6FF1gI1+j+R8
                                                              MD5:7D30802EDA70E31337CBF102445F62F0
                                                              SHA1:F7FF0022BDEE8912BE1195CE9F6ECDDE9547747E
                                                              SHA-256:C2489D049090A645DC8D78C4B5CADC39836B77819F1621C235A7F19EA9523521
                                                              SHA-512:51383EAD561A7605E007A1E68391ACB89D5E43B5458ABE478E257886CDA0BEAF9B28BA6EC4A628863A4D1927EE54236AFF62BFF031E8A605BEB71774F1207130
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c`."...K.J.. .A.2\..b5>..j..kL.fS...j.Izhh.#.P.~.:F6...P..~.M..~m".};[..`..h..-W.#....1... av{~V... &...#. yv&.... "..#?+.A.{.U.....u".A."I.B.L.5.R.......DX..4.b.%2:....6X..DP.N..Q...}9.J!...x.7..j..p.vK...j...p.t./...F...I.D?.-'..\.Q,...w.c......5."....9.5.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1490
                                                              Entropy (8bit):7.831566708508583
                                                              Encrypted:false
                                                              SSDEEP:24:NKagt3wgbZYBvARdxpiIkcqgzq1OiJq8pFsXhac5ZFoDwYZeBFjgFOKVMhppcS6N:nqwgbWBvAdpvkcrW19qE2XhaUmGBFjgn
                                                              MD5:5A46B56F02FDA5D6623DDF636DE197C6
                                                              SHA1:A5C99BEF8F42568CFC040C0A1D70F49C46DD10BE
                                                              SHA-256:36E9DC2B2B868E8B2100CE3FA77816793F7DCF85963DE85226E0F15E0398398E
                                                              SHA-512:16AB38152FBAB27EECE8E7AAC75307319500C7AF75D3EE0EC4EA718D56292F4BBA939FB84C538519D9B80411C1DB4716B142DAE95A29EF6A9E4AA6F89B7C0243
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<...._IDAT8O.U.W.u.......A..9.LEC...g.b...e^....T.}.&.....$.5.....A N.<`Q.......5.........}~.... ..c..x.F.rp.....|.... .c..[w.k9..........?..~n.ckf...."9..v.YC........Fo.(....)...>n..9......VC.`.t....4..2U{l/k,O..H......bz+...@......^^.}i..].....D.:7.]...k.<.u...\.a...1......k>....xg..|......H.....q-..w.Y_Tg.r..q.v.G...zj6xk&:.I...kW.0.t....X....=...dy|..k)..a0.....t.j7].e...c(....D.....Sc.ix.%<.Yq..h..e\.I.h......9c.o3..6.:..D..7..v.........:.N....y;oc...(.tt*].Z.....:........Syj.o.v.Y....Z..:'....J.$..\N.El...}..D..1.o}QU.4..^U.z.........O].tQ.....;*.1?a....../.._P3...@9a:...>>.qIb...sC.Z.G......K.r/..ip..0{.......[s...... d.*.3n@X..@r..tf.^.....>...41...+.....V".................OL?;.....c..Eay......E..m...skJ.t/%._./..!...-....rg.D..j.o.-.p.]...e...O...M.|..^\.6.|..`|..5..1'{....X...z..P.u1U...4....I..v.9o...a.......;)."..>qQ....7...$/.../....l..>2.^?...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):951
                                                              Entropy (8bit):7.747218915734698
                                                              Encrypted:false
                                                              SSDEEP:24:NKabe3s0vsdfihBvaxZuf4Y+ctisn54L9:nysvfwixwf4+tis49
                                                              MD5:1F74CB8E2355E6ACF43E44D28A138C7A
                                                              SHA1:3DC1FACE31D2B1E47B16A39C7463526FA085C17F
                                                              SHA-256:FAF1B5BC5867DC66F1AFAC3511B5D7A3DDA4CBBF64F432FD3CBB010A00E01336
                                                              SHA-512:F31ACF993BA7BE655E4B4E87FFA31CBD2EA5E26EC1174A72C41C3FD57D6F42D56DBEFB5DFF5BCB05A6575DEC2176667F7E9B8DA4A0A6BC6A043336A12EABAF08
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....DIDAT8..iv.0..M..B)K...b.0....=..-;t.f..`3.....y.._b.....j?.h......v[...{C....K-.`.&.........`Y.u....+...`.{.pC..K..P..0.....!..$..&..dl.....zv.....HP.z..X..7:.1.....!.".....=V.h...5....5....SV0........V...........*.l..gH.'.>.{.KS9@....Z.h....EUi...V.E.....}D.....d."@...v.6..Y.k.HP.n.Z.!z.I.........I....3.6.....6+.d....=..~Q.....$...Z.f.."ZD.8...]....q.m....L.a........l.m....@."..Q....3O.....v.......kz0R..uR..%.8F..o.,ya).?,y.<}.#P.^.z.`.V...].L..2V d...JT.....&)...y.A.PzN._......d.@..=K..x.....E.2...l)..j...T.u\..[....).....~)?f[E..N...h..EV"k.]u.9...c.5G\&..4...*..@....8..U"X..d....5....~...-[..C......fR..v..Io......o.v`.K.3.%.r6...s./;#(.....*p.i...-c..S.u.E:..\...8.88..6........2..x..<.k.{.A.AWqQi....*M>M.....\. .....*...1|.Ja0......h.S.....CZS...J.S...>...} Fv..6....V.Z.v]..:../.........:..c....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1312
                                                              Entropy (8bit):7.806633556387323
                                                              Encrypted:false
                                                              SSDEEP:24:NKaV3hhyuostgkZYNf9q9UVuS82GrfD3jrQpdtAr29iliH3UpICKop7bDztcJzYB:nV3h55tgW41qHL3rwdu6miXUh3pPftcg
                                                              MD5:685023499522C0ACACC3650269C2E8D0
                                                              SHA1:34A9CDF9EDAA4CC10EC7FACBED724179B7772E7F
                                                              SHA-256:B5BD53878939DDB310F67ED7A49FDBD9577E29FB73F53136057AE6BF2DF022D5
                                                              SHA-512:4D6D3CF2713F994E0ABE2B058043F54DC15263F915C2084A640BE5D128D2BFA30EAF4C37342E434044530EC707F362EE52603027E105EE17457DF8D7E8B61028
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8..mPTe..].m..l..S..D...0M.8...#.R.6..a.0..c..."j..../...(......./....+........}.sznl.H...g...;....;g...$...3.}&..p...Y]1..A..p....[n...A.h.f,.;....7..y.J.S..'f)..4J2.........1c..w.b.`..P.z<.t.........y.6.^....tb}Y...x.X.;.b...9....7..f...!.xz0.*=.....g...l....I..oYm.C%6.N.{.".)./..N0....e.g.EzA. ._...73_}........ .......T>]UEF.O..`..l...+;R.Wd`.i..O]..//.n..h~........C...LE...........2Jsb"......TL....Y[..C$.@$.t.*3..ja. ..tJ..F...j;.a..i..j.:.%..9....z6.,...:xZe..}~...W......g..*...d...n....xz.v.'....Gk.%'......fYE.(8>J.#.n.U..+.r...w.:1g..-7.H..)..X"Qp...O.^0.Z....!{?f...yZ......o2.h5...|*t^HH..o.A.G.#*.. ..u...{.S.p\^.....-:"\/=.;5.8.v..3>M!..T..e..>.O.e...Z..........1........Z....%.......;_.dS.s..f..L^#........O..sq..%...2u..='..l..+%{yM.....v.....^.b.L.?..T7xt<..F....(J..V.....LW..Cu...S....c%'....7.....o&V.,.....^U.1$p^@>.c .r.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):613
                                                              Entropy (8bit):7.427799481386969
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7aKaZXl0BKkPTHHmhW8GCTadF3X+ngTge44neweuwqpiETv4pY:NKa1SB7nmhVsZugM3UcqpXTQpY
                                                              MD5:7FFD376E74D922E67505ABCE95F6C685
                                                              SHA1:C0F712C0EB1B606EFA57B80742545F1B710C53D2
                                                              SHA-256:7453E8B9D33849D564B00FCDE2B998A1B8D85DF5A4522671E9753940E8721BD4
                                                              SHA-512:71718825F556E608ACAD212E5C6BCA2C255E23AC9766DDFBDAE036ECA73CDAC8887FDC8E3DDE3BB7746BE8D6BC49940CBC74F54E9E26CF8007EA738A6D085528
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.c`...v..?...`Qp........A.fy....qc*.?.......(....W..].S..xm...{...v....._....V..DP..)C.s....2...V.....Z.-.,...?.O.'.@..-6}.=......|.O.....\p....'......?nL..!.d..2u.F9.og*.)..(A......_.......w....`..?..J-..1.QVF {...\.........+8.k.3).c....#L.iH..l..i.0....C.S.4....3..8x...4V.._..*..R...w.=[.....MV.....~........A.....mu..gg...0....~g..;..g. ..b..?..}.............Y...p...;....2..(...L{.t.'.!....2....<.-..<..t..>.....fJrb.%0....Y.`..`.8.....,U.... `......LJ.......1........j.@.OLJ.........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):354
                                                              Entropy (8bit):6.967704790210181
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKc1MS3tIUieMhVPXxtKPs//smt48o+baQDyG2q3eW4ebkXTp:6v/7aKaZ1d3SUNMhVXzKW0mt48CxGJev
                                                              MD5:B9088083C16AF54A3EAF7A2B204CF399
                                                              SHA1:FA74CEDD7BF4B3F791A83A38A2F068D5CAAE1B85
                                                              SHA-256:BECAAA5A1B294B5602F9C24B40E28051A71074CB05249D31EB9CC54848078F2B
                                                              SHA-512:745A07FAC46DB5E13994BA8C358A93F52CC5A8BDD1334E716DDE5AB86FC6BCAD1CE8C63331BB37D85D08B176BE6F2B836CBCA20E9B6E42821A694AE401B481D3
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8.T...1.|..)..c.f..a.$.`.6...F.`.$D...#Y......../....nD....s?.c]...3N$7`..Z......E..r..+..Pa..}^..`....E....Nc_...y.....e@..x...G.j:.$../"*.0........E.z?.....c.MMg.I..h..`..8.d....@w6..}.E|...EB.r..$......I.T..;@..M.......Q..EP.......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1262
                                                              Entropy (8bit):7.74984945189834
                                                              Encrypted:false
                                                              SSDEEP:24:NKa/wQT4f+Fa43ASC/5N+vM1fz1O0rje0jwr2iw9yZmqLRHzAdvX0YDTnWz3azXd:nl4fLEAv5N+vcL1rjB0r2V0z6rW+zX75
                                                              MD5:A7963ABE71B89FF26D4972F6CC4A3C53
                                                              SHA1:78F9CFB460B8D0FA87B91492B60B210D573FC9A7
                                                              SHA-256:F26D903A567979894819BB5F10E5E91C17E5645D3500E63D431656D07857C97F
                                                              SHA-512:62598B21C1BA2593CCF91381B4B86A437D2B297DE8DA4F77E46E5A9BB0B77C2BDE8D81E5231B098C1B00AD4C8C06336DEC9709D03251AF13638F9E15CE354A7F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....{IDAT8..Kl.U..s..?f....g[...|%.;.....%..sibp.^7...&nL.....HLL4..A.........1.).:..?.=..LW.W|....w..<%..;..X.u...U..u..K...m^o6......l..z.@8........E...k.x..0.y...a..QP.x8..4......fKL...5.y.z". ^T..ld...,...1...,..(.ej_ub..W.=.K}...l..V..y.s.T.D&4.P.J.Z..a....dAL..k/.wh.K..%[...oB........Zd....@y....<R.j0....q.(..*S.\.(.:C.....7..Y.m....-.-.O...>.*YR.D..D.&.#/ri..+.$*.R....A9.`.kl.F.@..t..jem.PX........ .....*Pq.K[ii.4..*...Q...h?hw....dh.8.Q...*.T.......s.s.f.y.1:=..Z...8..Z_.[.<h.r.......)....p..W.."....N.n...o5..n.&2D..gnt..x..W.n.....r..E...*y...?..............Yw...-...n1....#;`J...Pt .D.3.8.....ZiU)]L.V.'.....kf...~g.....g_.f.@.>S.@.%V...^h.lr.a52..*aiU9og8W.......o...I.2 .L]..+H]g....7.-.@L......B..vn....ckT...P[}.@....sY;c..........'.#....,..K=(7.SM.v......X1Q.*!..L.....w.x......S{6...e..Y;O.n#...|.....16.[F*..ll..b"F.....[=..d.it.1...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):305
                                                              Entropy (8bit):6.885611004494081
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPyJg+aWdKclRA+7MxYjs80uO3tpNt6EozkfuJ1egDBRV75p:6v/7aKaZnA+7wYjb4tftRuJsgDnJ3
                                                              MD5:9E805445A938AE8B849051182375D425
                                                              SHA1:7A44BDBC0148AE1B816F279B87EF58CF205AFF93
                                                              SHA-256:41F08FCD57E266C4DB874ECC6C363DBA31F43C164B9A559FE4BEA8355286E1F6
                                                              SHA-512:F5E92409C71CB973239B8FD95E28EC5DD0EB1B62305980235EEAC092BDA3464DE65EDA010B9AB043CE1AE494A45FFDE651AACE1C4B4FADD47318A99FF273BB64
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8...A.. ..P....^...x..z.n.%.a....../.....4].>.....Sh.yn..wI..rgI.....m).F .fk....C...A.62.u.M......7P.Bj..!Z!...9....$....+....%.l..`..)qotQ..(..P.....BX#.....NMSO............U.t..!..........IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1379
                                                              Entropy (8bit):7.851578122642154
                                                              Encrypted:false
                                                              SSDEEP:24:NKazZG9rCnBno2MtYpvqDHkeN9kw6Ixiux1GXUyPxB+JbJC9:nuCnXMaADEeNuwbxfx1GkymJlU
                                                              MD5:6C19AC57A7B307C7B679DF83CA41D7AB
                                                              SHA1:C80F53D9F776194EB7F84C4FA179AF0FFFAE12BD
                                                              SHA-256:C1DCD18D5D3F947734425481D555C92C62EB6D0281DD9C907F877A62D6945781
                                                              SHA-512:341E56C4E09BBAEB3492277DE744ED2C15F7104FB902C47702A1A33C85D186C508D31E2C3A9AA198EA9E64CE4467BF36942F487847298017FE903AC958625804
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDAT8O.Tkk.V..9GwY.e;..;I.4i..XKW.V......}........`P......-.....$M.tn|......../.8.Y>z.....a>..>y.5...bJ.............N...Y..<...,...v.[w..Ro......<...M.~9V...UR.^0.B'0...#q...c/.nL...QJ{.n....1..<.....@..G5.....jA..B.f..SJ/h....9lX\.J*..+........e.zY .jF......9q.#'....../..clZ.#....*I..^....../~?.=.{..@..w.f..u1.n..9h...0.../..K...~MX..d..............(.....p.T.Y.O..U.+iA.^'tB)+..2W.M.[...v.v.O....&.K".PX.#@...%@..........,...y...X4h.R..$#.X*j..M.!a.V^.....j%@......\`..Sxu^%.*..nF..u{l......0UJmn......9...3j'...F...a..........._5.'.T........!...}%.\..F....u..'.F.6]N.....o......t..G..MDP.E..}5.Wu.g...../vD...........-.\......v.n...J.h...a@..~...|7"...'K. .z....*{..1I.2P......ZN.....U....Xg.'.........|.E...^..LIF.S|....H....=A..Q.~.]..P.b2!.J1....cN..Y....4..x3.M....m.P..iHY...+s........1....#P!S..G.....<...djW:hC."/......J~=./.g1.g@.._.:.p.`Vd9....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1454
                                                              Entropy (8bit):7.841228180729992
                                                              Encrypted:false
                                                              SSDEEP:24:NKa1j3DsQHMOXA1ZRXdeSAHvEfMhZTLHMWKbp7QBaeaNGDgBntMMvi2:n1jQQsXLXt0Ef+xSl8aF6gF/
                                                              MD5:90F436C4EB5EAA5DA54205F501C001F2
                                                              SHA1:F857DDD43CE290CB497C319CB0CD5048ADB90AC0
                                                              SHA-256:B355518DA68971D4682F2A7106792A9AFF066375D837D3484B349E36F4325E5B
                                                              SHA-512:ED6CEA414EC1889DF688AF0E479C1C203FBEA514AF181FF499E5C1BD2A19D09585E5E58E285B4B5CD7E4B56E2B1B130CC96B40CE13EAE8E45B0B1F3013326D7C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....;IDAT8.U.WTe..;w...a.E..L.%5M.D...W\.t.<.....[......IS..s...N.....".&.B 0!..3....=s.....8.}........,-_....}.!.l.x.0g..1}..JrcV.1....5..y.]..F;S..(..g..M.W.MW...h.....L-wc,MYBO.q.uL....-....Tk.e.k......KV...$..\.....8...>..Nr..C.'.....y._Q..T...vs' ,...4.....Y..^.)Y....y.Bo.....5ga...U...U.C4^.Q.g.._.u1a..b..I.1Q.j.+}+)T....zq..2\.k9.=l.n.........G...I.ai9g._..[........}~....!.7O....yK&).%:.tg...^.t....8.q...MT~<.n~.:#...@.W{...=..^]..;......E.c..zOV.....L..:...f.....t<...."..+.._..7...47........&k.....J@..*[G.......@kv.@;..ar.a.u.b~.c....tw....f.........d*M...br...X..B...@U C<>.;...V.&'..>...]...`.n.k.e....7.e...<-...Q...)_..^0...(3H=QI..*w...r.)..p9T....6..N....sB5..b.T..s..^.....*+.N............X.S|z....).JO..-$ h.u 0...!+....(W.'....5.X.?...N.U....|...R....(.m.V.......)Q.??r.0422rw....0.....H..C.h.}.-G...H.W...t:X.i[2..k..H.su......+...u|./.J...7
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1259
                                                              Entropy (8bit):7.803232996291471
                                                              Encrypted:false
                                                              SSDEEP:24:NKa9VJP+IHiJhJkMJtdGaIY+8b8tt5HkNmv5rktJNVh+RNJIyRR0hF0s3IS:nJziJz3dzIY+8YXHBkt/zMNJ/+WDS
                                                              MD5:6B1FF56502F329CADC3CFEFBDF6C1067
                                                              SHA1:7CDBE86E176E8003075A28EFE90580977B2B23A9
                                                              SHA-256:BA6B20376D36647802093350DE8945DB55420A816A1E5AB1E70B1B5092B62345
                                                              SHA-512:19E722E4CE2D1C6C78E7729C7147AB5B7DDE62CD467160F9189187F998B2FE3C69D5B025A0E921DA6436F950D49B573622AB4842BAF8DF5C8E9B7F277A9B79DE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR.............o.......pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....xIDAT8O...oTe.....W(Zk..**A.@.@..../E.b\.!$".....5.CC.....l.L$4....E.(H.Jki...B............{.y...9U...X..vf.....px,.....#.?>......e..Q...<.q..5.....n..C.m..E..|.....t...Mz..k.c....2.Og.5_kY...^,..".(5!....5.e..jg.hI.5%....w.....gV..l]..l......Wn.H.K.x.7...<Z.......U..VvH.qMT.......).ue...}....__....s#.n./...gOm..?..Q..E]x.BuaoI@Mx=^.#..D./...f.....3k.N.6.c\.{w.7..K......%.../m.w..U.W.Bs.~.R..Kq.vq.}Q.?{^.....4,...C...y..."....o./..q...Z.o.3X.T.3.*.&.....(wy....hQ....:)$.n.!...$o..^A.;j..N...4..a....M..Z.....>.<RG1G.Z...>.86YX..Zo...._...4R.....2W..6...'{.......~.......`.v9V..YcWh..O.T....Z.G.....&.k.{*.W.B.O.'^./..9..L:...j=;{.zz..D^........<..p/.T7T.l...P.;.b:...c..3._..u.=.=}....1..........k...gqA....y..C.....<...s%L...R.3.<J...W.X?..G.. ..`...$Z.G."{..)].U..3d..m)D#.'W.li`.V..+.xU0..u..n...&..$....(7.#RH..2.:..s..l....Q...+.=L...r.3.<
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):761
                                                              Entropy (8bit):7.518655013264083
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZms4A8a4Pd172GGemXR6EnQItP4B/SmLe19M0NkE5ht/avcQLJLfV23Yn6:HaArA8Jj1sRbREKd9MC15naECJDgQGR
                                                              MD5:24F6C36BC9BC1971C1C0E66B60A9E014
                                                              SHA1:712C61ED11A59D225CCC7D075B9B16CA3FA6DC49
                                                              SHA-256:31E68A423731C0EF3DC3B43029DD6E1205FA7D041BAFE98A8FE04F83DAF19B16
                                                              SHA-512:78A46FBC5D0F1714BDAF4F482BD9E60A3B0FC714EF9E8C2EC6CE1C1687EDFDF071793B0D1B7ACB8FEF5E0E37285D89AEA555002EC8256D663DDF600AC8019F59
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`aa.....Z.j......~......{......V<....o}...._..P..[.......|......0....~#l..?...<....m..y.......z......+...h..?y...M.`Xt........|.y...[...h...x.NlS.....p.x....3.8>..z....y...Nu.....f%+.'.:...........^...O<.b.fD...m..|...5m...W.ZR..........dx....i.....mY.h.K\.......E....}.q.sF&..z).P,!...'..8E..f&9.8.........M....R...p.u..6>.......nA..g...5(...4\P...f9.p..S...d.:.,\..o!0.d..8.KY..7)\.....G...../.".k/...Y...N.0....6.o.fN.....r3...[........s.K......s2.T...?.B).K.......-4^`.k..p...3.Z.>..'.~..y.......<..UO1.~K.. .......u..,..p....7^......E4.T...............................j.......o*...4...j.Ze...W}.?.e....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1488
                                                              Entropy (8bit):7.830263223589129
                                                              Encrypted:false
                                                              SSDEEP:24:Ham60wnVUp1TLilSCYiLEGYU22RlV8k8m8t9PhKedWHAXNbcyxsRC/i31wo6bNex:6m60wnVUplsYiLEGvP/V8k8VtPKe9XNc
                                                              MD5:AC9A1ED9E70F5B6A24646B0E78FF2286
                                                              SHA1:3D2A81753ED276F1435FBF14349E860A33DE298F
                                                              SHA-256:A7F481A0C1FD92E49AD223642F81B9BAA7F12552A576D03DEB45CC525890AC29
                                                              SHA-512:E01619CD73B2B6D3B87153B6DAAC00AE518BC4575854187BF3D3D10091712603901ABD3260E945E9E659BA3BC6E6D38106AF7EAA47A547A20DDC11930D37B4EA
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....]IDATH..{L.e..?..9.8..?....d.5.%k2..d..j..6]....rM+..$.X......V.X"......L.{\..9.....o.t..r....?......~.<.?8..n....p...L..z..Vt.5...-..i.G.>.....k.X{\..i3|e...p."..)..]...d).V..b...S.k......[.;.xt.GU.xy...!.t.j@OW..w..*....$.h0.....%@...9.S...Gl......g.b(....Q..;D.'.C;......W.6............Z>.&..=A.30...n.C.u&.^.w....WW!U..W..)...t..Ph.ah;.K..w.7.m.9x...........'>..U)3X.f.....m.h.h.......k.....G#...... ._|.S1{....`.].dm2...LF...f..yA.../..7h..CX.(CA..7...V...y....~...e+.4y"qc.$..c.....}.L..0.....0........Z..7...ufs..'...M.$.&.G>.}<ddM....^?...8...x.r..z.;.?I\..K....W.....t]..,....k.4ez...^q<...MsS./.6c.6J_n.....`..6v....J..,=.>.c'.w..t.........z8.b$..M@E(....r*..p].....yI.I.Q_.MK.........c..u.U...KxvU.'.H....yp...|..j.j%p...a.`...at<.PN..2.27.a..>.%.....:.}.........+...........4......W...........&.Iiii..;..v<.~dY.D.......9...}...B^.o..\..'......@?...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):828
                                                              Entropy (8bit):7.628531924625159
                                                              Encrypted:false
                                                              SSDEEP:24:HavvY8M1eY/ny0PmdFUp8Sl1L8Rnd4mgemq:6YZd/nyICK8+1AEeJ
                                                              MD5:42F443CCBEADC1FAD879DEA1F75B182F
                                                              SHA1:1BEE19280B64BA2609283B459E44DB3753CB925D
                                                              SHA-256:09E0C987889193585DBAE4A0E1A2E7DBD2629548AA2B4D962E51EB08B52023A4
                                                              SHA-512:4A22ACA03B3E84BC0DE63F76AFFC301FD58EEF2091C172551DB54C3111B847BCCEDDDA8CF5D31926A01D8EEECAC44EC4EC4BC4290D6509529E479648C6FAC26F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UmHSQ.>.C[...V?.#.........N(....(.h$..D..+S!A.>H..-..i..~4.id94..V&X`....v..n.....8..9...{.Z.l.....>f.....j:..u......................M2...0........IF....27k.a....%...@......:\..|...F.v...D.b...@...bmK?t.....Gx'....44........EQ.x...............7..........<...]"........L.Y.v..F=.`rz...........E..'.Z.0.\..|.....'g...8\....N..C%..AkD..R.....n.........D.}.Z..l.........q.@V.A...y\..:!..fyU.T.4.....'.i.No..S...@..-.."....[d.cV...[N.j.s.zj.d=..l......%LP..Ys.i.....`.3X."Bl...8..N..u...0....J....n......yy.TP...[M.Y..c>i.v..<)r..~.....?.k.U4....v.w.B..q.bx..H....UB^....@&.M..[.;.ee....X.=F..G-...9....+.lrH..z$.u..2G....Z.|........V...2G.5..w..".....R...G......X...}."fTAk.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):769
                                                              Entropy (8bit):7.577082747595084
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZtiE+PrUxLRyd2ypMZahJx9M48VokmuL3X9+8NIAOwNIXyf00zcjCZ1:HaqlPrUTylMZl4/E3X9+8NywGX2X1
                                                              MD5:F1B62A32CD22D12C712EC8971D448F1D
                                                              SHA1:60712C1D8E6FB520FB0D40A145B7BCAB6C00CC3F
                                                              SHA-256:A7846BFA398EC3C56A19C069955CAE92F70E31958EE9EEF729F04E50EDD3E857
                                                              SHA-512:E7FAE5B8D24BF76CB33178B4A89DCB390A3F6A19DE5177C956490791E8D893644DA8E734A03D0983B61C0E461FBEAB2570589D795482E26BB9AA1AE29CE2BF6D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.U]HSa...kmssS,.(.....u!.....HZ].Q....x....U.B.&..d....L........c.ZX.....y<o.w:..m...|..o.....m.{....X'..5.].y....o.B.@..=......K.p.BG.Y.....MV.........WJ...b...L.F.)+ ...a..c..t.!.o>.. x..@.p(....F.a..B...q..R...?.#..!8....`jv.z....{....0I,1....y>Yw..F_E ._...W.G?......M.....F.?...n.~......|......1......+..,.F.Z.q|.~..8.:..Ex........z.Tz..d...[.Wnx....g.-6...%:z.nR..|.......?.w|!.m./2....XR$T.f..uB[{_.....@.A..,..*....:.@..)..VH....'shF........"WT.G...4h.#...B...W...A....+.Q....3#r^q....i.4..s...j.(...ZM'k..../.{......r.y4we..t...8_...f)..U.G....e...I.mB&d...M.t$C.,^...|.....J..a...J.o.G...8...W......[q.3..f....94.....$...F.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):655
                                                              Entropy (8bit):7.418398877686977
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZcT4lYTthdiGLYShgVLBCBf8eghIQoR+pDggP0Y69C43sSnN:HaJYTtGGL/6DIfR+PPw9nsSnN
                                                              MD5:CEAE5E858757317F11698A82E51380F7
                                                              SHA1:0DC85782DE0935BB34754720A34977498766612E
                                                              SHA-256:0D8EAD3075AB89D7213641CD9E268F532730A616D69BECBFB9D698CDAE766E0D
                                                              SHA-512:9B0BBAA229D58947F2F30DD41124A4926150D362DD81A483FEAB70EED6A07E8C8FB449A52B9602B3A8E773717764290D33F2AC86D9C7AD717C9AE860A8754197
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..#....FX..5.h.R......'.>.....;fo._.>..N.$8...fdb...#..\|B...E.....1?.../...O..9.x0,... V.b.(...W.2.Y.../...c...s7.......K.........FF.....S4...by.$33.zn^.?.V.........=.......n>.?{.>....N.......p.[p.........q...Py...._Aqy.w................... ...d.?...l.#.E........?...6v...V......w........W..[ ,&.......I.......(."........Sw._......7.OX....t.. ..k.$h....{.]........?..n.%`$o.....r.,b....5...^.W......K....cl.....3P.......O.F....M..7M\..Xob]?.j..>E@C.s.........c..K.....@...A.L.......H..@\Ej.j....F.9`/4.8...C.....&....#....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):741
                                                              Entropy (8bit):7.401437975873439
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZQCyrOtEECaDehpQtHtOBX6DKx9p7P2+IQq4ze62JrlZ2:HafCOtEPaDpH6YWrP2/QNeDplA
                                                              MD5:EA5C6F7675A52D74B00E369EB9437524
                                                              SHA1:C11BD43C6F6A03F31E38D42E50DD20299456100D
                                                              SHA-256:80EBE115FB30963AC8541DEB3B48168DF559EE5BB1DADA6994B3FE6684398ECD
                                                              SHA-512:464AE83AE8F991E496F714FB76B9A29EA9C8F3EB368B82969E0C641242B830D77990191129C5FC2A1074507D5D938C8D8B45949A428F08A2ECBE60A4BD5AA781
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....rIDATH.c`...4.p..%k:.8.|....[.O^}...u..w.....}....Ip.a.!......G..............c~ .._.?....sr.`X@.(200....._.......n:...k..n?......?...;I.....y=7/..I+...y.............7....z............Z..H..,,,......>y...G..?z....;...Y..lAba....@........l.....:...g..>}...........@XL.......J.33.;c...{N........N..?a.....Y.H..^..B..t...[.......}.....?.+.......XXX..h..v...%....1.......(..@%........&..E.7...$.P.&...y........1$....T...b[.A\.... 1!...T.B.....b...>L.} ..X..UP6H..H.H-L.....s...|b.0.-....@r<...2&..1.R.ZG7.gfa.Y..dx H....UT....,.aM.hXP..b9 ...7 1..H..$[...z....... ...._..i.....?+..oXJa...m..U-Y....O.<).{e.TG....Q..b...#..U......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1340
                                                              Entropy (8bit):7.79907189110833
                                                              Encrypted:false
                                                              SSDEEP:24:HaYOFaXCM4MwRYRpPLpJheTPixZLo2JLzkXXu4unxejz/KsXweh:6nax4sRRpLeTQZpJLeu4uurv
                                                              MD5:3F41A37AA36ABD8A820D4CDDC1492D75
                                                              SHA1:14E65385F76AA1C5B560A0A2E3670B975ED5D4DB
                                                              SHA-256:D92F1A82CDA991A2A6887EC402A41D304E4D4F20C848C376074CFC0635E0E24A
                                                              SHA-512:1DED3D6BC7310C05132F24DBCC84C57157728CFF17A1EAA31D160F4A10BE68D41C253D6C1DF9340B574A08CB8FC62D726EC26A4C0C389A66D799FE0684B1005C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.T.P.U.........<7X.p.A...0I.^.%.C1Q.D...I B.(b.......y$o...@.J:&9.D.icV3..."..u...........9.|.;.W$.P.D".f.,+...Z.t.f..ts.....^...#.<...K(i..gU].44#%..q[.bCZ.........e.../.Y..:.+.. :..)...Ss...Q.t...<....$g...|.CW.C.)..FZDj.OD...u.y~.Xg@...jFZ.1..CeG?......H.E....@..wAk.....I..0.Q...l..7..-.....(l.C...PP...6|.[...."?....l..X..$.I.Y...&X...cU.!$.....\D....W..m......a.s.gp4..z.[...f.(.x/G.....Q..H......Q..'......f.,...w... .S-d.....z.............Dm.5._(...!..g.A&.f`a.,<.cabf#...k.PXiaK.c.o.`.f...-...f........rp........p&j..^....(j<#.5.9<..E3....gw.pH9%q.q..wQJ.]o....|... ..+l.Y..dh..b.o##...E.F5...C.....k...&:..@...7....=.I..Xk..1~..M'......{..d+......Ah...[.}.....o.x.*..~..fFIX9..rT.....O.)R.T...../.6.B].U2|...Y===...V(..V.e....q~..OFF..L..%.8...|...q[~=...!+..rG'.=O..?.z...(xR........l>...s.5.qC4#......3..H.1.F..8.1....%.q..=........o..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):894
                                                              Entropy (8bit):7.6708373779537435
                                                              Encrypted:false
                                                              SSDEEP:24:HaoN//yF0axmW7vLhADeuQadt5uLyBeGvZBVVqSDS912c:6a/KvvLhADerWt5yyBeGfVfSz
                                                              MD5:DE1DDB8F45F2BB1CF36C2047B21E7FFF
                                                              SHA1:FB1FE8851F84E8DEF21325E8284C818A1E039F42
                                                              SHA-256:258D0E407DAAB8B1971DD21C2CE12202433938620629241816CDA4118D6B9F88
                                                              SHA-512:6D5AF7D77EF35E145997C71FC8F777A490E9B1E472B32C6857FEF44BCF40EC41D30E70EAB36CAF28DC8373779C355D7ABF34C76544D864E9B05F4EB3E28AC68C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..TiHTQ.}...q|(ZQ.23....WQ...#...J.... .2sIp....erA..M&..df.c..ei...D..).%.....L..3!t.p......w.A..l....c...rH-n.mm...FHV.Bl.."W..s..o..9....3...D!..."c+@.Cq.E..q\.T....5.MR..4.}...&r..Qa.AY......N..y..n.U@bV1\L.{..r.)..LX..Kh....IyO!....sk .n3T..As.0t.....A......nHUi..N..).>`......q"....u-p.3@...e..Pm...1...hdK.kH...qY@..i..@...X|.......6....U.p:,..7uAO.........p#.......,IR:b...2f4(4...A....{.MS4=....g..h....'p5..NE\.......+..qr....C..9Zj....]..3..#...LM)...p.c.UV.a-.$.w.......4.c..Lul.....Pr..B..]$)..M..6....W........PT....!....a#..:HD...*.?rX.y5.........cY?^.[.B..z.D......v....{/..Zy...I..0D.I1......!.#..QXdL...S....;+.."W[..Y.)8.. ....(^...b.:.j..x.fG41..3q....._..x1.d..K.I..d......L...2....'.@wr...z.h....\.k..&.G...2.t.c.......L...f....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):600
                                                              Entropy (8bit):7.484814395261773
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZAozix/gQc64jpVKLH2pufHgkv2S5eVypvpkaN1CiyZp:HaDWx/gH64jLKLH2cfHNuSVdN1dKp
                                                              MD5:018BF653EC51BFAD946AC0213AAB0E68
                                                              SHA1:17DBA0866A37E42733B2E15E82ABDFB02889E62B
                                                              SHA-256:0E690C86DD547CA847C820BE499F1CA89CCC24821A4A5119BF5F5720E6847EA4
                                                              SHA-512:C89598BCFFDEE06E581E16D8C2E96025D50CBA3CA428D217F3BF58046BC026E6CAFB5A6CAF89FF4AB997FE561FADAAD4C5C1A1B41FAE760FFB3F40E4F0722739
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...=O.A...wf.<>..DE....hbch,,....Z..(l.l.....Zb."....F....`..gD.........\..jBcx.....[,.C....W.WOW...}..8@.T..7...;7..$.[,.C.r.n.q......p..0...tv.q]...`....W..{(..G..o_..4.. ...Q..b..C=...2xp?.}]...m.;.u..qk4Ir.3._..&R)R....u..)(...VWJ .4M......f.(N).!I..e.*1X...?..T.N.$.%..(.;.We.Z'T).0.h..,-Q..e....$.*.|8..I.Z...#...%I...Z.NN(....G.$'....._..f.......&C%.m26--.... Uj.m...F'....j<{:n?.6..".a..wo&..{.N..@.m..w..........#.......4h.~.8..,.....g......gW..~..:..].....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):758
                                                              Entropy (8bit):7.45404515221275
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZBCyrOtEECaDehpQtHtOBXxQHXrtwFZRFaReGZYzVb3oob/j2xebS2c:HaCCOtEPaDpH6BQbtwFZRFaRegYh3Pb+
                                                              MD5:950CE2E49A1FFCB55F9067B4CCC46754
                                                              SHA1:31EF1D8D60F5BBF75B833FD1C99998E209413B83
                                                              SHA-256:1B2F928DACD0BE76A895CC6C0D04AF3490FC9E033D8CA6F1B38723B0B461C3B3
                                                              SHA-512:4EA76D316F26DF2D861EEA9B16F97C4D2C05E948C7BF813BA996E10667A829746970FBABB8ABF66D2973BD7E52A06D2D6E5586EFB25557FE0123E1E5D45C9D1C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`...4.p..%k:.8.|....[.O^}...u..w.....}....Ip.a.!......G..............c~ .._.?....sr.`X@.(200....._.......n:...k..n?......?...;I.....y=7/..I+...y.............7....z............Z..H..,,,......>y...G..?z....;...Y..lAba....@........l.....:...g..>}...........@XL.......J.33.;c...{N........N..?a.....Y.H..^..B..t...[.......}.....?.+.......XXX..h..v...%....1.......(..@%........&..E.7.5.....<|...D@i......(.... [..F....H......Q.k.. .5..]n<.vy.d.....0..v?.A......a....Z.T......@.........o.Y....8....'..<^...9.A].V........P.O ....|...Z.Oj.....w..Pw.........@.Dl........)P..dspZp?....~C.<.w.}...h.# .A0..i.O.:6b...2................c7.x....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):623
                                                              Entropy (8bit):7.530319267640003
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZeaU20tYJBYh5ObFRUG2yn/YEowBAXaAeNuEWrweh5:HagtrtYJuh5kRJ2yn/YRajUpP
                                                              MD5:B10DCF9D0A2B17300087408AF6606682
                                                              SHA1:8C561A755C943F55C3D14155C6DE0575FC84D5B8
                                                              SHA-256:CA6A857B81EDE5A265769E7BFE71CFAAAC43B1C7C4337127C5A42D131C4045CF
                                                              SHA-512:6DF3F942BAD5FAFE49393F67B9F3089C201CC0A5F023ECE14E6278412CFF3ABB184282E1D89025E177BD52E1036ACB5A0FD35C25AC0556B01233B9EF17D39089
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.V=O.A..#.0...`LLD..'V6.....J.2"..J;........h...P........7{s.|..n......{o.e..bt:..z'8.d.....Xg....a.>...v..!x......Ep.A.b.6:6.EYAIp/..\.~h.....V..S.ew.`BM.w.....l...Z4._e.../..~,`u[....I.q..NiI.....V...-...p.f. .p............ P...9.d.G.@.....\.D+...B..x..dM....^@..qv./..h..7C.s..a.].,. ..X.......N..l....@..X{.D.DB.....d..]8.&.T|..$.9.....i3$......&.F..W }.x./&.Kr....b.t.[.n.h.h.X...G.$...........C?.h.2j4...C.j.4+....6...Ui..~..:...9...c..=.m..0..S....g/?.8...I.......S4.}........z....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):378
                                                              Entropy (8bit):6.968222383042327
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcjih8knzlRWjzdCh/29wc+r993SVXI3/VK7XXNuHatTT6p:6v/7saZjihhnzQi1cM993wXI39K7HEau
                                                              MD5:DDE84629A1D30F57CD5F3A1DF596318A
                                                              SHA1:2067D09EB69E37ED2E35766EF678203936BD97FC
                                                              SHA-256:ACBD63A47ADB67428015647C304E2F77EC6EC6681EFF9D813477305AF0E6AD13
                                                              SHA-512:62220DC3E0EB9A8E20923270799A25A560A5A792375519617198F331BF68518AB706E8DB5AD88DEB01DE8018E28E36E6EA1761743DA1F2985D795ACA49425E44
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`aa..........3............g.&.C-.....<~{...kk..?5....-.'l...7.r.@.^wj.....pM0.....-.mC.. ..*...n..%8-.k....4aS..@3i....9X.Y.............u8..W|.m.!.u..B......b.4.-.....D.F..WWH.d..pz:.., 5."2Z9A.v^\L^F.Y..I.B7..@..r9.E.2~....C...-..N-.[s...h.3H-.u...!..W{..{....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1404
                                                              Entropy (8bit):7.823759117422973
                                                              Encrypted:false
                                                              SSDEEP:24:Haqst6/WZfvkhgzOBfAoquXFWagbRI0kZpNeIEo1TRtU9CE3IksGqNMRkCwrtGHS:6vk/iHwBoiFWaSRIZ8pzC+IlGqOeueIk
                                                              MD5:02691D1183327E11C039CE8AE1FF8A12
                                                              SHA1:F4753709E5AFDC80B88E65D70B1EFAEC697F735C
                                                              SHA-256:B57572C16F509FCC87C7AA0A702F4A76C56FF30859309DB3C3C7CC0D35F8B684
                                                              SHA-512:EF32441396943B73F576EBBC87BE8A90D4509781D10EED809BCAE7AA229F5F30D66940C969D635743E0948BF7F83D042FF54D284AAE8767B380D2B96359E89EE
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kL.g.....mii.Ue.....dj..{.`....rG...M.#P.....e^7.....&.nlqsj6.if.,....,.VZ...<l.`.dnO...^~...<...._n.E.sv.]...........\...^p9.4.&U.7Y1..?...v!....W d...%?.c44q2..;.(..p2..J'.2_1".0/..Ib}.T....K.....l.@t./.,q.......eJq?F]..P.....#t./.e..G;).y..[...r^H....7..K......R..q$.$.vuG.k0.T...(x.Z....;.C....j..\nz..5`..-.ZJr..s...|.{aS....C|..^..!.5.'zvW.E.xk..0;.$E.K#.?.s.....M.F....U.....w. $..r.......N....wm..u.H.V......-. .?...X.....Sy.?...2...=.g.V.(]$.4~68...w.>..G){.w._..5pt.}..xb.8.{.m.=w.M..d~................|7....m.........-..@..x.P.t82...(.nZ.....z...;d...............=.....A'..Y..w..[...J6..]...,....5..x.. b.B..Y2..XN_n..l..I.Ie......N....&.J.....["...U'.....T{$o.}`....v.R.9.|.Z.ln...f.>Ko....l.h[`...9.w...+[..1U..5I..g.`..X.P. }....w%C....zA....;.6R.p.."h.Ph>w...ZA.k...d..5`T.?..:.....UR....Ws!.!...}F..ZAXUm4C=.5!...O......FKC.......LeG.-.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1186
                                                              Entropy (8bit):7.717202739319088
                                                              Encrypted:false
                                                              SSDEEP:24:Ha9wvVmF83N/aTBZ9jM8C5VczDoBAGXzzbxBKepwwfPn33+n+:6mtmFw/+ZgrpBPXzzbbK4Pn3O+
                                                              MD5:BB5A53B04BB6C089E8AC6E8DC531AB06
                                                              SHA1:7D49CF14FCBA6EF45D3758A17A83A1570A6AF423
                                                              SHA-256:4DC853AECCFA023576F97D5A15D3343C92E4FB9E673B80593F5BFB82E80B4EFF
                                                              SHA-512:A465336C4C390D1961BBFCAC7B47EA92243E3CC5D61599E65894126D6630ADBFBF58F99685F1CD6FBF555D607601A23D12DE6B1396F0D47323C0AA714BA7D97F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<..../IDATH.c` ..1.2.s..]..a..#.....y.P<....5T...9.[..$...[.p.o.3...lw..>..g..?u...<......~.s1?$.tV6.3L..............v....[...*\./'..?.6..$Y...1+2.k....!!..7....UME~..../Y...9I./...?y=.7.K.....7I..q.......|qj=..<..l.ezTD..7..Rj|........?w..q6...$Y...T..f..f....T?5.!.);.._./......N..l.,.I..xkW.]0...l...{........Ysl..,.(.....T.|.....?3..vR.....o....M;....K..?.L.oi./:'....]"....5..@.?VN..9.`...Gr..dA.6...3..ydi.......|.T....Y.Z.i....7.fA.v70..........>...&...........3...}`.!........i6..c............;.v..@.. .CS+...z.....O.._P$.......;@9.d...\.....LNW.....?Pn....?m...`x.S7...,s@.....G.,...f........i!f.gg....:....z....z.O.n._^W..K..-xCR....^...>S;.#..<.@._.N.Od...PA.f%..G...u....l.;..,.p....Q.'...i..`.g..6.[.;....A...K..,..E)?fec>N..<.{.f.LF..5..v...>...7.p.6..{........ZB..j...3.ka...o....T...d..1......F...\..S......41.6.ANs..;2..M...'...%E..0.?..=.Le.... bcc.t....R...}u.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1106
                                                              Entropy (8bit):7.689550690966777
                                                              Encrypted:false
                                                              SSDEEP:24:HaqITus7uL9OAJ+EsZF871L/urmq7zXYseQO9Ra1l6OZ5H:6VupL9OuKZFI/uK6bPOXMQOZ5H
                                                              MD5:9966CBE16A57DCC1B82D20840C01F0C3
                                                              SHA1:138B2C87B5710E6ECA9B239DF5ED5A3D333C1B9B
                                                              SHA-256:5BA79AF9D6B9C99B8A2D375CA3197D1135A20B14A49F3FD8604E258A4C967742
                                                              SHA-512:943450C22F1135453208886F8959B0965C6225D4C1E0BA953B0EC5B9A4295788EF3ADE188D2351E494A7E95E6DB4C9D088A74EAC246AFB3F56854E284E1058FF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`....-.....r003...r....|.e'.FD..%. .=>.......@5........l.x.._...O.b.v...Wnr...m..1A...+..:Aq.#..,.@.NHf%@14.xX.s.|3....<...PB8...?.7.?V..P....k.EXXY..K...`..a-.=..._.f..../...m'.[.....vn.@....*....`1n..../N._s..1$.u......A..2Z....t...s..\.....O`P.V1.=V.....X.....d8..g..f......m..^..w.-......?~Q..r.B..<e..../.+.>..tE...F...K..........o.8...8.x_G................?.28n..........Y.....Ojs...%...J`..J`<l.i.7...,.....-;.b0..==.?.0...G..x....U........Z~....{.R=^.7.|.......S0,Xq....(7...+".yg.}..U:....;.x8.f.F._.....'.XZy.....?W..[.d...Aq.....e..o.....`.}.u..Z......pp.5.....E......goN*...Y....=......n./,...vi......%z.`.l....hL.N......b.7LY[=3.2.eI.........)..qo...\.......j....p...n..=S.cD...5..=@c|pZ..I.6Z/..C..m.....k.D....._....+6...j6..+...h..>.,.y....E1X-.Y.._T.......yE8..q0oE2....b(.Z.].X.w.x..*f...S....R.......0x..L...1.ac..Z.S.R.O.D..%..K(..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):909
                                                              Entropy (8bit):7.6669428564650755
                                                              Encrypted:false
                                                              SSDEEP:24:HarsdqHGLF7QeILl8qAkMnEqefWDDEXKk04uoZUmEHirXY:645+egR5XKU3ZrEHH
                                                              MD5:79C741859126C7CC5F1AE10CE15B76D6
                                                              SHA1:AA020244049C78C5ED1F18ED83A6B991BCB087DA
                                                              SHA-256:20B0760ED8B786CB601E1D69FFDFC0D89A28FE43DA5D1D3C98F21B8BF5ACC5EE
                                                              SHA-512:B0CE451DE395E741F2E41DF1D766420F4A0DCED2D15CA4B5B7A64CB70A3EEB31A11FF370E602B5EB32BA4E699458E58AE2BB3BF065E5EE2D3439155FA37646B3
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kHSa...v.....V...S(.f..+.\....m...L..f./)!.LTP..`YA.".CA.!...}.CE.y....Q*';ZB.._.y........CQk...Z...]z.V..~...'....`...by..G5v{.e-....q...A0M..,fG...Ar.y.4nVQx7.s..L..h9X.L..._.....T......DJ....e.......V..(..l.b...3.....<.....uU9.....[K3..;...+s.i.D....8..,...Oi.$7.h...$.4....i...3...v./NEe.~e...X.4.B(.yC_..S..!..[.8.-....};@.....m....q.....3...M.s.ke.."..'..'W{!6G..A...J.4..f..;..P.Qy".,...L..O.0..wU]w...h.=/..geh..B~S.B...ay.fZ(..$.+.m..:...7@.h.q...lj.(..".QI...w... .E.......yf.|u{.......}.,.\.R....H6.....`....s....O)..H...*..S.~.X.GQ.1.>..'W..%aH0........!.;.A[.%~&v.)K..Z..u.HZa.tq..c..0(.....x.4.%.`.B%..".q.B...C...WT...7...... ....+....x....6-.F(...V.E-.pu.q...# X......6w.X.yE...#jk..&K...".......z.......!....4.a..@.."..?....3.p..5?.0ST...b.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1630
                                                              Entropy (8bit):7.811174047068751
                                                              Encrypted:false
                                                              SSDEEP:48:6pge4tcbGkLd+xHVVdaae+bmPYCoXHsgaYhCVh:ogBtcykL0jaV+bmwCEjs
                                                              MD5:41D4C4CC18FCB528AE0B544808673A7E
                                                              SHA1:4DC3EAFDD605699028F84CCDF3F5CE9C93CB8849
                                                              SHA-256:0436EC91851F214D792B7EA1E9F392ADE98B904A3009354B5D1733BF3BF7429C
                                                              SHA-512:83D66506DB5C9A630489FEC881F9E8598B5B2397EA62BC3F507D07E5BD861C65AD10D715088E30B2DDA1D2156206528E15C5CB8BF233FD57B2AD07AF8EE1154B
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...4Ti....{..4.):...Q..X.$..m.U..J..b..%j.P.I.0...'d.e.8.4.Fq.m.J.<kC.c.a.>....ck.s............3.R..HII...@ ....D*.>.q...j..%.......W.+.........A.M.f?`s..N.././.....e....Lib.3...|.G.K..5{..".^7.LNNf."""@...'...V.J..\.G..........8g.nA.`n7./.&)cs.......u,b..^.*JJJb."##AT.5.)u}'.}..Z..fZ..g.A.......%U.p.x....A..[Ph....g.h..#...a./^.O5H.L....f..R..-...N...-_....P|]..g.Vn3+.-w..o?S..1.P(,KMMe......p.=a......w....P....j...d...^..t.ug.(j....h.-..!.n,//....t. $$..G..>.O..}9.........WQ..g....1..'.>...|@............N_..4..%.Zm{...1=QQQ.t.........@h.hn.sh.@p......J.t..!#Qc:....ilX.l..MYp....}JI.Rhnn..H.999.......%XQQQ...c.........*......04,...r.......T1..*//.Z,??.tAA......z$.o.W<...&x!y.qqq`dd..c..`aa........AAA..'.....UZZ..~.zx....&NR..m-..W..s........3fUUU ..@.@.....ec..Yff&.......y..bf......w...x...o.g..B}..0..<==U`'''.....l..v.o...K`'.T`..u..L..8.z.\....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1056
                                                              Entropy (8bit):7.701852613120881
                                                              Encrypted:false
                                                              SSDEEP:24:Hai5d/8cLOb9kzfUsXIQXRkdcYuaqawk8ldTN:6q6bIfU+IQXRkdcYuaWN
                                                              MD5:00DE8537DF0EA8F77B9DD9CECB310B19
                                                              SHA1:EDF8DAAE50686CE3B643867DD985C32F8E4D0172
                                                              SHA-256:EA9EDEC7670BCA439D9B5DCA0A3B6DF0D44594CC3416F32EACBAA3B54B4892A9
                                                              SHA-512:12CD91B8B35CC0C6BBE9FE683C4F1DC7DC1CFB2CE2EA8CDC8FB137583FDC220F2357E98AB631E3C0FAC708A54AF48AE48866CF394961CA925DF285F67D916CAA
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c` .d....9xX.2.2}..c=......w.b^.2.033s<...iVv............r...n..6Z...G...8.Y..q0...I.bm f.e.(.g.q..bac..e'.).........;.b.\....n.....D.p.|c.`..-.......yv .....4.....K.6..4...i._\...#...ff..,..{.X...2.W1...P...t............B..5..2.0M``aa.w.7..1.p.....>!.P...S....`.=^.k........-..4...u....n.....S...j.G.../N...9[.:,....I..F.?~1...QJ.3gY#..............i.)..d0..h...... K.H.... <qe......q.~?=.l..J........-.....p..........N.U..]..-...>.4;.dA....Y....Llj...*.,.uFe.I.+.......!.311~.Y...%|.vR......M.?fmi.....A._|x..g....1x..p.M,..;og..`jZ.....6.6.^|....i...."h..ww._xp.....9s..Z ...........T..........S..`.`.y...y........j..0322.Y.vb.,..".~J...o....G6.Yn..*..0013}.....d....-e.....~UL...l.(X`..f..'........i........%..|.n..5ag...GrQ........|.8......vP........kS...0U,`ec.....?4....C98- .Dw_\...-.. .........|....cZ..../.i....#....}.CP..oJ...d...B.d.n8>.......u.o\.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1179
                                                              Entropy (8bit):7.785914688983405
                                                              Encrypted:false
                                                              SSDEEP:24:HaNOoTvO3QH/8zi7WcTXz2b5wDJ5EQ3S7FhU45KTpx4t6s4NWji1:6ocWAH/8zmWO+5wdC7FhU40v4t/4Eu1
                                                              MD5:4CA8A77CB603F65CAB0522BB395568C6
                                                              SHA1:D43BF8E4FC9FCB19F192B8E00BCD0FFCB308C264
                                                              SHA-256:1EBC65DAD53C3F74D9758CEB079CAC9318724B796670F27EAC691BCCA523E6F4
                                                              SHA-512:567E31373AADBE434129C2D51DFA4D37F8C19C26FAC6EEC3AD95D560993C70911E387EC12144F2748AEEC5C6EAE5BDC8B9D9BD3675D75CE67385F8E5FE93D99D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....(IDATH..kLSg...s.R.J..r..-.....X\%."^.u..e.-..:...&#b..g6.../.3^P.}!d...q..D62......(...y....z......sz.......W".~."...I..O....}.......K..3.....2./W1..:...iA..*VQ+.....L......w...z/9.......#+....+Sf...i....G..Bu....RRPj9~...]'^.......&U.'.......,...k.FK+lc...K........R....~.......e._qvX>g...X".([m.=...........6f[.?.O..=$.*.h..'..d....A..*.Vn.:...X.:...ot.5^..Y......F......!p.JA.`.w..:.:.U..8.,3..)..N.b..ia2.w#...p$..-.].../{B|...Z./,.....t,..)F..6.?.v.f}G...*l.o..U!..MP.].w.[.g..cmW,.e...I..#.......gp..>...=.!....Gj..1/..k..8..9..>B....,J.....{>..].......\..|....:()/....T.*......rf]=.7t..m.... .a..[....o.(.O...e.3(..Re..N..GKn.?2".Z,....o.._.X.....)......TuZ...J..z2'..Kv.u..._...T*..;'cn1,./.....4....;$e.A..JX.4.xD.........1..A2.@....).).c...".b.....l..b,3i,k.....L....p..dBxw...I.i.:.....S...'MU............t...C..NI..`7r...9.V.....G.Za.W.........
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):988
                                                              Entropy (8bit):7.631799691763389
                                                              Encrypted:false
                                                              SSDEEP:24:HaUN5N9Mbu3Rvtny2nQgzgn9nd+dQDwfdrykpl3k:6O58YRvE2Qsgn9dwQDwcu3k
                                                              MD5:34727D6D70E85120139CD8C38D8E6FBE
                                                              SHA1:1C452DC914392873D8E7AE4D7A6E6FBB9A4A0AD4
                                                              SHA-256:8A66BB00445B1611B986A7C620A8F37D013C529CB34DE08B9306839A3C08E22B
                                                              SHA-512:4258CC835CDA2B1F28B0789A2312C012DFCD49527B606A651B451A088F5530D1E2234881A6527FA5C7FD18C792EF250721F2A9373F9D71F2728403E5613408AD
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....iIDATH.c`...8....X..J@.........;7..}W...zB.Y..rp....d..T...:@.D...@Ck9xXo.s.|3.....m..f.....n`.bg...._.^.+.0.'fV..,lL......|....?.?.?.\..E+...c.Q-F..e........A.XY.....t68( ....4._.(..Ys...'M0./.....t..M..yfk.`.`>NL.5X....|qj..#=.E-q..,4~.K......!)......8...h..J.h9.f.[.}..J6v.-.X..c.r..#.D\....._..w..Z......].,..s..oY..?...w......:..w..V.cA.........w..F.....E...8....8.....?.F.u.X.+!-. .:.QBA...Y...A.. .*...87...m)..KL~zfi.P..<..[D...B"|.@q0kK.d.E.br|..5F......jY..!I...3..;'....68X..QR...Po<.9....hr.p>._^>?.$.]f}...Mi...&.O...o...O..o............tO.Jr^...&..).......Z.'.."..{......_....K.8.wMS...d .<.."V`.?.......)(...X....[........#3.j<fb..).;.U.V..f..z..B|.`._L....6..F.2..E._..T....\ `...z....c..?.0.P.._\../0X.....-I.m.b.`y.*.@.@.A..E...)(..eD.%..% ..b.|jo...G..X`........,.~B.E.$L(.X.. .*...I..Z....u|....d..U-.`......)...7...h~ .....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1074
                                                              Entropy (8bit):7.681932689849198
                                                              Encrypted:false
                                                              SSDEEP:24:HaXh6HuBALuUMtm5YuPzPsssq3NCOgimuFDwsHZjFfj:6x6OyLq+zPssHAOgm+sHZjBj
                                                              MD5:30C60B5220B323DDF9417A596E1F263B
                                                              SHA1:208A8046C56E485360EBDA7FFC973D9405810608
                                                              SHA-256:F0F6855C2DA350DD2F4F85FCB11302668C3BEA6F6B5820A99D0FB60DAC8DBA76
                                                              SHA-512:19C839A20710D6F2B3A64CDE5CED376662A7341A73C04CBE63FEC56F50DAD00BD5C1D95D3D3094926B8B318D235567483FF30757626A35DDC56FBDFC387AE9EF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`........31P.....q2..s.l..a...".^L..$;..]vn.CB2.sx....Jy.......h.Z.a......Cj...lw./Xb..f.[...6..-].....in~..l.,W.E..h.K8b......>011..w..U..qm.J.. .a...p.....s.P..uJ`..l^a.kb.<....3.Z..ir.H.r0...c{.h ..!Nes.r.V......,.n3.-.-......P.a|.ic|..7^..M. Y..vZB.w.0.n*..}rIQ}.Vk8]B..<.;...3....A..M..z.mX..>c...8...].n@W..6...r5O.8J<.R.......T..h..I.|P...6.....7...Q,..2...1......p0...,.>.....69....V.m.&..B...Gr'..C.0...p...D..t..G....>K!...].=..X...].F@_...1M..306.A'...X...lul.."..&:@....1..a.iT..l.A4/...T.0$t...........,).a .....=&.bzM...:...|2....'.M...T.~.h6.F..]f.....DD..-S_.w6.._.6..O.3..T...G..nX..}....B..>=I..`....2..r..%...e..H.n..v....L...:..?0g.wM...W.....9EQ...=.. ...,P~..$..N..%....-.......?y........<.....G.y.|..&.W.t...[\...q.....nA....0..lu....,.../.(.3M{.@..@..0R.xE8^........f(.].t@D.._.A..@=....!.`@XAOh......*.?....W.,.a..r...mG..F^2'.u..9...(..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1198
                                                              Entropy (8bit):7.679975891907876
                                                              Encrypted:false
                                                              SSDEEP:24:Ha/kd0JmWOez1Po9eVh0PAZExwaqi3C+I7VFs++qQtZHMTB:6ysTaimAowA3VmVFs++qQtMB
                                                              MD5:FC889A3ABE091582FDF7FBD398B73E7E
                                                              SHA1:8B0138DFA090C377FB6E1D4B867D87EE6E0785E4
                                                              SHA-256:5A163EB5126F9872300339777411BED9D847945B141654D7D40B7040515A0A51
                                                              SHA-512:86C906DFED708C9FBA8D84F1D73B38D54350324443828B3F2486C11108795B042D28D5AFD9626C480BA08998D705277D566A269FFCBE377055CDFD6E9B12B83A
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....;IDATH.c`..........X..._.c....c.P..Zv......s...b.....bv4}..`.f...g.q.."..m".>f.._......q...l.."H...*..A...|"..M.X...l._.8.........a06.>......a..@#b.Z .w>$.u.....~1...".....Wmq.08o...M[....\..35.i.o...n...y.,...]31.PVM......V...d...[H...3..=.....QY...!.?...>.V._...<..".f.....,.'..2.0...u5.7].....p.1.....~Q...N.g.....s.G.Z..P...4..d......f...:[;9swvM...Osw4..ta*.E.R|p.k.........i.QT..(..q...r..x~rC.....U.o..c~.5D.o.....v......&........@.el..&...s@C8....RrQ....?...6........aK..~...Q5.`K@...'..d..o.!p*b.o.......M1........J.l87..../<.&....Sg.5...". .y....p/l.[8q.....o2...6.....H.F..,....7.X.V....\.l..-@NAp>7/..t.'..._`.....'..q[..`...Al....N....g.oZ../...;...kb,......aj....zQ...o....O.....xx0.......g.<...Z...^.T...{Q.....%].....D.H..D..e......P.w.h.c....~.q.....js%.6.S....=[....D./..?oW..P..J..oY..?.....<....f?.cU>r."h..D..s..L..3.P...`<aG....1.......s
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1359
                                                              Entropy (8bit):7.8377593343058045
                                                              Encrypted:false
                                                              SSDEEP:24:Ha0CcwBqThBareuZB2T5K/BIM5tJ+A+s32N3wUJHHjP7ALgfSOlpZ02+2:6bcwBEHaDQlKZIMfJV6351DP7yg/Zo2
                                                              MD5:3D8FD81BDD5718D6E719B4783859552C
                                                              SHA1:E80FE55A5AB4BEC4E2D8CCB953CE253DC2DFD229
                                                              SHA-256:57FD10C279146711B42C45DA9A7C6A2DAC2729C860EF6709D07FEE5E38DB847E
                                                              SHA-512:C256ADA511E08B1ABF5156474BD064A70A487A7ED652EAC1B9C1882C9BCE1A0C6ADCDCC21F55A0A064E3A8A6E22465DCC365659B3F6EF2DC7EEACEF3A593F3B4
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..{PTu..w.c..]v....(.O...!...H..L.....!....8.f.=..GtF.QK..........(..i.......WXv.... y.....s..~.....#.L.T.A..n.-.&.b9}.....<.%.<.F.d.DN_...AX..uY..P.l...HX..n..6VJ...d3~..*.%.....I.NJDXC...-....-....q......:...X7.J..]..s....D.\..."t..;.GZz:eB.T...i...qBB.$).".h.<#..)..u.....r|...Aa&.f.....J...."...E.,.;[}.....&WH..O..>o..{.p...m..Q..I=E.......hK+..y.cu^.K..)s..7>(s....zV.._+.dw...||..r.......|9=....z(z......2._F.z. /,Z}q......].1?v.4C....e..A!.A.+...3A5....b......cs......^..o....,......w.W\,.l..c1...W..>..\.E5.T``..W(..z.A.l..a......O.V...d'...B.^]../<c.7.......,..>....4j.W..D.....?...........qX4.n*.KI..4..L..g._..E..*>..|O....?XtZ.jx*.x4h..W....5..m2...lG....(.....s..w__...>..j..&2.%..!.r,.....[}.\Sp0.. ....A..B.g...]'......-...V<E`.j..Lhp./.n...G}t...u.V...I..=......VQ.._..Y....U.....t46....f...AO....eY8.......z.Y.A.l.EG.5...-...qc..Q?W.,.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1284
                                                              Entropy (8bit):7.786659025253531
                                                              Encrypted:false
                                                              SSDEEP:24:HagCKQbywLcv9LKPL2+HfTDNwygg6vnRvztUOXEDvfmWZbMSo:6gwbjC9LQ19inRvz8DvzVo
                                                              MD5:51F47D579CEE5735CFDEDD2197F8E56D
                                                              SHA1:ADD0C8B4F0BEAFB130D473EC1AC3E888A0DA5086
                                                              SHA-256:228FE9ACC3D899777AC7EEEFF13ED50FC258A52AC798B0FA055FEA82189B42F1
                                                              SHA-512:3FFF99FECAA8E81AC7E647A3B6F701CA22C1DF5BCF6AA39A0CB78D1E5CA53B625357AC99E87AF382AE3343EFC2ED5703BB0D83D70ECC96642DAD6AC4AF5C75D7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH...L.g..K{.ki......B....-.H. .h2..ns... J....BB..N...2c.,.-Y\.F...&......_..XL..N#.w..G...x.'.{...>..<.S.%.5(.F.....U......<.5.(.C>.!Y...|..gg+0.........@|.\......V..A..6&....b.2.J.3.G}...q..k.{...<...<3...........Ulk.....Q...`>........^..GU5....yA.:B..:n.a..`..\...q...a.hp.hL...g..X...o.......Ff...>.b..}h.l....V.q.e.XG.U2....?..M1.9..k...1..].+/..&..}.....,tDx..].$/pT,..Q".kD<.>...x.]...%.......L.@.4.....rR.!SO|B ...N...Js.."a.vS..yEr...Ow.g.N......r$..'+ISG........z...*<.... ...idB.3........N..E..]m..r.l..5u....i$1I...../..wz.y.....HFz...0K.~.V.e43Sd....o...e.rz...`sC.V.P..w.....h...B.I....`..?@..'....4.....x.......iih...7.u.0C_Y'.j.....S..D..e..eXUWA..+.^..NJ.S..c._..{.tc...G.v......V...#/...o..l.2..7....j.."..R.n..d&.....]...k..'w.O.6D).....e.......x..]...Z....z..$.-....vN_Z...:.sV.R..J^=.<..4.$..sv...\.5@..N...Z.......%..Q.k.k..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1098
                                                              Entropy (8bit):7.772443665706941
                                                              Encrypted:false
                                                              SSDEEP:24:HawtzF/OGdnbikPCI1+124fGECIsBADkdcl8jd1:6KmIbikPF1+g4fsbBklsd1
                                                              MD5:D6B00FACABEFE77D2FE0FCA8A9226840
                                                              SHA1:C852AC78C44992BF1CB42D10E3CF223ED5D51A52
                                                              SHA-256:0EEB87EF373498763D9441590C44A8C6F8F27B930DE1306E98707933D569F71D
                                                              SHA-512:A5DBAC5E653D8C4560B9B3A5BB0BF3237158D0411298987C15E422799910874893C6FF32E3BD79FB22A09C9DDDD86AF20906B323AA4DF24C1BA7DC38F64AE0D0
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UmL.W.~y?..hq.h]E..t..K...~P.q...EQ.e.,.(..LD@e...`..l.....).`...`..-[.~.g.~-q~%....f&,b.Nw.'99...9.....a........DY.j$...w........a.....Y$.'.D@.=.4,.-C..!.kQH..@.@.qi..O6b......SN....d*./C@|...........E.C.7G.:.]"yv......%.)!...4k@...A.M.........3...).| ...3..(.u.(.A.V.+i..4VA.:...V.i....>2f$.+....b..t9q.e..G.C...,....zi.e...X.cX.=..lP./....p.P1..w>..@.....I...QL......4.h.a.N.9o.B[z..........:$i..)S.. .3.o...K.....|.Y.q`..xG.....dIa2..5R.. ...0M..m....K......$n.Q`..B.u.......fKJH./.D5G.d.gZ.K.......S.."7.D.n..E..&..o?W....z.;.lCQH. .u.;-C%.<..)3.s.{D....2...L.w..~.CW...x...d...X?_K..V.iY.6....@FA.5zv...UI).?..>...].cC.+....:....\.[...Z.{.)9^Y.8P.....V.Mzv....x..n......}....j->z......M...!m.....E...."._2.~..+.X$...U-..].+...U......B....kk.8.!..o...../..t..&..%.....V{..q.:....3.h...|.A..r"....T{,.y..W.zD...I.....y....#B;..Q...T...'.....\..$...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1252
                                                              Entropy (8bit):7.797631294703633
                                                              Encrypted:false
                                                              SSDEEP:24:Ha+41Hry8Df6RaR/VNZoOXRDqtsFDhBhFvX8bsR2djc:6+oHrN76aPDhDqiDvMQ8a
                                                              MD5:7ED8090B348BC71066281C049A319B37
                                                              SHA1:C9BF4BCA33330374B538A6306A558FE32C265036
                                                              SHA-256:6275484907BD978EDD03A23844B0EDB6D5303F2CFF1C0C24836DFB04E7DB0A54
                                                              SHA-512:228331AA94C9CAEBEBBD338E5A7A7596CA3BC630772D28A01962F0E5D623BB80DB24A637BFFB8FE8AF11E8F7F8AF4F8777A5E52C87955CFBCC16347F0849A9D7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....qIDATH.UyL.g...fgwgYv...EnX.K..^Z....T..r.@...H5h9lZZ.5i.1^..=hK4.....c..5m...* {...M5....%.d2...}....F$z.<..:..])...H.c.n;B...V`].....|1V..x<..FR .&........,ua~........K_u8m..u^....O..r....H,....@...%kZ.. ....#].........|0t..On.*....A.R.5-].),.Rx.......#.......x..@t...;D9G.b..gzC..C..">...\.V2.N..t1.J{b.r(...7.A..+.oaH).k.>...S...VNxN-.T..j.N.....G."....H.E+H..7..D.<]......1nP~d.ZM~...j.R@...6._.d7_..^....!.e..B-I..-,...........S.B>%x....y......w.DN..E.0...(~.Lg)......Y.....9..+.Eu`L...q.#"...S.."S2......\....c....v.....;....|.Oo.r....Y+..a.'.O$.q0.<..vTm..W]g$...(u(.(i.....M.M!.7e...K...^`<...o&......o..f.0.P^]....+B.TWR....C]G.j+^.8Re>0......t..^a....gU.Z.[t....'S....=...=$2.ve[....f.....<D...p....o.`t..z....l.M..xJ..^?..r]g....N~bf.1....@..9..88^..6..Aq..1....\......N..W.:..:Pk...~'A...jo..{.%.3.c....N:.I...c...$(U..&..|.l....=.[mg.....;
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):803
                                                              Entropy (8bit):7.541297801337646
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZt75gzLjhowZacw+swEvaTGzHv1GqBxh5wkRUlt3vqf8jHvMH0mHVpVX6l:HatQRowZacw+BEvyMHsofw33vxzmt6l
                                                              MD5:BE99344A6E4022C2C02569EB3A9612E7
                                                              SHA1:FB83938C60E503A943D936AD64B278FF8798C068
                                                              SHA-256:E3E9DBF01E6BCCFFD8F49F1F32938DE5EA6AF40035FFF8BBB46704FAB4BCAA66
                                                              SHA-512:E77E1CDA7870551E855200CA71ED6B0BA7B68C04E4E3FFC942194520C1B5F30515084326D5D357EA24E97D1EB1DB35A5F1EA8E4A8E9AD803A7997701C4052D7C
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`..\..w.v....Z.......\.........M..G.9..n.{M./... ...~ }...8..A........n.O.}.C.(....zN...>.N....$...;[....O...js.~...; ...[.=....>H...Sn.CC......8.]<.v.\..;..b3oj.c..;] ..3.Ib..1..0xd`b..n[.5L..C....:...>..m...0.......UW....n/F..E..}C.... ...aq.. .I...f.!....<..3 V.q"...b!<....= ......../.bA....j<p...! ...~..@.K..*P...I....|..%.#....C*...1'....gh.M....../P...G(}...U....+.e.q.W..4... @L..G3\UR...gd.5..X...K.1...zz..ee.@..........1xaT....`...&..g..n..9.T[{.....AssUR.....T_....bX.ZU.......gg......e....5....BKu.>... .Xp..T....@....A.o....\[{.X.&....YQ1.#..feE.${...ab.8.....)1.........?......@^[..l.........]TTK..@....c...(..."..QcceP...f.!.AA.T....01._(..H.@.....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):243
                                                              Entropy (8bit):6.422869898567927
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKchkVCpGQFHoshpMw7xRP2i0DslHJ1gbp:6v/7saZhkopGU/r7P+ig1
                                                              MD5:059D91E46C3142D8E4C9271DE40CE144
                                                              SHA1:3CBB3BF701A4A23378E91B8EB30A40080AF103B9
                                                              SHA-256:561EE41BFE3339532A4B14BB1C0F4379B37051394ED246CDD504AC0ABA79408C
                                                              SHA-512:E84780791E954CCF4C32E1BAE27CAF28FA537D5A09D13C32E680498A425F40EAA56727767ABE6B80EE577C91E16416F9DCDC1CC1218F565DB3F2651657F9289D
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c`bf........C4....I.j..........~......J.5.}......i.}0.-..".-...#9Ir....n.n......j....>..F....V.Q.........F&f..2P=...dA...I.c....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):854
                                                              Entropy (8bit):7.529945105993399
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZhJBp/xSl1hCH0l2XJJIpmGN4zjLfX+zQ3YhvzLDiCMDRiKNienICJj5vx:Hav2lrr2Z6ojLX+NVMQOJj1Lrd
                                                              MD5:0D8C6D90A8ACF1655E213E7CDC31C25E
                                                              SHA1:B475D9CBEE9264DEE63F3A8F72B595F3B537EF10
                                                              SHA-256:66D789CF6D1CCE8AEA7E6FC1F35129995529C0F6EC4CAE9C6BB1D4B1560AABDA
                                                              SHA-512:AE70E98C52DD7ACFF11AE2D8093F31D71AC92F2922E3592B1C04875B9C7653555D62E5DD9DC22264CE0792999AAA05A584A4F9AAA2DEA82D5C745E7999DDE0EF
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.c```x..... u.x.q.....p,.....p.d..-..?....{..s....y..x ,(......A9!...........c...p.'.....V..@....cA$..\....3s..fa.p..=..8..9y?6.Y88\.e...Y.g.......PX...../...'...G..MJ.... .pP........57.....s.HY..3)X._.<.-..W.P|&....UL,,...2..>......t.(>.XK.9.%...7.X..`....$..L..gb........':x.....M|....0......G.............q5q..-ffa;....I .GS....8MbffN.R*h.@\....&@.....H.qD.x*..P`da=.' .'..=.....j.#....%0.....p....MV>.XX>..|.bq....'...%".....7..&..s..^....K.|..\[T.S~.O.._.5..+.p.V.@....*.&.._DJ.&...u`.....v....._X...+;W6P<... .A.......e.gc.@X\..52...p.....B.......G.&.pP....|P.Ob...V.L{.2\.-.....%\qm...q...^...f6...q....".m..d..../V.nxP...es.._......8...@...`....&..$5...'8..f..q.2.a....M.8.$.....F........o.bM.dI....$.......nQ....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):461
                                                              Entropy (8bit):7.037071167502854
                                                              Encrypted:false
                                                              SSDEEP:12:6v/7saZ++irj8c5pxpHiLep0N8Gdg7R2SCYbDsAq7:Haw+irj8c5pniLa0z+CaO7
                                                              MD5:C48DBDD7111FC6370C99D9AF1DB5CA25
                                                              SHA1:94134E54328EB50BE24BA53005D0608D47C4A324
                                                              SHA-256:89267EFF928357F51A583A794AAFD9928D8E3B87376E0804ADF933CD1B794016
                                                              SHA-512:69BDB9963CCC2CD3ED55079A39F40B40EA8555E1A32AF0DDAFECDB9903F1222B9396B6F5C5909CFA399E956B79509892E348F4645DF8D827B0F2496C9D404254
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....ZIDATH.c`........~...> .....8..].x*..4.P.Z.@......3.83....'@.M..JPW.." ...qX..._ n!.Lq ...j N...0\...&..3...@..p. >........h..-`..~./..q,.3..Y..i.1..n.....Y..?..'T.....e..7.H.$6..?.1;5,..F ....=@...{HIa.,.....IM.,...Z.....ld\O@o0.d.e2FR-!dx......@....I.I=.>.....k..W....@E|..]..?...)....K...T .!..Jh.x..mPv3...v...tW.u.e ^Hm.$.x......P>...~.F.S......IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):456
                                                              Entropy (8bit):7.173747785075021
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKcwiOV4ZJp4EB4+ocdX4uwqowGUtnrNoZyrNlBpssBnDO5ckcM9s:6v/7saZwbiMC4oTwqJLNeknDO5cunpiB
                                                              MD5:BCA6E8F983FDC2FB7B423CB3167DAD11
                                                              SHA1:F240604385ACA89AD08B7CF9C5576C7708627E15
                                                              SHA-256:7F51D062663848D2D1F8556481878CFE38A27452166589524CAFEB35D7CFECD3
                                                              SHA-512:4CBC2535E117BC137264A90A30A683E2262BF99632ED35036BF799020E6FEAB942B91C5C209B75C99F91C20AE75A89E6ACEBD9B7DD71AE9527899982D9FE8E86
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....UIDATH.c`..0..+.s1...... ....8....e.......@<..oB-;I..9...._.b.$...%F.....[..;..4yA ...:8.....fA..-....@...m74o.@...1.....U.....%....h.N...h.'6o.C-h@..h.."..B-M...C1......DJ.Z@.....2,..J...4}.|..j...,..f.%@\...h..[@..Z...#.......C.>(s2Rj.....Bp9....BJ|R.E....A.3...9....../.b......L...P.V..\....:(.A.9..A..@...m>......x!.-...}...~(......... ....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):421
                                                              Entropy (8bit):7.186986765554187
                                                              Encrypted:false
                                                              SSDEEP:6:6v/lhPZi+aWdKc5JE3T8oD5wFlJkUSQWp2EAQy18AHBNOU0Q2YTeGe1seKFAkp:6v/7saZo3ihkUSkEixBNOU0qS5seQn
                                                              MD5:4F9496046D0CD092D3150913D3A170F8
                                                              SHA1:E4FD54ED05E62A1961406965CD9FA2C7220399C4
                                                              SHA-256:D2ABC6484210C8815F083EE84070EC040DB227D166984ECD3938B4B7AD6ABCB5
                                                              SHA-512:73E98EC3C1D11A9FC1BD90CD097CA88E52F5A4F28471A573C7673F6A78DD6DC226E538E762B82D6DE3450FD151B34155CA1FE7055C2311640804BE235446FE32
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<....2IDATH.....@..79K..i...]..@...@.....M..vZ_....`.3.\.De.b..Y......z..~.R0E\...?.'.....z_..p..w.s..b.4..8..(.f...X I.......k........i....y.Aq..i.!... .".t].@x...4MCk./... ..Q..a...,.s.,....... .!V=(....0...=...|lv...>...".m...y...^.......M.....0./.}r.....X.$>..H}b.0..@..+..'.=..HF...Kt.b.Zc....-....*..l*....IEND.B`.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1116
                                                              Entropy (8bit):7.754627554128948
                                                              Encrypted:false
                                                              SSDEEP:24:Ha29ycw0TbJM+kWDJRM1YZdIHVH2+U6AmR5GtIF15cejUEsPtTR:62k0TS+koRoYZdIHVWS6I150EsPtR
                                                              MD5:AF8F5AFB51E4EE017CB1C342DDC80F4B
                                                              SHA1:D8166710C0D5D9AE23D35A7CD07A0B1CADE2A255
                                                              SHA-256:42FE2B2847B16DD2F8DCC4DC4A69C77B7BCC13E004B1BF737FB5FED40DAE4EE7
                                                              SHA-512:37673D0F4CC6C2CF3145B5108C2E9DFDA16703BEC022F05F5B897039F06DBE76753686BDA02DB986324D8AC7D6A982CEEBB254C71F61B1ECC1B24F0F0007639F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q...jS.....i]h...)bP&...mn...........e.2.n....eYVP~.*D4.Z_.bTP..........l.u[{...xx.s.s..s..9.+..eS*...."N.V.)//...G+((..R....}ii)........p.^~~....B.hO...P.Vk...G.n........O.vw/.;@....O..///.kkk...hPS......l...7.>.......P.G.!..R...'.x.v.:.X.^........8.x.I..r...&.V<''g.........Q..2Q.......j..h. h./...+%%%....N7..y.....r.1...y8...x.aW....bf.pQK.Y.J.c.-L.dG......8.d.jg5..wb_,.........]55>.s....y.w...x._...!.O....4....kpq..n.....0"`..l...x.....b.............[.....FO1b....q...*...!A...l..........;...7....s._..Bi.....M. ;O55.G...bW0...d#...c.........$....Xg..d......w.....x..9h.Z....S-!..?f....F..X,..e..|,X.~3Z.z.n....u...)m....J...h,:::.....i..04<.....R...).A.-@..g..{zV.Z].PH}}.|.<.+.?...A?..X.a.\r...ef.J.$..2.nCK.C...;...#.,.X..!n,.d.].\....=w.VW7.im.....n...W.Lv..&..-H....+/...I.=.I....%55../.w*...'...........D.sg......t....G.|)...4...Zv.?..?fXX..**.`ttt
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1105
                                                              Entropy (8bit):7.709561833557226
                                                              Encrypted:false
                                                              SSDEEP:24:HaGRSu6+CJjcWzXg0eWdqh9kQZ3TQbzbveF58fz:6iNWJYWTgUEh7tQbneFOz
                                                              MD5:B6E1E5D06089AACAE7AB12C6448E9731
                                                              SHA1:7A81C81C63C0C06ABA0B08292326EFFD0EBA4B0D
                                                              SHA-256:5D565B1058E38726209CC254C75A00EA7545008FC1EF6F2571038F82E1601A56
                                                              SHA-512:1B462B02EF50F92D68004EAD43CEFB324BAFCE946836E32653173E2813ADB216F303139E6A4223BBE6A9DB94927BA1D69CC8875E05CCF4C7CEFAAD691E1558E7
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH..kH.Q..m...2E)BZ..E.].1(.T..67o}.Fv..>4......%A..e...........TP....M..|...;.zu..........;..y.YP....^....b.F.....?......l0....}qq1.......{q.Nnn........=.wkAq..h.j.....6x.......n....=....0.w999I..\YY.B;.1`{.N....py...0....^v|..;.....!.o.p....k.>..^./H.-.d..^7..=..*wvvv./...f#..8xH.1N..>.:t....,...d2=F..a.X.KEEEB....B...C.`V.9..s..<....P.*%%%.;.Uw..x....,"qG?....N.H....%@.....o.9......wm6.r....O..;F.....([...e@.:qnT..S3..........-R..<.;..8..U..zs+....(.x.1.e.x...........i..Ew.o....f....(.......-......".]..&...-.5...A..........cuu .@....I^d.o.la...6E..uzzz..3..p.Y.mS..6E....l6C\\.....*.2.mbGjk..A........*.n......t.6..]...x...j.....A................E..h.D.U'...h]..-Y@.........p....~.>.([)`.Z....L... ..8.j..nk[.Xo....$.0m.[...u.vWU...M..z.n4....g..l%.M...U.......C3Sp.......%...W........mx......?!dddt..._V..f\;IQ<fID..3..Q.c.DaJ.;.....30........QQQ5(....R..5.E.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1093
                                                              Entropy (8bit):7.743931751177379
                                                              Encrypted:false
                                                              SSDEEP:24:HaRV0uZNXr+iyPuiie4Lz9BjfkTCDbOtGlA+gdR3hSY+vQ/GW3N08wE3IS:6RV0aN7+iFNe6zfoTCDbOtGlAHhGvQ/p
                                                              MD5:AACA2345FBB42680C297C9D82E1564D9
                                                              SHA1:13CE3194A9E4613F402C082AA19171CA0027A985
                                                              SHA-256:7590CB06896645C94929873166C2F9E6B33C6F7ED6721B28AF13EA7CCBD9AB78
                                                              SHA-512:1EB11C63BFD7E5873BCEDFAA5CEBACD3AAD2578047B3779E96C8836E20D7D01C2751658D9BE9774695B1FD5DF6542C484078B4A7D9DD278D2281A91C9E38F36F
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UkHSq._....)J".z.,2.R.LR....|.E...Y...=\e..(..(.aYB.!....k}.M.......N...{:g....kO....{..w.....d.i..&@.VG.t.9EEE~......YZ...^....@aa! 8....deem.......I....m:...=x.nw....p..S....{.......fff..1rUU...8..;.v..?.....W........e...i....M.~.B#...0..8.:..........Q*GFFF./.....!.....O.D.n.H..PF.*............h...+....W.......At.q.X.(...n..`..R%&&..d..O....cF@.[E.VQ5,.......<6..c.R./'.....K ...|.aEv..]TE.f@..0f.....'../_....U..t<.Q...h..<..7"....^..K .*~G ..zk.h.Z...z.....%2.....D.0....d..{.c1../.Z..H.DFF..&.......X..f..,6j.g..=.....'%%.%...))).x....db.2.j...!`...i7......2....._..L...:.L.f.....z..A......=...S2..=..Vq....Q.\.....#..j.}.k.p...WHN.....pz.}W.jXkL.".......$....u.>.+^.a.*.....I....2.z...Sg2.n%..x~yr..$q.q.....Z.........sP\...$....T*...x.C..1.Q.......|....,MHH..M.......KMM..nV(.......X.T..l...}.8nv..;4..v'=...........?$$..AKq..5..#..)a.i[.G.Y..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1087
                                                              Entropy (8bit):7.726447155721982
                                                              Encrypted:false
                                                              SSDEEP:24:HayqeZgfR3ldEeM+mN5/2RrWQO003w2+B+p9FTohkYBb:6vX1EeZi5/2RSQDQw2+sF0hrb
                                                              MD5:0B7D9D952ABA12E25F7ABF2D5F744AE5
                                                              SHA1:86FAE6CA765B86879591145A489DADEE8E461553
                                                              SHA-256:6AB24D436C46A02C560C96280DD7292CC02754E7BEB1BC4E1F455C819AEBC92C
                                                              SHA-512:1C1538A60FE63DC4155315A4B1818C9CCA9186B2A17C46AC673C9414401AEB382635645C63692558FF72E8188ECA59F7DCC7D6DF62F1D1E619C508021AEE5DA8
                                                              Malicious:false
                                                              Preview:.PNG........IHDR..............w=.....pHYs..........o.d....tEXtSoftware.www.inkscape.org..<.....IDATH.UkHTA..6%.LQ....V#...(.I*.cw....mI....Gk....V.I.IE....BD#..OO.."{#=twu...s:.;.....8.3s...9W"..R...Je.F.YX\\./.....3_.V......B(**....;p.nvv........=...#8..h..c.p...O.......VW...:L....#z.........R....**..w.... `s..s..]{...*..x$r.C.?"....~.b.X..Fln..6...lh....'.Je.....<##c)...un/)..0#.2P..'.o.Q....V.....K.I.\PP...,??.2......d....]..Q.K.....5.n.;..C0...H..V.|.9.....Lx..I.O...3..!.@ ...LhC.{..H.#-.W...@.i>......z...<qEA?...g.Hp......y\.....zJ.....F.;.a..ov.J.v..Azz.K"...[&.@&3..du..9....J..$J...5..l?...<%.D.l.K....u..}J.{..$''.E.p.RSS{......L.%.,..G}.A..Att..b..Hq3.e"'...2...}'<Q..o..(...<~D.p.2.C.:.`.<.E[[.L.R...J008...T.V.....#ZAtD"..3+G.w......$..5.....2.....KJy.C.P4!.\.}.#..Wm:..f.I.......O.S..E.'.cr....^...p......%%..:...\..c.....$.......x.(6....AAA....z..~.`...........sE&....<Q....e[...].h.Z.......e...1....!!!GBCCk.t;...`gD.:m.b..]..a...R./_
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
                                                              Category:dropped
                                                              Size (bytes):2238
                                                              Entropy (8bit):2.6372815917381076
                                                              Encrypted:false
                                                              SSDEEP:24:suFS+FEi9JJiebtmD1yBjyMiUgoKsDZ07A97uEM/ArhVL7KFuqd5+75myJdfyE/k:m+Kioebt81MJ7p97u1/YHeFldgbjk
                                                              MD5:9AA3B592D6B0B33DADF80E8EDC7A3CE1
                                                              SHA1:16783BB3C7FCAAA86341C87527431E91CCE01023
                                                              SHA-256:4BEBB406645096C3B6EA129F6234C6D4B3B590ED0626C9D56742CE1132618ED4
                                                              SHA-512:D74130AE644EBC4599F460B1F8AA5385693F2B1F873B037E82171C3A43BD18B9B9F949BC60254808A66A63FC104F3899FC437A88A109E04E54D2BBFFACCB51E2
                                                              Malicious:false
                                                              Preview:...... ..............(... ...@.................................f.3....3..33......3f...3..33......3f...f..3....3...f..3.......33...........3f.....3...3.f.3....f........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PNG image data, 450 x 240, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):87939
                                                              Entropy (8bit):7.990756543245148
                                                              Encrypted:true
                                                              SSDEEP:1536:ts2l5YP6E32hEXBTl2AD+9v070pXZ55mSW8HPYDf4E7vpzONQkrSZ8k0Ah6GfAh9:ts2sPYOdl2Dv070PrZYDfnzOzSZ/0AkD
                                                              MD5:B5A476E63CA7C607BCC975181ACAD3F7
                                                              SHA1:5E1D6AC9973D67C55F92881A0FFFD957F5FFA614
                                                              SHA-256:D625A953C7B79C59D139BBED4BFA9B341EC6C24C9DC55D58AD05987735A1F9C9
                                                              SHA-512:8E7B0BD0365CC9C9A215D274A27031777CA8963243F3A23C62D310ACF11DB9F1C867240002EDFF6E7A5C923FDFF4B1DEF3FC11DDC9903235DDC585A1CC79D479
                                                              Malicious:false
                                                              Preview:.PNG........IHDR...............dW....sBIT....|.d.....pHYs..........+......tEXtSoftware.www.inkscape.org..<... .IDATx..y..eu?....]sso..I...] l.....J.h...W.....Z.m.j..E-.m..Z.......b .AvA.....Mr.....s..|.......zA....>.Y..|>3.E3{)......B.$r........,.W.o,.......v....q_.u.....8....cUEp.,.^<u0~-.2?u..xj;.G<...4V....p1.."...g.).g...s..}...:J...S..e.Y..y..TO.&_.....\..<(.#.c..AP..11.....1.p,._....v....k.@...A4....'/.Sw.d.u..R.N_.LJ];..........d.0.(..W.9N.c.\Pp.J...R?..T...;#.........k...N...N.q......y'.k.:x..\.*..5'..kN..8...p..p .4..R....... a&[g.-.G*.1..h...ao.8.WV...X....C..}...c.).....M...A.md.T.]q...se..b....7.a...5..p3.A..ie6N...0....t|sqxp;..8.8<.....u..<...8B.i...d.v.T..1...Kqxp7A.."A.8<x...w..|c...v..\s~{~.dcb.y8..".f.o.c.....b....>.~5..]kjL!.~.."c.II.j...7.N*+bK...YXg.!.....-..Q..U!I|\.Bh.Z.Z....n'H...A#\...\.O.1..k.gV.z...[..IO.d,Z..V.B.)H.m...Z.K.:...xk.M.....I.cZ.....gq.X.0C_;.z...N(...._UhV..*g.e...*..Q.....v2..uB..F'......R...UP[.....
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:XML 1.0 document, ASCII text
                                                              Category:dropped
                                                              Size (bytes):2552
                                                              Entropy (8bit):4.639660685199659
                                                              Encrypted:false
                                                              SSDEEP:24:2d6RzXXSs4E0xZXgie0eKeVegevXgD5v0rl3r2FrrQ9ppssWJ/lB+Rg4FpEp00rQ:cozXXpJaZXsv90DvXG1M2TU6+
                                                              MD5:5BB26A0E36CA2126C373A0A106369AE0
                                                              SHA1:8BEC490C77FCE71D9785417E10E80B2C6042CD26
                                                              SHA-256:9368E5566516F00A49FD62B4159FC431226503F4B178A1A0DC10C5DCCC52DA77
                                                              SHA-512:66C0F1C897467CC2D7065E489F8F0F43B7DBDE8738DD6BFE8DDB9B9D1AD0CE6F2182E44EBAACEB3934CC3AC243C4FAABC0D869AA784DB0EB055E3A73A0D0D0A9
                                                              Malicious:false
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.<toolbox width='5'>. <group id='view' title='View' translatable='true'>. <item type='builtin' function='zoom_in'/>. <item type='builtin' function='zoom_1_1'/>. <item type='builtin' function='zoom_out'/>. <item type='builtin' function='display_3d'/>. </group>. <group id='proc' title='Data Process' translatable='true'>. <item type='proc' function='fix_zero'/>. <item type='proc' function='scale'/>. <item type='proc' function='calibrate'/>. <item type='proc' function='arithmetic'/>. <item type='proc' function='level'/>. <item type='proc' function='facet-level'/>. <item type='proc' function='align_rows'/>. <item type='proc' function='scars_remove'/>. <item type='proc' function='grain_mark'/>. <item type='proc' function='grain_wshed'/>. <item type='proc' function='grain_filter'/>. <item type='proc' function='grain_dist'/>. <item type='proc' function='shade'/>. <item type='proc' function='polylevel
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):13745
                                                              Entropy (8bit):4.472050797347336
                                                              Encrypted:false
                                                              SSDEEP:192:aHKqRIbyUjLD5YwPpYfge9Y+JWvspzx9dYnnXuYFIHtcBj:aHKqaj/CwiYxvs8
                                                              MD5:C7B4A691528409973768359B1BAD8772
                                                              SHA1:F0EC8520F3FEE1B0B04E22E0D8CC2A584948760C
                                                              SHA-256:ECA4A6E2DDDDB769D7FC52076040BBE53F71E8D3E27DA1D9EA413230489B0D7A
                                                              SHA-512:C597EDCE88C0283166B64B13337EBB1CEC2403A667389582491252BD59B799247DC35C68AD77411E729B96B3CAB7EF9778FF9A3CE3776994B50DD3C15A319A90
                                                              Malicious:false
                                                              Preview:# vim: set ts=30 :.accurexii-txt.managing-files.acf2d.statistical-analysis.acf2d.afmw-spec.managing-files.aistfile.managing-files.alicona.managing-files.ambfile.managing-files.ambprofile.managing-files.anasys_xml.managing-files.andorsif.managing-files.anfatec.managing-files.angle_dist.statistical-analysis.angle-distribution.anneal_synth.synthetic.annealing-synthesis.apedaxfile.managing-files.apefile.managing-files.arc-revolve.leveling-and-background.revolve-arc.ardf.managing-files.arithmetic.multidata.data-arithmetic.asciiexport.managing-files.assing-afm.managing-files.attocube.managing-files.axis.selections.basicops.basic-operations.bcrfile.managing-files.bdep_synth.synthetic.ballistic-synthesis.binning.basic-operations.binning.blockstep.scan-line-defects.line-correction-block.burleigh_bii.managing-files.burleigh_exp.managing-files.burleigh.managing-files.calcoefs_load.caldata.calcoefs_new.caldata.calcoefs_simple.caldata.calcoefs_view.caldata.calibrate.basic-operations.dimensions-and-
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Zp\305\231\303\255stupn\304\233n\303\275 popis'
                                                              Category:dropped
                                                              Size (bytes):10628
                                                              Entropy (8bit):5.1324791193575825
                                                              Encrypted:false
                                                              SSDEEP:192:S5ewTiwExfniJqBURCySjGHzKYDYwlzPsqAky+RwybKz92sjSpw:SYwWhxfnigBURCzj8hpKZR+w
                                                              MD5:2C6B374EC95CC962BB39DC1545BA8426
                                                              SHA1:4168E6BEFCEE4ECCB5EC7AD3C765C21E68F5FC62
                                                              SHA-256:4CE0C6D761953B04122024716D02C7B00885012CBCDBF8A084C835F8E3FE83D2
                                                              SHA-512:B15C4BCCB451590218185CC36FCB2B5D2B65C3EB3A24A739F111CC159EAC17AF86AAA784807E0044DC194631BD436B2751CA597B86D62083D351C5BB0E7C4765
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf 'Ukazatel na pixelov\303\241 data obr\303\241zku pixbuf'
                                                              Category:dropped
                                                              Size (bytes):23987
                                                              Entropy (8bit):5.377577782299227
                                                              Encrypted:false
                                                              SSDEEP:384:yapCPnVIL/jFtcWDx8c0MYAqvch8Y0uOxWhY4tWfOGgKm5VBhH+:yapCPu/cWDx8JpgBWgy4gfdkBg
                                                              MD5:0FED09B38B369C55651BB895CC3A351C
                                                              SHA1:38D163D1F0745AA15F9AA88A5094A90218F5DFB8
                                                              SHA-256:F77427FE1F4474DC79728D8DA3F001F41AA74A75A94E51092B627E8AAE608C84
                                                              SHA-512:9AFEC2B667DE55D5880E43BAE6D9F53570D7712A0497012B6D3318631C941AB3CF95B80EE3D4225C11DFE4F1F27B1A4B91BFD31AA8742A9A82413FB59558AABC
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 29 messages, Project-Id-Version: gettext-runtime 0.19.4.73 ' -V, --version vypsat informace o verzi a skon\304\215it'
                                                              Category:dropped
                                                              Size (bytes):5814
                                                              Entropy (8bit):5.556195007588839
                                                              Encrypted:false
                                                              SSDEEP:96:qU1+HPMJ3Hlivn7vn8CJ6vOXt4Akhb2gZRmYM+qLYM+q2wttm4uIHJ9zkpeM0c:qw+PMJ3Hli/7/avOdFkgkPM+rM+qfHDs
                                                              MD5:DAFB13FD043ED5F0EA6927404456317F
                                                              SHA1:D3BDC902CF01068DD7FD5453C4E39EF2BA2ED8FF
                                                              SHA-256:E8B370809C930C64B4AC2BAD96CC10D59F2EBE82AF9BB370B6EA7400C6230B75
                                                              SHA-512:9FB759681486DBC2F3C8981B3A700A0804565F4626BF2C66E674B766C0CFC1091F58881549AA918A49CA02EEA9B2ED0AB2708FAB26F9AFCA3597390A2ADC6E8D
                                                              Malicious:false
                                                              Preview:....................)...............B.......9.......M...........\...(...x...........e.......:...........O.......i.......H...................1.......&...3.......Z.......i..."...~...9.......I...........%.......................................................1.......=...B.......B...b...T.......&......./...!.......Q...^...^...8...............................................*.......7...........J.......Y.......u...V.......k...........g.......).......5.......Q.......e.......v........................................................................................................................................................................................ -V, --version output version information and exit.. -h, --help display this help and exit.. -v, --variables output the variables occurring in SHELL-FORMAT..%s: invalid option -- '%c'..%s: option requires an argument -- '%c'..Bruno Haible.Display native language translation of a textual message w
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 56 messages, Project-Id-Version: GNU gettext 0.10.38 ' dokon\350eno.'
                                                              Category:dropped
                                                              Size (bytes):6377
                                                              Entropy (8bit):5.225263173206567
                                                              Encrypted:false
                                                              SSDEEP:96:eCnC6P5EIGfjJBHa0//xDZ+Lzr3ftK3cSXaonzpjlEDEhztJD4G5:eoPbGfjJBHaWJDZ+DPtKZaozVp82
                                                              MD5:9B83CA58A6C1142363A9AFE916414E9A
                                                              SHA1:DC0FCE7954412BC7D85863DBC99F7E54AC56C76A
                                                              SHA-256:ED7D2BC6269EB185D68AA6CD215CA50A12523A24D3D8F380A2F1BCD63B7775F5
                                                              SHA-512:55C12A9F70631F1A47D0D0E26F8559D6F91A6B0FD14A63CD03C6B93D16514E5B02F4F887BD94386332BEA01FAC29B1E9093EC2BBABE29CFC92CA36E8C139A263
                                                              Malicious:false
                                                              Preview:........8...........O.......................,....... .......3.../.../...c...+.......T...............4...C...?...x...!...............c.......X...F...].......O.......'...M.......u...R.......................$...........%...*...D...;...o...........................$.......$...!.......F......._.......}...........".......#.......*.......5...=.......s...............................................................).......8...+...H...*...t...'.......................!.......1...........H.......@...<...M...........8......./...............c...?...B.......H.......C.../.......s...........v.......V.......d...t..._.......(...9.......b...X...m...................).......#.......0...7...L...h...........................*.......*...:.......e... ...z...(.......4.......".......$.......N...A.../.........................................../.......?.......Y.......w...................0.......2.......0...........L.......c...$...}...F...........5.../...................,...........$... ...&...*...............".......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' P\305\230\303\215KAZ (Voliteln\303\275) p\305\231\303\255kaz, kter\303\275 m\303\241 b\303\275t pops\303\241n'
                                                              Category:dropped
                                                              Size (bytes):123325
                                                              Entropy (8bit):5.52459012162757
                                                              Encrypted:false
                                                              SSDEEP:1536:NZwErmJ8XIO6JnLQwF5kg7cRU17DipGQ4B1m1V6SMgOTVROhZCS/oXBwgMxG6tQP:NvW8F2LFF5kg7L17DDJurST62bMfCcc
                                                              MD5:F547A2921A74FA0255ABB1006839D972
                                                              SHA1:1252F6782F92A496A54DA0B671F57EEE45EA5D32
                                                              SHA-256:D393C41609B98B1DAC3D3CFB2D32B81BA0EFEA0FD88D6590AAEA5BFA5FE2F6E3
                                                              SHA-512:E991D14014350EBDB3BCE2EF79BFF7510FBE2A3C60925382BF302B12016AC46ED611C0B02EC8C3532FFEA9800E497953F3C2058BA066348E9AC9111590A00072
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+-properties 'GdkImage, kter\303\275 zobrazovat'
                                                              Category:dropped
                                                              Size (bytes):161754
                                                              Entropy (8bit):5.385381014680175
                                                              Encrypted:false
                                                              SSDEEP:3072:em1YvN/CkL47yS3RH49ljUYPw7sXK7BxaBcxMa/9xWThE:n1WBCkLMysy9ljUYPwI+BxaBcxMa/9xp
                                                              MD5:BBE17FBF39F832DC93ACDEE04959277B
                                                              SHA1:12D8320CA7B8616247EFAF8E5DE9A4EE1C55A9C5
                                                              SHA-256:51BAF6D145362DE46E38DA989154DCF7527178DDEA802AD1BAFCB6A54A28C377
                                                              SHA-512:1D640FCED357E6F0794A399B858BA3240FC2B839F1B75A0914C28732304095E67E239F29B864DEB46C54A75C371F9769E359FDAA915D2D5EEF0AC0E32A231C78
                                                              Malicious:false
                                                              Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 868 messages, Project-Id-Version: gtk+ '"%s" nemohlo b\303\275t p\305\231evedeno na hodnotu typu "%s" atributu "%s"'
                                                              Category:dropped
                                                              Size (bytes):57280
                                                              Entropy (8bit):5.421875086873875
                                                              Encrypted:false
                                                              SSDEEP:768:gKJHhOe1KPEBjSQ8zCtWG9+06llQ4c4FY834OeSZpqPpEl:gKJHYeYEizC49G4caSUQPpEl
                                                              MD5:87D0B5EDC1561695F781A92F210EBD2A
                                                              SHA1:961EF34B859060FB4A860CCE54A7368CC1311F2F
                                                              SHA-256:AF02CFE1A150A66016EA945190B5A1F5CF1FC8D55AD2FDC0A104DDE4777FCBA0
                                                              SHA-512:160D4932617169C6428E003D1DBBDA35E5E97F75BC9F682E2C7E10B3D5EF3FB675126AD036998DA32779198BABBBC5FBA9011029952BB997918A13A41420A23C
                                                              Malicious:false
                                                              Preview:........d.......<.......\6.......H..F....H.."....H.."....H..,....I......CI......\I......iI......oI......zI.......I.......I.......I.. ....I..7....I..)....I..4...(J..=...]J.......J.......J.......J.......J.......J..'....J..$....K..(....K..)...WK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...%L......VL......bL......nL..9...yL..6....L.......L.. ....L..0....M..5...KM..9....M..8....M..:....M..7.../N..2...gN..4....N..1....N..?....O..1...AO..?...sO.......O.......O.......O.......O.......O.......O..3....P......5P......CP......`P......}P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q.."...=Q..>...`Q.......Q.......Q.......Q.......Q.......Q..V....Q......8R.......R.......R.......R.......R.......R.......S.......S......,S......:S......GS......\S......nS.......S.......S.......S.......S.......S.......S.......S.......S.......T..+....T.......T..!....T..)....T.......U......(U..$...>U......cU..1....U..-....U.......U..!....U.......V.."....V......QV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 550 messages, Project-Id-Version: gtksourceview '.desktop'
                                                              Category:dropped
                                                              Size (bytes):33875
                                                              Entropy (8bit):5.288425965571156
                                                              Encrypted:false
                                                              SSDEEP:768:siKv2O9y0uEF2KQQCMovYtTmatdpa//xDKf3/7v7NzZvm1yW5BhfhQvH:Z30pF2KQ2ovYtCatraxWfzp5m5BhfhQP
                                                              MD5:C8EA11F5EE3DB1083E133CB627834C0C
                                                              SHA1:D4C95F9488814F800EB41E096B75445A02C27E9F
                                                              SHA-256:534A0D20F71D7940E6B20ACC2B4E0C1D855FC3E68BA904EB163A07FB4F870D99
                                                              SHA-512:17ED90C8A977CFCEB6B7B1C2275E87A393FABA55EBB6D6B91578D2B1896836577B5D3700475B8F707215F28662D01B4CBBC1DD10CB2E767B5C4CDF0505D386E5
                                                              Malicious:false
                                                              Preview:........&.......L.......|".......-.......-.......-.......-..............................&.......*.......5.......I.......O.......S.......Z.......a.......w................................................................/......./......"/......6/......G/......V/......b/......m/......~/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0.......0......%0......30......A0......H0......\0......d0......t0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1.......1......#1......,1..{...51.......1.......1.......1.......1.......1.......1.......1.......1.......2..)....2..&...72......^2......f2......t2......|2.......2.......2.......2.......2..1....2.......2.......3.......3......%3......23......:3......J3......L3......T3......[3../..._3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4....../4......@4......E4......O4......_4......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 4705 messages, Project-Id-Version: Gwyddion ' je svobodn\303\275 software uvoln\304\233n\303\275 pod GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):355466
                                                              Entropy (8bit):5.632714700197964
                                                              Encrypted:false
                                                              SSDEEP:6144:f/aeKKteR9o1LXX2TDbpJ7yVT8t5qWDHZyGB1XhJPI1g8kM3XYztLjg:XxmsGpJhLpNhJPI1g8kMYzu
                                                              MD5:B42B6816185C74C621250A445D86EB1C
                                                              SHA1:0C07AD5404F98ED2EB22C4F7E8ACA9219320689B
                                                              SHA-256:DA8EF2BD430B949EC3D08FAE34EFE964BADAA597313BC0C7FC2CCE63243F0E3F
                                                              SHA-512:427E075A95646F1EB1245B23475E2D9763DA67B0642F3C78D297B0BE23839AF1CEFF0948B98BC8AF9B9305A859D614E5B394146A6419277E02274E3BA2539A59
                                                              Malicious:false
                                                              Preview:........a.......$.......,&......@...)...A.......k.......x...................&.......-......(.........../...,...@... ...m...........%.......D..................%... ...9... ...Z...$...{...$...........................................&...(...%...O.......u................................................................$......."...B.......e...'.............................!...................3.......R.......h........... ...............%......(.......!...'...)...I... ...s... .......#....... ..........................7.......W.......h.......v...........................!...................... .......6...7...4...n...4.......4......5....... ...C..."...d.../...............,......-.......*...A...3...l...7.......'......%......."...&.......I.......g...+......................%......$.......%...-...!...S..."...u...#.......%.......#......$....... ...+.......L.......d...!......................0......*.......*...?...+...j............................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 1.5.4 'Barrierefreie Beschreibung'
                                                              Category:dropped
                                                              Size (bytes):10520
                                                              Entropy (8bit):4.955538150211772
                                                              Encrypted:false
                                                              SSDEEP:192:S5ew1rbZBIg5vqBURCySfGIy2VF8mY5RxAxP:SYwNbZWOSBURCzfWqFASxP
                                                              MD5:D2FD4CBCDA8036A4525E7217D6A1871B
                                                              SHA1:C712CBEAB8390EC36567D434303114CD58029027
                                                              SHA-256:D30DF7D8F0B6896A79E65E376F5180530D57CDC89B2BA3F98649D5BD96A9AC55
                                                              SHA-512:64DCEC8E43F02A91AC9E061FEE179E40613D3375FC33235CD6EC579F3C8CA488F39C0A65BC7F79A0E894354B919EB5BEAE270C880843DF369EBD1760E7B4828C
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf master 'Zeiger auf die Pixel-Daten eines Pixbuf'
                                                              Category:dropped
                                                              Size (bytes):23921
                                                              Entropy (8bit):5.17443570210766
                                                              Encrypted:false
                                                              SSDEEP:384:yapCAoFB7jFtcWDx8c0MYAqvch8Y0PoZ0mVgE+p6tLwapDNfl3wvAsihu/KQK7Hq:yapCzlcWDx8JpgBtZkpeLwalN2DGcKbq
                                                              MD5:0D2C5D6A6B2C83B3E01267D84A6D4857
                                                              SHA1:8FD93A8F660B026EAC1A9897BFA6618A2AFE6038
                                                              SHA-256:669BA31E4CB585F5C69E3EBA17A02D4529AFC17AB70A03818EFB49A0430A68A1
                                                              SHA-512:C650E404CD23F4BF936C17207887BE9F1DEE461E9CA4EA6813D8425C96FA297A044361649CB1EE4F2F9B539C2353FFCC89290013C96FF21FD6ACC3BD0741B6E9
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (zwecks Kompatibilit\303\244t; wird ignoriert)'
                                                              Category:dropped
                                                              Size (bytes):9188
                                                              Entropy (8bit):5.211599968885511
                                                              Encrypted:false
                                                              SSDEEP:192:T08zxxlurx9lHli/7/avO1inVFWo8TNBWjzYr:TjABFADWO1inLNe/
                                                              MD5:24E429512E04C6C5F52B64D3EDBDC2EB
                                                              SHA1:8907F58FEE79047EC5F10BCC286C74ECFD5112F0
                                                              SHA-256:518E2F317976094EC0A0BF8DFBBF2CDFE7697C74FB2B1C9C7E7DEC8DE3641859
                                                              SHA-512:4D3131E8EBFABE4174C5966E0D119B3F721ED17F52DE78DDA0D0ED74C8E2285535135E49A93A34BA1E2BF0B1F2332052D71D1C68BF012C2390DED3DB93846DE3
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................E.......C...F...@.......<.......E.......G...N...J.......@.......=..."...E...`...Q.......q...........j...E...........G... .......+.......%.......3...:...*...n...+...............................{.......I...X...@.......'.................... ....... ..e.... ..,...K!..*...x!.......!.......!..#....!..D....!..V...4"......."......Q#......f#.......#.......#.......#.......#.......#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: GNU gettext-tools 0.20.2 ' (nur XML-basierte Sprachen)'
                                                              Category:dropped
                                                              Size (bytes):121783
                                                              Entropy (8bit):5.086282383142756
                                                              Encrypted:false
                                                              SSDEEP:3072:8lOPBqQwP6xA4PnTOJ6mfyVTf+ZLrQjU/HU3Twp8MAM7I:8yNwPJPyV+/Vp8e7I
                                                              MD5:DFAE5A395D467CF2577E231EA67D8F67
                                                              SHA1:FD4B54E480D865A33EF9BE003652266AB49C2BB5
                                                              SHA-256:EE47380EB8EBE33B6BEFAC5290F1D65AC6560DEDFDC303EFB2EA2A6A9468333B
                                                              SHA-512:E200653DD3F0362CEB55600AB9F4FACC9C3006A469E4E106BC3AD756A28F517FEBC14C4341B183733696209B5FC970E53544F8096D87A46C4102B5A59C8BF589
                                                              Malicious:false
                                                              Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib master ' BEFEHL Der (optionale) zu erkl\303\244rende Befehl'
                                                              Category:dropped
                                                              Size (bytes):126996
                                                              Entropy (8bit):5.310048143107935
                                                              Encrypted:false
                                                              SSDEEP:3072:Nv7B1/C2LFF5kg7L17DcipVftvBTq3ChUiFAZ9FHD/XTA0w3:Nvf/CqlD1hBTqQAnFHD/TA0e
                                                              MD5:0561BFCCE12682622549355A19E9142D
                                                              SHA1:6E6709DED793B324A9A76F1742688AC28C5DA4DF
                                                              SHA-256:630D636B56A345331505CB9A93163F7C7EAA014AD621B2279D8B552BD3A39521
                                                              SHA-512:38B56170C1D96CA3CF4A4CAC799B03BEF9D8A04F702C1FE9161F728ACE7F12A9217418123C2D4EF3BC5A14E28AB2B0D24B81D3E503843547893B7BEC59C30169
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1912 messages, Project-Id-Version: GTK+ master 'Ein anzuzeigender GdkPixbuf'
                                                              Category:dropped
                                                              Size (bytes):181624
                                                              Entropy (8bit):5.194449993225638
                                                              Encrypted:false
                                                              SSDEEP:3072:IeyLeOBOs4sLyy4XZGjUYPfb1xA4LZ8EYbanl:j00sDWzJGjUYPfBxAVEYA
                                                              MD5:A44B4EF9237E50BA38C73BCE4FBE29DB
                                                              SHA1:D03CC52ACF8597684D7DFDF6948CE873BEF33CF8
                                                              SHA-256:A69EB1CD8B9161AD2D9FE9237DA3637EA81AD58B63D4723898342FD0A04ABD8F
                                                              SHA-512:3376803263D4D2F9482902653D065CC1AD31B8E9119BD5201367C7CB3EEE06FA93E03F5E209764457852055D9DA91410EFB3320BFC6574BBDBF178F8608CC70D
                                                              Malicious:false
                                                              Preview:........x........;.......w......p.......q...g.......e......C...V...5.......N......Q.......9...q...0.......*......<.......?...D..._..............2.......+...4...4...`...,.......Y......N.......N...k..................8......5...,.../...b............................................................................#.......9.......F.......U.......a.......t..........................................................................................................!.......+.......7.......C...'...O.......w...........$..............D......A..."... ...d...G..............5.......)...2...&...\...G..............#..................................'...5...V........................... ......0..............=...D......................................................................../...........@.......M.......[...#...c...0.............../..................................&.......=.......E.......T.......\.......t.............................................................4.......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 869 messages, Project-Id-Version: GTK+ 2-24 '\302\273%s\302\253 konnte f\303\274r das Attribut \302\273%s\302\253 nicht in einen Wert vom Typ \302\273%s\302\253 konvertiert werden'
                                                              Category:dropped
                                                              Size (bytes):58669
                                                              Entropy (8bit):5.289399969078758
                                                              Encrypted:false
                                                              SSDEEP:768:hH3d9ro9tlZq/HjLs/4B4SQ8zC/FwG9+0VBVwbtk/8AoIyEzqqZx2bxn3/:Z3dNaq/UQtzCNwkBHid/
                                                              MD5:37A80D9D20C3B3E7272C57553AD00BFD
                                                              SHA1:748C2483590DC2503248BC9B434E9FBBA1FAE726
                                                              SHA-256:6EDBD5D88BB0A5916A7F3B8615062A0EA6AD94A3A7DD59F8B886171BF20B06AC
                                                              SHA-512:4E2EEB0CD234C26EBB96D25C0EB92CA426780DFEEDC4F2D3EC87DB8EC95E9C4C0E036FEFB51C4BDEFFCEDA99E625199B559640F91DEBD07B12A0B94B52134532
                                                              Malicious:false
                                                              Preview:........e.......D.......l6.......H..F....H.."....H.."....I..,...&I......SI......lI......yI.......I.......I.......I.......I.......I.. ....I..7....I..)....J..4...8J..=...mJ.......J.......J.......J.......J.......J..'....J..$....K..(...>K..)...gK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...5L......fL......rL......~L..9....L..6....L.......L.. ....M..0...*M..5...[M..9....M..8....M..:....N..7...?N..2...wN..4....N..1....N..?....O..1...QO..?....O.......O.......O.......O.......O.......O.......O..3....P......EP......SP......pP.......P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q..3...MQ.."....Q..>....Q.......Q.......Q.......R.......R.......R..V...%R......|R.......S.......S......!S......1S......=S......JS......WS......pS......~S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T......2T......GT..+....T.......T..!....U..)...(U......RU......lU..$....U.......U..1....U..-....U......&V..!...<V......^V.."...rV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 550 messages, Project-Id-Version: GtkSourceView master '.desktop'
                                                              Category:dropped
                                                              Size (bytes):33792
                                                              Entropy (8bit):5.102855731704914
                                                              Encrypted:false
                                                              SSDEEP:768:siKvbFfVwPMHOx2KQQCMovYtTmatdpa/+bVzeooLdziTLO:Z5S22KQ2ovYtCatrpbVzeooViTK
                                                              MD5:61AD58B2A8FCA56B1F00D77577D006D4
                                                              SHA1:FBE8E0C6317E87E120B3C95F309F743411F8A5AC
                                                              SHA-256:536CA6EE2E3E17A1E931EADB55FF6AF9F98C3C45E567F15D8F2FDF19B2D2BBA5
                                                              SHA-512:27D775E20437E4CE3303EA8660CA5EA934D005C7CFF1BE28F233C29A1EE7E6EBA335495DAC73D349C4ACA136D850E7577C49A2061063A011F239E128A5200356
                                                              Malicious:false
                                                              Preview:........&.......L.......|".......-.......-.......-.......-..............................&.......*.......5.......I.......O.......S.......Z.......a.......w................................................................/......./......"/......6/......G/......V/......b/......m/......~/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0.......0......%0......30......A0......H0......\0......d0......t0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1.......1......#1......,1..{...51.......1.......1.......1.......1.......1.......1.......1.......1.......2..)....2..&...72......^2......f2......t2......|2.......2.......2.......2.......2..1....2.......2.......3.......3......%3......23......:3......J3......L3......T3......[3../..._3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4....../4......@4......E4......O4......_4......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1212 messages, Project-Id-Version: gwyddion ' ist freie Software, ver\303\266ffentlicht unter der GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):84550
                                                              Entropy (8bit):5.356655353819349
                                                              Encrypted:false
                                                              SSDEEP:1536:wFex52+rwa/6co/I96Wx6I9TK4dDu2fdn8nGUASDB9qzwYldwttddGk8DIEpzHzC:bw+4clv6I9TK4dFdnAGUASDB9MwvtjG6
                                                              MD5:BBA105A796BCF67D2B81B0904F4325F4
                                                              SHA1:950359D281FE998D5D59F01EB09006296EB12421
                                                              SHA-256:CAC4DBFB8A23706DF05B1227BA5BED1061EFF9CECA94E9F58FC66EBC8E25EC9A
                                                              SHA-512:3C0FDF9CCC4E70D47B3B07D31D9D363AFF1C63AFE2BEDA12A76FD9105D165BF3811B68C0545A39A6ECFB4EF4308E56BAB23B9D4933EBF47E18975E24ED7173BC
                                                              Malicious:false
                                                              Preview:.................%..S....K......(e..)...)e......Se..,...de.......f.......f.......f.......f..&....f..%....g......Cg......Xg......pg......{g..'....g.......g.......g..!....g.......h......*h......@h......[h......lh......zh.......h.......h..6....h..4....h..4....i..4...Qi..5....i.......i..,....i..-....j..*...Fj..3...qj..7....j..%....j.......k......"k..%...8k..$...^k..%....k.."....k..#....k..%....k..#....l.. ...:l......[l......sl.......l.......l.......l.......l.......l.......l..#....m......'m..%...Em..#...km..$....m..+....m..&....m.......n......#n..+...Bn.. ...nn.. ....n.......n.......n.......n.......n.."....o..'...2o.. ...Zo......{o..$....o.......o.......o.......o..!....p..'...3p......[p.. ...wp.......p.......p..#....p.......p.......q.......q......1q......Lq......eq.......q.. ....q.. ....q.. ....q..,....r..(...3r......\r..%...|r.......r.......r.......r.......r.......r.......s......(s......As......Vs......rs..!....s.......s.......s.......s.......s.......s.......t......*t......>t......Qt......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Accessible Description'
                                                              Category:dropped
                                                              Size (bytes):9907
                                                              Entropy (8bit):4.839428044426715
                                                              Encrypted:false
                                                              SSDEEP:96:TFoi84hrwVl7kQMxbaK2LTJrBSaPGgqBc8CySOaI5RCGuDMPKgqBcPC1SOaI5d:S5ewUQwF2LTJgqBURCySjGuDM9UwC1SG
                                                              MD5:8D357A4F22FF1CB6656B8C0B9D0739FF
                                                              SHA1:C85821F279BFF41B5938929DB0F86ED6B6638DAA
                                                              SHA-256:FB63EF5C40CF1E332DAD4E296A86B822CA2EF9785244FC818391AD55ACD0590C
                                                              SHA-512:42BB97A28AB60D9A40F648A1E1B2B1D513F0B4348B01D14CCE6BF8F02553BD4F220BC4D73604DE3695B5EE07781941923BFC3902FB6B4ECAD5A63A83A2F2A4F2
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 212 messages, Project-Id-Version: gtk+ 'A pointer to the pixel data of the pixbuf'
                                                              Category:dropped
                                                              Size (bytes):21706
                                                              Entropy (8bit):5.0821426689270846
                                                              Encrypted:false
                                                              SSDEEP:384:RzuoVbZUaFtcWx8O0MYAqvch8YkFjFEzWx8ciMYst2ch9chrB:RLVJcWx8vpgBY2zWx8Lp0aj
                                                              MD5:B94703CA58C0B70998BFA10D87EC8558
                                                              SHA1:51E670C8ED5E63CE69047E9344E840A40261FFEC
                                                              SHA-256:5C4139C7514838AD331898AD7484FB760C4DC222C580FD8CFE65B3A1E8296A69
                                                              SHA-512:1B2C07D4D63EE299FB334C9EC1F354A80E5A415A4CA9CE0F86563F722767B9B94D2C405258A80F39288D074438D700706B4C6A8C0020602A24667922EAC96034
                                                              Malicious:false
                                                              Preview:........................\...........).......&...................:.......Y...%...y...........................).......-.......!...6.......X...-...q...,.......,....................... ...-...$...N...*...s..........."...............................*...!...)...L.......v...........,.......0...............%...<.../...b...........................<...................'.......D.......b...".......'...................................%...`...C...*.......R.......(..."..."...K...&...n...........V.......!.......N...(.......w... ...............'..............."...........6...Z...P...........8.......8...........7...!...O..."...q...&.......%.......%.......B.......N...J...0...............&........... .......*...&...1...$...X.......}...........!...............".......".......$...(...q...M...;...............$.... ......? ..$...n ..*.... ..O.... ..*....!..%...9!../..._!..-....!..e....!..%...#"..x...I".......".......".......".......#.......#..N...5#..S....#..N....#..N...'$..2...v$..H....$.......$.......$..$...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1043 messages, Project-Id-Version: glib ' COMMAND The (optional) command to explain'
                                                              Category:dropped
                                                              Size (bytes):108822
                                                              Entropy (8bit):5.159169751548222
                                                              Encrypted:false
                                                              SSDEEP:1536:a4MIHc4YNy4AZ5LvtxJghMsJGp/UwxJHrh+JGpW+Y:vNPYNyzx6hMBp/HxFrhPpWP
                                                              MD5:CA9DA959377FF2838BFF334CE165D344
                                                              SHA1:8CA5AB76F333F514BFF6B1837828C1A275E3BDD5
                                                              SHA-256:CDA3FB9BF1449D68CDA26FD2EEF72858D25D889E3F9DC113D873F301B349476B
                                                              SHA-512:3181AD7E69EC2547E4B7823C29FC048A9BB3BBE10572F7BCB26468B123349BE45CFA8907E3BC929557419027ECAE56621DAB3602C444E713D42DEB345A8A69EA
                                                              Malicious:false
                                                              Preview:................. ..w...LA......(W......)W..7...XW.._....W..1....W..&..."X......IX..9...fX..Q....X..9....X..+...,Y......XY......vY..&....Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Z.......Z.......Z.......Z..:...0Z......kZ......wZ.......Z.......Z..Y....Z.._....Z..a..._[.......[.......[.......[.......\......0\......N\..)...e\..<....\..*....\.......\..!....].."...-]......P]......o]..#....]..!....]..[....]..&...1^..4...X^..a....^.."....^..5...._..J...H_..8...._..&...._..$...._.......`.......`......%`......>`......N`......X`......c`..B....`..!....`.......`.......`..K....a..1...]a..)....a.......a..U....a..8...$b......]b......sb..?....b..+....b.......b..(....c......)c.. ...Ac..!...bc.......c.......c..4....c.......c..)....c..#....d..#...@d......dd......~d..2....d..9....d..!....e..4...%e../...Ze..6....e..+....e..1....e..-....f../...Mf..#...}f.. ....f..*....f.......f..(....g..=...2g..,...pg..,....g..&....g.......g..^....h..a...mh..B....h.......i..+...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1722 messages, Project-Id-Version: gtk+ 'A GdkImage to display'
                                                              Category:dropped
                                                              Size (bytes):155232
                                                              Entropy (8bit):5.073310288287369
                                                              Encrypted:false
                                                              SSDEEP:3072:nT9sJGyw1S3RH4oYjUYPApufqFDlj6YxV:Zmw1sqoYjUYPA4+Dlj6YxV
                                                              MD5:FD1C51B71DB5655FC8317986C5FEB23B
                                                              SHA1:61552D97EB10E69C72DA8198F44CB04F3EA28F06
                                                              SHA-256:C07FDA44AE310EEFA2FA8074A0E874D5A69ED156B6A36E3F326D4AC04C756D65
                                                              SHA-512:00B1C80A4232DE86CD08C691A2D175EA701152346DC28D46030EE06CECA531C78A9BBC2AF79BCFC918E4C1685D9DCF0C2FCC5649F922DFB029FE7F64A8189EB2
                                                              Malicious:false
                                                              Preview:.................5.......k.................................e......C...K...5.......N......Q.......9...f...0.......*......<.......?...9..._...y..........2.......+...)...4...U...,.......Y.......N.......N...`..................8......5...!.../...W....................................................................................).......8.......D.......W.......c.......j.......w....................................................................................................(.......3.......?...'...L.......t...................$.....................D.......A...A... .......G..............5.......)...Q...&...{...G..............#..........................1.......M.......l...5.....................0...........(...=...W................................................................/...........N.......[.......i...#...q...0................................................................-...5...>.......t.............................................................6.......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 868 messages, Project-Id-Version: gtk+ '"%s" could not be converted to a value of type "%s" for attribute "%s"'
                                                              Category:dropped
                                                              Size (bytes):54764
                                                              Entropy (8bit):5.213343358885846
                                                              Encrypted:false
                                                              SSDEEP:768:gKJHhOgPKkJ3JwzJPEBjSQ8zCtWG9+0yo1hQtzCWCnjvgE:gKJHYEKkJ3e1EizC4LzCtgE
                                                              MD5:E3E29D0F964571BA3D375438C228E63A
                                                              SHA1:B3FD7813D87B4D11C2DBD502E5794A8B287778E7
                                                              SHA-256:828358174B83A54A0463561215BD9BFED710CE3C79999194E6851A88C8D2E8E5
                                                              SHA-512:81385CE796E14967F5413BE89C0C978F66E0C2E7658CDEE4B9FE3660956B6386F1749A45E5471D788624B66FA5ACDCD2D484EBBD94387C5CAD1048059E6D5A3D
                                                              Malicious:false
                                                              Preview:........d.......<.......\6.......H..F....H.."....H.."....H..,....I......CI......\I......iI......oI......zI.......I.......I.......I.. ....I..7....I..)....I..4...(J..=...]J.......J.......J.......J.......J.......J..'....J..$....K..(....K..)...WK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...%L......VL......bL......nL..9...yL..6....L.......L.. ....L..0....M..5...KM..9....M..8....M..:....M..7.../N..2...gN..4....N..1....N..?....O..1...AO..?...sO.......O.......O.......O.......O.......O.......O..3....P......5P......CP......`P......}P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q.."...=Q..>...`Q.......Q.......Q.......Q.......Q.......Q..V....Q......8R.......R.......R.......R.......R.......R.......S.......S......,S......:S......GS......\S......nS.......S.......S.......S.......S.......S.......S.......S.......S.......T..+....T.......T..!....T..)....T.......U......(U..$...>U......cU..1....U..-....U.......U..!....U.......V.."....V......QV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview '.desktop'
                                                              Category:dropped
                                                              Size (bytes):30947
                                                              Entropy (8bit):4.9987576750073375
                                                              Encrypted:false
                                                              SSDEEP:768:T6XjjsHGA/0TpywALjQCqofYtUmatdn1/2ms8ofqPWzat439/3:T6Tju0poIofYtratJsoofqP6atKV
                                                              MD5:1DA36B276ECDF3DCEB0F4BF5EAC24D66
                                                              SHA1:D5044689462823AFB080F64282B188168208B675
                                                              SHA-256:A855D12A1C6E3C0E2E63267951D4E27291D09CF88B8E3752CB08A6CB338A1693
                                                              SHA-512:FD500CA3DEE3A5D30F11505F16EEC09B13EAF0E259785FC5274CF957C0321C1FEE20A18C50B1CD449E74E78FAC8621C6CC894A6AC166034F69A2B376296E7544
                                                              Malicious:false
                                                              Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 4705 messages, Project-Id-Version: Gwyddion ' is free software released under GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):335788
                                                              Entropy (8bit):5.3832050386990025
                                                              Encrypted:false
                                                              SSDEEP:6144:f/aedO6bnqLXX2TDbpJ7yVT8t5qWP0NUXNPJ7kr4sSkVy:XxqGpJhXZPJOST
                                                              MD5:C9D960D6BE12C7C08F9DE8D72C97BC65
                                                              SHA1:74E33A79CB34222F36EC54B85606BDC7CE9AEE2D
                                                              SHA-256:360FC1C1006E82DC3C2E45E2BE4748518B565F7CB24862642E52EA7B17A21862
                                                              SHA-512:1118CC798DF0D880324E47A679CE0515F74E77BB6DBE28AC85BB31BA7D3BB3A010861065E35011DC500135EF6ABF7D480C25783AC194A73B602B3149E9234377
                                                              Malicious:false
                                                              Preview:........a.......$.......,&......@...)...A.......k.......x...................&.......-......(.........../...,...@... ...m...........%.......D..................%... ...9... ...Z...$...{...$...........................................&...(...%...O.......u................................................................$......."...B.......e...'.............................!...................3.......R.......h........... ...............%......(.......!...'...)...I... ...s... .......#....... ..........................7.......W.......h.......v...........................!...................... .......6...7...4...n...4.......4......5....... ...C..."...d.../...............,......-.......*...A...3...l...7.......'......%......."...&.......I.......g...+......................%......$.......%...-...!...S..."...u...#.......%.......#......$....... ...+.......L.......d...!......................0......*.......*...?...+...j............................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk.HEAD 'Descripci\303\263n accesible'
                                                              Category:dropped
                                                              Size (bytes):10733
                                                              Entropy (8bit):4.865953628025581
                                                              Encrypted:false
                                                              SSDEEP:192:S5ew7BTE5u9qBURCySPGDSWbnnsVDnDKIn:SYwFYu8BURCzP/anO
                                                              MD5:63643CB196115CA92116677936AB503B
                                                              SHA1:DC5745FF0F867B90987D7AD07BF55A1DFE810532
                                                              SHA-256:B40118A505E04E3F29802658D87956ECF182B1504EEFFA693BFD72295F6CE437
                                                              SHA-512:4BDC0DB5976CF5FB144E5E3D70EA644F5734146266CB49A7766E535EEEE823F143CBAEA80733C92176BF30757F47B13DF581E11B6017E7E4CF396E9FCE6DBF71
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf.master.es 'Un puntero a los datos del p\303\255xel del b\303\272fer de p\303\255xeles'
                                                              Category:dropped
                                                              Size (bytes):24268
                                                              Entropy (8bit):5.048306540654722
                                                              Encrypted:false
                                                              SSDEEP:384:yapC+UabIsjFtcWDx8c0MYAqvch8YyPlIaCqEo0vPonl118aaw72AqRh:yapCYIscWDx8JpgBc+aCqx04lMAO
                                                              MD5:BA94634DD9E0D57807C05383CDFED141
                                                              SHA1:D7B2CE9C451C0A9C7BF7BDB7629CDB97F8469A7E
                                                              SHA-256:600E9840267E2A4352EBAB50B1187B300F251FAB3C1555E962A839A9D7A8CA8A
                                                              SHA-512:AAC131CFF9E5792C8D079361F9C31B1DA857984D1682A0B353D346CAAF0E5E5E664FE18FE1AB741F9F19F293818E76D28D1627B2D6D9A8D8DE6D8A43A854DD73
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: GNU gettext-runtime 0.20.2 ' -E (desestimado por compatibilidad)'
                                                              Category:dropped
                                                              Size (bytes):9164
                                                              Entropy (8bit):5.148091276523689
                                                              Encrypted:false
                                                              SSDEEP:192:Ts0xxlurx9lHli/7/avO1izP3WZdZbqxRMnmygW:TDABFADWO1izvWZjwJyF
                                                              MD5:C2A0106D8BCBF804879AFE34094BF321
                                                              SHA1:EBE4E4BDBDAAC07754C6329DE6971F0261892C6A
                                                              SHA-256:B14C6780F4E66FEAF077C305BE69E4A290EAC9E54D18F203897D8BF84EA30D13
                                                              SHA-512:EF7FBE7FF6A6E2C401E0AF57A8C31467B35DF491920777F84BBE47D8784ABEFA8383D2939B0035EB9DC4E5F7A1102C1B128433C48E390FC3CEFD0AFC8C8EEFB0
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................=.......=.......;...<...>...x...I.......L.......S...N...E.......C.......7...,.......d...q.......M...k...J.......}...............2.......!.......0.......,...(...-...U...!.......................l.......>......."...J...$...m................ ....... ..].... ..3....!..+...@!......l!..$...{!..C....!..F....!.._...+"......."......C#......T#......o#.......#.......#.......#.......#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 699 messages, Project-Id-Version: GNU gettext-tools 0.20.2 ' (solo lenguajes basados en XML)'
                                                              Category:dropped
                                                              Size (bytes):123220
                                                              Entropy (8bit):4.9811759708787715
                                                              Encrypted:false
                                                              SSDEEP:1536:+u70DsyeAeMIbMICqQwPDa0xuu21pcSTOyjOF3v4RwxRhotnyQI:p70CFbcqQwP1xuuInTOy6F/4RwxR+fI
                                                              MD5:3FD4BA4330530C7417144CD55829FF85
                                                              SHA1:149DB719BBCC6E0A6E383F50CDD1828BBFC8C434
                                                              SHA-256:1F81E923489C3F8D0FF45F9C3B54746192FC58CD310657183A8B15EBEDCAD2F5
                                                              SHA-512:5340BB39FE95A2CDDD1623CEC5C43DDAE98187D8F2EA27F0ABA46F6BCFC881785199B041BC971D4EA85288C59B8894E38F7D74B56B8D3C9C882277E7FE1BFCDA
                                                              Malicious:false
                                                              Preview:.........................+......p:..;...q:..4....:..D....:......';..&...E<......l=..6....>..=....>..z....>......x?..F....@..O...I@.......@..;...\A..<....A..L....A......"B..@....C..A...JC..A....C..Q....C..Q... D..L...rD..K....D..K....E......WE..I....E......>F..L....F..:....G..L...NG..v....G..E....H..L...XH..4....H..8....H..9....I..P...MI..=....I..L....I..G...)J..L...qJ..G....J..=....K..J...DK..D....K..@....K..:....L..L...PL.......L..K...1M..G...}M..H....M..;....N..8...JN..9....N..?....N..J....N......HO..@....O..>....P..:...HP.......P..7...>Q..8...vQ..;....Q..5....Q..M...!R..B...oR..:....R..;....R..L...)S..:...vS..P....S..p....T..I...sT..F....T..?....U..H...DU..H....U..L....U..L...#V......pV..5....W..<...6W..:...sW.......W..>...:X..A...yX..=....X.......X.......Y.......Z..;....Z..O....Z......-[..K....[..I....\..;...L\..C....\..u....\..8...B]..G...{]..I....]..D....^..s...R^..B....^..J...._..2...T_......._..D....`......\`..M...ka..F....a..:....b..L...;b..N....b..4....b..H....c..G...Uc..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib.master ' COMANDO El comando (opcional) que explicar'
                                                              Category:dropped
                                                              Size (bytes):125714
                                                              Entropy (8bit):5.227110849063442
                                                              Encrypted:false
                                                              SSDEEP:1536:NZwEM85NY4c9O6JnLQwF5kg7cRU17Di/sbVVpNd6SLl/1guzyEvmqTjw3KytACvF:Nv75NjcM2LFF5kg7L17Dh5sQ0uqL
                                                              MD5:76F6A007B8DCF321459A15A2BCE0BAC1
                                                              SHA1:F63BFADB284B3620745C46062F975DD67A7F4FC2
                                                              SHA-256:D98A665B6FFCB52AD9C0B31548BBECA87B1FA9C9708D71F4919E639B918880C6
                                                              SHA-512:214D63B7F1F0EDA4CB429A63808AAB9861D41ECDBAC10D5A393A7AEEBE6420C8230D3E139C861C8BB1B4C8FD3FD61122E74C569BA09EBED13D3D0FC5C165E110
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+-properties.gtk-2-22 'Un GdkImage para mostrar'
                                                              Category:dropped
                                                              Size (bytes):169606
                                                              Entropy (8bit):5.0689044915654495
                                                              Encrypted:false
                                                              SSDEEP:3072:em1YvN/COXoyS3RH49ljUYPAJ2nVYJ5abFfraO0RR76B:n1WBCOXoysy9ljUYPNO7A
                                                              MD5:7F0C5E406FA7B02E8E2078F3F0B1EB00
                                                              SHA1:80E2DD3EFEE95FDB92265E324E5139A6AC161AB2
                                                              SHA-256:4C8868F15655C88FDEF1BAAF5DF71B2A46F8DF2E621F8E4AF91A08A55B9679AE
                                                              SHA-512:EB0F7856A00DF7D1080344B5525B2E166185EC8AD4F4771F436AB81F82655C841EA1A226C8D81A0F7F77A45070C755AAB282BDA4980DDED85D3202BFFF035BB9
                                                              Malicious:false
                                                              Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 1.1, 868 messages, 1 sysdep message, Project-Id-Version: gtk+.gtk-2-22 '"%s" no se pudo convertir a un valor de tipo "%s"para el atributo "%s"'
                                                              Category:dropped
                                                              Size (bytes):58800
                                                              Entropy (8bit):5.236057716366569
                                                              Encrypted:false
                                                              SSDEEP:768:To5DBFSkMCniPoKrb2f/oRbFmsa/4SQ8zC/FwG9+07KXXK+jCHEEEe9/3bFAy:ESrCHKrKopF3+zCNwQKHykJIfbFAy
                                                              MD5:3233D03B617FB99B7EB5426185D3FE76
                                                              SHA1:2F18EFCE576D0E063E4984CDCB81E07E98A79314
                                                              SHA-256:602D7D97A724A89A83DBBBFCB75F518DAD5200F9EB00A933A43BCB6FF824058F
                                                              SHA-512:B696F3960A8D92EC6E88536B0AF8E6D5F6763E330895487AAAB34AD38F9BC9A6F4AB4A2C3111D701793393BB0C0D281F5AED88740E2E9ECF3144FEFF19350314
                                                              Malicious:false
                                                              Preview:........d...0...P.......p6.......H.......H...H.......H..F....H.."....I.."...7I..,...ZI.......I.......I.......I.......I.......I.......I.......I.......I.. ....I..7....J..)...BJ..4...lJ..=....J.......J.......J.......J.......K.......K..'...%K..$...MK..(...rK..)....K.......K.......K.......K.......K.......K.."....L..#...#L..!...GL..0...iL.......L.......L.......L..9....L..6....L.......M.. ...=M..0...^M..5....M..9....M..8....M..:...8N..7...sN..2....N..4....N..1....O..?...EO..1....O..?....O.......O.......P.......P.......P.......P......%P..3...EP......yP.......P.......P.......P.......P.......P.......P.......Q.......Q.......Q.......Q......!Q..!.../Q../...QQ..3....Q.."....Q..>....Q.......R....../R......?R......GR......NR..V...YR.......R......FS......OS......US......eS......qS......~S.......S.......S.......S.......S.......S.......S.......S.......T.......T......"T......+T......>T......MT......fT......{T..+....T......'U..!...:U..)...\U.......U.......U..$....U.......U..1....U..-...,V......ZV..!...pV..
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 550 messages, Project-Id-Version: gtksourceview.HEAD '.desktop'
                                                              Category:dropped
                                                              Size (bytes):33988
                                                              Entropy (8bit):5.039000051452868
                                                              Encrypted:false
                                                              SSDEEP:768:siKv03j2KQQCMovYtTmatdpa/O2wbyoVis1hcGg/BJ/:ZfT2KQ2ovYtCatrfh2oT1hcGg/B5
                                                              MD5:D662DFDDCCA56A4E3399A5EFBF09725C
                                                              SHA1:57ACABD8970F59EAB27235F7FA4348602F4A4A3C
                                                              SHA-256:E2EC9A36F16EC1412073EF606AA32221A669126774CCD2B84D6F628CAB90BEC4
                                                              SHA-512:4FE633E241164A272E420F1A5C9128EE5B1CA97B981113008E8E57E040C2CAC1B7CF044B42C2B3F9FD157B9CEB4C7B685C68B92F163D442D022CC7E63D309336
                                                              Malicious:false
                                                              Preview:........&.......L.......|".......-.......-.......-.......-..............................&.......*.......5.......I.......O.......S.......Z.......a.......w................................................................/......./......"/......6/......G/......V/......b/......m/......~/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0.......0......%0......30......A0......H0......\0......d0......t0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1.......1......#1......,1..{...51.......1.......1.......1.......1.......1.......1.......1.......1.......2..)....2..&...72......^2......f2......t2......|2.......2.......2.......2.......2..1....2.......2.......3.......3......%3......23......:3......J3......L3......T3......[3../..._3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4....../4......@4......E4......O4......_4......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 842 messages, Project-Id-Version: Gwyddion '%s es software libre; puedes redistribuirlo y/o modificarlo bajo los t\303\251rminos de el GNU General Public Licence como est\303\241 publ'
                                                              Category:dropped
                                                              Size (bytes):52097
                                                              Entropy (8bit):5.245262154638303
                                                              Encrypted:false
                                                              SSDEEP:768:n6ZJC9CbXLwlou5Gt9gI8uThbcOvgdD13TrUXVcw57HxL5ZXwe+jdv7AxI7r:nCICbXt9gS5odD1fUXOw57HVge+xv7Nf
                                                              MD5:02423EAD74293F76C45139C688A101C4
                                                              SHA1:EAB4B5D1327958465B24376D97D30B951B314870
                                                              SHA-256:B55827A36015D7F7D49E100B17F4170F7D0724CF958C2EB688D6A7175ACB0C5C
                                                              SHA-512:7B928D6509F0BB4EC8996D9A8F573C3108E5FAE15F6D80E2CD04A53068BA66E43B3D6EA0BC706358326649A655464674071F13B31C7ADD25821DDE11D11A3810
                                                              Malicious:false
                                                              Preview:........J.......l...c....4......HF..,...IF......vG.......G.......G.......G.......G.......G.......G.......G.......G.......G.......G.......H..t....H.......H.......H.......H.......H.......H.......H.......I.......I......<I.."...DI......gI......tI......zI.......I..,....I.......I.......I.......I.......I.......J.......J.......J......(J......5J......MJ......VJ......rJ......yJ.......J.......J.......J.......J.......J.......J.......J.......J.......J..9....K......EK......ZK......_K......gK......lK......uK......{K.."....K..#....K.......K..a....K..!...IL......kL......zL.......L.......L.......L.......L.......L.......L.......L.......L.......L..h....L......\M......gM......wM..!....M.......M.......M.......M.......M.......M.......M.......M.......M.......M.......N.......N.......N..'...-N......UN......jN......rN......wN......}N.......N.......N.......N.......N.......N.......N.......N.......O.......O..[...!O......}O.......O.......O.......O.......O.......O.......O.......O.......O.......P.......P...... P......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk HEAD 'Description accessible'
                                                              Category:dropped
                                                              Size (bytes):10673
                                                              Entropy (8bit):4.885148337883671
                                                              Encrypted:false
                                                              SSDEEP:192:S5ewLIetaxZqBURCyShGNKCVLcaCZR7Shcl9wPu1RRKRY5Evl/Q:SYwUNxQBURCzhsVLcaCZR72eKw8lY
                                                              MD5:930C9F509B7F1CF4E97F646C55A67F67
                                                              SHA1:0B67573CC6394530A3237935D752118CA977CA61
                                                              SHA-256:D55071A2344138778923B00B794F3F78D4D384AA58C95DE001302F4E215074AA
                                                              SHA-512:F58E8DB008FFA789CA10C340D8799465C54773478341C7C6A8BDF5AB29D4EA2F80841F2A06ECCB488F290787674E8F9E97C4573EAFE766DBC326450F95A1DE8D
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf master 'Un pointeur vers les donn\303\251es de pixels du tampon de pixels'
                                                              Category:dropped
                                                              Size (bytes):25316
                                                              Entropy (8bit):5.155472250184355
                                                              Encrypted:false
                                                              SSDEEP:768:yapCSa20XlcWDx8JpgBRFHWhwWguzz8+yry:BpCSWQpgDFHWhw7ry
                                                              MD5:ED7BD86F974D416FBE1585A7D8872C87
                                                              SHA1:BAFCB36FFEE9F5D67AA4C79F03B55272017BE48C
                                                              SHA-256:70D3D27FEE678FB501BF27C9F9D507A081880C4EBC5CE9A686FC311E282C921B
                                                              SHA-512:A161EFD7C0FB95803F7DA499B83FE2D2FAE1E908E85360A440CF811A8D9256D76B4993A068573FEBA989DF1AE774B03CEC6CF12D4454FC618468F7B0A84F0961
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (ignor\303\251 pour la compatibilit\303\251)'
                                                              Category:dropped
                                                              Size (bytes):8909
                                                              Entropy (8bit):5.151174521158977
                                                              Encrypted:false
                                                              SSDEEP:192:T1Kxxlurx9lHli/7/avO1inbfQmNl/uH0ZgaG1/4fd:T1gABFADWO1inbomNM+fG5Wd
                                                              MD5:09708D4B994E6FA7A59FA19CCB78A82C
                                                              SHA1:C03322E2D9AB57AA27EB6A3580E397C9F10D3E26
                                                              SHA-256:16F90AB0EC7B2C0F05BB53F0FA2DA3BE8F136D7D94ECE68E5AFA590E14EEE526
                                                              SHA-512:93A1391A1D67623FC834B93DA1AE19388FD81A784D7BA4E70A3671E11791F38F4347F48515AEEB18EF78C8BA78B291172ED3B4DA514C3E95DC7C4F38E283E9E6
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................=.......G.......E...>...<.......K.......I.......W...W...6.......9.......A... ...T...b...c.......P.......K...l...y....... ...2...3...S...&.......9.......+.......(.......*...=.......h.......u...l...h...>................... .......$...................Z.......6...N ..2.... ....... ....... ..#.... ..9....!..G...E!.......!......;"..%...K"......q".......".......".......".......".............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: gettext-tools 0.20.2 ' (seulement les langages de la famille XML)'
                                                              Category:dropped
                                                              Size (bytes):124508
                                                              Entropy (8bit):5.100469941426852
                                                              Encrypted:false
                                                              SSDEEP:3072:8HTbBqQwP6xA4PnTOJ6bBfKkVpJkJgvc71H4phmW96Cz:8z9NwPJ6fKkHWYc71H4pr6W
                                                              MD5:DE8D4310BF6D87A881F986C52F16ECA5
                                                              SHA1:1F6C95D54DB345D3DB54F29DEE2C187BF4E5251E
                                                              SHA-256:CE14C56766E8F0C2278B4856CE64AC39B59DAB10ABEC9A5761980D0D35C39323
                                                              SHA-512:D4107A62FF116505E787944A3D4362EDCE0FE008260704529AF8721392FA99165493846405C57F9A21C9000A255CC0D9AF96FF510A713411EC76301D0A20164A
                                                              Malicious:false
                                                              Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib master ' COMMANDE La commande (facultative) \303\240 expliquer'
                                                              Category:dropped
                                                              Size (bytes):132447
                                                              Entropy (8bit):5.313444916910655
                                                              Encrypted:false
                                                              SSDEEP:3072:NvAPgrH1T2LFF5kg7L17D7bsek0oUl5vRdSamfLCQ:NvtH1TqlD7bsek0HTSapQ
                                                              MD5:7BB56EA22755D17EE656D4BE32FEA4BC
                                                              SHA1:102BEF41819531D788E472ECA304C946019794D9
                                                              SHA-256:A0895FFEB432967810274C36205E2DA4D7B31F980ACECC87F50930430740D0AD
                                                              SHA-512:49F74AD636E7840D8F3002111FF34700D723776F2ABAAB74FC909E0EA25A02065F706990CF50124814BADD1BBABB2AB47B83347C9AFA34E74741E9D3A0B29347
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+_properties HEAD 'Un GdkImage \303\240 afficher'
                                                              Category:dropped
                                                              Size (bytes):172038
                                                              Entropy (8bit):5.127969048470811
                                                              Encrypted:false
                                                              SSDEEP:3072:em1YvN/CTnUyS3RH49ljUYPKPFgZVrOgrX:n1WBCoysy9ljUYPKdfuX
                                                              MD5:5DA9D6D5D743F975B7A3F7A9CD5AA01C
                                                              SHA1:CC8AE1CB2CB96BF2337D4799289A380596E1162A
                                                              SHA-256:A02C51B49C9EC2757C816058DB32A3E04566D054C22A5864788DC006F9B03DF7
                                                              SHA-512:799FFED0209DCC6A806ADFC0EC3E24EEEB3E2FBD933D8755E2BA2D9D7616E086DE1F0200155DDCC35FF4BF6AF684E680AE2A8B647585808B02C8C7539ABA6E9A
                                                              Malicious:false
                                                              Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 867 messages, Project-Id-Version: gtk+ HEAD '\302\253\302\240%s\302\240\302\273 ne peut pas \303\252tre converti en une valeur de type \302\253\302\240%s\302\240\302\273 pour l'attribut \302\253\302\240%s\302\240\302\273'
                                                              Category:dropped
                                                              Size (bytes):59666
                                                              Entropy (8bit):5.298531752944225
                                                              Encrypted:false
                                                              SSDEEP:1536:5mX5pwmVe/fkzizC4I9KLxeKErWbUzFN2V2t:50EmeH2izCF9YeKESbUzD20
                                                              MD5:8698415DE61C5A421E701C500B798C32
                                                              SHA1:D295B4294F09BCA45185B04D8978F5A7AB65C4A7
                                                              SHA-256:69F1E659F15C1F2FC154F37FE126673E0ED56BE9E42060E2A760E2665B6D5C06
                                                              SHA-512:2915C4BFD7069F6BA781340E1FD6E9D8E269BD14F3F90FFEDAF3106A2C9273C09FDC921D65466B6601CFF1BA34A8670314F8B27E367DA90220081C10BBB31D26
                                                              Malicious:false
                                                              Preview:........c.......4.......L6......xH..F...yH.."....H.."....H..,....I......3I......LI......YI......_I......jI......qI......|I.......I.. ....I..7....I..)....I..4....J..=...MJ.......J.......J.......J.......J.......J..'....J..$....J..(....K..)...GK......qK.......K.......K.......K.......K.."....K..#....K..!....K..0....L......FL......RL......^L..9...iL..6....L.......L.. ....L..0....M..5...;M..9...qM..8....M..:....M..7....N..2...WN..4....N..1....N..?....N..1...1O..?...cO.......O.......O.......O.......O.......O.......O..3....O......%P......3P......PP......mP.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....P.."...-Q..>...PQ.......Q.......Q.......Q.......Q.......Q..V....Q......(R.......R.......R.......R.......R.......R.......R.......S.......S......*S......7S......LS......^S......tS.......S.......S.......S.......S.......S.......S.......S.......S..+...sT.......T..!....T..)....T.......T.......U..$....U......SU..1...rU..-....U.......U..!....U.......V.."....V......AV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview HEAD '.desktop'
                                                              Category:dropped
                                                              Size (bytes):34078
                                                              Entropy (8bit):5.090096811849565
                                                              Encrypted:false
                                                              SSDEEP:768:T6XjjsHBgYBK/I4xjQCqofYtUmatdn1/OVXOJiYJCUKDv:T6TjuBJ4VIofYtratJ6XOJiYJ6v
                                                              MD5:6FB94218B155E58CDACADA6306FFF57D
                                                              SHA1:D258275A8B3E89E71B93E2E9AD42D0E9366292C9
                                                              SHA-256:E546EA7312D817A4C20C0C1247B571D6C0E868E4AD6A275C9E68460452D523F0
                                                              SHA-512:6198F98254BEE7341EB0A9AC7BC4B0E7388B56FBF80993C6F86B4ADB6B48270CD04A666A1CA144352D4775D0BE2DB580FEE0BDCFA6B6A3057FA0BFD1A614F935
                                                              Malicious:false
                                                              Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 4272 messages, Project-Id-Version: French localization ' est un logiciel libre d\303\251velopp\303\251 sous la licence GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):331884
                                                              Entropy (8bit):5.389016196957693
                                                              Encrypted:false
                                                              SSDEEP:6144:3z+gji8M/ji8WfaIeiDb3tpyB1toB8WSZxmfig0Rq7HcwbSqQR:jjCni3tsPxmfGRq7HcwbM
                                                              MD5:31821A11DA4578F294A8D82FAC7935E7
                                                              SHA1:BD163DDBD0DF3FDE3E16FDA474FB4BD2EA74C94D
                                                              SHA-256:88D23108AB437F8D8997BC632CDE9D919DEBFA257CA078BED6C225015D8A92F2
                                                              SHA-512:9490A5625C185B63E9A7E9C4BED0B9AF1E3100D35DF4AA68F4568F1D154EF6C1EA7A15F5C76DE87310F64790AEE666124F848739DB29FA8BD5E785E5922F53E2
                                                              Malicious:false
                                                              Preview:....................E...........0d..)...1d......[d......hd......|d.......d.......d..,....d.. ....e.......f..%....f..D...?f.......f.......f.. ....f.. ....f..$....f..$....g......7g......?g......Ng......ag.......g..&....g..%....g.......g.......g.......h......'h......2h..$...Dh.."...ih.......h..'....h.......h.......h.......i..!....i......?i......Zi......yi.......i.......i.. ....i.......i..%....i..(...%j.. ...Nj.. ...oj.......j.......j.......j.......j.......j.......j.......k......!k..!...3k......Uk..6...qk..4....k..4....k..4....l..5...Gl......}l..,....l..-....l..*....m..3...2m..7...fm..%....m.."....m.......m.......n..+...$n......Pn..%...fn..$....n..%....n.."....n..#....n..%....o..#...Do.. ...ho.......o.......o.......o.......o.......o.......o.......p.......p......+p......6p.."...Tp..#...wp.......p..%....p..#....p.."....q..#...&q..$...Jq..+...oq..&....q.."....q.. ....q.......r..%..."r..(...Hr..!...qr.......r.......r.......r..+....r.......s......+s.. ...Fs.. ...gs.......s.......s.......s..!...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Descrizione accessibile'
                                                              Category:dropped
                                                              Size (bytes):10825
                                                              Entropy (8bit):4.824338692034769
                                                              Encrypted:false
                                                              SSDEEP:192:S5ewfslOvk0gqBURCySjGRuHQvVMd3pgZxhp9HZDlu5O:SYwUc80bBURCzjj/kHpxtf
                                                              MD5:667FFE0CBC33462AC5813A5CC5AE46AF
                                                              SHA1:5F86783C4F362753387A8B304B92B69883358E9C
                                                              SHA-256:21850C4817C6A7D24B9BE092161156F8D50B099993D34FF99DF550487E05F2B1
                                                              SHA-512:F20779A5FC550AB608B04778B74401787519C80E2DA45D61D78645B1759CC00C1E57753F44F5B9AEBB55D85CB8670F63325C3CF739378357D3C585B243579348
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf 'Un puntatore ai dati pixel del pixbuf'
                                                              Category:dropped
                                                              Size (bytes):24095
                                                              Entropy (8bit):5.046749425997171
                                                              Encrypted:false
                                                              SSDEEP:384:yapC6chYqyZjFtcWDx8c0MYAqvch8Y0kjf099h+XTu0Vww0x65ycKLm256:yapC6cOzdcWDx8JpgBpsv6nH
                                                              MD5:30977C0A3D9C5C1E01AC177FBDAAEEED
                                                              SHA1:68C90E8228B97A0B8148BA457F18503088050304
                                                              SHA-256:2B04B5F34FF7A910CED3B34C5517E8E83E4F75BC7F3D7965A8765D4768E1B55C
                                                              SHA-512:68F96049C62EB6B096D3B54672EB729FD081D66ADC12383B7AD0929033634CCE045370BD718304027E1695E7D76263780958454CEF8B314A14A9EC2CB9B80699
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 29 messages, Project-Id-Version: gettext-runtime 0.19.4.73 ' -V, --version mostra le informazioni sulla versione ed esce'
                                                              Category:dropped
                                                              Size (bytes):5672
                                                              Entropy (8bit):5.158511300750996
                                                              Encrypted:false
                                                              SSDEEP:96:qU1+tgQPMJ3Hlivn7vn8CJ6vOXt4AuvVjR6MJFngiFLngi777UYdICtAA4:qwOgQPMJ3Hli/7/avOdFGL6ibFb7XOCC
                                                              MD5:D8ED72CFD78D89846E17EC6AEA5F2CED
                                                              SHA1:BC898EAE36D71EF57DF13D8B317E93755691022D
                                                              SHA-256:8D3D87343D0581B7791E717D3F7721E11205455BCAF51869AF2F24B0682BEDAE
                                                              SHA-512:6ECB47B176705C7FADF1E7DC4A93A85B04C614C156D8F216FA54DCCE38156AF8BC03F570117638663C00F93EA7350C3D833EC4777C57E5BD043FA81FFB5EF482
                                                              Malicious:false
                                                              Preview:....................)...............B.......9.......M...........\...(...x...........e.......:...........O.......i.......H...................1.......&...3.......Z.......i..."...~...9.......I...........%.......................................................1.......=...L.......:.......P...M...........,...............u.......D...n...(.......................................1.......-...........%.......4..."...R...;...u...I.......................!.................................................................................................................................................................................................................... -V, --version output version information and exit.. -h, --help display this help and exit.. -v, --variables output the variables occurring in SHELL-FORMAT..%s: invalid option -- '%c'..%s: option requires an argument -- '%c'..Bruno Haible.Display native language translation of a textual message w
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 602 messages, Project-Id-Version: gettext-tools 0.19.4.73 ' (solo linguaggio C++)'
                                                              Category:dropped
                                                              Size (bytes):105947
                                                              Entropy (8bit):4.9293611820453345
                                                              Encrypted:false
                                                              SSDEEP:1536:GRrZIgvB5IJ60wPDazRAN1pULTOfi4LLAUzIoryejZ7sOX8v4FB:OZG60wPmRAV6TOfiKUUzSal8v4FB
                                                              MD5:CC270EC0907FB47A303A488BED25D238
                                                              SHA1:C15DFF1EEE7465ABE853FFBFA477CB6D7C9F9903
                                                              SHA-256:F60430BB4DEDE9F6B5DDFCA0E0ACBBC7997AE4F72705C8AFA86353A3FE4004C2
                                                              SHA-512:83EA8DDAB7C7B34800F13D71CE744530804C68EB949D4CD21BC553B2E70727AC4BC9608DB7D3237D3FCB9761C80181B1C0B774709CB6821820000BD71375B01D
                                                              Malicious:false
                                                              Preview:........Z...........)....%......`2..4...a2..D....2.......2..&....3...... 5..6...<6..=...s6..z....6......,7..F....7..O....7..;...M8..<....8..L....8.......9..@....9..A...;:..A...}:..Q....:..Q....;..L...c;..K....;.......;..I....<.......<..:...k=..L....=..v....=..E...j>..L....>..4....>..P...2?..=....?..L....?..G....@..L...V@..G....@..=....@..J...)A..D...tA..@....A..:....A..L...5B.......B..K....C..G...bC..H....C..;....C..8.../D..9...hD..?....D..J....D......-E..@....E..>....E..:...-F..7...hF..8....F..;....F..5....G..M...KG..B....G..:....G..;....H..L...SH..:....H..P....H..p...,I..I....I..F....I..?....J..H...nJ..H....J..L....K..L...MK.......K..5...*L..<...`L.......L..>...)M..A...hM.......M......<N.......N..;...RO..O....O.......O..K...gP..I....P..;....P..u...9Q..8....Q..G....Q..I...0R..D...zR..s....R..B...3S..J...vS..2....S.......S.......T..M....U..F....U..:...(V..L...cV..N....V..4....V..H...4W..G...}W..|....W..@...BX.......X..:....Y..9...?Y..4...yY..:....Y..F....Y..,...0Z..-...]Z..9....Z..N...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' COMANDO Il comando (opzionale) da spiegare'
                                                              Category:dropped
                                                              Size (bytes):124440
                                                              Entropy (8bit):5.2114813099255075
                                                              Encrypted:false
                                                              SSDEEP:1536:NZwEhPqhYOI5OhyO6JnLQwF5kg7cRU17DizPuOcgOZN3:NvVcYOI5Ot2LFF5kg7L17D0uOgN3
                                                              MD5:437B8E189A094820267E940FE6E6478B
                                                              SHA1:70101C8463379BA40F2A1910B3CB04D3CB178957
                                                              SHA-256:13B9BCE2EF000CD55DEE5B80409276ABBE3D85C04574DAEE44CA3BAAF16FCD9D
                                                              SHA-512:481F2D61AAC32E8F388AB129E42CD99FBF249914D1B8FBB9D81F0C7C0BEDFB1874BEAEF64C5CE4EF6E38E2C8028226BBA812E287699F28B2EEE314A0DBA5DA77
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1724 messages, Project-Id-Version: gtk+-properties 'Un GdkImage da visualizzare'
                                                              Category:dropped
                                                              Size (bytes):170013
                                                              Entropy (8bit):5.041453396288932
                                                              Encrypted:false
                                                              SSDEEP:3072:uAahoAbPvS3RHsoljUYPGHPn1XtIlXwc4+b:rahPbPvsGoljUYPGPRSlAc4+b
                                                              MD5:092C35E75E4A88E1531CAB71642A97CD
                                                              SHA1:B393E202AE61381DF6858A974846303AF5FF8896
                                                              SHA-256:2D4406C29ACF7E639FF32D7F2241F23DD1596864C89419C52075382FC636588E
                                                              SHA-512:611C5063685B0741A0B89DCD9AE85E52795B12E15C0AB21DD8C74260F67E2F1345DB63A2BD0C63354A0CC194E277DE76EB9538E1BAE9A42A18E17828361A127A
                                                              Malicious:false
                                                              Preview:.................5.......k.................................e...5...C.......5......N.......Q...d...9.......0......*...!...<...L...?......._..........)...2...F...+...y...4.......,......Y.......N...a...N.......................8...8...5...q.../........................................................2.......B.......V.......l.......y....................................................................................................).......7.......M.......X.......b.......l.......x...................'............................$...........%.......:...D...L...A....... ......G...........<...5...k...).......&......G..........:...#...@.......d.......n...........................5..........!.......1...0...G.......x...=..........................................&.......;.......P.......`.../...n...........................#.......0..................$......./.......F.......N.......].......e.......}...5.........................................-.......H.......W.......o...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 868 messages, Project-Id-Version: gtk+ 2.24.x 'Non \303\250 possibile convertire \302\253%s\302\273 in un valore di tipo \302\253%s\302\273 per l'attributo \302\253%s\302\273'
                                                              Category:dropped
                                                              Size (bytes):57923
                                                              Entropy (8bit):5.210724408876679
                                                              Encrypted:false
                                                              SSDEEP:768:gKJHhOHo1cNmqsiPEBjSQ8zCtWG9+0LzlWP9s/RDW5s6qPKPVPXFQMkgg:gKJHYHLNZsOEizC48WP9s/uq24gg
                                                              MD5:44927F0087E80505F9FD0DF2B4A9AEE9
                                                              SHA1:55434936DA9D404F5485C3B607F5B3C766C207A4
                                                              SHA-256:B976386D20D12DAB558F1BFE73387A504729EB9970200EB393F466CD97C5270D
                                                              SHA-512:DBF071609482226AEDFA90C513423D25B6CB7B22D452874797A32B96D18A9668A17CE5AE64463652B19F1816F5A56F24F50FA95D3E926D7E7B12F583310D0032
                                                              Malicious:false
                                                              Preview:........d.......<.......\6.......H..F....H.."....H.."....H..,....I......CI......\I......iI......oI......zI.......I.......I.......I.. ....I..7....I..)....I..4...(J..=...]J.......J.......J.......J.......J.......J..'....J..$....K..(....K..)...WK.......K.......K.......K.......K.......K.."....K..#....K..!....L..0...%L......VL......bL......nL..9...yL..6....L.......L.. ....L..0....M..5...KM..9....M..8....M..:....M..7.../N..2...gN..4....N..1....N..?....O..1...AO..?...sO.......O.......O.......O.......O.......O.......O..3....P......5P......CP......`P......}P.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....Q.."...=Q..>...`Q.......Q.......Q.......Q.......Q.......Q..V....Q......8R.......R.......R.......R.......R.......R.......S.......S......,S......:S......GS......\S......nS.......S.......S.......S.......S.......S.......S.......S.......S.......T..+....T.......T..!....T..)....T.......U......(U..$...>U......cU..1....U..-....U.......U..!....U.......V.."....V......QV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview '.desktop'
                                                              Category:dropped
                                                              Size (bytes):32945
                                                              Entropy (8bit):4.9863910962423015
                                                              Encrypted:false
                                                              SSDEEP:768:T6XjjsHi3hxg22+sEYkKjQCqofYtUmatdn1/6LCRzP7/oefA+/Lp+:T6Tjui3bckMIofYtratJIYXoK+
                                                              MD5:ED1D6D04D3052A5D7AD9C6812ADA6104
                                                              SHA1:32A7E07CDB7044E8CED7A5898E875B5077F122E7
                                                              SHA-256:E66E11AD65F1F562B91CBE02984A53A4865BC60BF3E183DFD7C7E5DA56223311
                                                              SHA-512:65C89F3FB8C83ACA41EC832ECC3E08F3473843850E83AE05AECD3B1165C6055884B6B3C8FA8E7218E5DC02A86DDFBC97BBF33208231B847F207123D7F8A2E16A
                                                              Malicious:false
                                                              Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 2840 messages, Project-Id-Version: it ' \303\250 un software libero rilasciato sotto GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):218655
                                                              Entropy (8bit):5.30202429230508
                                                              Encrypted:false
                                                              SSDEEP:6144:1MsEJtSkuBI4s5wbjqdHufceOhqy5jUhCeGzBtuq:w0PjqufCeGzbuq
                                                              MD5:5567F9446101C530646657ED483242F6
                                                              SHA1:90E9C4A06F69B1740BAAD77047866AD6C892F1C7
                                                              SHA-256:5D3C36B6AC57E6D0C59B0B61E667B96B2B1F6978904B97D0EF07F3B07FAEB1E9
                                                              SHA-512:DAC28FE593AC26F4C48EF4B556D0D2C75535941191FC9D539DFFFBE8D7BC7EFA6384BB96EE55ABEBA3F6248A79EA64B4BD36599394462B31B868F2A4D888EA14
                                                              Malicious:false
                                                              Preview:.................X..................)...........................,.......H...,...Y...........%.......D...........................=...&...V...%...}...................................$...............'...........V...!...q................... ...........................................,.......;.......M.......e.......}...................................................%.......#...9...$...]...+.......&.......".......%.......+....... ...J... ...k...........................#...............'....... ...7.......X...$...u...#.......(......."...................&...!...@...'...b........................... .......#...................1...&...I... ...p...................................!...................2... ...Q... ...r... .......,.......(.......!...........,.......L.......a.......s...................................................!...........5.......G.......e.......z...........................................................$.......!.......&...A...2...h...(.......%.......-.......+.......+...D...5...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 140 messages, Project-Id-Version: atk master '\343\202\242\343\202\257\343\202\273\343\202\271\345\217\257\350\203\275\343\201\252\350\252\254\346\230\216'
                                                              Category:dropped
                                                              Size (bytes):9964
                                                              Entropy (8bit):5.518032919494422
                                                              Encrypted:false
                                                              SSDEEP:192:oWtewPH61vNqFKxrsC+/GXvR2Too4/tqsJ2og:or4WXrsCCERs6Uskog
                                                              MD5:912393130B94993B26D2D9D0A9392751
                                                              SHA1:34E373ED93B53AF2FF4798C0E543756FEF908EDD
                                                              SHA-256:B0423565F5583DEA6A0804BBBA6917D1C0C0619DF371A678F7D096C0FECF092B
                                                              SHA-512:204F9178810C6DDB738E8025EFCF473DC2F4EEB6A7897063CA05ADC46CFE4C9F8D4FA7FB4CED82ED670DF53139B2E37F0FE2316ECF11FBD45DD95C95DE5CA5B2
                                                              Malicious:false
                                                              Preview:................|.......................................................&.......8.......H.......a...#............... ...............................C...+.......o...-...y...4...............?...k...:.......<.......7...#...4...[...,.......$...............B...........7...5...E.......{...'.......#.......".......(.......=.......6...]...*...................................................................................................(.......8.......F.......T.......^.......f.......q.......................................................................................................!.......4.......:.......G.......N.......Z.......a.......f.......l.......w.......................................................................................................................................................%......./.......<.......H.......M.......V.......d.......j.......t...............................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 203 messages, Project-Id-Version: gdk-pixbuf master 'BMP \347\224\273\345\203\217\343\201\256\343\203\230\343\203\203\343\203\200\343\203\274\343\201\256\343\203\207\343\203\274\343\202\277\343\201\214\344\270\215\346\255\243\343\201\247\343\201\231'
                                                              Category:dropped
                                                              Size (bytes):25288
                                                              Entropy (8bit):5.791552083597433
                                                              Encrypted:false
                                                              SSDEEP:384:po3P6gzufduW02j8cAxmXmX6BBA0PEY2ZD+BEY98U:p06YuKSEY2ZU
                                                              MD5:760D49D3F26E252356B2FAA9F71391CA
                                                              SHA1:3DDCDC88B975F5D0894F9D3D5877DCDE091DB449
                                                              SHA-256:86F709BD79369E52F11B0DD4101B6CA6C482DD5DCD3B8AD198EAE493DF5E1582
                                                              SHA-512:F07908460723CCA62B438C387DAE4448BD02685F7D31A157FFB7E53966F6FC181D737CFD2F7D4780C3832BD85BD0181D3A7AC526DDF423DF91BFB4733CC9984B
                                                              Malicious:false
                                                              Preview:................t...........................%...).......O...)...d...-.......!....... .......".......(..."...*...K...-...v...,.......,...............'...........A.......Z... ...w...$.......&......."...................%.......A...*...\...).......................&.......*.......+...<...#...h...&...............,.......#.......-...3.......a.......|...................6...................................5.......Q...!...n...".......'...................................6...`...J...*.......N.......(...%..."...N...&...q...........R...............J...#...#...n..................................."...........%...Z...?...........8.......8...........&...!...>..."...`...&.......%.......%.......B.......N...9...0...............&...................$... ...8.......Y...%...n...........-...........................................<..."...U... ...x...".......o.......7..., ......d ..$.... ....... ..$.... ..*.... ..O...'!..*...w!..%....!../....!..-....!..e...&"..%...."..r...."......%#......6#......I#......e#..J...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: GNU gettext-runtime 0.20.2 ' -E (\270\337\264\271\300\255\244\316\244\277\244\341\244\313\314\265\273\353)'
                                                              Category:dropped
                                                              Size (bytes):8529
                                                              Entropy (8bit):5.966358131691811
                                                              Encrypted:false
                                                              SSDEEP:96:TDHD9cdxxwKTurZb9lHlivn7vn8CJ6vO1At4g+SbGm0pwMfiV+5eTgR5Ukt/8:TDCxxlurx9lHli/7/avO1izXkUx
                                                              MD5:BF38A296ACA2860708F16B653ABA313A
                                                              SHA1:B23DCA3BC4AAA1399A2C3005EC9C9B41FEADBA4E
                                                              SHA-256:07E6C9677BD281B34E506DD7901B7E58AAAEA405C3887F6485CE5C6C0FF56DD3
                                                              SHA-512:962C23CF7376EDE8D3BE8C4E52869BC9E5769AB14CAF3D2D16A942CFD681FDA8DC6494431F6BE403BC6F54228203FFBEABAF1FA81BA47BEC6307BF1071D9DA9C
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................1.......;.......9...?...=...y...J.......J.......I...M...7.......5.......-.......;...3...E...o...J.......J.......x...K...........).......!.......-.......)...\...#...............................F...k...$.......................*.......................E...........>...=...S...................%.......>.......S.... ..m...n ....... ....... ....... .......!......(!......1!......B!.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: GNU gettext-tools 0.20.2 ' (XML\245\331\241\274\245\271\244\316\270\300\270\354\244\316\244\337)'
                                                              Category:dropped
                                                              Size (bytes):109793
                                                              Entropy (8bit):5.853754584632392
                                                              Encrypted:false
                                                              SSDEEP:1536:wAIeeoeIhzICqQwPDaHxA421GcSTOJjO/5Sc6uT24ADdMQ3i:8eVBqQwP6xA4PnTOJ6/Ec6Y24auQ3i
                                                              MD5:A71F1DBB3C90F31D254AB51F9980703B
                                                              SHA1:5C65EC12A7DCB95A195D97108E04E954558180D5
                                                              SHA-256:9B6A81BC68888754A901B910EE8A338FC8D6D8FBDB0C27D140B9342975A80784
                                                              SHA-512:8C61F2617CD939ED32C9BD8DCE5B701D3F5BC0AF616AA0D2CE95AC1C398F144A99268680592A907E3160DC95E15A1F612C3FB7FCDE50A59B77B8446B28AEF3C0
                                                              Malicious:false
                                                              Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 648 messages, Project-Id-Version: glib glib-2-28 ' COMMAND \345\257\276\350\261\241\343\201\256\343\202\263\343\203\236\343\203\263\343\203\211 (\344\273\273\346\204\217)'
                                                              Category:dropped
                                                              Size (bytes):82470
                                                              Entropy (8bit):5.866943687121482
                                                              Encrypted:false
                                                              SSDEEP:1536:LPfNBpGHOAAXQ4w3eGTT379GcU8H/3aUv:L5GcXLcxTT379I8faUv
                                                              MD5:222DF600434C42BA72FAE2ED5C1C628D
                                                              SHA1:E70609F76AE3E5715210A982BE29EFF91C274DFB
                                                              SHA-256:D8E6956938F1B4BC964A0183B73178D55F643D375264056EA9F16479A2CE370E
                                                              SHA-512:662F83F4F46B774A284767C5E6C84889A73E0317A7609577CBCBC090677699E6ABE4B40724B72B3AA90279FC59BFC8BC495A5F9E8F73090FC44C81161C5934DE
                                                              Malicious:false
                                                              Preview:................\...m....(......P6......Q6..1....6..&....6..Q....6..9...+7......e7.......7..&....7.......7.......7.......7.......7.......7.......7.......7.......7.......8..Y....8.._...m8..a....8..).../9..<...Y9.......9..!....9.."....9.......9.......:..#....:..!...R:..[...t:..&....:..4....:..a...,;.."....;..J....;..&....;..$...#<......H<..!...g<.......<..K....<..U....<..8...B=......{=.......=..+....=..(....=.. ....=.......>.......>..)...6>..#...`>..#....>.......>.......>..2....>..9....?..!...G?..4...i?../....?.......?..+....?..1....@..-...C@../...q@..#....@.......@.. ....@.......@..(....A..=...@A..,...~A.......A..^....A..a...'B..B....B.......B..+..._C..%....C..&....C.......C.."....C..1....D..0...HD.."...yD..)....D..!....D.. ....D..A....E......KE.......E.......F.......F.......F.......F.......F.......G......1G..;...QG..#....G..*....G.......G.......H..*...$H......OH..&...YH.......H..$....H.......H..4....H..$....I..&...:I..a...aI..F....I..4....J..2...?J..:...rJ..A....J..@....J..;...0K..W...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1714 messages, Project-Id-Version: gtk+-properties gtk-2-22 '\350\241\250\347\244\272\343\201\231\343\202\213 GdkImage \343\201\247\343\201\231'
                                                              Category:dropped
                                                              Size (bytes):180122
                                                              Entropy (8bit):5.869888259674955
                                                              Encrypted:false
                                                              SSDEEP:3072:XqR0lZnREfN9qS3RX49XjUYPTt25o7EeqmCro1vmmlso9uOuTiLNvF:XE0lZnRENUsy9XjUYP4kCro1viw
                                                              MD5:7D31107FE2363C922BBD7EFC66956485
                                                              SHA1:496092E2E1D782AB36124EEE38EF877D605D9891
                                                              SHA-256:949A73A630256FD2F665119847296F05C2CF5E8BCD773076D34490730BCB7BB8
                                                              SHA-512:E12DE79EF8E9CAA3C655D66D15E730B682444E95ADEB88BA2AB9D267843F5A047240E3EAF51F75B21CC7EC9150219BD423CEFB94FD3516C5A50F394B3A666249
                                                              Malicious:false
                                                              Preview:.................5......<k..............................&...e...=...C.......5......N.......Q...l...9.......0.......*...)...<...T...?......._..........1...2...N...+.......4.......,......Y.......N...i...N..................."...8...@...5...y.../.................................................'.......:.......J.......^.......t...................................................................................................#.......1.......?.......U.......`.......j.......t...........................'............................$...........-.......B...D...T...A....... ......G...........D...5...s...).......&......G...........B...#...H.......l.......v..........................5..........).......9...0...O...........=..................................#...............C.......X.......h.../...v...........................#......0..................,.......7.......N.......V.......e.......m...........5.........................................5.......P......._.......w...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 862 messages, Project-Id-Version: gtk+ gtk-2-24 '"%s" \343\202\222 "%s" (\345\261\236\346\200\247\343\201\257 "%s") \343\201\250\343\201\204\343\201\206\347\250\256\351\241\236\343\201\256\345\200\244\343\201\253\345\244\211\346\217\233\343\201\247\343\201\215\343\201\276\343\201\233\343\202\223\343\201\247\343\201\227\343\201\237'
                                                              Category:dropped
                                                              Size (bytes):61803
                                                              Entropy (8bit):5.887837117731422
                                                              Encrypted:false
                                                              SSDEEP:768:A4j11v5tjTngKfWJ4vyaY55oEKKKBjSQ8zCLlG9+0HWzXxIJIgdAT0Ed:ApKfWJ4vyaY5SNizCZeWrxmAIEd
                                                              MD5:A088DA5F8386E1D741284432A93795C7
                                                              SHA1:4CBC9AD610A29E6DBB9E67AE178642D7324ADE27
                                                              SHA-256:79E4962387F1735A7FCBA9380B26407DA6F1A00C475F130D44AE9C454A100DE9
                                                              SHA-512:823D1914AAF7EE9936662C3BC90ED0E4D8B2BEDAA30EBBF09B0979CE8F1474EAA4C43C27E35BD1B969753A9CE78B41C7BC5859590347FBCBC4646A6D16F8AFB1
                                                              Malicious:false
                                                              Preview:........^................5.......G..F....G.."...@H.."...cH..,....H.......H.......H.......H.......H.......H.......H.......H.......I.. ....I..7...6I..)...nI..4....I..=....I.......J.......J.......J.......J......BJ..'...QJ..$...yJ..(....J..)....J.......J.......K.......K.......K.......K.."...,K..#...OK..!...sK..0....K.......K.......K.......K..9....K..6...#L......ZL.. ...iL..0....L..5....L..9....L..8...+M..:...dM..7....M..2....M..4....N..1...?N..?...qN..1....N..?....N......#O....../O......4O......=O......DO......QO..3...qO.......O.......O.......O.......O.......P.......P......&P......,P......3P......<P......DP......MP..!...[P../...}P.."....P..>....P.......Q......'Q......7Q......?Q......FQ..V...QQ.......Q......>R......GR......MR......]R......iR......vR.......R.......R.......R.......R.......R.......R.......R.......S.......S.......S......#S......6S......ES......^S......sS..+....S.......T..!...2T..)...TT......~T.......T..$....T.......T..1....T..-...$U......RU..!...hU.......U.."....U.......U......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 439 messages, Project-Id-Version: gtksourceview trunk '.desktop'
                                                              Category:dropped
                                                              Size (bytes):27375
                                                              Entropy (8bit):5.688906548954756
                                                              Encrypted:false
                                                              SSDEEP:384:s662m34TILtXi44V80/WVLDhH56wMgzhLnod93eIlj+K/OJ0ZsMdRBqVzYNgEIxZ:f2i4EWLYHMboXOIBf/fndRB2mrXzgn
                                                              MD5:568AA478F69A09BA9DB0F0DACC9002C1
                                                              SHA1:8594AF2EC3379537995050027D30645AD1DFA5CF
                                                              SHA-256:D35C2087BBBAF768B87CD5C3E930104973DADA9859825C5E56385E4BE7737177
                                                              SHA-512:BCF106304B7B89B1D9FA8F25D125DD0D4463C1340139208641A41CFB45534B06007DE8F38DF5A760D14A4B1A61BC042F6FD0DCFB0CE5650AC86FCB6BEA07579C
                                                              Malicious:false
                                                              Preview:....................K............$.......$.......$.......$.......$.......$.......$.......$.......$.......%.......%......&%......:%......U%......Z%......o%......~%.......%.......%.......%.......%.......%.......%.......%.......%.......&.......&......!&....../&......G&......V&......[&......d&......h&......p&......~&.......&.......&.......&.......&.......&.......&.......&.......&.......'.......'.......'.......'......#'......5'......E'......K'......O'......X'..{...a'.......'.......'.......'.......'.......(.......(......$(......+(......6(..)...<(..&...f(.......(.......(.......(.......(.......(.......(.......(.......(.......(.......).......).......)......,).......)......6)......=)../...A)......q)......{).......).......).......).......).......).......).......).......).......).......).......).......).......).......*.......*...... *......0*......8*......N*......l*......v*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 3839 messages, Project-Id-Version: Gwyddion ' is free software released under GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):311897
                                                              Entropy (8bit):6.054308057117594
                                                              Encrypted:false
                                                              SSDEEP:6144:7OkbERgbXb/7Wye5p0NJW5X1CDBMmzN7qOtItXJ:7dIc/7mBgDSmzN7qOtItZ
                                                              MD5:7FCA9D93CD7CC17D02F249A7CA445F4F
                                                              SHA1:A022252D9CAB50C961F1D573DD3D721D9D2FCA92
                                                              SHA-256:A84270E7A3C28C3667CD4E5A3994BC247B45B2CC0CC3C2DE8D1758036236BEDD
                                                              SHA-512:C5B5254D305FCCB47797B5A1E10883E1EF50A095098C59F956B4797B4ED49303A318EC111BA895D7368F41EF8E2A409763267C1D262B7FF25621892D354D7ED7
                                                              Malicious:false
                                                              Preview:.................x...............@..)....@......3@......@@......T@......p@..,....@.......A..%....A..D....A......2B......EB.. ...YB.. ...zB..$....B..$....B.......B.......B.......C...... C..&...9C..%...`C.......C.......C.......C.......C..$....C.."....C.......D..'...4D......\D......wD.......D..!....D.......D.......D.......E.......E......8E.. ...OE......pE..%....E..(....E.. ....E.. ....E.......F......;F......[F......lF......zF.......F.......F.......F..6....F..4....F..4...+G..4...`G..5....G.......G..,....G..-...'H..*...UH..3....H..7....H..%....H.."....I......5I......SI..+...rI.......I..%....I..$....I..%....I.."...%J..#...HJ..%...lJ..#....J.. ....J.......J.......J.......K.......K......*K......>K......PK......aK..#....K.......K..%....K..#....K.."....L..$....L..+...SL..&....L.."....L.......L..%....L..(....M......4M..+...SM.. ....M.. ....M.......M.......M.......M..!....N......<N..#...DN......hN.."....N..'....N.. ....N.......N..$....O..#...4O......XO..(...vO.."....O..$....O..+....O.......P..$...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk '\354\240\221\352\267\274\354\204\261 \354\204\244\353\252\205'
                                                              Category:dropped
                                                              Size (bytes):10235
                                                              Entropy (8bit):5.523398594530372
                                                              Encrypted:false
                                                              SSDEEP:192:S5ew9r6EvAlowxwqBURCySjGDwzZaEhpP8GM3LsU+6Yvq:SYwRJvAltBURCzj73pPqLUi
                                                              MD5:6565CD8D6F957893C3314F34FD9E60B8
                                                              SHA1:1DC9E1EDA4A4931234FBA6C71D6C2598D00F517C
                                                              SHA-256:E4EDB2A8CFD93F97899B9B51CABEAB7B7F005A1BFA044EDC0300B531D8CA6787
                                                              SHA-512:F5BB3B9CD79B6094DB53D32AF2872572CE23EE793A176418CA47A1B9017B6CB4982F75069D673CCAD09A6033AFDEB1524039E0B3CD4F77B163FD0D1ADF5D036F
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf '\355\224\275\354\205\200\353\262\204\355\215\274\354\235\230 \355\224\275\354\205\200 \353\215\260\354\235\264\355\204\260\354\227\220 \353\214\200\355\225\234 \355\217\254\354\235\270\355\204\260'
                                                              Category:dropped
                                                              Size (bytes):25118
                                                              Entropy (8bit):5.8827262911764855
                                                              Encrypted:false
                                                              SSDEEP:384:yapCWIj37nH0jFtcWDx8c0MYAqvch8Y03xiT2Iu1Owt6fU:yapCWIjrkcWDx8JpgB2xicR
                                                              MD5:CA6769DF81A20C89FCCCB8F0E4CEB8B9
                                                              SHA1:306BBA9C872FA2CA06877689E8B4FC419579EAF3
                                                              SHA-256:32181FDAB6C1E0ADA6C7023AE307BC8C329FD7260C43F39AA3FBC956C2137EB9
                                                              SHA-512:5348680EFCAFA1FAF45F779CF1B912A7995D2F40116C58AC947922BFCD1ED3B209C57E22FED6D5843AED1543FC4CBD362BC38B197CA81BE3701BE906F0DDF508
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: GNU gettext-runtime 0.20.2 ' -E (\354\225\204\353\254\264 \355\232\250\352\263\274 \354\227\206\354\235\214, \355\230\270\355\231\230\354\204\261 \354\230\265\354\205\230)'
                                                              Category:dropped
                                                              Size (bytes):9059
                                                              Entropy (8bit):5.897092934389264
                                                              Encrypted:false
                                                              SSDEEP:192:T7dxxlurx9lHli/7/avO1izEvf2XyJtCmfHierk4ygwg:TvABFADWO1izEWiJUmfHierk4ygwg
                                                              MD5:2EB43DE2274B52D789416364A850BD1F
                                                              SHA1:151F00BCA0277F73F8941C192311DC4781554721
                                                              SHA-256:79EEE949883F5FF651AC9A3B6E73D9754B863262A225817DBBE441E6FF9D3A59
                                                              SHA-512:882748793EBEC77D3898A18A993727C928D841577FDC3069848636E1EC14C17247CD6D809BAB396B3DCD776F19D55AF87D80AF390EB42CEC168B467AE5520482
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................E.......I.......G...Y...J.......S.......S...@...P.......I.......G.../...E...w...R.......W.......Z...h...R.......................9......./.......D...&.../...k...4.......'.......................o.......F...O...!...........................A ......Q ..^...a ..&.... ..9.... ......!!......0!..(...P!..H...y!..Z....!......."......."..(....".......".......#....../#......=#......U#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 687 messages, Project-Id-Version: gettext-tools 0.20.2 ' (XML \352\270\260\353\260\230 \354\226\270\354\226\264\353\247\214 \354\247\200\354\233\220)'
                                                              Category:dropped
                                                              Size (bytes):122891
                                                              Entropy (8bit):5.832110677535913
                                                              Encrypted:false
                                                              SSDEEP:1536:wAIAiydRhzICqQwPDaHxA421GcSTOJjOUHXstDM+8+pYRNZIXpk0JA8962/KXnpI:8AiytBqQwP6xA4PnTOJ6UWDM7g/P
                                                              MD5:8D6DE35F8C27D2F524FE22C809EFEF0B
                                                              SHA1:1991C5F02CD6770972318B80A851D2E411049994
                                                              SHA-256:475AE09E2BFED1420D891E0A3594A98B37DE4DAFFEE5C27535AC483E2F769047
                                                              SHA-512:B427918BFF0C5F74E78A0B71C1272A0094E30ABAE0567875D603DA81C02C78A0F69D3911A5419FC5CBC871862A68A33113248DD520E0C89EAF8B6B6F4C69C412
                                                              Malicious:false
                                                              Preview:.........................+......h9..;...i9..4....9..D....9.......:..&...=;......d<..6....=..=....=..z....=......p>..F....>..O...A?.......?..;...T@..<....@..L....@.......A..@....B..A...BB..A....B..Q....B..Q....C..L...jC..K....C..K....D......OD..I....D......6E..L....E..:....F..L...FF..v....F..E....G..L...PG..4....G..8....G..9....H..P...EH..=....H..L....H..G...!I..L...iI..G....I..=....I..J...<J..D....J..@....J..:....K..L...HK.......K..K...)L..G...uL..H....L..;....M..8...BM..9...{M..?....M..J....M......@N..@....N..>....O..:...@O......{O..7...6P..8...nP..;....P..5....P..M....Q..B...gQ..:....Q..;....Q..L...!R..:...nR..P....R..p....R..I...kS..F....S..?....S..H...<T..H....T..L....T..L....U......hU..5....U..<....V..:...kV.......V..>...2W..A...qW..=....W.......W.......X.......Y..;....Y..O....Y......%Z..K....Z..I....Z..;...D[..C....[..u....[..8...:\..G...s\..I....\..D....]..s...J]..B....]..J....^..2...L^.......^..D...._......T_..M...c`..F....`..:....`..L...3a..N....a..4....a..H....b..G...Mb..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' <\353\252\205\353\240\271> \354\204\244\353\252\205\355\225\240 \353\252\205\353\240\271\354\226\264(\354\230\265\354\205\230)'
                                                              Category:dropped
                                                              Size (bytes):131376
                                                              Entropy (8bit):6.004169772817626
                                                              Encrypted:false
                                                              SSDEEP:1536:NZwE4AXZVsvw2O6JnLQwF5kg7cRU17Di7J6Wez+VGrKN60xyVPf1421tPf2E/Ykk:NvFKIr2LFF5kg7L17DYJ6n+gKN62b
                                                              MD5:C0AB2DE931B2774E058F985765EFC42D
                                                              SHA1:C43C2122C4A22191F161F6101CF03EB9343D1983
                                                              SHA-256:953575AB179038132062F2A60BA8E0340B43F512E32258C56CFA51A0939F1F22
                                                              SHA-512:A3920E1FFD8732BE0F1EE5F4FA860823991B919E4DCE2C592A2ABD0E1BDF58E73016A5FD35DA4B0A4A2EFDFCD9E3AC1558FEAF23920893290D5D745F518D50DE
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+-properties.HEAD '\355\221\234\354\213\234\355\225\240 GdkImage'
                                                              Category:dropped
                                                              Size (bytes):162384
                                                              Entropy (8bit):5.9156735973544174
                                                              Encrypted:false
                                                              SSDEEP:3072:em1YvN/CFT9zIyS3RH49ljUYP1nHtAVh7cC9:n1WBCFTBIysy9ljUYP1nKhQg
                                                              MD5:2FB3BD761F9E0EC26B7C27918FECEECA
                                                              SHA1:E093A043FBD09C859617BD1558D756D122B7590B
                                                              SHA-256:A42C05EE3AD3D2F35ECD62CEACC21D126119E1BF7F803FE6D9091A723B1E88BA
                                                              SHA-512:D8BACABE2FDDD44B7C1A2E480EB6B49AC8CB37CE99883F7E05A8B9D3E9BC108E2D0609266BD91E81C238AC4E2C47571D7251245635B73E83947FED91C721848E
                                                              Malicious:false
                                                              Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 867 messages, Project-Id-Version: gtk+ '"%1$s"\354\235\200(\353\212\224) "%3$s" \354\225\240\355\212\270\353\246\254\353\267\260\355\212\270\354\235\230 "%2$s" \355\203\200\354\236\205\354\235\230 \352\260\222\354\234\274\353\241\234 \353\263\200\355\231\230\355\225\240 \354\210\230 \354\227\206\354\212\265\353\213\210\353\213\244'
                                                              Category:dropped
                                                              Size (bytes):59727
                                                              Entropy (8bit):5.879539153893844
                                                              Encrypted:false
                                                              SSDEEP:768:5m5vRUx/B4SMcVbvkHLHBjSQ8zCtWG9+0nR7kaGNAhPjGpFODZj:5mXUvBMcV7kzizC44kaGNAhbSij
                                                              MD5:BC85A9421177EF7B8239F7D9A7C589DA
                                                              SHA1:5179F7FED24BD2DB14CBEFAD8C81DA258E43C184
                                                              SHA-256:93FC45E2385A4899E902811BB4274BBA41D420A43062786F038FD0A084824910
                                                              SHA-512:D5301DEDC5F76FC405EC5DE4C37AABAFC7928EC6DE862514CB5654392D98430E9F736966B48AAD8761187BECEB95D68A9BC12B15436DC7F4084B8711101D9DE3
                                                              Malicious:false
                                                              Preview:........c.......4.......L6......xH..F...yH.."....H.."....H..,....I......3I......LI......YI......_I......jI......qI......|I.......I.. ....I..7....I..)....I..4....J..=...MJ.......J.......J.......J.......J.......J..'....J..$....J..(....K..)...GK......qK.......K.......K.......K.......K.."....K..#....K..!....K..0....L......FL......RL......^L..9...iL..6....L.......L.. ....L..0....M..5...;M..9...qM..8....M..:....M..7....N..2...WN..4....N..1....N..?....N..1...1O..?...cO.......O.......O.......O.......O.......O.......O..3....O......%P......3P......PP......mP.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....P.."...-Q..>...PQ.......Q.......Q.......Q.......Q.......Q..V....Q......(R.......R.......R.......R.......R.......R.......R.......S.......S......*S......7S......LS......^S......tS.......S.......S.......S.......S.......S.......S.......S.......S..+...sT.......T..!....T..)....T.......T.......U..$....U......SU..1...rU..-....U.......U..!....U.......V.."....V......AV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 449 messages, Project-Id-Version: gtksourceview '.desktop'
                                                              Category:dropped
                                                              Size (bytes):25802
                                                              Entropy (8bit):5.626747785647055
                                                              Encrypted:false
                                                              SSDEEP:384:yXRUsq8b5Uxw2BBXMA3BKgzhLnod95HeBlQ+2/K/qvDINb0AIDC2XCwSo/E5d:Ib5UremKMboX5+Bi+2i/WINerSwdEL
                                                              MD5:B3ECBEF13ECEFAB04A27890F2D5894E4
                                                              SHA1:B2A9F9CAA844828E6B0ACA759A33D683528E0082
                                                              SHA-256:A6B30DF7EAE0024DE09BE09EDF969B77D49A7F92C971EFF158B493660A06044F
                                                              SHA-512:0099AE77451E95A8A50E2BE998EA7C96F1BD1DAB748E5D7F08B6878ACC672ECB1111369569B1F367F5354129AD40D8ABD31C745E1F44196DF185B81A5A4CE22D
                                                              Malicious:false
                                                              Preview:................$...W...,........%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......%.......&......%&......*&......?&......N&......^&......m&......}&.......&.......&.......&.......&.......&.......&.......&.......&.......&.......'......&'......5'......:'......C'......G'......O'......]'......k'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......(.......(......$(......*(.......(......7(..{...@(.......(.......(.......(.......(.......(.......(.......).......).......)..)....)..&...E)......l)......t).......).......).......).......).......).......).......).......).......).......).......*.......*.......*.......*../... *......P*......Z*......d*......i*......o*......z*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+.......+......-+......K+......U+......a+......p+......w+.......+.......+.......+.......+.......+.......+.......+.......+.......+.......+.......+......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 583 messages, Project-Id-Version: gwyddion '\354\235\200 GNU GPL\352\270\260\353\260\230 \353\254\264\353\243\214 \355\224\204\353\241\234\352\267\270\353\236\251\354\236\205\353\213\210\353\213\244.'
                                                              Category:dropped
                                                              Size (bytes):35057
                                                              Entropy (8bit):5.750768121478152
                                                              Encrypted:false
                                                              SSDEEP:768:JQSg1GH/tZQcZlZL7cbxqPSG8pXL5MjbYODh:JlmGHFacZ/cbYiXWJh
                                                              MD5:A0A57F1B6D87B4D85309A83F7C2167A8
                                                              SHA1:1C29E1C07FAB980BA39B1035FEADFDA265B8235C
                                                              SHA-256:4EF33D66268119C7E7CCFF5F26F964C8092DEE4234707079CE28424F496E2500
                                                              SHA-512:46A8F697E78F01184E20DC28E5065D18DBFAC85CACC8F61F204C36074B1911C9938774B55C3EDD1B2AF313831FD7FC216AF8D02A0E24BC8D5CAC0281CBBC1A76
                                                              Malicious:false
                                                              Preview:........G.......T........$.......0..)....0.......1.......1......!1......A1..&...Z1..%....1.......1.......1.......1.......1.......2.......2...... 2......22......?2......S2......d2.......2..%....2..#....2..$....2..+....3..&...;3.."...b3..%....3..+....3.. ....3.. ....3.......4......64..#...R4..#...v4.......4.......4.......4.......4.......4.......5.......5......75......L5..!...e5.......5.......5.......5.......5.......5.......5.......5..#....5.......5.......6.......6.......6......,6......=6......K6..'...\6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......7.......7.......7.......7......37......J7......R7......b7..9...w7.......7.......7.......7..+....7.......8..-....8......J8......h8..!....8..!....8.......8.......8.......8.......9.......9......)9......;9......M9......g9......y9.......9.......9.......9.......9.......9.......9.......9.......9.......9.......9.......:...... :......+:......;:......A:......P:......f:......z:.......:.......:.......:.......:......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk 'Descri\303\247\303\243o acess\303\255vel'
                                                              Category:dropped
                                                              Size (bytes):10583
                                                              Entropy (8bit):4.919373241321581
                                                              Encrypted:false
                                                              SSDEEP:192:S5ew6jg4VG3ooGltk3qBURCySjGAoAeReRyGX0OUg70PyVN:SYw33oomkaBURCzjThX6i
                                                              MD5:68E2977FB423665D3D064FD16F6E3C51
                                                              SHA1:A214793EBDCCD515CC190972AA385241CE830120
                                                              SHA-256:74DC425DA17BF9A6092842147EABE694836DDF58BC72F5AE060D8EF4512C476C
                                                              SHA-512:D35A94C38AB7CA157AB7A2BD802EEA0C2BB2A556C9C9950D7A1825519B2FF9FEC4F8D69905B6CBABA5FADD600ED6984330E58E6B834242DF24EF1C558B079438
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 214 messages, Project-Id-Version: gdk-pixbuf 'Um ponteiro para os dados de pixel do pixbuf'
                                                              Category:dropped
                                                              Size (bytes):23881
                                                              Entropy (8bit):5.119815589307243
                                                              Encrypted:false
                                                              SSDEEP:384:yapCHxjFtcWDx8c0MYAqvch8Y0fLoHu+7SemeyBkqJDo6:yapCHFcWDx8JpgBOoH6gaD/
                                                              MD5:3574A52E5E1D20D5A12D2394D2928931
                                                              SHA1:9204325BE6250C3153201E6F6C7D27A654B206EA
                                                              SHA-256:8715B7D44F80083437AEBDC0CCC0B0BA20DD7CEC6AC8E1F7EDE7711F36661437
                                                              SHA-512:EC8C6D7A90D58607DEFE8F1976E41A11576CDD716A4A642B0A3815F4F2A4B0B0412126639D252737E82852F2C67954EA6AA8AB23DEED69770F2FCAB18AE9A582
                                                              Malicious:false
                                                              Preview:....................%...|...........).......&...;.......b...................%...............................)...&...-...P...!...~...........-.......,.......,...........A.......\... ...u...$.......*..............."...................2.......N...*...i...).......................,.......0...$...*...U...........%......./...........................4...<...M...........................................".......'...2.......Z.......w...................`.......*...4...R..._...(.......".......&...........%...V...?...!.......N............... ...!.......B...'...`..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&.......................&.......$..................."...!...7.......Y..."...r...".......$.......q.......;...O ....... ..$.... ....... ..$.... ..*...#!..O...N!..*....!..%....!../....!..-...."..e...M"..%...."..x...."......R#......c#......v#.......#.......#..N....#..S....$..N...h$..N....$..2....%..H...9%......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (ignorado por quest\303\243o de compatibilidade)'
                                                              Category:dropped
                                                              Size (bytes):8983
                                                              Entropy (8bit):5.229725788115492
                                                              Encrypted:false
                                                              SSDEEP:192:TF0xxlurx9lHli/7/avO1in5eDwuaFiwGwb/G1q4sM0TF:TFeABFADWO1in5ezvsMIF
                                                              MD5:BF505D1B3EE9270C7957D0966B46E80D
                                                              SHA1:31480A14A1D15ACF98039925B7ACE7E5BAA55FCA
                                                              SHA-256:B8A6FEBCE5B924E6C1DED8AA98B4BC538823AE61565693032AED094747C60669
                                                              SHA-512:88C6AA73B8B73E89178BA56E2FDECC9D94CFBF5D2267182A281323CABCDACDB08855FD0D190F05F74D5F3251C66A752A291B6E4F7E170B1366ADD28206073276
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................G.......D...N...B.......;.......H.......J...[...P.......5.......3...-...8...a...M.......P.......M...9...H.......{...........L.../...k...!.......1.......(.......)....... ...B.......c.......p...g...e...;.......6...........@.......>........ ....... ......+ ..1.... ..+.... .......!......&!.."...C!..=...f!..J....!.......!.......".......".......".......".......".......".......#.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 699 messages, Project-Id-Version: gettext-tools 0.20.2 ' (apenas linguagens baseadas em XML)'
                                                              Category:dropped
                                                              Size (bytes):121234
                                                              Entropy (8bit):5.039990419882178
                                                              Encrypted:false
                                                              SSDEEP:3072:p70QgbcqQwP1xuuInTOy6Gm5RUAKttLnnMnJiYFcKa5rHsuBQ0KbcJEHmLQ8v:pgkNwPAq5RTH6Xv
                                                              MD5:8C4CC15F94739A8F51FE91D0C52D24E8
                                                              SHA1:9329048FAE51EA473CF2BAD39A5BDF3155C88B45
                                                              SHA-256:2235AAD8CA2D418973613527D39166F20679FECCBFC574FFDB9ECDF2182DC94A
                                                              SHA-512:762AF8603458F85B966EDDBC48B2940109A4BA12092DB29A727A532453EF9D76F2086BBB17FE04B27C4D3E69AF8E1531C6BD516011C68A4E8A5E894B41FAB371
                                                              Malicious:false
                                                              Preview:.........................+......p:..;...q:..4....:..D....:......';..&...E<......l=..6....>..=....>..z....>......x?..F....@..O...I@.......@..;...\A..<....A..L....A......"B..@....C..A...JC..A....C..Q....C..Q... D..L...rD..K....D..K....E......WE..I....E......>F..L....F..:....G..L...NG..v....G..E....H..L...XH..4....H..8....H..9....I..P...MI..=....I..L....I..G...)J..L...qJ..G....J..=....K..J...DK..D....K..@....K..:....L..L...PL.......L..K...1M..G...}M..H....M..;....N..8...JN..9....N..?....N..J....N......HO..@....O..>....P..:...HP.......P..7...>Q..8...vQ..;....Q..5....Q..M...!R..B...oR..:....R..;....R..L...)S..:...vS..P....S..p....T..I...sT..F....T..?....U..H...DU..H....U..L....U..L...#V......pV..5....W..<...6W..:...sW.......W..>...:X..A...yX..=....X.......X.......Y.......Z..;....Z..O....Z......-[..K....[..I....\..;...L\..C....\..u....\..8...B]..G...{]..I....]..D....^..s...R^..B....^..J...._..2...T_......._..D....`......\`..M...ka..F....a..:....b..L...;b..N....b..4....b..H....c..G...Uc..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1084 messages, Project-Id-Version: glib ' COMANDO O comando a ser explicado (opcional)'
                                                              Category:dropped
                                                              Size (bytes):124031
                                                              Entropy (8bit):5.290274987230353
                                                              Encrypted:false
                                                              SSDEEP:1536:NZwE1sAUgfFfO6JnLQwF5kg7cRU17DiBOQ9ADVIClXO52iifkRkfC89:Nvxc2LFF5kg7L17D7QylXO5BM
                                                              MD5:A22D63AAF558C85358C4D25F0DA3A843
                                                              SHA1:2238B6AE1AE3773E29C96C5E9266F866C803BF5E
                                                              SHA-256:12D9EE4F2BD4671A02D30A4866F13559A3ECAEC5CC7CBEDA475043E7AECDCD59
                                                              SHA-512:EC445AF3485643AB55482F00C302B22FFE0CBBF0A8E2ECF5AC40DE29C2156CF89AD1E77EC3884D831ED5ACC2A97570879E55E2048DC89B96225A63242015459B
                                                              Malicious:false
                                                              Preview:........<........!.......C......xZ......yZ..7....Z.._....Z..1...@[..&...r[.......[..9....[..Q....[..9...B\..+...|\.......\.......\..&....\.......].......].......].......]......#]......+]......4]......<]......E]......M]......V]......^]......g]......o]..:....].......].......].......].......]..Y....].._...S^..a....^......._......._......M_......k_..)...._..@...._..*...._.......`..!...,`.."...N`......q`.......`..'....`..4....`..;....a..,...Ia..&...va..%....a..E....a..R....b..(...\b..Z....b..+....b..#....c.."...0c..(...Sc..J...|c..,....c../....c..!...$d..[...Fd..&....d..6....d..'....e..-...(e..1...Ve..i....e.."....e..9....f..J...Of..<....f..$....f..*....f..1...'g..$...Yg......~g.......g.......g.......g.......g.......g.......g..B....g..!...+h......Mh......`h..5...wh..)....h.......h..O....h..U...<i..8....i.......i.......i.......i..?....j..+...Nj......zj.......j.. ....j..0....j..!....j.......k.......k..4...Ck......xk..(....k..=....k..)....k..,....l..(...>l..4...gl..&....l.......l..^....l..a...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1717 messages, Project-Id-Version: gtk+ 'Uma GdkImage a ser exibida'
                                                              Category:dropped
                                                              Size (bytes):163995
                                                              Entropy (8bit):5.128043244037343
                                                              Encrypted:false
                                                              SSDEEP:3072:em1YvN/CLwl7xByS3RH49ljUYPq+79jMRHHF:n1WBCLAnysy9ljUYPK
                                                              MD5:8C4A1B982E39F179A3978EA45D03D8B6
                                                              SHA1:378711959062C3988D1975EF86C94D24A987BD88
                                                              SHA-256:4ABE61CF09946662B78A1895EBA4568E1BEDD6A45456ADB92907289CDAF0BE43
                                                              SHA-512:FF358D7480647EED7C9CF2C6A4C9960ECF7F35F67CE3CCB8EA62A36D73ABC71292AE4DBAAFC920F0BD02B25F1B79738C694F62FB0FC01A317B782C587EA171D3
                                                              Malicious:false
                                                              Preview:.................5......lk......@.......A.......W.......n...e.......C......5.../...N...e...Q.......9.......0...@...*...q...<.......?......_...........y...2.......+......4.......,...*...Y...W...N.......N...........O.......j...8.......5......./...........'.......3.......?.......J.......^.......o............................................................................................*.......6.......H.......O.......[.......k.......y................................................................'.................. .......7...$...P.......u...........D.......A...... ...#...G...D...........5.......)......&.......G...B...........#.............................................5...;.......q...........0..............=...........5.......M.......].......k.......v.........................../..............................#.......0...5.......f.......t..................................................5..................3.......P.......f.......}......................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 867 messages, Project-Id-Version: gtk+ 'N\303\243o foi poss\303\255vel converter "%s" para um valor do tipo "%s" para o atributo "%s"'
                                                              Category:dropped
                                                              Size (bytes):57577
                                                              Entropy (8bit):5.2526229700977165
                                                              Encrypted:false
                                                              SSDEEP:768:5m5vR//TlE/+JrOOrDJvkHLHBjSQ8zCtWG9+0FqGfveRIR4xbRKAnCZv0sGxQsAd:5mXHTlNSOrDdkzizC4+XiD03t/mu
                                                              MD5:57E39BED2231FF1B0E187ACD3C68D1B2
                                                              SHA1:D76471FDB3B06D9189B93B675CAA3C38F5581AA0
                                                              SHA-256:4147DBD7BA0D698FB1C2980E3770F0E23C70B8D2FC9036B8908EE1520C827582
                                                              SHA-512:96810533A955EF08BAFBD010C5C86A4BF3B078550A1DC2E32F7A5D3DE8AE45A206616B93B5E5F00F783674E5B5E6556BB355EA236C9774E85E30C5EC54985352
                                                              Malicious:false
                                                              Preview:........c.......4.......L6......xH..F...yH.."....H.."....H..,....I......3I......LI......YI......_I......jI......qI......|I.......I.. ....I..7....I..)....I..4....J..=...MJ.......J.......J.......J.......J.......J..'....J..$....J..(....K..)...GK......qK.......K.......K.......K.......K.."....K..#....K..!....K..0....L......FL......RL......^L..9...iL..6....L.......L.. ....L..0....M..5...;M..9...qM..8....M..:....M..7....N..2...WN..4....N..1....N..?....N..1...1O..?...cO.......O.......O.......O.......O.......O.......O..3....O......%P......3P......PP......mP.......P.......P.......P.......P.......P.......P.......P.......P..!....P../....P.."...-Q..>...PQ.......Q.......Q.......Q.......Q.......Q..V....Q......(R.......R.......R.......R.......R.......R.......R.......S.......S......*S......7S......LS......^S......tS.......S.......S.......S.......S.......S.......S.......S.......S..+...sT.......T..!....T..)....T.......T.......U..$....U......SU..1...rU..-....U.......U..!....U.......V.."....V......AV......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: gtksourceview '.desktop'
                                                              Category:dropped
                                                              Size (bytes):33445
                                                              Entropy (8bit):5.0680221462784125
                                                              Encrypted:false
                                                              SSDEEP:768:T6XjjsHyf+9DjmZYocRjQCqofYtUmatdn1//tqyvp1nQ:T6Tju9oKIofYtratJPqyv8
                                                              MD5:27301ABECBE6F7BF28BD0718842CE3F0
                                                              SHA1:ECF9DACD17B86FD9D41E5883F4D5E079594310D5
                                                              SHA-256:5E27B09D6CB45FDBD0E9D503FAFD83C6EA5092A2642DC2263EF6D4EBFB7C5ED9
                                                              SHA-512:AEC2673F32699C0EAB840DF172312A248C90E650992E322B9589DFD3A1072AFB26DCA4F156E0AB8223F9A7C4006A7E2BBBAB1D9E8FAB2713DC810C1EA0A7927D
                                                              Malicious:false
                                                              Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 3301 messages, Project-Id-Version: Gwyddion 2.46 ' \303\251 software atualizado sob a licen\303\247a GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):258782
                                                              Entropy (8bit):5.399866329836044
                                                              Encrypted:false
                                                              SSDEEP:6144:kWLD8fckH7uPbHwdMCy/bVqzJ/E5Ug1c4kXTM3Mfft+:DQRH0HwKRqzJcXc4kXTM8ffI
                                                              MD5:4890BA63DA13B651031866D7D25377BC
                                                              SHA1:0EEBC0D36E29BFDFAC3B97228FCBABF3B72C4F3C
                                                              SHA-256:F952FD97569ACFF06D8DF1CAD883CD5E258B522A0DFEA8448B8DC1B9A5B199A5
                                                              SHA-512:9302DE46B45ED4E582E9F6AE4F91330AA2770629A3F273EFAE3303B4F8888DA8553E548C3B3485645917288A3AA45C606CF2B608287A817F6692E1B42161F170
                                                              Malicious:false
                                                              Preview:................Dg..9...l.......P...)...Q.......{...........................,...............%.......D...5.......z... ....... .......$.......$...................".......5.......U...&...n...%.......................................$......."...*.......M...'...i...................!............................... ...3.......T.......o...........................................%.......$.......%......."...D...#...g...%.......#....... ...........................&.......<.......I.......].......o...................%.......#.......".......$...)...+...N...&...z..."...............%...............+...%... ...Q... ...r...........................#...............'....... ...>......._...$...|...#...............(.......".........../.......K...!...e...'............... ....................... .......#...4.......X.......w...........&....... .................... ....... ......2 ......L ..!...e ....... ....... .. .... .. .... .. ....!..,...(!..(...U!..!...~!.......!.......!.......!.......!.......!......."......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 170 messages, Project-Id-Version: atk trunk '\320\236\320\261\320\273\320\265\320\263\321\207\321\221\320\275\320\275\320\276\320\265 \320\276\320\277\320\270\321\201\320\260\320\275\320\270\320\265'
                                                              Category:dropped
                                                              Size (bytes):13625
                                                              Entropy (8bit):5.216037224042169
                                                              Encrypted:false
                                                              SSDEEP:192:S5ewFqbSiyK1qBURCySFGGpdLYPJPkQVSkRp:SYwFqbSiyNBURCzFPU8kRp
                                                              MD5:77D67B2E3DBE2D46F0F0555A81F55DE0
                                                              SHA1:C340E9008DDBDC96E9C43483A2CF28BB1A311304
                                                              SHA-256:A5C5B5EEED3BCD3EF518984B22F2C71C21F502047DC88FA4D4D1E9381F2A6C2C
                                                              SHA-512:BF9CD52A5247FB3E27E265678E4B2077BF7231061C619506F31D189B8CC20F1E8E17761D0B3C52D1F5F57DEE2F30924FA73FC96B57630A1437AC4F745D894B2F
                                                              Malicious:false
                                                              Preview:................l...............H.......I.......`.......q...........................................#............... ...4.......U.......q...........C...............4...............?.......:.......<...(...7...e...4.......,.......$...........$...B...6...G...y...........5...............'.......#...9..."...]...(.......=.......6.......*...........I.......[.......f.......l.......v.......................................................................................................................................................).......4.......E.......V.......h.......v.......................................................................................................+.......1.......>.......E.......Q.......X.......].......c.......n.......s.......|...............................................................................................................................................!.......+......./.......7.......<.......C.......H.......Q.......[.......h.......t.......y...............
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 209 messages, Project-Id-Version: gtk+.master '\320\243\320\272\320\260\320\267\320\260\321\202\320\265\320\273\321\214 \320\275\320\260 \320\277\320\270\320\272\321\201\320\265\320\273\321\214\320\275\321\213\320\265 \320\264\320\260\320\275\320\275\321\213\320\265 pixbuf'
                                                              Category:dropped
                                                              Size (bytes):32397
                                                              Entropy (8bit):5.291577124714546
                                                              Encrypted:false
                                                              SSDEEP:384:uTx8EKfQLF3QfnAivchincd80gwvAqSABHmuEYJpVTuZPSdK:+cfZ/ond80gwvAqSAxmuEYJpNuZ6E
                                                              MD5:A28307EEDACECB51B88CCD888EAEFBB0
                                                              SHA1:6D1ADEFD0576D3746C984E40F3E1D45469F1530E
                                                              SHA-256:6B18378BEEB98C84502C4F627EA7619DD5A069FF0E0AE9F3CB46F0DE445ECFBD
                                                              SHA-512:9DE6F668EC6D55F1074FB77179FFBDF73BBE980B176C2CF89A13C86D75A9F015068990959693367110A78B97B58358E81BEA217E99B39DA233CC63E44ED9320C
                                                              Malicious:false
                                                              Preview:........................,...........).......&...........................!...%...A.......g...................).......-.......!........... ...-...9...,...g...,....................... .......$.......&...;.......b..."...m...........................*.......)...........:.......Y...*...s...........,.......#.......-...........L.......b.......w...6......................................."...'...'...J.......r...........................`.......*...L...N...w...(.......".......&...........9...R...S...........J.......#...........3.......M.......j..........."...............Z...........;...8...U...8...............!.......".......&...$...%...K...%...q...B.......N.......0...).......Z...&....................... .......................!..............."...G... ...j...".......o.......7...........V...$...u...........$.......*.......O.... ..*...i ..%.... ../.... ..-.... ..e....!..%...~!..r....!......."......("......;"......W"..J...s"..O...."..J....#..J...Y#..2....#..H....#...... $......%$..$...B$..,...g$......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 48 messages, Project-Id-Version: gettext-runtime 0.20.2 ' -E (\320\270\320\263\320\275\320\276\321\200\320\270\321\200\321\203\320\265\321\202\321\201\321\217 \320\264\320\273\321\217 \321\201\320\276\320\262\320\274\320\265\321\201\321\202\320\270\320\274\320\276\321\201\321\202\320\270)'
                                                              Category:dropped
                                                              Size (bytes):11509
                                                              Entropy (8bit):5.483885548289898
                                                              Encrypted:false
                                                              SSDEEP:192:T2ypxxlurx9lHli/7/avO1indiyh5BUhtQhQzW9qBCygElH0wN:TzABFADWO1indTHShtQhQzW99ElH0s
                                                              MD5:EC113491493A417C39C80174E539A3ED
                                                              SHA1:96134CE7B26072767B075353C7828FC915D6713C
                                                              SHA-256:72002E6570003A411ED50A1A9A3714048C5090A90BEAE17D52DE664B47F8886B
                                                              SHA-512:84AD4887BB9EE6D7E8FEF5FCE57B9C082B9786C96A1F2FDA57384E2A6A3363F043BF07009CDE05ECF5ABDDEE65E4FEB5D2F3C491813AB95AF9529BBB8D7D729E
                                                              Malicious:false
                                                              Preview:........0...........C...........(...8...)...B...b...A.......6.......H.......I...g...F.......9.......7...2...6...j...M.......L.......O...<...H.......{...........Q...,...m...................'.......(...........:.......Z.......g...e...A...:...................................n...........<.......1.......&...........*.......9..."...N...9...q...I...............................................................................[.......f...q...j.......J...C...v.......v...........|...W...2...W.......j.......y...M...................v...V...........9.......^.......9...!...^...[...K.......M.......;...T...$.......G...............M............ .......!.......$..)....'.......'..t....'..Q...o(..q....(..,...3)..6...`)..R....)..]....)..}...H*..(....*..&....+.. ....,......7,..4...W,.......,.......,.......,.............................................................................."...0...........................................+...........'.........../...!...,...#...............-...%........... .......(...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 699 messages, Project-Id-Version: gettext-tools 0.20.2 ' (\321\202\320\276\320\273\321\214\320\272\320\276 \320\264\320\273\321\217 \321\217\320\267\321\213\320\272\320\276\320\262 \320\275\320\260 \320\276\321\201\320\275\320\276\320\262\320\265 XML)'
                                                              Category:dropped
                                                              Size (bytes):152383
                                                              Entropy (8bit):5.365909676313479
                                                              Encrypted:false
                                                              SSDEEP:3072:p70VCbcqQwP1xuuInTOy6+y+lJmmnMn9Vuikz9iTsmiMsmbxi7jbnZbGb2Gxyr0i:pg3NwPA7lJmmnMn9Vuikz9iTsmiMsmbg
                                                              MD5:3069B4404783DBE06054BBA6C0CDACA3
                                                              SHA1:E8C9F9DB98D19A2450B4D7884824353EC682C396
                                                              SHA-256:AFD2DCB2B69A3F046A2E7215ECA03738F4EB29F5A277D6E6E731ED1F6E77BC9D
                                                              SHA-512:A45F4C8C88F51F129F0423C1745BFF2574959F6585FCAE591524AE5046085B7086D4D4D8E4BB15EF3DAA56D03AD1F5558A07F2B21C885CFD3E98EDA982220B38
                                                              Malicious:false
                                                              Preview:.........................+......p:..;...q:..4....:..D....:......';..&...E<......l=..6....>..=....>..z....>......x?..F....@..O...I@.......@..;...\A..<....A..L....A......"B..@....C..A...JC..A....C..Q....C..Q... D..L...rD..K....D..K....E......WE..I....E......>F..L....F..:....G..L...NG..v....G..E....H..L...XH..4....H..8....H..9....I..P...MI..=....I..L....I..G...)J..L...qJ..G....J..=....K..J...DK..D....K..@....K..:....L..L...PL.......L..K...1M..G...}M..H....M..;....N..8...JN..9....N..?....N..J....N......HO..@....O..>....P..:...HP.......P..7...>Q..8...vQ..;....Q..5....Q..M...!R..B...oR..:....R..;....R..L...)S..:...vS..P....S..p....T..I...sT..F....T..?....U..H...DU..H....U..L....U..L...#V......pV..5....W..<...6W..:...sW.......W..>...:X..A...yX..=....X.......X.......Y.......Z..;....Z..O....Z......-[..K....[..I....\..;...L\..C....\..u....\..8...B]..G...{]..I....]..D....^..s...R^..B....^..J...._..2...T_......._..D....`......\`..M...ka..F....a..:....b..L...;b..N....b..4....b..H....c..G...Uc..|...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1046 messages, Project-Id-Version: ru ' \320\232\320\236\320\234\320\220\320\235\320\224\320\220 \320\232\320\276\320\274\320\260\320\275\320\264\320\260 \320\264\320\273\321\217 \320\277\320\276\321\217\321\201\320\275\320\265\320\275\320\270\321\217 (\320\275\320\265\320\276\320\261\321\217\320\267\320\260\321\202\320\265\320\273\321\214\320\275\321\213\320\271)'
                                                              Category:dropped
                                                              Size (bytes):154573
                                                              Entropy (8bit):5.472591587333734
                                                              Encrypted:false
                                                              SSDEEP:3072:bnEbNMNLFsWuYtBSrFn4od69AVNu+eevGzx+/Fu+dqN3qHqW1:bngMJVBS5569UeIGzx+Nu+dqN3qH51
                                                              MD5:EA1697575BF7FF7931AEDE45871787D2
                                                              SHA1:8B39713CD6557DC6649EA1C7342E83D68648B12C
                                                              SHA-256:C6844EE5B90B1E4960294643E88AE80D743E38C9975026CAC915E7EC08F0CA57
                                                              SHA-512:4838124A0C816E7BCEB9696E6E8F7976CDD3043D25AF1E4C4C7D8E78CF2CF531B5DFF6CC52A676C632052E3AFB708F6E0122401A4F24B2C206E8C039AB34BCD7
                                                              Malicious:false
                                                              Preview:................. ..w...|A......XW......YW..7....W.._....W..1... X..&...RX......yX..9....X..Q....X..9..."Y..+...\Y.......Y.......Y..&....Y.......Y.......Y.......Y.......Y.......Z.......Z.......Z.......Z......%Z......-Z......6Z......>Z......GZ......OZ..:...`Z.......Z.......Z.......Z.......Z..Y....Z.._...3[..a....[.......[.......\......-\......K\..)...b\..@....\..*....\.......\..!....].."....]......Q]......p]..#....]..!....]..[....]..&...2^..4...Y^..a....^.."....^..5...._..J...I_..8...._..*...._..$...._.......`......$`......*`......C`......S`......]`......h`..B....`..!....`.......`.......`..5....a..)...La......va..O....a..U....a..8...1b......jb.......b..?....b..+....b.......c.......c.. ...%c..0...Fc..!...wc.......c.......c..4....c.......c..)....d..#...1d..(...Ud..=...~d..,....d..4....d..&....e......Ee..^...be..a....e..g...#f..B....f.......f../...ag..)....g..*....g.......g.."....h..&...$h..1...Kh..0...}h..$....h.."....h..8....h..>.../i..%...ni.......i.......i..4....i..;....i..#...;j..6...
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1719 messages, Project-Id-Version: ru '\320\236\321\202\320\276\320\261\321\200\320\260\320\266\320\260\320\265\320\274\320\276\320\265 \320\270\320\267\320\276\320\261\321\200\320\260\320\266\320\265\320\275\320\270\320\265 (GdkImage)'
                                                              Category:dropped
                                                              Size (bytes):217914
                                                              Entropy (8bit):5.324923633586286
                                                              Encrypted:false
                                                              SSDEEP:6144:f86XfpjUYP3QKVJPQLUHwCWv+iJP96Bq9h8/Vi64UKIhz8ADj4LBVwDLNImJth:E6XJfgJ9h894UNhz8ij4L7wfymJth
                                                              MD5:DA52FFF084804539D2C4E347EE686070
                                                              SHA1:8DA5A33F5F9868818B5086E7F7B1E882B6A5C2AF
                                                              SHA-256:51592251430540410920E7832D85AB556891F393F19D122A78D1BC48DBA49C9F
                                                              SHA-512:54F83BA9E692741979E103F29787FE5BBE70772A69C7F29722ECCDED1AACA7245FF040A87A4F4924F61C3D6C0BB20D623C5130486191F0413BE8C3E860A94B23
                                                              Malicious:false
                                                              Preview:.................5.......k......`.......a.......w...........e.......C.......5...O...N.......Q......9...&...0...`...*.......<.......?......._...9...........2.......+......).......4...?...,...t...Y.......N.......N...J...................8......5......./...A.......q.......}............................................................................"...............A.......M.......T.......a.......t...........................................................................................................)...'...6.......^.......j...........$......................D......A...+... ...m...G..............5.......)...;...&...e...G..............#..................................7.......V...5......................0..............=...A................................................................./...........8.......E.......S...#...[...0.....................................................................5...(.......^.......}....................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 1064 messages, Project-Id-Version: gtk+.master '\302\253%s\302\273 \320\275\320\265 \320\274\320\276\320\266\320\265\321\202 \320\261\321\213\321\202\321\214 \320\277\321\200\320\265\320\276\320\261\321\200\320\260\320\267\320\276\320\262\320\260\320\275\320\276 \320\272 \320\267\320\275\320\260\321\207\320\265\320\275\320\270\321\216 \321\202\320\270\320\277\320\260 \302\253%s\302\273 \320\264\320\273\321\217 \320\260\321\202\321\200\320\270\320\261\321\203\321\202\320\260 \302\253%s\302\273'
                                                              Category:dropped
                                                              Size (bytes):98356
                                                              Entropy (8bit):5.5337280228207995
                                                              Encrypted:false
                                                              SSDEEP:1536:6XmQDQrxzyk1NZVtX1juTNiEzS75uDGOnXvcx0O6:6HQ+kvFFuTdzS75uqOnXU6
                                                              MD5:A3EB9B3918614E9D23BC9880726C0804
                                                              SHA1:AF8D910D8BBB0C5D21432EEC24F6D4BEB4B500C9
                                                              SHA-256:649B0483869D47EE15C83D4BD097E6DEFDB0E9AB3DF95122487A201746BB41B1
                                                              SHA-512:FD8DD0E9213016AE4E761882FB8304436303BE7885063D0FED4311E7DC87EE6320BA9FE37035966B4F3AE4A4AFAEE73DDF8A6BB0AC28E3FE1E455695748A8F87
                                                              Malicious:false
                                                              Preview:........(.......\!.......B.......X..F....X.."... Y.."...CY..,...fY.......Y.......Y.......Y.......Y.......Y.......Y.......Y.......Y.. ....Y..7....Z..)...NZ..4...xZ..=....Z.......Z.......Z.......Z.......[......"[..'...1[..$...Y[..(...~[..)....[.......[.......[.......[.......[.......[.."....\..#.../\..!...S\..0...u\.......\.......\.......\..9....\..6....]......:].. ...I]..0...j]..5....]..9....]..8....^..:...D^..7....^..2....^..4....^..1...._..?...Q_..1...._..?...._.......`.......`.......`..%...4`......Z`......o`......x`.......`..)....`..-....`.......`..3....a......8a......Fa......ca.......a.......a.......a.......a.......a.......a.......a.......a.......a..!....a..!....b.. ...2b.."...Sb..(...vb..*....b..-....b..,....b..,...%c......Rc..'...mc../....c.."....c..>....c......'d......?d......Xd......ud.......d.. ....d.......d.......d..V....d.......e.......e.......e.......e.......e.......e..$....e.......f.......f......0f.."...>f......af......nf.......f.......f.......f.......f.......f.......f......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 539 messages, Project-Id-Version: ru '.desktop'
                                                              Category:dropped
                                                              Size (bytes):41712
                                                              Entropy (8bit):5.343842538573471
                                                              Encrypted:false
                                                              SSDEEP:768:T6XjjsHoxQe/rdtjQCqofYtUmatdn1/TqcYX3kSVlP:T6TjuoLrTIofYtratJ5qtX3kSVlP
                                                              MD5:D5AFE120BE7DDBC9BE85E62787CD967D
                                                              SHA1:8E7A27ABADFEDD8254A1D07E74165ACD51C4512C
                                                              SHA-256:89C9AA7DF27E05D4305B12696CCA6590F36287AA3DF7CECB0E45511FDDBEBFA5
                                                              SHA-512:77B21192AC473225754BEFF24AC24FFC7B95A4959D3E99996079DDBDA5B501E7E47B8846159662B7267721C6549A27974661B1B80624EE1C1E22D4264D99C1C3
                                                              Malicious:false
                                                              Preview:.........................!.......-.......-.......-.......-.......-......&-......3-......>-......B-......M-......a-......e-......l-.......-.......-.......-.......-.......-.......-.......-.......-......................-.......A.......R.......a.......m.......x................................................................................/......./......./......./......!/......)/......7/......E/......L/......`/......h/......x/......./......./......./......./......./......./......./......./......./......./.......0.......0.......0......"0......'0......00..{...90.......0.......0.......0.......0.......0.......0.......0.......1.......1..)....1..&...;1......b1......j1......x1.......1.......1.......1.......1.......1..1....1.......1.......2...... 2......)2......62......>2......N2......P2......X2......_2../...c2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3...... 3......33......D3......I3......S3......c3......k3......z3.......3......
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:GNU message catalog (little endian), revision 0.0, 4705 messages, Project-Id-Version: gwyddion ' \342\200\223 \321\201\320\262\320\276\320\261\320\276\320\264\320\275\320\276\320\265 \320\237\320\236 \320\277\320\276\320\264 \320\273\320\270\321\206\320\265\320\275\320\267\320\270\320\265\320\271 GNU GPL.'
                                                              Category:dropped
                                                              Size (bytes):466221
                                                              Entropy (8bit):5.569131496880889
                                                              Encrypted:false
                                                              SSDEEP:12288:XT2GpJh4q+t+GpzCWqZ019gjb1jeET85l+C09lt+FWJQxxh7Cuh+slh4EEmVh99z:XKGRAG1ioI
                                                              MD5:1BEFBF52541E433F7F826196595D11EA
                                                              SHA1:950B0011765595701DC5016B762921AEE1FAD49C
                                                              SHA-256:AF35056B29700F4D919FA5E6F31973F523FBC7BEB029033EEE91E94326BEFD53
                                                              SHA-512:A92616371E1530E1AB51F638FDB1F37985252F4383B9A691FB2DE50AF8CAD7A4EC96DC69BD1786E1DCF11B4700370720E8FFCA9C93DEB72E64522194E16F08AE
                                                              Malicious:false
                                                              Preview:........a.......$.......,&......@...)...A.......k.......x...................&.......-......(.........../...,...@... ...m...........%.......D..................%... ...9... ...Z...$...{...$...........................................&...(...%...O.......u................................................................$......."...B.......e...'.............................!...................3.......R.......h........... ...............%......(.......!...'...)...I... ...s... .......#....... ..........................7.......W.......h.......v...........................!...................... .......6...7...4...n...4.......4......5....... ...C..."...d.../...............,......-.......*...A...3...l...7.......'......%......."...&.......I.......g...+......................%......$.......%...-...!...S..."...u...#.......%.......#......$....... ...+.......L.......d...!......................0......*.......*...?...+...j............................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):82
                                                              Entropy (8bit):4.179232823699804
                                                              Encrypted:false
                                                              SSDEEP:3:LFhmEr0NaIVR0D5lo2oJYRAgpFab4:LK7VRElrALb4
                                                              MD5:4AE0697CE8CE144E285609DD83AD53F3
                                                              SHA1:F4886997FDB05B998F3510EE4BFC62257E15DD30
                                                              SHA-256:DCDBB5A775EB9DBF659D80B6694D381A822AF3665706C3ED7488B84D95EB8F8A
                                                              SHA-512:C9E8BA2431BD469D7AC212FD7E548CC1FD8285E216A1BF0FCBF9EA9AFF16D7E2B9B31CF0D1A2BE5233A9E0EC0B27313FA094DE5208204C3DAD4E8DD41B332ADF
                                                              Malicious:false
                                                              Preview:#.# Default keybinding set. Empty because it is implemented inline in the code..#.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):3818
                                                              Entropy (8bit):5.004948993395511
                                                              Encrypted:false
                                                              SSDEEP:48:d+cwyUjHSuyPAho/ThvyS4XE7XE5dz4vw5Y2Tr9x:F4pyf/ThvyS4XuX4kvw5/Trf
                                                              MD5:4B600A3C3C2AC37F7D0C13C4D86AC752
                                                              SHA1:D1DA549C070D74AA9F9456C4C1E0CCBDDE5256C8
                                                              SHA-256:4214BEE389645EDCC7C9971BA35DC4D96E8C135EBC92C51C05B0C7DD36ABD8E5
                                                              SHA-512:D4ECE8E39A80073BEC016B375A75BB5FF5C697AFF560E5D4AAFC6031F26451F8D3EF32FAF1A0B2BE3470450EB2EA3AE8978CC444EE0E2D2EF374EF43340E64BA
                                                              Malicious:false
                                                              Preview:# GTK - The GIMP Toolkit.# Copyright (C) 2002 Owen Taylor.#.# This library is free software; you can redistribute it and/or.# modify it under the terms of the GNU Lesser General Public.# License as published by the Free Software Foundation; either.# version 2 of the License, or (at your option) any later version..#.# This library is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU.# Lesser General Public License for more details..#.# You should have received a copy of the GNU Lesser General Public.# License along with this library; if not, write to the.# Free Software Foundation, Inc., 59 Temple Place - Suite 330,.# Boston, MA 02111-1307, USA....# Modified by the GTK+ Team and others 1997-2000. See the AUTHORS.# file for a list of people on the GTK+ Team. See the ChangeLog.# files for a list of changes. These files are distributed with.# GTK+ at ftp://f
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):1825
                                                              Entropy (8bit):5.031325379211077
                                                              Encrypted:false
                                                              SSDEEP:48:ScqeT1e9fw22war0FG+V9NHBunH4tc8s69so:ScqucwXwarCbOH4qbG
                                                              MD5:94D104680CEC5F3D8BBEC56258D0C926
                                                              SHA1:72EDE372FCB34B29754F20AD44F49BC8605CF22C
                                                              SHA-256:E9DD3015F76E05F185EBE7564D364AEF8B8168B05E62421C99875E14E4597977
                                                              SHA-512:CF7D04304FA58E2DD9A8492B31B065C03C1F7EA96AB71D7D3D212EB17436C7C181470C23296FA3F599F1EF56C6B243921ED7F0A92AD3E0A6CD40A5FE857955A9
                                                              Malicious:false
                                                              Preview:gtk-icon-sizes = "gtk-menu=13,13:gtk-small-toolbar=16,16:gtk-large-toolbar=24,24:gtk-dnd=32,32".gtk-toolbar-icon-size = small-toolbar..# disable images in buttons. i've only seen ugly delphi apps use this feature..gtk-button-images = 0..# enable/disable images in menus. most "stock" microsoft apps don't use these, except sparingly..# the office apps use them heavily, though..gtk-menu-images = 1..# use the win32 button ordering instead of the GNOME HIG one, where applicable.gtk-alternative-button-order = 1..# use the win32 sort indicators direction, as in Explorer.gtk-alternative-sort-arrows = 1..# Windows users don't expect the PC Speaker beeping at them when they backspace in an empty textview and stuff like that.gtk-error-bell = 0..style "msw-default".{. GtkWidget::interior-focus = 1. GtkOptionMenu::indicator-size = { 9, 5 }. GtkOptionMenu::indicator-spacing = { 7, 5, 2, 2 }. GtkSpinButton::shadow-type = in.. # Owen and I disagree that these should be themable. #GtkUIManager::a
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):69
                                                              Entropy (8bit):3.7974371816690633
                                                              Encrypted:false
                                                              SSDEEP:3:LFxLyVLfr7g7F3+9FVpAGCevn:LfIja5ltev
                                                              MD5:5FC9003DDC2C64B110B1161259F61923
                                                              SHA1:4ECDDBCCEDDBD90A3A654D3788EC3AEF8C197A8A
                                                              SHA-256:6D9BEAF039092AEC5C1FBC23A62402BCD0704C45C430189A6AC69AE8AA797A67
                                                              SHA-512:5C90F3F1037FFF9F10AA2030BED2C670EDD528482532E617549DB2133E26CF801BDEC56D4543FEB024CDEC1C0026909CA9A21B378EC3B89489C18C395660C9FC
                                                              Malicious:false
                                                              Preview:#.# This theme is the default theme if no other theme is selected..#.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                                                              Category:dropped
                                                              Size (bytes):46083
                                                              Entropy (8bit):6.5041152230714125
                                                              Encrypted:false
                                                              SSDEEP:768:4XWsAYF0UQj0TU9a+IWNu9B1MxlthhMLWI027zpiUGtuzoO4ppjGwZ:4msAYBdTU9fEAIS2PEtucO47j5
                                                              MD5:A9F7CD1F2A75255C18CCED66C384059B
                                                              SHA1:172784899B46D51F248CB3983A40D934BE97F55B
                                                              SHA-256:AABFE1E8892653AA6342959769810552C2FD74D84FDE070B98197664008C5993
                                                              SHA-512:70E89F90A01E8248E40E86040A68F4CB4BD46046EB66F0CE17A783C821E4037D8B010158694BE07138B4699CC3DF5692ECF4FE846E691889C0D095FAFACE9DAA
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf.sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*......@6............@.......................................@.............................................x............................................................................................................text...vf.......h.................. ..`.rdata...............l..............@..@.data...x...........................@....ndata... ...............................rsrc...x...........................@..@................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu Jan 4 13:33:30 2024, mtime=Thu Apr 25 06:08:04 2024, atime=Thu Jan 4 13:33:30 2024, length=678139, window=hide
                                                              Category:dropped
                                                              Size (bytes):1977
                                                              Entropy (8bit):3.44759729771446
                                                              Encrypted:false
                                                              SSDEEP:48:8rdWr4s+ecdx6gdxj1qdxMxwIkCmdxMxwIL:8w+edw19xwMBxw
                                                              MD5:D95FA1E97FB8E23EB6D03F6B69A25290
                                                              SHA1:EF3D6C088F48CCD9E4ED331D546F3A250F2ABA94
                                                              SHA-256:B72A9C763FCFDC4D906ED10E950B5EA90B609789B344F9DEA859D1E97F83DACB
                                                              SHA-512:36EEA53AFC44E4B58EFC3E56C13E96C161872F8873744DA218197F5610BC87B0A8E2CB6DBB196BFEFCD9B8756AE3EDFF6338B46A74132166A5A40E6CB498A71E
                                                              Malicious:false
                                                              Preview:L..................F.@.. ....Y...?...F<Q....Y...?...X...........................P.O. .:i.....+00.../C:\.....................1......X.9..PROGRA~1..t......O.I.X.9....B...............J.....-...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....Z.1......X.9..Gwyddion..B......X.9.X.9..........................@...G.w.y.d.d.i.o.n.....J.1......X.9..bin.8......X.9.X.9....G.....................<...b.i.n.....f.2..X..$X/t .gwyddion.exe..J......$X/t.X.9.....4........................g.w.y.d.d.i.o.n...e.x.e.......Y...............-.......X...................C:\Program Files\Gwyddion\bin\gwyddion.exe....G.w.y.d.d.i.o.n. .-. .S.P.M. .d.a.t.a. .a.n.a.l.y.s.i.s.6.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.w.y.d.d.i.o.n.\.b.i.n.\.g.w.y.d.d.i.o.n...e.x.e.5.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.w.y.d.d.i.o.n.\.s.h.a.r.e.\.l.o.c.a.l.e.\.e.s.\.L.C._.M.E.S.S.A.G.E.S.=.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.w.y.d.d.i.o.n.\.s.h.a.r.e.\.g.w.y.d.d.i.o.n.\.p.i.x.m.a.p.s.\.g.w.
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):114838592
                                                              Entropy (8bit):5.997136140691001
                                                              Encrypted:false
                                                              SSDEEP:1572864:Nhtl4OQ38PaIhHkh8l9XSHIh/nnTkhu0XJJ1WQhHYyMOG:5zdTkhut
                                                              MD5:F2675EB0394F42ADC85F11FA4161CC7D
                                                              SHA1:F8BBDD138E2747E08C20EE249CF2E93D50918513
                                                              SHA-256:3A312FC1798482E017BD061A0B5C0604928F6BA7C2D5986B67847CACC2ADF043
                                                              SHA-512:C1B61BF3698DD6B4F3BC6516E9BD44ED38B0332D0D9777002DFF26D259807449940C97DB341B47F4428A6372900EA155C3F141A969A1B250612596C8D4EE50AF
                                                              Malicious:false
                                                              Preview:l.......,.......l...............................$...........................S...i...............................?...........<...'...........................................................................................................................................................G...J...........n=..f.......................t.......................v...............g.......................t...............................................T.......................................................j.......................t...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):9728
                                                              Entropy (8bit):5.158136237602734
                                                              Encrypted:false
                                                              SSDEEP:96:o0svUu3Uy+sytcS8176b+XR8pCHFcMcxSgB5PKtAtgt+Nt+rnt3DVEB3YcNqkzfS:o0svWyNO81b8pCHFcM0PuAgkOyuIFc
                                                              MD5:6C3F8C94D0727894D706940A8A980543
                                                              SHA1:0D1BCAD901BE377F38D579AAFC0C41C0EF8DCEFD
                                                              SHA-256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2
                                                              SHA-512:2094F0E4BB7C806A5FF27F83A1D572A5512D979EEFDA3345BAFF27D2C89E828F68466D08C3CA250DA11B01FC0407A21743037C25E94FBE688566DD7DEAEBD355
                                                              Malicious:false
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|..c8O`08O`08O`08Oa0.O`0.@=05O`0llP0=O`0.If09O`0.od09O`0Rich8O`0........PE..L.....Oa...........!.........0......g........0............................................@..........................6..k....0.......p...............................................................................0...............................text............................... ..`.rdata..{....0......................@..@.data...h!...@......................@....rsrc........p....... ..............@..@.reloc..~............"..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                                                              Entropy (8bit):7.999962277329862
                                                              TrID:
                                                              • Win32 Executable (generic) a (10002005/4) 99.96%
                                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                                              • DOS Executable Generic (2002/1) 0.02%
                                                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                              File name:Gwyddion-2.65.win64.exe
                                                              File size:25'494'309 bytes
                                                              MD5:e8bf214322468427498ea461d2eb6877
                                                              SHA1:60b37ab0f9c02feff7675482bdf776e30e9bdc60
                                                              SHA256:7e7db531308ab8ff8574796279b086bdf3e36a62f32702b7c04ea878bb8135c4
                                                              SHA512:7f4306f9a033700bec1538875f1aed29c1d1fb4400a48f262de4269db6fad51a90f92e0cdb798059cfba31c76174aa4455671486f78e0790539313c85c37de56
                                                              SSDEEP:393216:gqESni+EuWCir0u73GYefpAU5yq/OqWmcIvir2WF3OUXT9NO15voj9:gIiL5Bwu73GqU5dOscqi13OUD9NO15vW
                                                              TLSH:3147335831F96535C7E673303DC51BB9E2AAF084912D2BFFFC8A4169A5D29B474C0E22
                                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf..sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*.....
                                                              Icon Hash:c2e8d89cccc8e6e6
                                                              Entrypoint:0x403640
                                                              Entrypoint Section:.text
                                                              Digitally signed:false
                                                              Imagebase:0x400000
                                                              Subsystem:windows gui
                                                              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                                              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                              Time Stamp:0x614F9B1F [Sat Sep 25 21:56:47 2021 UTC]
                                                              TLS Callbacks:
                                                              CLR (.Net) Version:
                                                              OS Version Major:4
                                                              OS Version Minor:0
                                                              File Version Major:4
                                                              File Version Minor:0
                                                              Subsystem Version Major:4
                                                              Subsystem Version Minor:0
                                                              Import Hash:61259b55b8912888e90f516ca08dc514
                                                              Instruction
                                                              push ebp
                                                              mov ebp, esp
                                                              sub esp, 000003F4h
                                                              push ebx
                                                              push esi
                                                              push edi
                                                              push 00000020h
                                                              pop edi
                                                              xor ebx, ebx
                                                              push 00008001h
                                                              mov dword ptr [ebp-14h], ebx
                                                              mov dword ptr [ebp-04h], 0040A230h
                                                              mov dword ptr [ebp-10h], ebx
                                                              call dword ptr [004080C8h]
                                                              mov esi, dword ptr [004080CCh]
                                                              lea eax, dword ptr [ebp-00000140h]
                                                              push eax
                                                              mov dword ptr [ebp-0000012Ch], ebx
                                                              mov dword ptr [ebp-2Ch], ebx
                                                              mov dword ptr [ebp-28h], ebx
                                                              mov dword ptr [ebp-00000140h], 0000011Ch
                                                              call esi
                                                              test eax, eax
                                                              jne 00007FFBBCC8C1EAh
                                                              lea eax, dword ptr [ebp-00000140h]
                                                              mov dword ptr [ebp-00000140h], 00000114h
                                                              push eax
                                                              call esi
                                                              mov ax, word ptr [ebp-0000012Ch]
                                                              mov ecx, dword ptr [ebp-00000112h]
                                                              sub ax, 00000053h
                                                              add ecx, FFFFFFD0h
                                                              neg ax
                                                              sbb eax, eax
                                                              mov byte ptr [ebp-26h], 00000004h
                                                              not eax
                                                              and eax, ecx
                                                              mov word ptr [ebp-2Ch], ax
                                                              cmp dword ptr [ebp-0000013Ch], 0Ah
                                                              jnc 00007FFBBCC8C1BAh
                                                              and word ptr [ebp-00000132h], 0000h
                                                              mov eax, dword ptr [ebp-00000134h]
                                                              movzx ecx, byte ptr [ebp-00000138h]
                                                              mov dword ptr [0042A318h], eax
                                                              xor eax, eax
                                                              mov ah, byte ptr [ebp-0000013Ch]
                                                              movzx eax, ax
                                                              or eax, ecx
                                                              xor ecx, ecx
                                                              mov ch, byte ptr [ebp-2Ch]
                                                              movzx ecx, cx
                                                              shl eax, 10h
                                                              or eax, ecx
                                                              Programming Language:
                                                              • [EXP] VC++ 6.0 SP5 build 8804
                                                              NameVirtual AddressVirtual Size Is in Section
                                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x85040xa0.rdata
                                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x4d0000x1578.rsrc
                                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IAT0x80000x2b0.rdata
                                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                              .text0x10000x66760x68006f5abe9eeda26ee84b3c1ed1a6c82001False0.6568134014423077data6.4174599871908855IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                              .rdata0x80000x139a0x14008c5edfd8ff9cc0135e197611be38ca18False0.4498046875data5.141066817170598IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              .data0xa0000x203780x6004b2421975c21b032f7ea000f5e7f9fbfFalse0.509765625data4.110582127654237IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .ndata0x2b0000x220000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .rsrc0x4d0000x15780x16008ad9f7797086a24df973506488db409dFalse0.3552911931818182data3.9438390822746894IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                                              RT_ICON0x4d2200x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0EnglishUnited States0.2666967509025271
                                                              RT_DIALOG0x4dac80xb4dataEnglishUnited States0.6111111111111112
                                                              RT_DIALOG0x4db800x120dataEnglishUnited States0.5138888888888888
                                                              RT_DIALOG0x4dca00x202dataEnglishUnited States0.4085603112840467
                                                              RT_DIALOG0x4dea80xf8dataEnglishUnited States0.6290322580645161
                                                              RT_DIALOG0x4dfa00xa0dataEnglishUnited States0.60625
                                                              RT_DIALOG0x4e0400xeedataEnglishUnited States0.6302521008403361
                                                              RT_GROUP_ICON0x4e1300x14dataEnglishUnited States1.15
                                                              RT_MANIFEST0x4e1480x42eXML 1.0 document, ASCII text, with very long lines (1070), with no line terminatorsEnglishUnited States0.5130841121495328
                                                              DLLImport
                                                              ADVAPI32.dllRegCreateKeyExW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetFileSecurityW, RegOpenKeyExW, RegEnumValueW
                                                              SHELL32.dllSHGetSpecialFolderLocation, SHFileOperationW, SHBrowseForFolderW, SHGetPathFromIDListW, ShellExecuteExW, SHGetFileInfoW
                                                              ole32.dllOleInitialize, OleUninitialize, CoCreateInstance, IIDFromString, CoTaskMemFree
                                                              COMCTL32.dllImageList_Create, ImageList_Destroy, ImageList_AddMasked
                                                              USER32.dllGetClientRect, EndPaint, DrawTextW, IsWindowEnabled, DispatchMessageW, wsprintfA, CharNextA, CharPrevW, MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, GetSystemMetrics, FillRect, AppendMenuW, TrackPopupMenu, OpenClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcW, GetMessagePos, CheckDlgButton, LoadCursorW, SetCursor, GetSysColor, SetWindowPos, GetWindowLongW, PeekMessageW, SetClassLongW, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, FindWindowExW, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, EmptyClipboard, CreatePopupMenu
                                                              GDI32.dllSetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectW, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject
                                                              KERNEL32.dllGetExitCodeProcess, WaitForSingleObject, GetModuleHandleA, GetProcAddress, GetSystemDirectoryW, lstrcatW, Sleep, lstrcpyA, WriteFile, GetTempFileNameW, lstrcmpiA, RemoveDirectoryW, CreateProcessW, CreateDirectoryW, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceW, WideCharToMultiByte, lstrcpynW, lstrlenW, SetErrorMode, GetVersionExW, GetCommandLineW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, CopyFileW, ExitProcess, GetCurrentProcess, GetModuleFileNameW, GetFileSize, CreateFileW, GetTickCount, MulDiv, SetFileAttributesW, GetFileAttributesW, SetCurrentDirectoryW, MoveFileW, GetFullPathNameW, GetShortPathNameW, SearchPathW, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalFree, GlobalAlloc, GetModuleHandleW, LoadLibraryExW, MoveFileExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, lstrlenA, MultiByteToWideChar, ReadFile, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW
                                                              Language of compilation systemCountry where language is spokenMap
                                                              EnglishUnited States
                                                              No network behavior found

                                                              Click to jump to process

                                                              Click to jump to process

                                                              Click to dive into process behavior distribution

                                                              Target ID:0
                                                              Start time:09:07:53
                                                              Start date:25/04/2024
                                                              Path:C:\Users\user\Desktop\Gwyddion-2.65.win64.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Users\user\Desktop\Gwyddion-2.65.win64.exe"
                                                              Imagebase:0x400000
                                                              File size:25'494'309 bytes
                                                              MD5 hash:E8BF214322468427498EA461D2EB6877
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:low
                                                              Has exited:false

                                                              Reset < >

                                                                Execution Graph

                                                                Execution Coverage:27%
                                                                Dynamic/Decrypted Code Coverage:0%
                                                                Signature Coverage:14.9%
                                                                Total number of Nodes:1606
                                                                Total number of Limit Nodes:51
                                                                execution_graph 3675 403640 SetErrorMode GetVersionExW 3676 403692 GetVersionExW 3675->3676 3677 4036ca 3675->3677 3676->3677 3678 403723 3677->3678 3679 406a35 5 API calls 3677->3679 3766 4069c5 GetSystemDirectoryW 3678->3766 3679->3678 3681 403739 lstrlenA 3681->3678 3682 403749 3681->3682 3769 406a35 GetModuleHandleA 3682->3769 3685 406a35 5 API calls 3686 403757 3685->3686 3687 406a35 5 API calls 3686->3687 3688 403763 #17 OleInitialize SHGetFileInfoW 3687->3688 3775 406668 lstrcpynW 3688->3775 3691 4037b0 GetCommandLineW 3776 406668 lstrcpynW 3691->3776 3693 4037c2 3777 405f64 3693->3777 3696 4038f7 3697 40390b GetTempPathW 3696->3697 3781 40360f 3697->3781 3699 403923 3700 403927 GetWindowsDirectoryW lstrcatW 3699->3700 3701 40397d DeleteFileW 3699->3701 3703 40360f 12 API calls 3700->3703 3791 4030d0 GetTickCount GetModuleFileNameW 3701->3791 3702 405f64 CharNextW 3705 4037f9 3702->3705 3706 403943 3703->3706 3705->3696 3705->3702 3709 4038f9 3705->3709 3706->3701 3708 403947 GetTempPathW lstrcatW SetEnvironmentVariableW SetEnvironmentVariableW 3706->3708 3707 403990 3710 403a54 3707->3710 3716 405f64 CharNextW 3707->3716 3751 403a45 3707->3751 3712 40360f 12 API calls 3708->3712 3877 406668 lstrcpynW 3709->3877 3931 403c25 3710->3931 3715 403975 3712->3715 3715->3701 3715->3710 3732 4039b2 3716->3732 3718 403b91 3721 403b99 GetCurrentProcess OpenProcessToken 3718->3721 3722 403c0f ExitProcess 3718->3722 3719 403b7c 3940 405cc8 3719->3940 3727 403bb0 LookupPrivilegeValueW AdjustTokenPrivileges 3721->3727 3728 403bdf 3721->3728 3724 403a1b 3878 40603f 3724->3878 3725 403a5c 3894 405c33 3725->3894 3727->3728 3730 406a35 5 API calls 3728->3730 3745 403be6 3730->3745 3732->3724 3732->3725 3735 403a72 lstrcatW 3736 403a7d lstrcatW lstrcmpiW 3735->3736 3736->3710 3738 403a9d 3736->3738 3737 403bfb ExitWindowsEx 3737->3722 3740 403c08 3737->3740 3742 403aa2 3738->3742 3743 403aa9 3738->3743 3944 40140b 3740->3944 3897 405b99 CreateDirectoryW 3742->3897 3902 405c16 CreateDirectoryW 3743->3902 3744 403a3a 3893 406668 lstrcpynW 3744->3893 3745->3737 3745->3740 3750 403aae SetCurrentDirectoryW 3752 403ac0 3750->3752 3753 403acb 3750->3753 3821 403d17 3751->3821 3905 406668 lstrcpynW 3752->3905 3906 406668 lstrcpynW 3753->3906 3758 403b19 CopyFileW 3763 403ad8 3758->3763 3759 403b63 3761 406428 36 API calls 3759->3761 3761->3710 3762 4066a5 17 API calls 3762->3763 3763->3759 3763->3762 3765 403b4d CloseHandle 3763->3765 3907 4066a5 3763->3907 3924 406428 MoveFileExW 3763->3924 3928 405c4b CreateProcessW 3763->3928 3765->3763 3767 4069e7 wsprintfW LoadLibraryExW 3766->3767 3767->3681 3770 406a51 3769->3770 3771 406a5b GetProcAddress 3769->3771 3772 4069c5 3 API calls 3770->3772 3773 403750 3771->3773 3774 406a57 3772->3774 3773->3685 3774->3771 3774->3773 3775->3691 3776->3693 3778 405f6a 3777->3778 3779 4037e8 CharNextW 3778->3779 3780 405f71 CharNextW 3778->3780 3779->3705 3780->3778 3947 4068ef 3781->3947 3783 40361b 3784 403625 3783->3784 3956 405f37 lstrlenW CharPrevW 3783->3956 3784->3699 3787 405c16 2 API calls 3788 403633 3787->3788 3959 406187 3788->3959 3963 406158 GetFileAttributesW CreateFileW 3791->3963 3793 403113 3820 403120 3793->3820 3964 406668 lstrcpynW 3793->3964 3795 403136 3965 405f83 lstrlenW 3795->3965 3799 403147 GetFileSize 3800 403241 3799->3800 3819 40315e 3799->3819 3970 40302e 3800->3970 3804 403286 GlobalAlloc 3806 40329d 3804->3806 3805 4032de 3809 40302e 32 API calls 3805->3809 3811 406187 2 API calls 3806->3811 3808 403267 3810 4035e2 ReadFile 3808->3810 3809->3820 3812 403272 3810->3812 3814 4032ae CreateFileW 3811->3814 3812->3804 3812->3820 3813 40302e 32 API calls 3813->3819 3815 4032e8 3814->3815 3814->3820 3984 4035f8 SetFilePointer 3815->3984 3817 4032f6 3985 403371 3817->3985 3819->3800 3819->3805 3819->3813 3819->3820 4000 4035e2 3819->4000 3820->3707 3822 406a35 5 API calls 3821->3822 3823 403d2b 3822->3823 3824 403d31 3823->3824 3825 403d43 3823->3825 4067 4065af wsprintfW 3824->4067 3826 406536 3 API calls 3825->3826 3827 403d73 3826->3827 3828 403d92 lstrcatW 3827->3828 3830 406536 3 API calls 3827->3830 3831 403d41 3828->3831 3830->3828 4047 403fed 3831->4047 3834 40603f 18 API calls 3835 403dc4 3834->3835 3836 403e58 3835->3836 4055 406536 3835->4055 3837 40603f 18 API calls 3836->3837 3839 403e5e 3837->3839 3841 403e6e LoadImageW 3839->3841 3844 4066a5 17 API calls 3839->3844 3842 403f14 3841->3842 3843 403e95 RegisterClassW 3841->3843 3846 40140b 2 API calls 3842->3846 3845 403ecb SystemParametersInfoW CreateWindowExW 3843->3845 3876 403f1e 3843->3876 3844->3841 3845->3842 3850 403f1a 3846->3850 3847 403e17 lstrlenW 3848 403e25 lstrcmpiW 3847->3848 3849 403e4b 3847->3849 3848->3849 3853 403e35 GetFileAttributesW 3848->3853 3854 405f37 3 API calls 3849->3854 3856 403fed 18 API calls 3850->3856 3850->3876 3851 405f64 CharNextW 3852 403e14 3851->3852 3852->3847 3855 403e41 3853->3855 3857 403e51 3854->3857 3855->3849 3858 405f83 2 API calls 3855->3858 3859 403f2b 3856->3859 4068 406668 lstrcpynW 3857->4068 3858->3849 3861 403f37 ShowWindow 3859->3861 3862 403fba 3859->3862 3864 4069c5 3 API calls 3861->3864 4060 40579d OleInitialize 3862->4060 3866 403f4f 3864->3866 3865 403fc0 3867 403fc4 3865->3867 3868 403fdc 3865->3868 3869 403f5d GetClassInfoW 3866->3869 3873 4069c5 3 API calls 3866->3873 3875 40140b 2 API calls 3867->3875 3867->3876 3872 40140b 2 API calls 3868->3872 3870 403f71 GetClassInfoW RegisterClassW 3869->3870 3871 403f87 DialogBoxParamW 3869->3871 3870->3871 3874 40140b 2 API calls 3871->3874 3872->3876 3873->3869 3874->3876 3875->3876 3876->3710 3877->3697 4084 406668 lstrcpynW 3878->4084 3880 406050 4085 405fe2 CharNextW CharNextW 3880->4085 3883 403a27 3883->3710 3892 406668 lstrcpynW 3883->3892 3884 4068ef 5 API calls 3887 406066 3884->3887 3885 406097 lstrlenW 3886 4060a2 3885->3886 3885->3887 3889 405f37 3 API calls 3886->3889 3887->3883 3887->3885 3891 405f83 2 API calls 3887->3891 4091 40699e FindFirstFileW 3887->4091 3890 4060a7 GetFileAttributesW 3889->3890 3890->3883 3891->3885 3892->3744 3893->3751 3895 406a35 5 API calls 3894->3895 3896 403a61 lstrcatW 3895->3896 3896->3735 3896->3736 3898 403aa7 3897->3898 3899 405bea GetLastError 3897->3899 3898->3750 3899->3898 3900 405bf9 SetFileSecurityW 3899->3900 3900->3898 3901 405c0f GetLastError 3900->3901 3901->3898 3903 405c2a GetLastError 3902->3903 3904 405c26 3902->3904 3903->3904 3904->3750 3905->3753 3906->3763 3909 4066b2 3907->3909 3908 4068d5 3910 403b0d DeleteFileW 3908->3910 4096 406668 lstrcpynW 3908->4096 3909->3908 3912 4068a3 lstrlenW 3909->3912 3914 406536 3 API calls 3909->3914 3915 4066a5 10 API calls 3909->3915 3916 4067ba GetSystemDirectoryW 3909->3916 3918 4067cd GetWindowsDirectoryW 3909->3918 3919 4066a5 10 API calls 3909->3919 3920 406844 lstrcatW 3909->3920 3921 4068ef 5 API calls 3909->3921 3922 4067fc SHGetSpecialFolderLocation 3909->3922 4094 4065af wsprintfW 3909->4094 4095 406668 lstrcpynW 3909->4095 3910->3758 3910->3763 3912->3909 3914->3909 3915->3912 3916->3909 3918->3909 3919->3909 3920->3909 3921->3909 3922->3909 3923 406814 SHGetPathFromIDListW CoTaskMemFree 3922->3923 3923->3909 3925 40643c 3924->3925 3927 406449 3924->3927 4097 4062ae 3925->4097 3927->3763 3929 405c8a 3928->3929 3930 405c7e CloseHandle 3928->3930 3929->3763 3930->3929 3932 403c40 3931->3932 3933 403c36 CloseHandle 3931->3933 3934 403c54 3932->3934 3935 403c4a CloseHandle 3932->3935 3933->3932 4131 403c82 3934->4131 3935->3934 3941 405cdd 3940->3941 3942 403b89 ExitProcess 3941->3942 3943 405cf1 MessageBoxIndirectW 3941->3943 3943->3942 3945 401389 2 API calls 3944->3945 3946 401420 3945->3946 3946->3722 3954 4068fc 3947->3954 3948 406972 3949 406977 CharPrevW 3948->3949 3951 406998 3948->3951 3949->3948 3950 406965 CharNextW 3950->3948 3950->3954 3951->3783 3952 405f64 CharNextW 3952->3954 3953 406951 CharNextW 3953->3954 3954->3948 3954->3950 3954->3952 3954->3953 3955 406960 CharNextW 3954->3955 3955->3950 3957 405f53 lstrcatW 3956->3957 3958 40362d 3956->3958 3957->3958 3958->3787 3960 406194 GetTickCount GetTempFileNameW 3959->3960 3961 4061ca 3960->3961 3962 40363e 3960->3962 3961->3960 3961->3962 3962->3699 3963->3793 3964->3795 3966 405f91 3965->3966 3967 40313c 3966->3967 3968 405f97 CharPrevW 3966->3968 3969 406668 lstrcpynW 3967->3969 3968->3966 3968->3967 3969->3799 3971 403057 3970->3971 3972 40303f 3970->3972 3975 403067 GetTickCount 3971->3975 3976 40305f 3971->3976 3973 403048 DestroyWindow 3972->3973 3974 40304f 3972->3974 3973->3974 3974->3804 3974->3820 4003 4035f8 SetFilePointer 3974->4003 3975->3974 3978 403075 3975->3978 4018 406a71 3976->4018 3979 4030aa CreateDialogParamW ShowWindow 3978->3979 3980 40307d 3978->3980 3979->3974 3980->3974 4004 403012 3980->4004 3982 40308b wsprintfW 4007 4056ca 3982->4007 3984->3817 3986 403380 SetFilePointer 3985->3986 3987 40339c 3985->3987 3986->3987 4022 403479 GetTickCount 3987->4022 3990 403439 3990->3820 3993 403479 42 API calls 3994 4033d3 3993->3994 3994->3990 3995 40343f ReadFile 3994->3995 3997 4033e2 3994->3997 3995->3990 3997->3990 3998 4061db ReadFile 3997->3998 4037 40620a WriteFile 3997->4037 3998->3997 4001 4061db ReadFile 4000->4001 4002 4035f5 4001->4002 4002->3819 4003->3808 4005 403021 4004->4005 4006 403023 MulDiv 4004->4006 4005->4006 4006->3982 4008 4056e5 4007->4008 4017 405787 4007->4017 4009 405701 lstrlenW 4008->4009 4010 4066a5 17 API calls 4008->4010 4011 40572a 4009->4011 4012 40570f lstrlenW 4009->4012 4010->4009 4014 405730 SetWindowTextW 4011->4014 4015 40573d 4011->4015 4013 405721 lstrcatW 4012->4013 4012->4017 4013->4011 4014->4015 4016 405743 SendMessageW SendMessageW SendMessageW 4015->4016 4015->4017 4016->4017 4017->3974 4019 406a8e PeekMessageW 4018->4019 4020 406a84 DispatchMessageW 4019->4020 4021 406a9e 4019->4021 4020->4019 4021->3974 4023 4035d1 4022->4023 4024 4034a7 4022->4024 4025 40302e 32 API calls 4023->4025 4039 4035f8 SetFilePointer 4024->4039 4032 4033a3 4025->4032 4027 4034b2 SetFilePointer 4031 4034d7 4027->4031 4028 4035e2 ReadFile 4028->4031 4030 40302e 32 API calls 4030->4031 4031->4028 4031->4030 4031->4032 4033 40620a WriteFile 4031->4033 4034 4035b2 SetFilePointer 4031->4034 4040 406bb0 4031->4040 4032->3990 4035 4061db ReadFile 4032->4035 4033->4031 4034->4023 4036 4033bc 4035->4036 4036->3990 4036->3993 4038 406228 4037->4038 4038->3997 4039->4027 4041 406bd5 4040->4041 4042 406bdd 4040->4042 4041->4031 4042->4041 4043 406c64 GlobalFree 4042->4043 4044 406c6d GlobalAlloc 4042->4044 4045 406ce4 GlobalAlloc 4042->4045 4046 406cdb GlobalFree 4042->4046 4043->4044 4044->4041 4044->4042 4045->4041 4045->4042 4046->4045 4048 404001 4047->4048 4069 4065af wsprintfW 4048->4069 4050 404072 4070 4040a6 4050->4070 4052 403da2 4052->3834 4053 404077 4053->4052 4054 4066a5 17 API calls 4053->4054 4054->4053 4073 4064d5 4055->4073 4058 403df6 4058->3836 4058->3847 4058->3851 4059 40656a RegQueryValueExW RegCloseKey 4059->4058 4077 404610 4060->4077 4062 4057e7 4063 404610 SendMessageW 4062->4063 4064 4057f9 OleUninitialize 4063->4064 4064->3865 4065 4057c0 4065->4062 4080 401389 4065->4080 4067->3831 4068->3836 4069->4050 4071 4066a5 17 API calls 4070->4071 4072 4040b4 SetWindowTextW 4071->4072 4072->4053 4074 4064e4 4073->4074 4075 4064e8 4074->4075 4076 4064ed RegOpenKeyExW 4074->4076 4075->4058 4075->4059 4076->4075 4078 404628 4077->4078 4079 404619 SendMessageW 4077->4079 4078->4065 4079->4078 4082 401390 4080->4082 4081 4013fe 4081->4065 4082->4081 4083 4013cb MulDiv SendMessageW 4082->4083 4083->4082 4084->3880 4086 405fff 4085->4086 4089 406011 4085->4089 4087 40600c CharNextW 4086->4087 4086->4089 4090 406035 4087->4090 4088 405f64 CharNextW 4088->4089 4089->4088 4089->4090 4090->3883 4090->3884 4092 4069b4 FindClose 4091->4092 4093 4069bf 4091->4093 4092->4093 4093->3887 4094->3909 4095->3909 4096->3910 4098 406304 GetShortPathNameW 4097->4098 4099 4062de 4097->4099 4101 406423 4098->4101 4102 406319 4098->4102 4124 406158 GetFileAttributesW CreateFileW 4099->4124 4101->3927 4102->4101 4104 406321 wsprintfA 4102->4104 4103 4062e8 CloseHandle GetShortPathNameW 4103->4101 4105 4062fc 4103->4105 4106 4066a5 17 API calls 4104->4106 4105->4098 4105->4101 4107 406349 4106->4107 4125 406158 GetFileAttributesW CreateFileW 4107->4125 4109 406356 4109->4101 4110 406365 GetFileSize GlobalAlloc 4109->4110 4111 406387 4110->4111 4112 40641c CloseHandle 4110->4112 4113 4061db ReadFile 4111->4113 4112->4101 4114 40638f 4113->4114 4114->4112 4126 4060bd lstrlenA 4114->4126 4117 4063a6 lstrcpyA 4120 4063c8 4117->4120 4118 4063ba 4119 4060bd 4 API calls 4118->4119 4119->4120 4121 4063ff SetFilePointer 4120->4121 4122 40620a WriteFile 4121->4122 4123 406415 GlobalFree 4122->4123 4123->4112 4124->4103 4125->4109 4127 4060fe lstrlenA 4126->4127 4128 4060d7 lstrcmpiA 4127->4128 4130 406106 4127->4130 4129 4060f5 CharNextA 4128->4129 4128->4130 4129->4127 4130->4117 4130->4118 4132 403c90 4131->4132 4133 403c59 4132->4133 4134 403c95 FreeLibrary GlobalFree 4132->4134 4135 405d74 4133->4135 4134->4133 4134->4134 4136 40603f 18 API calls 4135->4136 4137 405d94 4136->4137 4138 405db3 4137->4138 4139 405d9c DeleteFileW 4137->4139 4140 405ede 4138->4140 4175 406668 lstrcpynW 4138->4175 4145 403b71 OleUninitialize 4139->4145 4140->4145 4148 40699e 2 API calls 4140->4148 4142 405dd9 4143 405dec 4142->4143 4144 405ddf lstrcatW 4142->4144 4147 405f83 2 API calls 4143->4147 4146 405df2 4144->4146 4145->3718 4145->3719 4149 405e02 lstrcatW 4146->4149 4150 405df8 4146->4150 4147->4146 4151 405ef8 4148->4151 4152 405e0d lstrlenW FindFirstFileW 4149->4152 4150->4149 4150->4152 4151->4145 4153 405efc 4151->4153 4154 405ed3 4152->4154 4173 405e2f 4152->4173 4155 405f37 3 API calls 4153->4155 4154->4140 4156 405f02 4155->4156 4157 405d2c 5 API calls 4156->4157 4160 405f0e 4157->4160 4159 405eb6 FindNextFileW 4161 405ecc FindClose 4159->4161 4159->4173 4162 405f12 4160->4162 4163 405f28 4160->4163 4161->4154 4162->4145 4166 4056ca 24 API calls 4162->4166 4165 4056ca 24 API calls 4163->4165 4165->4145 4168 405f1f 4166->4168 4167 405d74 60 API calls 4167->4173 4170 406428 36 API calls 4168->4170 4169 4056ca 24 API calls 4169->4159 4171 405f26 4170->4171 4171->4145 4172 4056ca 24 API calls 4172->4173 4173->4159 4173->4167 4173->4169 4173->4172 4174 406428 36 API calls 4173->4174 4176 406668 lstrcpynW 4173->4176 4177 405d2c 4173->4177 4174->4173 4175->4142 4176->4173 4185 406133 GetFileAttributesW 4177->4185 4180 405d59 4180->4173 4181 405d47 RemoveDirectoryW 4183 405d55 4181->4183 4182 405d4f DeleteFileW 4182->4183 4183->4180 4184 405d65 SetFileAttributesW 4183->4184 4184->4180 4186 405d38 4185->4186 4187 406145 SetFileAttributesW 4185->4187 4186->4180 4186->4181 4186->4182 4187->4186 4803 6e211021 4804 6e211e4e 2 API calls 4803->4804 4805 6e211054 4804->4805 4806 6e2110b4 4805->4806 4807 6e211e4e 2 API calls 4805->4807 4808 6e211e9c 2 API calls 4806->4808 4809 6e211069 4807->4809 4810 6e2110be 4808->4810 4809->4806 4811 6e21106d SHBrowseForFolderW 4809->4811 4811->4806 4812 6e2110c0 4811->4812 4813 6e211e9c 2 API calls 4812->4813 4814 6e2110e5 CoTaskMemFree 4813->4814 4814->4810 4188 401941 4189 401943 4188->4189 4194 402da6 4189->4194 4192 405d74 67 API calls 4193 401951 4192->4193 4195 402db2 4194->4195 4196 4066a5 17 API calls 4195->4196 4197 402dd3 4196->4197 4198 401948 4197->4198 4199 4068ef 5 API calls 4197->4199 4198->4192 4199->4198 4223 401c43 4245 402d84 4223->4245 4225 401c4a 4226 402d84 17 API calls 4225->4226 4227 401c57 4226->4227 4228 401c6c 4227->4228 4229 402da6 17 API calls 4227->4229 4230 401c7c 4228->4230 4233 402da6 17 API calls 4228->4233 4229->4228 4231 401cd3 4230->4231 4232 401c87 4230->4232 4235 402da6 17 API calls 4231->4235 4234 402d84 17 API calls 4232->4234 4233->4230 4236 401c8c 4234->4236 4237 401cd8 4235->4237 4238 402d84 17 API calls 4236->4238 4239 402da6 17 API calls 4237->4239 4240 401c98 4238->4240 4241 401ce1 FindWindowExW 4239->4241 4242 401cc3 SendMessageW 4240->4242 4243 401ca5 SendMessageTimeoutW 4240->4243 4244 401d03 4241->4244 4242->4244 4243->4244 4246 4066a5 17 API calls 4245->4246 4247 402d99 4246->4247 4247->4225 4826 6e211c29 4827 6e212053 2 API calls 4826->4827 4828 6e211c2f 4827->4828 4829 6e212053 2 API calls 4828->4829 4830 6e211c36 4829->4830 4831 6e211c51 4830->4831 4832 6e211c3e SetTimer 4830->4832 4832->4831 4847 401e4e GetDC 4848 402d84 17 API calls 4847->4848 4849 401e60 GetDeviceCaps MulDiv ReleaseDC 4848->4849 4850 402d84 17 API calls 4849->4850 4851 401e91 4850->4851 4852 4066a5 17 API calls 4851->4852 4853 401ece CreateFontIndirectW 4852->4853 4854 402638 4853->4854 4619 402950 4620 402da6 17 API calls 4619->4620 4622 40295c 4620->4622 4621 402972 4624 406133 2 API calls 4621->4624 4622->4621 4623 402da6 17 API calls 4622->4623 4623->4621 4625 402978 4624->4625 4647 406158 GetFileAttributesW CreateFileW 4625->4647 4627 402985 4628 402a3b 4627->4628 4629 4029a0 GlobalAlloc 4627->4629 4630 402a23 4627->4630 4631 402a42 DeleteFileW 4628->4631 4632 402a55 4628->4632 4629->4630 4633 4029b9 4629->4633 4634 403371 44 API calls 4630->4634 4631->4632 4648 4035f8 SetFilePointer 4633->4648 4636 402a30 CloseHandle 4634->4636 4636->4628 4637 4029bf 4638 4035e2 ReadFile 4637->4638 4639 4029c8 GlobalAlloc 4638->4639 4640 4029d8 4639->4640 4641 402a0c 4639->4641 4643 403371 44 API calls 4640->4643 4642 40620a WriteFile 4641->4642 4644 402a18 GlobalFree 4642->4644 4646 4029e5 4643->4646 4644->4630 4645 402a03 GlobalFree 4645->4641 4646->4645 4647->4627 4648->4637 4887 401956 4888 402da6 17 API calls 4887->4888 4889 40195d lstrlenW 4888->4889 4890 402638 4889->4890 4899 402b59 4900 402b60 4899->4900 4901 402bab 4899->4901 4903 402ba9 4900->4903 4905 402d84 17 API calls 4900->4905 4902 406a35 5 API calls 4901->4902 4904 402bb2 4902->4904 4906 402da6 17 API calls 4904->4906 4907 402b6e 4905->4907 4908 402bbb 4906->4908 4909 402d84 17 API calls 4907->4909 4908->4903 4910 402bbf IIDFromString 4908->4910 4912 402b7a 4909->4912 4910->4903 4911 402bce 4910->4911 4911->4903 4917 406668 lstrcpynW 4911->4917 4916 4065af wsprintfW 4912->4916 4915 402beb CoTaskMemFree 4915->4903 4916->4903 4917->4915 4918 402a5b 4919 402d84 17 API calls 4918->4919 4920 402a61 4919->4920 4921 40292e 4920->4921 4922 402aa4 4920->4922 4923 402a88 4920->4923 4926 402abe 4922->4926 4927 402aae 4922->4927 4924 402a8d 4923->4924 4925 402a9e 4923->4925 4932 406668 lstrcpynW 4924->4932 4933 4065af wsprintfW 4925->4933 4928 4066a5 17 API calls 4926->4928 4929 402d84 17 API calls 4927->4929 4928->4921 4929->4921 4932->4921 4933->4921 4783 40175c 4784 402da6 17 API calls 4783->4784 4785 401763 4784->4785 4786 406187 2 API calls 4785->4786 4787 40176a 4786->4787 4788 406187 2 API calls 4787->4788 4788->4787 4934 401d5d 4935 402d84 17 API calls 4934->4935 4936 401d6e SetWindowLongW 4935->4936 4937 402c2a 4936->4937 4945 406d5f 4946 406be3 4945->4946 4947 40754e 4946->4947 4948 406c64 GlobalFree 4946->4948 4949 406c6d GlobalAlloc 4946->4949 4950 406ce4 GlobalAlloc 4946->4950 4951 406cdb GlobalFree 4946->4951 4948->4949 4949->4946 4949->4947 4950->4946 4950->4947 4951->4950 4955 6e211000 4956 6e211007 SendMessageW 4955->4956 4957 6e21101c 4955->4957 4956->4957 4958 401563 4959 402ba4 4958->4959 4962 4065af wsprintfW 4959->4962 4961 402ba9 4962->4961 4383 6e211407 4384 6e211415 4383->4384 4385 6e211434 CallWindowProcW 4383->4385 4384->4385 4388 6e211430 4384->4388 4386 6e211454 4385->4386 4385->4388 4387 6e211458 DestroyWindow GetProcessHeap RtlFreeHeap 4386->4387 4386->4388 4387->4388 4970 401968 4971 402d84 17 API calls 4970->4971 4972 40196f 4971->4972 4973 402d84 17 API calls 4972->4973 4974 40197c 4973->4974 4975 402da6 17 API calls 4974->4975 4976 401993 lstrlenW 4975->4976 4977 4019a4 4976->4977 4978 4019e5 4977->4978 4982 406668 lstrcpynW 4977->4982 4980 4019d5 4980->4978 4981 4019da lstrlenW 4980->4981 4981->4978 4982->4980 4983 40166a 4984 402da6 17 API calls 4983->4984 4985 401670 4984->4985 4986 40699e 2 API calls 4985->4986 4987 401676 4986->4987 5022 404a6e 5023 404aa4 5022->5023 5024 404a7e 5022->5024 5026 40462b 8 API calls 5023->5026 5025 4045c4 18 API calls 5024->5025 5027 404a8b SetDlgItemTextW 5025->5027 5028 404ab0 5026->5028 5027->5023 4571 40176f 4572 402da6 17 API calls 4571->4572 4573 401776 4572->4573 4574 401796 4573->4574 4575 40179e 4573->4575 4610 406668 lstrcpynW 4574->4610 4611 406668 lstrcpynW 4575->4611 4578 4017a9 4580 405f37 3 API calls 4578->4580 4579 40179c 4582 4068ef 5 API calls 4579->4582 4581 4017af lstrcatW 4580->4581 4581->4579 4597 4017bb 4582->4597 4583 40699e 2 API calls 4583->4597 4584 406133 2 API calls 4584->4597 4586 4017cd CompareFileTime 4586->4597 4587 40188d 4588 4056ca 24 API calls 4587->4588 4591 401897 4588->4591 4589 4056ca 24 API calls 4599 401879 4589->4599 4590 406668 lstrcpynW 4590->4597 4592 403371 44 API calls 4591->4592 4593 4018aa 4592->4593 4594 4018be SetFileTime 4593->4594 4596 4018d0 FindCloseChangeNotification 4593->4596 4594->4596 4595 4066a5 17 API calls 4595->4597 4598 4018e1 4596->4598 4596->4599 4597->4583 4597->4584 4597->4586 4597->4587 4597->4590 4597->4595 4606 405cc8 MessageBoxIndirectW 4597->4606 4608 401864 4597->4608 4609 406158 GetFileAttributesW CreateFileW 4597->4609 4600 4018e6 4598->4600 4601 4018f9 4598->4601 4603 4066a5 17 API calls 4600->4603 4602 4066a5 17 API calls 4601->4602 4605 401901 4602->4605 4604 4018ee lstrcatW 4603->4604 4604->4605 4605->4599 4607 405cc8 MessageBoxIndirectW 4605->4607 4606->4597 4607->4599 4608->4589 4608->4599 4609->4597 4610->4579 4611->4578 5029 401a72 5030 402d84 17 API calls 5029->5030 5031 401a7b 5030->5031 5032 402d84 17 API calls 5031->5032 5033 401a20 5032->5033 5034 401573 5035 401583 ShowWindow 5034->5035 5036 40158c 5034->5036 5035->5036 5037 402c2a 5036->5037 5038 40159a ShowWindow 5036->5038 5038->5037 5056 401b77 5057 402da6 17 API calls 5056->5057 5058 401b7e 5057->5058 5059 402d84 17 API calls 5058->5059 5060 401b87 wsprintfW 5059->5060 5061 402c2a 5060->5061 5064 40167b 5065 402da6 17 API calls 5064->5065 5066 401682 5065->5066 5067 402da6 17 API calls 5066->5067 5068 40168b 5067->5068 5069 402da6 17 API calls 5068->5069 5070 401694 MoveFileW 5069->5070 5071 4016a7 5070->5071 5072 4016a0 5070->5072 5073 40699e 2 API calls 5071->5073 5076 4022f6 5071->5076 5074 401423 24 API calls 5072->5074 5075 4016b6 5073->5075 5074->5076 5075->5076 5077 406428 36 API calls 5075->5077 5077->5072 5108 401000 5109 401037 BeginPaint GetClientRect 5108->5109 5110 40100c DefWindowProcW 5108->5110 5112 4010f3 5109->5112 5115 401179 5110->5115 5113 401073 CreateBrushIndirect FillRect DeleteObject 5112->5113 5114 4010fc 5112->5114 5113->5112 5116 401102 CreateFontIndirectW 5114->5116 5117 401167 EndPaint 5114->5117 5116->5117 5118 401112 6 API calls 5116->5118 5117->5115 5118->5117 5130 401503 5131 40150b 5130->5131 5133 40151e 5130->5133 5132 402d84 17 API calls 5131->5132 5132->5133 5140 402c05 SendMessageW 5141 402c2a 5140->5141 5142 402c1f InvalidateRect 5140->5142 5142->5141 4464 405809 4465 4059b3 4464->4465 4466 40582a GetDlgItem GetDlgItem GetDlgItem 4464->4466 4468 4059e4 4465->4468 4469 4059bc GetDlgItem CreateThread FindCloseChangeNotification 4465->4469 4509 4045f9 SendMessageW 4466->4509 4471 405a0f 4468->4471 4472 405a34 4468->4472 4473 4059fb ShowWindow ShowWindow 4468->4473 4469->4468 4512 40579d 5 API calls 4469->4512 4470 40589a 4477 4058a1 GetClientRect GetSystemMetrics SendMessageW SendMessageW 4470->4477 4474 405a23 4471->4474 4475 405a49 ShowWindow 4471->4475 4478 405a6f 4471->4478 4476 40462b 8 API calls 4472->4476 4511 4045f9 SendMessageW 4473->4511 4480 40459d SendMessageW 4474->4480 4482 405a69 4475->4482 4483 405a5b 4475->4483 4481 405a42 4476->4481 4484 4058f3 SendMessageW SendMessageW 4477->4484 4485 40590f 4477->4485 4478->4472 4486 405a7d SendMessageW 4478->4486 4480->4472 4488 40459d SendMessageW 4482->4488 4487 4056ca 24 API calls 4483->4487 4484->4485 4489 405922 4485->4489 4490 405914 SendMessageW 4485->4490 4486->4481 4491 405a96 CreatePopupMenu 4486->4491 4487->4482 4488->4478 4493 4045c4 18 API calls 4489->4493 4490->4489 4492 4066a5 17 API calls 4491->4492 4494 405aa6 AppendMenuW 4492->4494 4495 405932 4493->4495 4496 405ac3 GetWindowRect 4494->4496 4497 405ad6 TrackPopupMenu 4494->4497 4498 40593b ShowWindow 4495->4498 4499 40596f GetDlgItem SendMessageW 4495->4499 4496->4497 4497->4481 4500 405af1 4497->4500 4501 405951 ShowWindow 4498->4501 4502 40595e 4498->4502 4499->4481 4503 405996 SendMessageW SendMessageW 4499->4503 4504 405b0d SendMessageW 4500->4504 4501->4502 4510 4045f9 SendMessageW 4502->4510 4503->4481 4504->4504 4505 405b2a OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 4504->4505 4507 405b4f SendMessageW 4505->4507 4507->4507 4508 405b78 GlobalUnlock SetClipboardData CloseClipboard 4507->4508 4508->4481 4509->4470 4510->4499 4511->4471 5151 404e0b 5152 404e37 5151->5152 5153 404e1b 5151->5153 5155 404e6a 5152->5155 5156 404e3d SHGetPathFromIDListW 5152->5156 5162 405cac GetDlgItemTextW 5153->5162 5158 404e54 SendMessageW 5156->5158 5159 404e4d 5156->5159 5157 404e28 SendMessageW 5157->5152 5158->5155 5160 40140b 2 API calls 5159->5160 5160->5158 5162->5157 5163 40290b 5164 402da6 17 API calls 5163->5164 5165 402912 FindFirstFileW 5164->5165 5166 402925 5165->5166 5167 40293a 5165->5167 5169 402943 5167->5169 5171 4065af wsprintfW 5167->5171 5172 406668 lstrcpynW 5169->5172 5171->5169 5172->5166 5173 40190c 5174 401943 5173->5174 5175 402da6 17 API calls 5174->5175 5176 401948 5175->5176 5177 405d74 67 API calls 5176->5177 5178 401951 5177->5178 5203 40190f 5204 402da6 17 API calls 5203->5204 5205 401916 5204->5205 5206 405cc8 MessageBoxIndirectW 5205->5206 5207 40191f 5206->5207 5220 401f12 5221 402da6 17 API calls 5220->5221 5222 401f18 5221->5222 5223 402da6 17 API calls 5222->5223 5224 401f21 5223->5224 5225 402da6 17 API calls 5224->5225 5226 401f2a 5225->5226 5227 402da6 17 API calls 5226->5227 5228 401f33 5227->5228 5229 401423 24 API calls 5228->5229 5230 401f3a 5229->5230 5237 405c8e ShellExecuteExW 5230->5237 5232 401f82 5234 40292e 5232->5234 5238 406ae0 WaitForSingleObject 5232->5238 5235 401f9f CloseHandle 5235->5234 5237->5232 5239 406afa 5238->5239 5240 406b0c GetExitCodeProcess 5239->5240 5241 406a71 2 API calls 5239->5241 5240->5235 5242 406b01 WaitForSingleObject 5241->5242 5242->5239 5264 6e211d76 5265 6e212053 2 API calls 5264->5265 5266 6e211d7b 5265->5266 5267 401d17 5268 402d84 17 API calls 5267->5268 5269 401d1d IsWindow 5268->5269 5270 401a20 5269->5270 5271 40261c 5272 402da6 17 API calls 5271->5272 5273 402623 5272->5273 5276 406158 GetFileAttributesW CreateFileW 5273->5276 5275 40262f 5276->5275 4513 40252a 4524 402de6 4513->4524 4516 402da6 17 API calls 4517 40253d 4516->4517 4518 402548 RegQueryValueExW 4517->4518 4521 40292e 4517->4521 4519 402568 4518->4519 4523 40256e RegCloseKey 4518->4523 4519->4523 4529 4065af wsprintfW 4519->4529 4523->4521 4525 402da6 17 API calls 4524->4525 4526 402dfd 4525->4526 4527 4064d5 RegOpenKeyExW 4526->4527 4528 402534 4527->4528 4528->4516 4529->4523 5321 40202a 5322 402da6 17 API calls 5321->5322 5323 402031 5322->5323 5324 406a35 5 API calls 5323->5324 5325 402040 5324->5325 5326 40205c GlobalAlloc 5325->5326 5328 4020cc 5325->5328 5327 402070 5326->5327 5326->5328 5329 406a35 5 API calls 5327->5329 5330 402077 5329->5330 5331 406a35 5 API calls 5330->5331 5332 402081 5331->5332 5332->5328 5336 4065af wsprintfW 5332->5336 5334 4020ba 5337 4065af wsprintfW 5334->5337 5336->5334 5337->5328 5345 401a30 5346 402da6 17 API calls 5345->5346 5347 401a39 ExpandEnvironmentStringsW 5346->5347 5348 401a4d 5347->5348 5350 401a60 5347->5350 5349 401a52 lstrcmpW 5348->5349 5348->5350 5349->5350 5351 405031 GetDlgItem GetDlgItem 5352 405083 7 API calls 5351->5352 5356 4052a8 5351->5356 5353 40512a DeleteObject 5352->5353 5354 40511d SendMessageW 5352->5354 5355 405133 5353->5355 5354->5353 5357 40516a 5355->5357 5360 4066a5 17 API calls 5355->5360 5362 40538a 5356->5362 5382 405317 5356->5382 5405 404f7f SendMessageW 5356->5405 5358 4045c4 18 API calls 5357->5358 5361 40517e 5358->5361 5359 405436 5363 405440 SendMessageW 5359->5363 5364 405448 5359->5364 5365 40514c SendMessageW SendMessageW 5360->5365 5366 4045c4 18 API calls 5361->5366 5362->5359 5367 4053e3 SendMessageW 5362->5367 5391 40529b 5362->5391 5363->5364 5374 405461 5364->5374 5375 40545a ImageList_Destroy 5364->5375 5379 405471 5364->5379 5365->5355 5383 40518f 5366->5383 5372 4053f8 SendMessageW 5367->5372 5367->5391 5368 40537c SendMessageW 5368->5362 5369 40462b 8 API calls 5373 405637 5369->5373 5371 4055eb 5380 4055fd ShowWindow GetDlgItem ShowWindow 5371->5380 5371->5391 5378 40540b 5372->5378 5376 40546a GlobalFree 5374->5376 5374->5379 5375->5374 5376->5379 5377 40526a GetWindowLongW SetWindowLongW 5381 405283 5377->5381 5389 40541c SendMessageW 5378->5389 5379->5371 5398 4054ac 5379->5398 5410 404fff 5379->5410 5380->5391 5384 4052a0 5381->5384 5385 405288 ShowWindow 5381->5385 5382->5362 5382->5368 5383->5377 5388 4051e2 SendMessageW 5383->5388 5390 405265 5383->5390 5392 405220 SendMessageW 5383->5392 5393 405234 SendMessageW 5383->5393 5404 4045f9 SendMessageW 5384->5404 5403 4045f9 SendMessageW 5385->5403 5388->5383 5389->5359 5390->5377 5390->5381 5391->5369 5392->5383 5393->5383 5395 4055b6 5396 4055c1 InvalidateRect 5395->5396 5399 4055cd 5395->5399 5396->5399 5397 4054da SendMessageW 5402 4054f0 5397->5402 5398->5397 5398->5402 5399->5371 5400 404f3a 20 API calls 5399->5400 5400->5371 5401 405564 SendMessageW SendMessageW 5401->5402 5402->5395 5402->5401 5403->5391 5404->5356 5406 404fa2 GetMessagePos ScreenToClient SendMessageW 5405->5406 5407 404fde SendMessageW 5405->5407 5408 404fd6 5406->5408 5409 404fdb 5406->5409 5407->5408 5408->5382 5409->5407 5419 406668 lstrcpynW 5410->5419 5412 405012 5420 4065af wsprintfW 5412->5420 5414 40501c 5415 40140b 2 API calls 5414->5415 5416 405025 5415->5416 5421 406668 lstrcpynW 5416->5421 5418 40502c 5418->5398 5419->5412 5420->5414 5421->5418 5422 6e211c53 5423 6e212053 2 API calls 5422->5423 5424 6e211c58 KillTimer 5423->5424 5440 402434 5441 402467 5440->5441 5442 40243c 5440->5442 5444 402da6 17 API calls 5441->5444 5443 402de6 17 API calls 5442->5443 5446 402443 5443->5446 5445 40246e 5444->5445 5451 402e64 5445->5451 5448 40247b 5446->5448 5449 402da6 17 API calls 5446->5449 5450 402454 RegDeleteValueW RegCloseKey 5449->5450 5450->5448 5452 402e71 5451->5452 5453 402e78 5451->5453 5452->5448 5453->5452 5455 402ea9 5453->5455 5456 4064d5 RegOpenKeyExW 5455->5456 5457 402ed7 5456->5457 5458 402f81 5457->5458 5459 402ee7 RegEnumValueW 5457->5459 5464 402f0a 5457->5464 5458->5452 5460 402f71 RegCloseKey 5459->5460 5459->5464 5460->5458 5461 402f46 RegEnumKeyW 5462 402f4f RegCloseKey 5461->5462 5461->5464 5463 406a35 5 API calls 5462->5463 5466 402f5f 5463->5466 5464->5460 5464->5461 5464->5462 5465 402ea9 6 API calls 5464->5465 5465->5464 5466->5458 5467 402f63 RegDeleteKeyW 5466->5467 5467->5458 5468 404734 lstrlenW 5469 404753 5468->5469 5470 404755 WideCharToMultiByte 5468->5470 5469->5470 5471 401735 5472 402da6 17 API calls 5471->5472 5473 40173c SearchPathW 5472->5473 5474 401757 5473->5474 5512 401d38 5513 402d84 17 API calls 5512->5513 5514 401d3f 5513->5514 5515 402d84 17 API calls 5514->5515 5516 401d4b GetDlgItem 5515->5516 5517 402638 5516->5517 5522 40563e 5523 405662 5522->5523 5524 40564e 5522->5524 5527 40566a IsWindowVisible 5523->5527 5533 405681 5523->5533 5525 405654 5524->5525 5526 4056ab 5524->5526 5529 404610 SendMessageW 5525->5529 5528 4056b0 CallWindowProcW 5526->5528 5527->5526 5530 405677 5527->5530 5532 40565e 5528->5532 5529->5532 5531 404f7f 5 API calls 5530->5531 5531->5533 5533->5528 5534 404fff 4 API calls 5533->5534 5534->5526 5535 40263e 5536 402652 5535->5536 5537 40266d 5535->5537 5540 402d84 17 API calls 5536->5540 5538 402672 5537->5538 5539 40269d 5537->5539 5541 402da6 17 API calls 5538->5541 5542 402da6 17 API calls 5539->5542 5549 402659 5540->5549 5543 402679 5541->5543 5544 4026a4 lstrlenW 5542->5544 5552 40668a WideCharToMultiByte 5543->5552 5544->5549 5546 40268d lstrlenA 5546->5549 5547 4026d1 5548 40620a WriteFile 5547->5548 5550 4026e7 5547->5550 5548->5550 5549->5547 5549->5550 5551 406239 5 API calls 5549->5551 5551->5547 5552->5546 4200 4015c1 4201 402da6 17 API calls 4200->4201 4202 4015c8 4201->4202 4203 405fe2 4 API calls 4202->4203 4217 4015d1 4203->4217 4204 401631 4206 401663 4204->4206 4207 401636 4204->4207 4205 405f64 CharNextW 4205->4217 4209 401423 24 API calls 4206->4209 4219 401423 4207->4219 4215 40165b 4209->4215 4211 405c16 2 API calls 4211->4217 4213 405c33 5 API calls 4213->4217 4214 40164a SetCurrentDirectoryW 4214->4215 4216 401617 GetFileAttributesW 4216->4217 4217->4204 4217->4205 4217->4211 4217->4213 4217->4216 4218 405b99 4 API calls 4217->4218 4218->4217 4220 4056ca 24 API calls 4219->4220 4221 401431 4220->4221 4222 406668 lstrcpynW 4221->4222 4222->4214 4822 4028c4 4823 4028ca 4822->4823 4824 4028d2 FindClose 4823->4824 4825 402c2a 4823->4825 4824->4825 4306 4040c5 4307 4040dd 4306->4307 4308 40423e 4306->4308 4307->4308 4309 4040e9 4307->4309 4310 40428f 4308->4310 4311 40424f GetDlgItem GetDlgItem 4308->4311 4312 4040f4 SetWindowPos 4309->4312 4313 404107 4309->4313 4315 4042e9 4310->4315 4326 401389 2 API calls 4310->4326 4314 4045c4 18 API calls 4311->4314 4312->4313 4317 404110 ShowWindow 4313->4317 4318 404152 4313->4318 4319 404279 SetClassLongW 4314->4319 4316 404610 SendMessageW 4315->4316 4320 404239 4315->4320 4348 4042fb 4316->4348 4321 404130 GetWindowLongW 4317->4321 4322 4041fc 4317->4322 4323 404171 4318->4323 4324 40415a DestroyWindow 4318->4324 4325 40140b 2 API calls 4319->4325 4321->4322 4328 404149 ShowWindow 4321->4328 4327 40462b 8 API calls 4322->4327 4330 404176 SetWindowLongW 4323->4330 4331 404187 4323->4331 4329 40454d 4324->4329 4325->4310 4332 4042c1 4326->4332 4327->4320 4328->4318 4329->4320 4337 40457e ShowWindow 4329->4337 4330->4320 4331->4322 4335 404193 GetDlgItem 4331->4335 4332->4315 4336 4042c5 SendMessageW 4332->4336 4333 40140b 2 API calls 4333->4348 4334 40454f DestroyWindow EndDialog 4334->4329 4338 4041c1 4335->4338 4339 4041a4 SendMessageW IsWindowEnabled 4335->4339 4336->4320 4337->4320 4341 4041ce 4338->4341 4342 404215 SendMessageW 4338->4342 4343 4041e1 4338->4343 4351 4041c6 4338->4351 4339->4320 4339->4338 4340 4066a5 17 API calls 4340->4348 4341->4342 4341->4351 4342->4322 4346 4041e9 4343->4346 4347 4041fe 4343->4347 4345 4045c4 18 API calls 4345->4348 4349 40140b 2 API calls 4346->4349 4350 40140b 2 API calls 4347->4350 4348->4320 4348->4333 4348->4334 4348->4340 4348->4345 4352 4045c4 18 API calls 4348->4352 4368 40448f DestroyWindow 4348->4368 4349->4351 4350->4351 4351->4322 4380 40459d 4351->4380 4353 404376 GetDlgItem 4352->4353 4354 404393 ShowWindow KiUserCallbackDispatcher 4353->4354 4355 40438b 4353->4355 4377 4045e6 KiUserCallbackDispatcher 4354->4377 4355->4354 4357 4043bd KiUserCallbackDispatcher 4362 4043d1 4357->4362 4358 4043d6 GetSystemMenu EnableMenuItem SendMessageW 4359 404406 SendMessageW 4358->4359 4358->4362 4359->4362 4361 4040a6 18 API calls 4361->4362 4362->4358 4362->4361 4378 4045f9 SendMessageW 4362->4378 4379 406668 lstrcpynW 4362->4379 4364 404435 lstrlenW 4365 4066a5 17 API calls 4364->4365 4366 40444b SetWindowTextW 4365->4366 4367 401389 2 API calls 4366->4367 4367->4348 4368->4329 4369 4044a9 CreateDialogParamW 4368->4369 4369->4329 4370 4044dc 4369->4370 4371 4045c4 18 API calls 4370->4371 4372 4044e7 GetDlgItem GetWindowRect ScreenToClient SetWindowPos 4371->4372 4373 401389 2 API calls 4372->4373 4374 40452d 4373->4374 4374->4320 4375 404535 ShowWindow 4374->4375 4376 404610 SendMessageW 4375->4376 4376->4329 4377->4357 4378->4362 4379->4364 4381 4045a4 4380->4381 4382 4045aa SendMessageW 4380->4382 4381->4382 4382->4322 4836 4016cc 4837 402da6 17 API calls 4836->4837 4838 4016d2 GetFullPathNameW 4837->4838 4839 40170e 4838->4839 4840 4016ec 4838->4840 4841 401723 GetShortPathNameW 4839->4841 4842 402c2a 4839->4842 4840->4839 4843 40699e 2 API calls 4840->4843 4841->4842 4844 4016fe 4843->4844 4844->4839 4846 406668 lstrcpynW 4844->4846 4846->4839 4855 6e211cae 4858 6e211c66 4855->4858 4859 6e212053 2 API calls 4858->4859 4860 6e211c6d 4859->4860 4861 6e212053 2 API calls 4860->4861 4862 6e211c74 IsWindow 4861->4862 4863 6e211c81 4862->4863 4864 6e211c87 4862->4864 4866 6e2113d2 GetPropW 4863->4866 4867 6e2113e5 4866->4867 4867->4864 4875 403cd5 4876 403ce0 4875->4876 4877 403ce4 4876->4877 4878 403ce7 GlobalAlloc 4876->4878 4878->4877 4879 6e211bb4 4880 6e212053 2 API calls 4879->4880 4881 6e211bba IsWindow 4880->4881 4882 6e211bc7 4881->4882 4883 6e2113d2 GetPropW 4882->4883 4884 6e211bd3 4883->4884 4885 6e211be5 4884->4885 4886 6e211e4e 2 API calls 4884->4886 4886->4885 4891 6e211cb6 4892 6e211c66 4 API calls 4891->4892 4893 6e211cbd 4892->4893 4894 4014d7 4895 402d84 17 API calls 4894->4895 4896 4014dd Sleep 4895->4896 4898 402c2a 4896->4898 4732 4020d8 4733 40219c 4732->4733 4734 4020ea 4732->4734 4736 401423 24 API calls 4733->4736 4735 402da6 17 API calls 4734->4735 4737 4020f1 4735->4737 4742 4022f6 4736->4742 4738 402da6 17 API calls 4737->4738 4739 4020fa 4738->4739 4740 402110 LoadLibraryExW 4739->4740 4741 402102 GetModuleHandleW 4739->4741 4740->4733 4743 402121 4740->4743 4741->4740 4741->4743 4754 406aa4 4743->4754 4746 402132 4748 402151 KiUserCallbackDispatcher 4746->4748 4749 40213a 4746->4749 4747 40216b 4750 4056ca 24 API calls 4747->4750 4752 402142 4748->4752 4751 401423 24 API calls 4749->4751 4750->4752 4751->4752 4752->4742 4753 40218e FreeLibrary 4752->4753 4753->4742 4759 40668a WideCharToMultiByte 4754->4759 4756 406ac1 4757 406ac8 GetProcAddress 4756->4757 4758 40212c 4756->4758 4757->4758 4758->4746 4758->4747 4759->4756 4938 4028de 4939 4028e6 4938->4939 4940 4028ea FindNextFileW 4939->4940 4941 4028fc 4939->4941 4940->4941 4942 402943 4940->4942 4944 406668 lstrcpynW 4942->4944 4944->4941 4789 6e2117be 4790 6e2117f1 4789->4790 4800 6e212053 4790->4800 4792 6e211811 GetDlgItem GetWindowRect MapWindowPoints CreateDialogParamW 4793 6e211852 4792->4793 4794 6e21185e SetWindowPos SetWindowLongW GetProcessHeap 4792->4794 4795 6e211e9c 2 API calls 4793->4795 4797 6e2118ab 4794->4797 4796 6e21185c 4795->4796 4798 6e2118c1 4796->4798 4799 6e2120b3 3 API calls 4797->4799 4799->4798 4801 6e211e4e 2 API calls 4800->4801 4802 6e21206d 4801->4802 4802->4792 4988 402aeb 4989 402d84 17 API calls 4988->4989 4990 402af1 4989->4990 4991 40292e 4990->4991 4992 4066a5 17 API calls 4990->4992 4992->4991 4993 4026ec 4994 402d84 17 API calls 4993->4994 4995 4026fb 4994->4995 4996 402745 ReadFile 4995->4996 4997 4061db ReadFile 4995->4997 4998 402785 MultiByteToWideChar 4995->4998 4999 40283a 4995->4999 5002 4027ab SetFilePointer MultiByteToWideChar 4995->5002 5003 40284b 4995->5003 5005 402838 4995->5005 5006 406239 SetFilePointer 4995->5006 4996->4995 4996->5005 4997->4995 4998->4995 5015 4065af wsprintfW 4999->5015 5002->4995 5004 40286c SetFilePointer 5003->5004 5003->5005 5004->5005 5007 406255 5006->5007 5014 40626d 5006->5014 5008 4061db ReadFile 5007->5008 5009 406261 5008->5009 5010 406276 SetFilePointer 5009->5010 5011 40629e SetFilePointer 5009->5011 5009->5014 5010->5011 5012 406281 5010->5012 5011->5014 5013 40620a WriteFile 5012->5013 5013->5014 5014->4995 5015->5005 5016 6e21148c 5017 6e2113d2 GetPropW 5016->5017 5018 6e211497 5017->5018 5019 6e2114d2 5018->5019 5020 6e2114a1 LoadCursorW SetCursor 5018->5020 5021 6e2114ba CallWindowProcW 5018->5021 5020->5019 5021->5019 5039 4023f4 5040 402da6 17 API calls 5039->5040 5041 402403 5040->5041 5042 402da6 17 API calls 5041->5042 5043 40240c 5042->5043 5044 402da6 17 API calls 5043->5044 5045 402416 GetPrivateProfileStringW 5044->5045 5046 4014f5 SetForegroundWindow 5047 402c2a 5046->5047 5048 401ff6 5049 402da6 17 API calls 5048->5049 5050 401ffd 5049->5050 5051 40699e 2 API calls 5050->5051 5052 402003 5051->5052 5054 402014 5052->5054 5055 4065af wsprintfW 5052->5055 5055->5054 5062 6e211b98 CreateControl 5063 4046fa lstrcpynW lstrlenW 5085 4022ff 5086 402da6 17 API calls 5085->5086 5087 402305 5086->5087 5088 402da6 17 API calls 5087->5088 5089 40230e 5088->5089 5090 402da6 17 API calls 5089->5090 5091 402317 5090->5091 5092 40699e 2 API calls 5091->5092 5093 402320 5092->5093 5094 402331 lstrlenW lstrlenW 5093->5094 5098 402324 5093->5098 5096 4056ca 24 API calls 5094->5096 5095 4056ca 24 API calls 5099 40232c 5095->5099 5097 40236f SHFileOperationW 5096->5097 5097->5098 5097->5099 5098->5095 5098->5099 5100 4019ff 5101 402da6 17 API calls 5100->5101 5102 401a06 5101->5102 5103 402da6 17 API calls 5102->5103 5104 401a0f 5103->5104 5105 401a16 lstrcmpiW 5104->5105 5106 401a28 lstrcmpW 5104->5106 5107 401a1c 5105->5107 5106->5107 5119 401d81 5120 401d94 GetDlgItem 5119->5120 5121 401d87 5119->5121 5123 401d8e 5120->5123 5122 402d84 17 API calls 5121->5122 5122->5123 5124 401dd5 GetClientRect LoadImageW SendMessageW 5123->5124 5125 402da6 17 API calls 5123->5125 5127 401e33 5124->5127 5129 401e3f 5124->5129 5125->5124 5128 401e38 DeleteObject 5127->5128 5127->5129 5128->5129 4248 404783 4249 40479b 4248->4249 4253 4048b5 4248->4253 4279 4045c4 4249->4279 4250 40491f 4251 4049e9 4250->4251 4252 404929 GetDlgItem 4250->4252 4291 40462b 4251->4291 4255 404943 4252->4255 4256 4049aa 4252->4256 4253->4250 4253->4251 4257 4048f0 GetDlgItem SendMessageW 4253->4257 4255->4256 4263 404969 SendMessageW LoadCursorW SetCursor 4255->4263 4256->4251 4260 4049bc 4256->4260 4284 4045e6 KiUserCallbackDispatcher 4257->4284 4258 404802 4262 4045c4 18 API calls 4258->4262 4264 4049d2 4260->4264 4265 4049c2 SendMessageW 4260->4265 4267 40480f CheckDlgButton 4262->4267 4288 404a32 4263->4288 4270 4049e4 4264->4270 4271 4049d8 SendMessageW 4264->4271 4265->4264 4266 40491a 4285 404a0e 4266->4285 4282 4045e6 KiUserCallbackDispatcher 4267->4282 4271->4270 4274 40482d GetDlgItem 4283 4045f9 SendMessageW 4274->4283 4276 404843 SendMessageW 4277 404860 GetSysColor 4276->4277 4278 404869 SendMessageW SendMessageW lstrlenW SendMessageW SendMessageW 4276->4278 4277->4278 4278->4270 4280 4066a5 17 API calls 4279->4280 4281 4045cf SetDlgItemTextW 4280->4281 4281->4258 4282->4274 4283->4276 4284->4266 4286 404a21 SendMessageW 4285->4286 4287 404a1c 4285->4287 4286->4250 4287->4286 4305 405c8e ShellExecuteExW 4288->4305 4290 404998 LoadCursorW SetCursor 4290->4256 4292 4046ee 4291->4292 4293 404643 GetWindowLongW 4291->4293 4292->4270 4293->4292 4294 404658 4293->4294 4294->4292 4295 404685 GetSysColor 4294->4295 4296 404688 4294->4296 4295->4296 4297 404698 SetBkMode 4296->4297 4298 40468e SetTextColor 4296->4298 4299 4046b0 GetSysColor 4297->4299 4300 4046b6 4297->4300 4298->4297 4299->4300 4301 4046c7 4300->4301 4302 4046bd SetBkColor 4300->4302 4301->4292 4303 4046e1 CreateBrushIndirect 4301->4303 4304 4046da DeleteObject 4301->4304 4302->4301 4303->4292 4304->4303 4305->4290 5134 402383 5135 40238a 5134->5135 5138 40239d 5134->5138 5136 4066a5 17 API calls 5135->5136 5137 402397 5136->5137 5137->5138 5139 405cc8 MessageBoxIndirectW 5137->5139 5139->5138 5143 6e211be7 5144 6e212053 2 API calls 5143->5144 5145 6e211bed IsWindow 5144->5145 5146 6e211c00 5145->5146 5147 6e211bfa 5145->5147 5149 6e211e9c 2 API calls 5146->5149 5148 6e2113d2 GetPropW 5147->5148 5148->5146 5150 6e211c14 5149->5150 4530 40248a 4531 402da6 17 API calls 4530->4531 4532 40249c 4531->4532 4533 402da6 17 API calls 4532->4533 4534 4024a6 4533->4534 4547 402e36 4534->4547 4537 402c2a 4538 4024de 4540 4024ea 4538->4540 4543 402d84 17 API calls 4538->4543 4539 402da6 17 API calls 4542 4024d4 lstrlenW 4539->4542 4541 402509 RegSetValueExW 4540->4541 4544 403371 44 API calls 4540->4544 4545 40251f RegCloseKey 4541->4545 4542->4538 4543->4540 4544->4541 4545->4537 4548 402e51 4547->4548 4551 406503 4548->4551 4552 406512 4551->4552 4553 4024b6 4552->4553 4554 40651d RegCreateKeyExW 4552->4554 4553->4537 4553->4538 4553->4539 4554->4553 5179 6e2110ef 5180 6e211e4e 2 API calls 5179->5180 5181 6e211151 5180->5181 5182 6e211e4e 2 API calls 5181->5182 5183 6e211158 5182->5183 5184 6e211e4e 2 API calls 5183->5184 5185 6e21115f lstrcmpiW GetFileAttributesW 5184->5185 5186 6e211185 5185->5186 5187 6e2111a8 5185->5187 5186->5187 5189 6e211189 lstrcpyW 5186->5189 5188 6e2111b2 lstrcpyW 5187->5188 5191 6e2111be 5187->5191 5188->5191 5189->5187 5190 6e2111e5 GetCurrentDirectoryW 5193 6e211205 GetSaveFileNameW 5190->5193 5194 6e21120d GetOpenFileNameW 5190->5194 5191->5190 5192 6e2111d8 CharNextW 5191->5192 5192->5191 5195 6e21120f 5193->5195 5194->5195 5196 6e211213 CommDlgExtendedError 5195->5196 5197 6e21123a 5195->5197 5196->5197 5198 6e211220 5196->5198 5199 6e211e9c 2 API calls 5197->5199 5200 6e211230 GetSaveFileNameW 5198->5200 5201 6e211238 GetOpenFileNameW 5198->5201 5202 6e21124f SetCurrentDirectoryW 5199->5202 5200->5197 5201->5197 5208 401491 5209 4056ca 24 API calls 5208->5209 5210 401498 5209->5210 5211 402891 5212 402898 5211->5212 5214 402ba9 5211->5214 5213 402d84 17 API calls 5212->5213 5215 40289f 5213->5215 5216 4028ae SetFilePointer 5215->5216 5216->5214 5217 4028be 5216->5217 5219 4065af wsprintfW 5217->5219 5219->5214 5243 402f93 5244 402fa5 SetTimer 5243->5244 5245 402fbe 5243->5245 5244->5245 5246 40300c 5245->5246 5247 403012 MulDiv 5245->5247 5248 402fcc wsprintfW SetWindowTextW SetDlgItemTextW 5247->5248 5248->5246 4760 401b9b 4761 401ba8 4760->4761 4762 401bec 4760->4762 4763 401c31 4761->4763 4768 401bbf 4761->4768 4764 401bf1 4762->4764 4765 401c16 GlobalAlloc 4762->4765 4766 4066a5 17 API calls 4763->4766 4773 40239d 4763->4773 4764->4773 4781 406668 lstrcpynW 4764->4781 4767 4066a5 17 API calls 4765->4767 4769 402397 4766->4769 4767->4763 4779 406668 lstrcpynW 4768->4779 4769->4773 4774 405cc8 MessageBoxIndirectW 4769->4774 4772 401c03 GlobalFree 4772->4773 4774->4773 4775 401bce 4780 406668 lstrcpynW 4775->4780 4777 401bdd 4782 406668 lstrcpynW 4777->4782 4779->4775 4780->4777 4781->4772 4782->4773 5284 40149e 5285 4014ac PostQuitMessage 5284->5285 5286 40239d 5284->5286 5285->5286 5287 40259e 5288 402de6 17 API calls 5287->5288 5289 4025a8 5288->5289 5290 402d84 17 API calls 5289->5290 5291 4025b1 5290->5291 5292 4025d9 RegEnumValueW 5291->5292 5293 4025cd RegEnumKeyW 5291->5293 5294 40292e 5291->5294 5295 4025ee RegCloseKey 5292->5295 5293->5295 5295->5294 5297 4015a3 5298 402da6 17 API calls 5297->5298 5299 4015aa SetFileAttributesW 5298->5299 5300 4015bc 5299->5300 5301 401fa4 5302 402da6 17 API calls 5301->5302 5303 401faa 5302->5303 5304 4056ca 24 API calls 5303->5304 5305 401fb4 5304->5305 5306 405c4b 2 API calls 5305->5306 5307 401fba 5306->5307 5309 406ae0 5 API calls 5307->5309 5310 40292e 5307->5310 5313 401fdd CloseHandle 5307->5313 5311 401fcf 5309->5311 5311->5313 5314 4065af wsprintfW 5311->5314 5313->5310 5314->5313 5315 6e211cc6 5318 6e211c9b 5315->5318 5319 6e212053 2 API calls 5318->5319 5320 6e211ca0 5319->5320 4389 6e2118c9 GetProcessHeap 4390 6e2118ec 4389->4390 4391 6e211900 4390->4391 4392 6e21190f 4390->4392 4451 6e211e9c 4391->4451 4426 6e211e4e 4392->4426 4397 6e21194c 4400 6e211e9c 2 API calls 4397->4400 4398 6e211b93 4402 6e211956 GetProcessHeap 4400->4402 4401 6e211920 4403 6e212083 2 API calls 4401->4403 4404 6e211b8c HeapFree 4402->4404 4405 6e211928 4403->4405 4404->4398 4434 6e21125b GetClientRect 4405->4434 4407 6e211940 4408 6e211e4e 2 API calls 4407->4408 4409 6e211948 4408->4409 4409->4397 4410 6e211960 GetProcessHeap HeapReAlloc lstrcmpiW 4409->4410 4411 6e2119bb lstrcmpiW 4410->4411 4419 6e2119a0 4410->4419 4412 6e2119e2 lstrcmpiW 4411->4412 4411->4419 4413 6e211a09 lstrcmpiW 4412->4413 4412->4419 4414 6e211a30 lstrcmpiW 4413->4414 4413->4419 4418 6e211a54 lstrcmpiW 4414->4418 4414->4419 4415 6e211adb lstrcmpiW 4416 6e211ae7 4415->4416 4417 6e211aec CreateWindowExW SetPropW SendMessageW SendMessageW 4415->4417 4416->4417 4420 6e211b60 SetWindowLongW 4417->4420 4421 6e211b7b 4417->4421 4418->4419 4422 6e211a78 lstrcmpiW 4418->4422 4419->4415 4420->4421 4454 6e2120b3 wsprintfW 4421->4454 4422->4419 4424 6e211a9c lstrcmpiW 4422->4424 4424->4419 4427 6e211917 4426->4427 4430 6e211e58 4426->4430 4427->4397 4431 6e212083 4427->4431 4428 6e211e86 GlobalFree 4428->4427 4429 6e211e72 lstrcpynW 4429->4428 4430->4427 4430->4428 4430->4429 4432 6e211e4e 2 API calls 4431->4432 4433 6e21209d 4432->4433 4433->4401 4435 6e211e4e 2 API calls 4434->4435 4436 6e211292 4435->4436 4450 6e211303 4436->4450 4457 6e211332 lstrlenW CharPrevW 4436->4457 4439 6e211e4e 2 API calls 4440 6e2112b6 4439->4440 4441 6e211332 4 API calls 4440->4441 4440->4450 4442 6e2112c9 4441->4442 4443 6e211e4e 2 API calls 4442->4443 4444 6e2112db 4443->4444 4445 6e211332 4 API calls 4444->4445 4444->4450 4446 6e2112ed 4445->4446 4447 6e211e4e 2 API calls 4446->4447 4448 6e2112ff 4447->4448 4449 6e211332 4 API calls 4448->4449 4448->4450 4449->4450 4450->4407 4452 6e211ea5 GlobalAlloc lstrcpynW 4451->4452 4453 6e21190a 4451->4453 4452->4453 4453->4398 4455 6e211e9c 2 API calls 4454->4455 4456 6e211b81 GetProcessHeap 4455->4456 4456->4404 4458 6e211358 4457->4458 4459 6e211360 MulDiv 4458->4459 4460 6e211375 4458->4460 4463 6e2112a4 4459->4463 4462 6e21137b MapDialogRect 4460->4462 4460->4463 4462->4463 4463->4439 4555 4021aa 4556 402da6 17 API calls 4555->4556 4557 4021b1 4556->4557 4558 402da6 17 API calls 4557->4558 4559 4021bb 4558->4559 4560 402da6 17 API calls 4559->4560 4561 4021c5 4560->4561 4562 402da6 17 API calls 4561->4562 4563 4021cf 4562->4563 4564 402da6 17 API calls 4563->4564 4565 4021d9 4564->4565 4566 402218 CoCreateInstance 4565->4566 4567 402da6 17 API calls 4565->4567 4570 402237 4566->4570 4567->4566 4568 401423 24 API calls 4569 4022f6 4568->4569 4570->4568 4570->4569 4612 6e211cce SendMessageW ShowWindow 4613 6e211d53 SetWindowLongW 4612->4613 4614 6e211d02 4612->4614 4615 6e211d09 KiUserCallbackDispatcher IsDialogMessageW 4614->4615 4617 6e211d52 4614->4617 4615->4614 4616 6e211d26 IsDialogMessageW 4615->4616 4616->4614 4618 6e211d36 TranslateMessage DispatchMessageW 4616->4618 4617->4613 4618->4614 5430 4023b2 5431 4023c0 5430->5431 5432 4023ba 5430->5432 5434 402da6 17 API calls 5431->5434 5436 4023ce 5431->5436 5433 402da6 17 API calls 5432->5433 5433->5431 5434->5436 5435 4023dc 5438 402da6 17 API calls 5435->5438 5436->5435 5437 402da6 17 API calls 5436->5437 5437->5435 5439 4023e5 WritePrivateProfileStringW 5438->5439 4649 404ab5 4650 404ae1 4649->4650 4651 404af2 4649->4651 4729 405cac GetDlgItemTextW 4650->4729 4653 404afe GetDlgItem 4651->4653 4659 404b6a 4651->4659 4655 404b12 4653->4655 4654 404aec 4657 4068ef 5 API calls 4654->4657 4658 404b26 SetWindowTextW 4655->4658 4665 405fe2 4 API calls 4655->4665 4656 404c41 4712 404df0 4656->4712 4716 405cac GetDlgItemTextW 4656->4716 4657->4651 4663 4045c4 18 API calls 4658->4663 4659->4656 4661 4066a5 17 API calls 4659->4661 4659->4712 4666 404bd1 SHBrowseForFolderW 4661->4666 4662 404c71 4667 40603f 18 API calls 4662->4667 4668 404b42 4663->4668 4664 40462b 8 API calls 4669 404e04 4664->4669 4673 404b1c 4665->4673 4666->4656 4670 404be9 CoTaskMemFree 4666->4670 4671 404c77 4667->4671 4672 4045c4 18 API calls 4668->4672 4674 405f37 3 API calls 4670->4674 4717 406668 lstrcpynW 4671->4717 4675 404b50 4672->4675 4673->4658 4676 405f37 3 API calls 4673->4676 4677 404bf6 4674->4677 4715 4045f9 SendMessageW 4675->4715 4676->4658 4680 404c2d SetDlgItemTextW 4677->4680 4685 4066a5 17 API calls 4677->4685 4680->4656 4681 404c8e 4683 406a35 5 API calls 4681->4683 4682 404b56 4684 406a35 5 API calls 4682->4684 4694 404c95 4683->4694 4686 404b5d 4684->4686 4687 404c15 lstrcmpiW 4685->4687 4689 404b65 SHAutoComplete 4686->4689 4686->4712 4687->4680 4691 404c26 lstrcatW 4687->4691 4688 404cd6 4730 406668 lstrcpynW 4688->4730 4689->4659 4691->4680 4692 404ca4 GetDiskFreeSpaceExW 4692->4694 4702 404d2e 4692->4702 4693 404cdd 4695 405fe2 4 API calls 4693->4695 4694->4688 4694->4692 4697 405f83 2 API calls 4694->4697 4696 404ce3 4695->4696 4698 404ce9 4696->4698 4699 404cec GetDiskFreeSpaceW 4696->4699 4697->4694 4698->4699 4700 404d07 MulDiv 4699->4700 4699->4702 4700->4702 4701 404d9f 4704 404dc2 4701->4704 4706 40140b 2 API calls 4701->4706 4702->4701 4718 404f3a 4702->4718 4731 4045e6 KiUserCallbackDispatcher 4704->4731 4706->4704 4708 404da1 SetDlgItemTextW 4708->4701 4709 404d91 4721 404e71 4709->4721 4710 404dde 4710->4712 4713 404deb 4710->4713 4712->4664 4714 404a0e SendMessageW 4713->4714 4714->4712 4715->4682 4716->4662 4717->4681 4719 404e71 20 API calls 4718->4719 4720 404d8c 4719->4720 4720->4708 4720->4709 4722 404e8a 4721->4722 4723 4066a5 17 API calls 4722->4723 4724 404eee 4723->4724 4725 4066a5 17 API calls 4724->4725 4726 404ef9 4725->4726 4727 4066a5 17 API calls 4726->4727 4728 404f0f lstrlenW wsprintfW SetDlgItemTextW 4727->4728 4728->4701 4729->4654 4730->4693 4731->4710 5475 6e2114d6 5476 6e211775 5475->5476 5477 6e2114ee 5475->5477 5480 6e2115b3 5476->5480 5484 6e211781 RemovePropW 5476->5484 5478 6e2114f7 5477->5478 5479 6e211666 5477->5479 5482 6e2115e0 5478->5482 5483 6e211500 5478->5483 5481 6e2113d2 GetPropW 5479->5481 5486 6e211687 5481->5486 5485 6e2113d2 GetPropW 5482->5485 5487 6e211507 5483->5487 5488 6e21153c GetDlgItem 5483->5488 5484->5480 5484->5484 5490 6e2115ea 5485->5490 5486->5480 5491 6e21168f GetWindowTextW DrawTextW 5486->5491 5487->5480 5492 6e211524 SendMessageW 5487->5492 5489 6e2113d2 GetPropW 5488->5489 5497 6e211552 5489->5497 5490->5480 5495 6e2120b3 3 API calls 5490->5495 5493 6e2116e3 5491->5493 5492->5480 5494 6e21174b 5493->5494 5496 6e211717 GetWindowLongW 5493->5496 5494->5480 5504 6e211763 DrawFocusRect 5494->5504 5498 6e211618 5495->5498 5499 6e211735 DrawTextW 5496->5499 5500 6e211726 5496->5500 5497->5480 5505 6e2120b3 3 API calls 5497->5505 5501 6e2120b3 3 API calls 5498->5501 5499->5494 5510 6e2117ac GetSysColor 5500->5510 5502 6e211620 5501->5502 5506 6e2120b3 3 API calls 5502->5506 5504->5480 5505->5480 5508 6e211627 5506->5508 5508->5480 5509 6e211653 SetWindowLongW 5508->5509 5509->5480 5511 6e21172b SetTextColor 5510->5511 5511->5499 5518 4014b8 5519 4014be 5518->5519 5520 401389 2 API calls 5519->5520 5521 4014c6 5520->5521

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 0 403640-403690 SetErrorMode GetVersionExW 1 403692-4036c6 GetVersionExW 0->1 2 4036ca-4036d1 0->2 1->2 3 4036d3 2->3 4 4036db-40371b 2->4 3->4 5 40371d-403725 call 406a35 4->5 6 40372e 4->6 5->6 11 403727 5->11 8 403733-403747 call 4069c5 lstrlenA 6->8 13 403749-403765 call 406a35 * 3 8->13 11->6 20 403776-4037d8 #17 OleInitialize SHGetFileInfoW call 406668 GetCommandLineW call 406668 13->20 21 403767-40376d 13->21 28 4037e1-4037f4 call 405f64 CharNextW 20->28 29 4037da-4037dc 20->29 21->20 25 40376f 21->25 25->20 32 4038eb-4038f1 28->32 29->28 33 4038f7 32->33 34 4037f9-4037ff 32->34 37 40390b-403925 GetTempPathW call 40360f 33->37 35 403801-403806 34->35 36 403808-40380e 34->36 35->35 35->36 38 403810-403814 36->38 39 403815-403819 36->39 44 403927-403945 GetWindowsDirectoryW lstrcatW call 40360f 37->44 45 40397d-403995 DeleteFileW call 4030d0 37->45 38->39 41 4038d9-4038e7 call 405f64 39->41 42 40381f-403825 39->42 41->32 60 4038e9-4038ea 41->60 47 403827-40382e 42->47 48 40383f-403878 42->48 44->45 64 403947-403977 GetTempPathW lstrcatW SetEnvironmentVariableW * 2 call 40360f 44->64 66 40399b-4039a1 45->66 67 403b6c-403b7a call 403c25 OleUninitialize 45->67 52 403830-403833 47->52 53 403835 47->53 54 403894-4038ce 48->54 55 40387a-40387f 48->55 52->48 52->53 53->48 57 4038d0-4038d4 54->57 58 4038d6-4038d8 54->58 55->54 61 403881-403889 55->61 57->58 65 4038f9-403906 call 406668 57->65 58->41 60->32 62 403890 61->62 63 40388b-40388e 61->63 62->54 63->54 63->62 64->45 64->67 65->37 70 4039a7-4039ba call 405f64 66->70 71 403a48-403a4f call 403d17 66->71 77 403b91-403b97 67->77 78 403b7c-403b8b call 405cc8 ExitProcess 67->78 84 403a0c-403a19 70->84 85 4039bc-4039f1 70->85 80 403a54-403a57 71->80 82 403b99-403bae GetCurrentProcess OpenProcessToken 77->82 83 403c0f-403c17 77->83 80->67 91 403bb0-403bd9 LookupPrivilegeValueW AdjustTokenPrivileges 82->91 92 403bdf-403bed call 406a35 82->92 86 403c19 83->86 87 403c1c-403c1f ExitProcess 83->87 88 403a1b-403a29 call 40603f 84->88 89 403a5c-403a70 call 405c33 lstrcatW 84->89 93 4039f3-4039f7 85->93 86->87 88->67 105 403a2f-403a45 call 406668 * 2 88->105 103 403a72-403a78 lstrcatW 89->103 104 403a7d-403a97 lstrcatW lstrcmpiW 89->104 91->92 106 403bfb-403c06 ExitWindowsEx 92->106 107 403bef-403bf9 92->107 97 403a00-403a08 93->97 98 4039f9-4039fe 93->98 97->93 100 403a0a 97->100 98->97 98->100 100->84 103->104 108 403b6a 104->108 109 403a9d-403aa0 104->109 105->71 106->83 111 403c08-403c0a call 40140b 106->111 107->106 107->111 108->67 113 403aa2-403aa7 call 405b99 109->113 114 403aa9 call 405c16 109->114 111->83 121 403aae-403abe SetCurrentDirectoryW 113->121 114->121 123 403ac0-403ac6 call 406668 121->123 124 403acb-403af7 call 406668 121->124 123->124 128 403afc-403b17 call 4066a5 DeleteFileW 124->128 131 403b57-403b61 128->131 132 403b19-403b29 CopyFileW 128->132 131->128 134 403b63-403b65 call 406428 131->134 132->131 133 403b2b-403b4b call 406428 call 4066a5 call 405c4b 132->133 133->131 142 403b4d-403b54 CloseHandle 133->142 134->108 142->131
                                                                APIs
                                                                • SetErrorMode.KERNELBASE(00008001), ref: 00403663
                                                                • GetVersionExW.KERNEL32(?), ref: 0040368C
                                                                • GetVersionExW.KERNEL32(0000011C), ref: 004036A3
                                                                • lstrlenA.KERNEL32(UXTHEME,UXTHEME), ref: 0040373A
                                                                • #17.COMCTL32(00000007,00000009,0000000B), ref: 00403776
                                                                • OleInitialize.OLE32(00000000), ref: 0040377D
                                                                • SHGetFileInfoW.SHELL32(00421708,00000000,?,000002B4,00000000), ref: 0040379B
                                                                • GetCommandLineW.KERNEL32(00429260,NSIS Error), ref: 004037B0
                                                                • CharNextW.USER32(00000000,"C:\Users\user\Desktop\Gwyddion-2.65.win64.exe",00000020,"C:\Users\user\Desktop\Gwyddion-2.65.win64.exe",00000000), ref: 004037E9
                                                                • GetTempPathW.KERNEL32(00000400,C:\Users\user\AppData\Local\Temp\,00000000,?), ref: 0040391C
                                                                • GetWindowsDirectoryW.KERNEL32(C:\Users\user\AppData\Local\Temp\,000003FB), ref: 0040392D
                                                                • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,\Temp), ref: 00403939
                                                                • GetTempPathW.KERNEL32(000003FC,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,\Temp), ref: 0040394D
                                                                • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,Low), ref: 00403955
                                                                • SetEnvironmentVariableW.KERNEL32(TEMP,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,Low), ref: 00403966
                                                                • SetEnvironmentVariableW.KERNEL32(TMP,C:\Users\user\AppData\Local\Temp\), ref: 0040396E
                                                                • DeleteFileW.KERNELBASE(1033), ref: 00403982
                                                                • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,~nsu), ref: 00403A69
                                                                • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,0040A328), ref: 00403A78
                                                                  • Part of subcall function 00405C16: CreateDirectoryW.KERNELBASE(?,00000000,00403633,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405C1C
                                                                • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,.tmp), ref: 00403A83
                                                                • lstrcmpiW.KERNEL32(C:\Users\user\AppData\Local\Temp\,C:\Users\user\Desktop,C:\Users\user\AppData\Local\Temp\,.tmp,C:\Users\user\AppData\Local\Temp\,~nsu,"C:\Users\user\Desktop\Gwyddion-2.65.win64.exe",00000000,?), ref: 00403A8F
                                                                • SetCurrentDirectoryW.KERNEL32(C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\), ref: 00403AAF
                                                                • DeleteFileW.KERNEL32(00420F08,00420F08,?,0042B000,?), ref: 00403B0E
                                                                • CopyFileW.KERNEL32(C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,00420F08,00000001), ref: 00403B21
                                                                • CloseHandle.KERNEL32(00000000,00420F08,00420F08,?,00420F08,00000000), ref: 00403B4E
                                                                • OleUninitialize.OLE32(?), ref: 00403B71
                                                                • ExitProcess.KERNEL32 ref: 00403B8B
                                                                • GetCurrentProcess.KERNEL32(00000028,?), ref: 00403B9F
                                                                • OpenProcessToken.ADVAPI32(00000000), ref: 00403BA6
                                                                • LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 00403BBA
                                                                • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000), ref: 00403BD9
                                                                • ExitWindowsEx.USER32(00000002,80040002), ref: 00403BFE
                                                                • ExitProcess.KERNEL32 ref: 00403C1F
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: lstrcat$FileProcess$DirectoryExit$CurrentDeleteEnvironmentPathTempTokenVariableVersionWindows$AdjustCharCloseCommandCopyCreateErrorHandleInfoInitializeLineLookupModeNextOpenPrivilegePrivilegesUninitializeValuelstrcmpilstrlen
                                                                • String ID: "C:\Users\user\Desktop\Gwyddion-2.65.win64.exe"$.tmp$1033$C:\Program Files\Gwyddion$C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES$C:\Users\user\AppData\Local\Temp\$C:\Users\user\Desktop$C:\Users\user\Desktop\Gwyddion-2.65.win64.exe$Error launching installer$Error writing temporary file. Make sure your temp folder is valid.$Low$NSIS Error$SeShutdownPrivilege$TEMP$TMP$UXTHEME$\Temp$~nsu
                                                                • API String ID: 3859024572-1313693769
                                                                • Opcode ID: ed5248a912319d130effd7f05a4d843c659f0a5d51aace41cf0d3086d1e01474
                                                                • Instruction ID: d56582c8b11bee4b9d4e83ad1f604629a9588d533935b381636b20c84fba3529
                                                                • Opcode Fuzzy Hash: ed5248a912319d130effd7f05a4d843c659f0a5d51aace41cf0d3086d1e01474
                                                                • Instruction Fuzzy Hash: D4E1F471A00214AADB20AFB58D45A6E3EB8EB05709F50847FF945B32D1DB7C8A41CB6D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 143 405809-405824 144 4059b3-4059ba 143->144 145 40582a-4058f1 GetDlgItem * 3 call 4045f9 call 404f52 GetClientRect GetSystemMetrics SendMessageW * 2 143->145 147 4059e4-4059f1 144->147 148 4059bc-4059de GetDlgItem CreateThread FindCloseChangeNotification 144->148 167 4058f3-40590d SendMessageW * 2 145->167 168 40590f-405912 145->168 150 4059f3-4059f9 147->150 151 405a0f-405a19 147->151 148->147 155 405a34-405a3d call 40462b 150->155 156 4059fb-405a0a ShowWindow * 2 call 4045f9 150->156 152 405a1b-405a21 151->152 153 405a6f-405a73 151->153 157 405a23-405a2f call 40459d 152->157 158 405a49-405a59 ShowWindow 152->158 153->155 161 405a75-405a7b 153->161 164 405a42-405a46 155->164 156->151 157->155 165 405a69-405a6a call 40459d 158->165 166 405a5b-405a64 call 4056ca 158->166 161->155 169 405a7d-405a90 SendMessageW 161->169 165->153 166->165 167->168 172 405922-405939 call 4045c4 168->172 173 405914-405920 SendMessageW 168->173 174 405b92-405b94 169->174 175 405a96-405ac1 CreatePopupMenu call 4066a5 AppendMenuW 169->175 182 40593b-40594f ShowWindow 172->182 183 40596f-405990 GetDlgItem SendMessageW 172->183 173->172 174->164 180 405ac3-405ad3 GetWindowRect 175->180 181 405ad6-405aeb TrackPopupMenu 175->181 180->181 181->174 184 405af1-405b08 181->184 185 405951-40595c ShowWindow 182->185 186 40595e 182->186 183->174 187 405996-4059ae SendMessageW * 2 183->187 188 405b0d-405b28 SendMessageW 184->188 189 405964-40596a call 4045f9 185->189 186->189 187->174 188->188 190 405b2a-405b4d OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 188->190 189->183 192 405b4f-405b76 SendMessageW 190->192 192->192 193 405b78-405b8c GlobalUnlock SetClipboardData CloseClipboard 192->193 193->174
                                                                APIs
                                                                • GetDlgItem.USER32(?,00000403), ref: 00405867
                                                                • GetDlgItem.USER32(?,000003EE), ref: 00405876
                                                                • GetClientRect.USER32(?,?), ref: 004058B3
                                                                • GetSystemMetrics.USER32(00000002), ref: 004058BA
                                                                • SendMessageW.USER32(?,00001061,00000000,?), ref: 004058DB
                                                                • SendMessageW.USER32(?,00001036,00004000,00004000), ref: 004058EC
                                                                • SendMessageW.USER32(?,00001001,00000000,00000110), ref: 004058FF
                                                                • SendMessageW.USER32(?,00001026,00000000,00000110), ref: 0040590D
                                                                • SendMessageW.USER32(?,00001024,00000000,?), ref: 00405920
                                                                • ShowWindow.USER32(00000000,?,0000001B,000000FF), ref: 00405942
                                                                • ShowWindow.USER32(?,00000008), ref: 00405956
                                                                • GetDlgItem.USER32(?,000003EC), ref: 00405977
                                                                • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 00405987
                                                                • SendMessageW.USER32(00000000,00000409,00000000,?), ref: 004059A0
                                                                • SendMessageW.USER32(00000000,00002001,00000000,00000110), ref: 004059AC
                                                                • GetDlgItem.USER32(?,000003F8), ref: 00405885
                                                                  • Part of subcall function 004045F9: SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                                                • GetDlgItem.USER32(?,000003EC), ref: 004059C9
                                                                • CreateThread.KERNELBASE(00000000,00000000,Function_0000579D,00000000), ref: 004059D7
                                                                • FindCloseChangeNotification.KERNELBASE(00000000), ref: 004059DE
                                                                • ShowWindow.USER32(00000000), ref: 00405A02
                                                                • ShowWindow.USER32(?,00000008), ref: 00405A07
                                                                • ShowWindow.USER32(00000008), ref: 00405A51
                                                                • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405A85
                                                                • CreatePopupMenu.USER32 ref: 00405A96
                                                                • AppendMenuW.USER32(00000000,00000000,00000001,00000000), ref: 00405AAA
                                                                • GetWindowRect.USER32(?,?), ref: 00405ACA
                                                                • TrackPopupMenu.USER32(00000000,00000180,?,?,00000000,?,00000000), ref: 00405AE3
                                                                • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405B1B
                                                                • OpenClipboard.USER32(00000000), ref: 00405B2B
                                                                • EmptyClipboard.USER32 ref: 00405B31
                                                                • GlobalAlloc.KERNEL32(00000042,00000000), ref: 00405B3D
                                                                • GlobalLock.KERNEL32(00000000), ref: 00405B47
                                                                • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405B5B
                                                                • GlobalUnlock.KERNEL32(00000000), ref: 00405B7B
                                                                • SetClipboardData.USER32(0000000D,00000000), ref: 00405B86
                                                                • CloseClipboard.USER32 ref: 00405B8C
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend$Window$ItemShow$Clipboard$GlobalMenu$CloseCreatePopupRect$AllocAppendChangeClientDataEmptyFindLockMetricsNotificationOpenSystemThreadTrackUnlock
                                                                • String ID: H7B${
                                                                • API String ID: 4154960007-2256286769
                                                                • Opcode ID: 0185fb71cb0ebac8bb253ddb79263eb6e3c4c27c477fa06c1930d1494c9be16a
                                                                • Instruction ID: d0bbb34d81c2c7a38b5cdb5171fa906e4f4201ee6cbe22cb0b3272b57562556b
                                                                • Opcode Fuzzy Hash: 0185fb71cb0ebac8bb253ddb79263eb6e3c4c27c477fa06c1930d1494c9be16a
                                                                • Instruction Fuzzy Hash: D8B137B0900608FFDF119FA0DD89AAE7B79FB08354F00417AFA45A61A0CB755E52DF68
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 467 404ab5-404adf 468 404ae1-404aed call 405cac call 4068ef 467->468 469 404af2-404afc 467->469 468->469 471 404b6a-404b71 469->471 472 404afe-404b14 GetDlgItem call 405fae 469->472 475 404b77-404b80 471->475 476 404c48-404c4f 471->476 483 404b26-404b5f SetWindowTextW call 4045c4 * 2 call 4045f9 call 406a35 472->483 484 404b16-404b1e call 405fe2 472->484 479 404b82-404b8d 475->479 480 404b9a-404b9f 475->480 481 404c51-404c58 476->481 482 404c5e-404c79 call 405cac call 40603f 476->482 485 404b93 479->485 486 404df6-404e08 call 40462b 479->486 480->476 487 404ba5-404be7 call 4066a5 SHBrowseForFolderW 480->487 481->482 481->486 505 404c82-404c9a call 406668 call 406a35 482->505 506 404c7b 482->506 483->486 525 404b65-404b68 SHAutoComplete 483->525 484->483 503 404b20-404b21 call 405f37 484->503 485->480 499 404c41 487->499 500 404be9-404c03 CoTaskMemFree call 405f37 487->500 499->476 512 404c05-404c0b 500->512 513 404c2d-404c3f SetDlgItemTextW 500->513 503->483 523 404cd6-404ce7 call 406668 call 405fe2 505->523 524 404c9c-404ca2 505->524 506->505 512->513 516 404c0d-404c24 call 4066a5 lstrcmpiW 512->516 513->476 516->513 527 404c26-404c28 lstrcatW 516->527 539 404ce9 523->539 540 404cec-404d05 GetDiskFreeSpaceW 523->540 524->523 528 404ca4-404cb6 GetDiskFreeSpaceExW 524->528 525->471 527->513 530 404cb8-404cba 528->530 531 404d2e-404d48 528->531 534 404cbc 530->534 535 404cbf-404cd4 call 405f83 530->535 533 404d4a 531->533 537 404d4f-404d59 call 404f52 533->537 534->535 535->523 535->528 545 404d74-404d7d 537->545 546 404d5b-404d62 537->546 539->540 540->533 543 404d07-404d2c MulDiv 540->543 543->537 547 404daf-404db9 545->547 548 404d7f-404d8f call 404f3a 545->548 546->545 549 404d64 546->549 551 404dc5-404dcb 547->551 552 404dbb-404dc2 call 40140b 547->552 560 404da1-404daa SetDlgItemTextW 548->560 561 404d91-404d9a call 404e71 548->561 553 404d66-404d6b 549->553 554 404d6d 549->554 557 404dd0-404de1 call 4045e6 551->557 558 404dcd 551->558 552->551 553->545 553->554 554->545 565 404df0 557->565 566 404de3-404de9 557->566 558->557 560->547 567 404d9f 561->567 565->486 566->565 568 404deb call 404a0e 566->568 567->547 568->565
                                                                APIs
                                                                • GetDlgItem.USER32(?,000003FB), ref: 00404B04
                                                                • SetWindowTextW.USER32(00000000,?), ref: 00404B2E
                                                                • SHAutoComplete.SHLWAPI(00000000,00000001,00000008,00000000,?,00000014,?,?,00000001,?), ref: 00404B68
                                                                • SHBrowseForFolderW.SHELL32(?), ref: 00404BDF
                                                                • CoTaskMemFree.OLE32(00000000), ref: 00404BEA
                                                                • lstrcmpiW.KERNEL32(00428200,00423748,00000000,?,?), ref: 00404C1C
                                                                • lstrcatW.KERNEL32(?,00428200), ref: 00404C28
                                                                • SetDlgItemTextW.USER32(?,000003FB,?), ref: 00404C3A
                                                                  • Part of subcall function 00405CAC: GetDlgItemTextW.USER32(?,?,00000400,00404C71), ref: 00405CBF
                                                                  • Part of subcall function 004068EF: CharNextW.USER32(?,*?|<>/":,00000000,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406952
                                                                  • Part of subcall function 004068EF: CharNextW.USER32(?,?,?,00000000,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406961
                                                                  • Part of subcall function 004068EF: CharNextW.USER32(?,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406966
                                                                  • Part of subcall function 004068EF: CharPrevW.USER32(?,?,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406979
                                                                • GetDiskFreeSpaceExW.KERNELBASE(00421718,?,?,?,00000001,00421718,?,?,000003FB,?), ref: 00404CB1
                                                                • GetDiskFreeSpaceW.KERNEL32(00421718,?,?,0000040F,?,00421718,00421718,?,00000001,00421718,?,?,000003FB,?), ref: 00404CFD
                                                                • MulDiv.KERNEL32(?,0000040F,00000400), ref: 00404D18
                                                                  • Part of subcall function 00404E71: lstrlenW.KERNEL32(00423748,00423748,?,%u.%u%s%s,00000005,00000000,00000000,?,000000DC,00000000,?,000000DF,00000000,00000400,?), ref: 00404F12
                                                                  • Part of subcall function 00404E71: wsprintfW.USER32 ref: 00404F1B
                                                                  • Part of subcall function 00404E71: SetDlgItemTextW.USER32(?,00423748), ref: 00404F2E
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CharItemText$FreeNext$DiskSpace$AutoBrowseCompleteFolderPrevTaskWindowlstrcatlstrcmpilstrlenwsprintf
                                                                • String ID: A$C:\Program Files\Gwyddion$H7B
                                                                • API String ID: 4039761011-2924953911
                                                                • Opcode ID: 8fe5d6185855569599b0147f93014e69bfe7dcd8b72b59fe1028842fc76bdad0
                                                                • Instruction ID: 9155a42c54a3203d4d9709c494e168d8d926bd307d67cbb08bf4d9f42020e7e3
                                                                • Opcode Fuzzy Hash: 8fe5d6185855569599b0147f93014e69bfe7dcd8b72b59fe1028842fc76bdad0
                                                                • Instruction Fuzzy Hash: 94A171F1900219ABDB11EFA5CD41AAFB7B8EF84315F11843BF601B62D1D77C8A418B69
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 643 405d74-405d9a call 40603f 646 405db3-405dba 643->646 647 405d9c-405dae DeleteFileW 643->647 648 405dbc-405dbe 646->648 649 405dcd-405ddd call 406668 646->649 650 405f30-405f34 647->650 651 405dc4-405dc7 648->651 652 405ede-405ee3 648->652 656 405dec-405ded call 405f83 649->656 657 405ddf-405dea lstrcatW 649->657 651->649 651->652 652->650 655 405ee5-405ee8 652->655 658 405ef2-405efa call 40699e 655->658 659 405eea-405ef0 655->659 660 405df2-405df6 656->660 657->660 658->650 667 405efc-405f10 call 405f37 call 405d2c 658->667 659->650 663 405e02-405e08 lstrcatW 660->663 664 405df8-405e00 660->664 666 405e0d-405e29 lstrlenW FindFirstFileW 663->666 664->663 664->666 668 405ed3-405ed7 666->668 669 405e2f-405e37 666->669 683 405f12-405f15 667->683 684 405f28-405f2b call 4056ca 667->684 668->652 671 405ed9 668->671 672 405e57-405e6b call 406668 669->672 673 405e39-405e41 669->673 671->652 685 405e82-405e8d call 405d2c 672->685 686 405e6d-405e75 672->686 677 405e43-405e4b 673->677 678 405eb6-405ec6 FindNextFileW 673->678 677->672 682 405e4d-405e55 677->682 678->669 681 405ecc-405ecd FindClose 678->681 681->668 682->672 682->678 683->659 687 405f17-405f26 call 4056ca call 406428 683->687 684->650 696 405eae-405eb1 call 4056ca 685->696 697 405e8f-405e92 685->697 686->678 688 405e77-405e80 call 405d74 686->688 687->650 688->678 696->678 700 405e94-405ea4 call 4056ca call 406428 697->700 701 405ea6-405eac 697->701 700->678 701->678
                                                                APIs
                                                                • DeleteFileW.KERNELBASE(?,?,74DF3420,74DF2EE0,00000000), ref: 00405D9D
                                                                • lstrcatW.KERNEL32(00425750,\*.*), ref: 00405DE5
                                                                • lstrcatW.KERNEL32(?,0040A014), ref: 00405E08
                                                                • lstrlenW.KERNEL32(?,?,0040A014,?,00425750,?,?,74DF3420,74DF2EE0,00000000), ref: 00405E0E
                                                                • FindFirstFileW.KERNEL32(00425750,?,?,?,0040A014,?,00425750,?,?,74DF3420,74DF2EE0,00000000), ref: 00405E1E
                                                                • FindNextFileW.KERNEL32(00000000,00000010,000000F2,?,?,?,?,0000002E), ref: 00405EBE
                                                                • FindClose.KERNEL32(00000000), ref: 00405ECD
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FileFind$lstrcat$CloseDeleteFirstNextlstrlen
                                                                • String ID: .$.$PWB$\*.*
                                                                • API String ID: 2035342205-2468439962
                                                                • Opcode ID: eb4081a649fdbb44c8907daec76b44e1c805ca5b036c6d0867ef95af4715127c
                                                                • Instruction ID: 3801e3340fbbb9c460ab277ab089a7ece50ce31247a5b640c745bca9484d7288
                                                                • Opcode Fuzzy Hash: eb4081a649fdbb44c8907daec76b44e1c805ca5b036c6d0867ef95af4715127c
                                                                • Instruction Fuzzy Hash: 46410330800A15AADB21AB61CC49BBF7678EF41715F50413FF881711D1DB7C4A82CEAE
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CallWindowProcW.USER32(?,?,?,?), ref: 6E211447
                                                                • DestroyWindow.USER32 ref: 6E21145E
                                                                • GetProcessHeap.KERNEL32(00000000), ref: 6E21146B
                                                                • RtlFreeHeap.NTDLL(00000000), ref: 6E211472
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: HeapWindow$CallDestroyFreeProcProcess
                                                                • String ID:
                                                                • API String ID: 1278960361-0
                                                                • Opcode ID: f78ae308bd60caa35619472fba14da17c579e78005887f4a79d8ec5738a039e5
                                                                • Instruction ID: 00b983cae1d3ca21df50ac388e898fd8d0bdbe778148d99bad68d58e683fbfae
                                                                • Opcode Fuzzy Hash: f78ae308bd60caa35619472fba14da17c579e78005887f4a79d8ec5738a039e5
                                                                • Instruction Fuzzy Hash: 8C019E32124A49ABCF418FD5C84DADA7BBBFB46722B094029FB1482612CF708654DF20
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 6ae840c17bc4cb012e3c6e2f9739eb08ea49decd14d2b7f73774d31e5ba5825a
                                                                • Instruction ID: 02c1e40b0c9780dd067322b7733c474732bd0f187a49f53fd7fd3c108ee94619
                                                                • Opcode Fuzzy Hash: 6ae840c17bc4cb012e3c6e2f9739eb08ea49decd14d2b7f73774d31e5ba5825a
                                                                • Instruction Fuzzy Hash: 7CF15570D04229CBDF28CFA8C8946ADBBB0FF44305F24816ED456BB281D7386A86DF45
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CoCreateInstance.OLE32(004084E4,?,00000001,004084D4,?,?,00000045,000000CD,00000002,000000DF,000000F0), ref: 00402229
                                                                Strings
                                                                • C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES, xrefs: 00402269
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CreateInstance
                                                                • String ID: C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES
                                                                • API String ID: 542301482-923977919
                                                                • Opcode ID: 077b7362f6a1d4038be91bf7f4b9e5842d68daf9de23732b557fb751e09ce78c
                                                                • Instruction ID: f110e38d5ccd8909b9e85e2ea6b1342c5fae2602ce40754bea02e3b472428d32
                                                                • Opcode Fuzzy Hash: 077b7362f6a1d4038be91bf7f4b9e5842d68daf9de23732b557fb751e09ce78c
                                                                • Instruction Fuzzy Hash: BC411771A00209EFCF40DFE4C989E9D7BB5BF49304B20456AF505EB2D1DB799981CB94
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • FindFirstFileW.KERNELBASE(74DF3420,00426798,00425F50,00406088,00425F50,00425F50,00000000,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0), ref: 004069A9
                                                                • FindClose.KERNEL32(00000000), ref: 004069B5
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Find$CloseFileFirst
                                                                • String ID:
                                                                • API String ID: 2295610775-0
                                                                • Opcode ID: 1093b80bdde5f117a2aeaff90f04fc035896fcf98737a4a628a8a679d5dfa397
                                                                • Instruction ID: 0ca7534fdffec89160a31ceabb6ef5ff718bfc83d1618d69d17f9e635378cbc3
                                                                • Opcode Fuzzy Hash: 1093b80bdde5f117a2aeaff90f04fc035896fcf98737a4a628a8a679d5dfa397
                                                                • Instruction Fuzzy Hash: 5ED012B15192205FC34057387E0C84B7A989F563317268A36B4AAF11E0CB348C3297AC
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 194 4040c5-4040d7 195 4040dd-4040e3 194->195 196 40423e-40424d 194->196 195->196 197 4040e9-4040f2 195->197 198 40429c-4042b1 196->198 199 40424f-404297 GetDlgItem * 2 call 4045c4 SetClassLongW call 40140b 196->199 200 4040f4-404101 SetWindowPos 197->200 201 404107-40410e 197->201 203 4042f1-4042f6 call 404610 198->203 204 4042b3-4042b6 198->204 199->198 200->201 206 404110-40412a ShowWindow 201->206 207 404152-404158 201->207 212 4042fb-404316 203->212 209 4042b8-4042c3 call 401389 204->209 210 4042e9-4042eb 204->210 213 404130-404143 GetWindowLongW 206->213 214 40422b-404239 call 40462b 206->214 215 404171-404174 207->215 216 40415a-40416c DestroyWindow 207->216 209->210 235 4042c5-4042e4 SendMessageW 209->235 210->203 211 404591 210->211 223 404593-40459a 211->223 220 404318-40431a call 40140b 212->220 221 40431f-404325 212->221 213->214 222 404149-40414c ShowWindow 213->222 214->223 226 404176-404182 SetWindowLongW 215->226 227 404187-40418d 215->227 224 40456e-404574 216->224 220->221 232 40432b-404336 221->232 233 40454f-404568 DestroyWindow EndDialog 221->233 222->207 224->211 231 404576-40457c 224->231 226->223 227->214 234 404193-4041a2 GetDlgItem 227->234 231->211 236 40457e-404587 ShowWindow 231->236 232->233 237 40433c-404389 call 4066a5 call 4045c4 * 3 GetDlgItem 232->237 233->224 238 4041c1-4041c4 234->238 239 4041a4-4041bb SendMessageW IsWindowEnabled 234->239 235->223 236->211 266 404393-4043cf ShowWindow KiUserCallbackDispatcher call 4045e6 KiUserCallbackDispatcher 237->266 267 40438b-404390 237->267 241 4041c6-4041c7 238->241 242 4041c9-4041cc 238->242 239->211 239->238 243 4041f7-4041fc call 40459d 241->243 244 4041da-4041df 242->244 245 4041ce-4041d4 242->245 243->214 247 404215-404225 SendMessageW 244->247 249 4041e1-4041e7 244->249 245->247 248 4041d6-4041d8 245->248 247->214 248->243 252 4041e9-4041ef call 40140b 249->252 253 4041fe-404207 call 40140b 249->253 262 4041f5 252->262 253->214 263 404209-404213 253->263 262->243 263->262 270 4043d1-4043d2 266->270 271 4043d4 266->271 267->266 272 4043d6-404404 GetSystemMenu EnableMenuItem SendMessageW 270->272 271->272 273 404406-404417 SendMessageW 272->273 274 404419 272->274 275 40441f-40445e call 4045f9 call 4040a6 call 406668 lstrlenW call 4066a5 SetWindowTextW call 401389 273->275 274->275 275->212 286 404464-404466 275->286 286->212 287 40446c-404470 286->287 288 404472-404478 287->288 289 40448f-4044a3 DestroyWindow 287->289 288->211 290 40447e-404484 288->290 289->224 291 4044a9-4044d6 CreateDialogParamW 289->291 290->212 292 40448a 290->292 291->224 293 4044dc-404533 call 4045c4 GetDlgItem GetWindowRect ScreenToClient SetWindowPos call 401389 291->293 292->211 293->211 298 404535-404548 ShowWindow call 404610 293->298 300 40454d 298->300 300->224
                                                                APIs
                                                                • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000013), ref: 00404101
                                                                • ShowWindow.USER32(?), ref: 00404121
                                                                • GetWindowLongW.USER32(?,000000F0), ref: 00404133
                                                                • ShowWindow.USER32(?,00000004), ref: 0040414C
                                                                • DestroyWindow.USER32 ref: 00404160
                                                                • SetWindowLongW.USER32(?,00000000,00000000), ref: 00404179
                                                                • GetDlgItem.USER32(?,?), ref: 00404198
                                                                • SendMessageW.USER32(00000000,000000F3,00000000,00000000), ref: 004041AC
                                                                • IsWindowEnabled.USER32(00000000), ref: 004041B3
                                                                • GetDlgItem.USER32(?,00000001), ref: 0040425E
                                                                • GetDlgItem.USER32(?,00000002), ref: 00404268
                                                                • SetClassLongW.USER32(?,000000F2,?), ref: 00404282
                                                                • SendMessageW.USER32(0000040F,00000000,00000001,?), ref: 004042D3
                                                                • GetDlgItem.USER32(?,00000003), ref: 00404379
                                                                • ShowWindow.USER32(00000000,?), ref: 0040439A
                                                                • KiUserCallbackDispatcher.NTDLL(?,?), ref: 004043AC
                                                                • KiUserCallbackDispatcher.NTDLL(?,?), ref: 004043C7
                                                                • GetSystemMenu.USER32(?,00000000,0000F060,00000001), ref: 004043DD
                                                                • EnableMenuItem.USER32(00000000), ref: 004043E4
                                                                • SendMessageW.USER32(?,000000F4,00000000,00000001), ref: 004043FC
                                                                • SendMessageW.USER32(?,00000401,00000002,00000000), ref: 0040440F
                                                                • lstrlenW.KERNEL32(00423748,?,00423748,00000000), ref: 00404439
                                                                • SetWindowTextW.USER32(?,00423748), ref: 0040444D
                                                                • ShowWindow.USER32(?,0000000A), ref: 00404581
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Window$Item$MessageSendShow$Long$CallbackDispatcherMenuUser$ClassDestroyEnableEnabledSystemTextlstrlen
                                                                • String ID: H7B
                                                                • API String ID: 3964124867-2300413410
                                                                • Opcode ID: 2f4dad2f818047668635e16f952da299a81014d83ff1599baf972819d0fbfd0c
                                                                • Instruction ID: 1d4a55fced449df2e2a9dfc159c1061f424388fbea236c5341ec002980a30b6c
                                                                • Opcode Fuzzy Hash: 2f4dad2f818047668635e16f952da299a81014d83ff1599baf972819d0fbfd0c
                                                                • Instruction Fuzzy Hash: C0C1C2B1600604FBDB216F61EE85E2A3B78EB85745F40097EF781B51F0CB3958529B2E
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                APIs
                                                                • GetProcessHeap.KERNEL32(00000008,?), ref: 6E2118E3
                                                                • HeapAlloc.KERNEL32(00000000), ref: 6E2118E6
                                                                • GetProcessHeap.KERNEL32(00000000,00000000,error,00000000,00000000), ref: 6E211959
                                                                • HeapFree.KERNEL32(00000000), ref: 6E211B8D
                                                                  • Part of subcall function 6E211E9C: GlobalAlloc.KERNEL32(00000040,?,?,6E2110BE,error,?,00000104), ref: 6E211EB2
                                                                  • Part of subcall function 6E211E9C: lstrcpynW.KERNEL32(00000004,?,?,6E2110BE,error,?,00000104), ref: 6E211EC8
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Heap$AllocProcess$FreeGloballstrcpyn
                                                                • String ID: BUTTON$COMBOBOX$EDIT$LINK$LISTBOX$NSIS: nsControl pointer property$RICHEDIT_CLASS$RichEdit$STATIC$error$p^v
                                                                • API String ID: 1913068523-1412186473
                                                                • Opcode ID: e3e616ff34577feca48b7906d3c505661023a88f665d293ff9b0d045fe240798
                                                                • Instruction ID: 7aed01856eb270438b3f07b33b5aded4f8236840d6e7c77bcf945ef133d6ab26
                                                                • Opcode Fuzzy Hash: e3e616ff34577feca48b7906d3c505661023a88f665d293ff9b0d045fe240798
                                                                • Instruction Fuzzy Hash: FA81A17291861CABDB509BE5CD89FDEBBFEBB16304F064015EB04B7241DA709B44CB60
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 349 403d17-403d2f call 406a35 352 403d31-403d41 call 4065af 349->352 353 403d43-403d7a call 406536 349->353 361 403d9d-403dc6 call 403fed call 40603f 352->361 357 403d92-403d98 lstrcatW 353->357 358 403d7c-403d8d call 406536 353->358 357->361 358->357 367 403e58-403e60 call 40603f 361->367 368 403dcc-403dd1 361->368 374 403e62-403e69 call 4066a5 367->374 375 403e6e-403e93 LoadImageW 367->375 368->367 369 403dd7-403df1 call 406536 368->369 373 403df6-403dff 369->373 373->367 378 403e01-403e05 373->378 374->375 376 403f14-403f1c call 40140b 375->376 377 403e95-403ec5 RegisterClassW 375->377 392 403f26-403f31 call 403fed 376->392 393 403f1e-403f21 376->393 380 403fe3 377->380 381 403ecb-403f0f SystemParametersInfoW CreateWindowExW 377->381 383 403e17-403e23 lstrlenW 378->383 384 403e07-403e14 call 405f64 378->384 385 403fe5-403fec 380->385 381->376 386 403e25-403e33 lstrcmpiW 383->386 387 403e4b-403e53 call 405f37 call 406668 383->387 384->383 386->387 391 403e35-403e3f GetFileAttributesW 386->391 387->367 395 403e41-403e43 391->395 396 403e45-403e46 call 405f83 391->396 402 403f37-403f51 ShowWindow call 4069c5 392->402 403 403fba-403fbb call 40579d 392->403 393->385 395->387 395->396 396->387 410 403f53-403f58 call 4069c5 402->410 411 403f5d-403f6f GetClassInfoW 402->411 406 403fc0-403fc2 403->406 408 403fc4-403fca 406->408 409 403fdc-403fde call 40140b 406->409 408->393 414 403fd0-403fd7 call 40140b 408->414 409->380 410->411 412 403f71-403f81 GetClassInfoW RegisterClassW 411->412 413 403f87-403faa DialogBoxParamW call 40140b 411->413 412->413 419 403faf-403fb8 call 403c67 413->419 414->393 419->385
                                                                APIs
                                                                  • Part of subcall function 00406A35: GetModuleHandleA.KERNEL32(?,00000020,?,00403750,0000000B), ref: 00406A47
                                                                  • Part of subcall function 00406A35: GetProcAddress.KERNEL32(00000000,?), ref: 00406A62
                                                                • lstrcatW.KERNEL32(1033,00423748), ref: 00403D98
                                                                • lstrlenW.KERNEL32(00428200,?,?,?,00428200,00000000,C:\Program Files\Gwyddion,1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000,00000002,74DF3420), ref: 00403E18
                                                                • lstrcmpiW.KERNEL32(004281F8,.exe,00428200,?,?,?,00428200,00000000,C:\Program Files\Gwyddion,1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000), ref: 00403E2B
                                                                • GetFileAttributesW.KERNEL32(00428200,?,00000000,?), ref: 00403E36
                                                                • LoadImageW.USER32(00000067,00000001,00000000,00000000,00008040,C:\Program Files\Gwyddion), ref: 00403E7F
                                                                  • Part of subcall function 004065AF: wsprintfW.USER32 ref: 004065BC
                                                                • RegisterClassW.USER32(00429200), ref: 00403EBC
                                                                • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00403ED4
                                                                • CreateWindowExW.USER32(00000080,_Nb,00000000,80000000,?,?,?,?,00000000,00000000,00000000), ref: 00403F09
                                                                • ShowWindow.USER32(00000005,00000000,?,00000000,?), ref: 00403F3F
                                                                • GetClassInfoW.USER32(00000000,RichEdit20W,00429200), ref: 00403F6B
                                                                • GetClassInfoW.USER32(00000000,RichEdit,00429200), ref: 00403F78
                                                                • RegisterClassW.USER32(00429200), ref: 00403F81
                                                                • DialogBoxParamW.USER32(?,00000000,004040C5,00000000), ref: 00403FA0
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Class$Info$RegisterWindow$AddressAttributesCreateDialogFileHandleImageLoadModuleParamParametersProcShowSystemlstrcatlstrcmpilstrlenwsprintf
                                                                • String ID: .DEFAULT\Control Panel\International$.exe$1033$C:\Program Files\Gwyddion$C:\Users\user\AppData\Local\Temp\$Control Panel\Desktop\ResourceLocale$H7B$RichEd20$RichEd32$RichEdit$RichEdit20W$_Nb
                                                                • API String ID: 1975747703-1484214092
                                                                • Opcode ID: 78a63079156de9a95659751e2075cee6996798d0e51b0c114acce594fd97feca
                                                                • Instruction ID: e235badc60aeba35c86cf297cd954ec43a22164425911800af60bc979c7621a1
                                                                • Opcode Fuzzy Hash: 78a63079156de9a95659751e2075cee6996798d0e51b0c114acce594fd97feca
                                                                • Instruction Fuzzy Hash: E661D570640201BAD730AF66AD45E2B3A7CEB84B49F40457FF945B22E1DB3D5911CA3D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 423 404783-404795 424 4048b5-4048c2 423->424 425 40479b-4047a3 423->425 426 4048c4-4048cd 424->426 427 40491f-404923 424->427 428 4047a5-4047b4 425->428 429 4047b6-4047da 425->429 430 4048d3-4048d9 426->430 431 4049f8 426->431 434 4049e9-4049f0 427->434 435 404929-404941 GetDlgItem 427->435 428->429 432 4047e3-40485e call 4045c4 * 2 CheckDlgButton call 4045e6 GetDlgItem call 4045f9 SendMessageW 429->432 433 4047dc 429->433 430->431 436 4048df-4048ea 430->436 439 4049fb-404a02 call 40462b 431->439 465 404860-404863 GetSysColor 432->465 466 404869-4048b0 SendMessageW * 2 lstrlenW SendMessageW * 2 432->466 433->432 434->431 438 4049f2 434->438 440 404943-40494a 435->440 441 4049aa-4049b1 435->441 436->431 443 4048f0-40491a GetDlgItem SendMessageW call 4045e6 call 404a0e 436->443 438->431 450 404a07-404a0b 439->450 440->441 446 40494c-404967 440->446 441->439 442 4049b3-4049ba 441->442 442->439 447 4049bc-4049c0 442->447 443->427 446->441 451 404969-4049a7 SendMessageW LoadCursorW SetCursor call 404a32 LoadCursorW SetCursor 446->451 452 4049d2-4049d6 447->452 453 4049c2-4049d0 SendMessageW 447->453 451->441 458 4049e4-4049e7 452->458 459 4049d8-4049e2 SendMessageW 452->459 453->452 458->450 459->458 465->466 466->450
                                                                APIs
                                                                • CheckDlgButton.USER32(?,-0000040A,00000001), ref: 00404821
                                                                • GetDlgItem.USER32(?,000003E8), ref: 00404835
                                                                • SendMessageW.USER32(00000000,0000045B,00000001,00000000), ref: 00404852
                                                                • GetSysColor.USER32(?), ref: 00404863
                                                                • SendMessageW.USER32(00000000,00000443,00000000,?), ref: 00404871
                                                                • SendMessageW.USER32(00000000,00000445,00000000,04010000), ref: 0040487F
                                                                • lstrlenW.KERNEL32(?), ref: 00404884
                                                                • SendMessageW.USER32(00000000,00000435,00000000,00000000), ref: 00404891
                                                                • SendMessageW.USER32(00000000,00000449,00000110,00000110), ref: 004048A6
                                                                • GetDlgItem.USER32(?,0000040A), ref: 004048FF
                                                                • SendMessageW.USER32(00000000), ref: 00404906
                                                                • GetDlgItem.USER32(?,000003E8), ref: 00404931
                                                                • SendMessageW.USER32(00000000,0000044B,00000000,00000201), ref: 00404974
                                                                • LoadCursorW.USER32(00000000,00007F02), ref: 00404982
                                                                • SetCursor.USER32(00000000), ref: 00404985
                                                                • LoadCursorW.USER32(00000000,00007F00), ref: 0040499E
                                                                • SetCursor.USER32(00000000), ref: 004049A1
                                                                • SendMessageW.USER32(00000111,00000001,00000000), ref: 004049D0
                                                                • SendMessageW.USER32(00000010,00000000,00000000), ref: 004049E2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend$Cursor$Item$Load$ButtonCheckColorlstrlen
                                                                • String ID: N
                                                                • API String ID: 3103080414-1130791706
                                                                • Opcode ID: 7b7ce6e7f04c0852b245e81234b58653da2c4cab9b10fb98097c13f3cf17b06e
                                                                • Instruction ID: 690b4d321b533a2a97605fa3f7bb2423a24794fe1ec6c961d913f822d5f12d1b
                                                                • Opcode Fuzzy Hash: 7b7ce6e7f04c0852b245e81234b58653da2c4cab9b10fb98097c13f3cf17b06e
                                                                • Instruction Fuzzy Hash: AB6181F1900209FFDB109F61CD85A6A7B69FB84304F00813AF705B62E0C7799951DFA9
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 570 4030d0-40311e GetTickCount GetModuleFileNameW call 406158 573 403120-403125 570->573 574 40312a-403158 call 406668 call 405f83 call 406668 GetFileSize 570->574 575 40336a-40336e 573->575 582 403243-403251 call 40302e 574->582 583 40315e 574->583 590 403322-403327 582->590 591 403257-40325a 582->591 585 403163-40317a 583->585 587 40317c 585->587 588 40317e-403187 call 4035e2 585->588 587->588 595 40318d-403194 588->595 596 4032de-4032e6 call 40302e 588->596 590->575 593 403286-4032d2 GlobalAlloc call 406b90 call 406187 CreateFileW 591->593 594 40325c-403274 call 4035f8 call 4035e2 591->594 621 4032d4-4032d9 593->621 622 4032e8-403318 call 4035f8 call 403371 593->622 594->590 616 40327a-403280 594->616 600 403210-403214 595->600 601 403196-4031aa call 406113 595->601 596->590 605 403216-40321d call 40302e 600->605 606 40321e-403224 600->606 601->606 619 4031ac-4031b3 601->619 605->606 612 403233-40323b 606->612 613 403226-403230 call 406b22 606->613 612->585 620 403241 612->620 613->612 616->590 616->593 619->606 624 4031b5-4031bc 619->624 620->582 621->575 630 40331d-403320 622->630 624->606 626 4031be-4031c5 624->626 626->606 629 4031c7-4031ce 626->629 629->606 631 4031d0-4031f0 629->631 630->590 632 403329-40333a 630->632 631->590 633 4031f6-4031fa 631->633 634 403342-403347 632->634 635 40333c 632->635 636 403202-40320a 633->636 637 4031fc-403200 633->637 638 403348-40334e 634->638 635->634 636->606 639 40320c-40320e 636->639 637->620 637->636 638->638 640 403350-403368 call 406113 638->640 639->606 640->575
                                                                APIs
                                                                • GetTickCount.KERNEL32 ref: 004030E4
                                                                • GetModuleFileNameW.KERNEL32(00000000,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,00000400), ref: 00403100
                                                                  • Part of subcall function 00406158: GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,80000000,00000003), ref: 0040615C
                                                                  • Part of subcall function 00406158: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                                                • GetFileSize.KERNEL32(00000000,00000000,00439000,00000000,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,80000000,00000003), ref: 00403149
                                                                • GlobalAlloc.KERNELBASE(00000040,?), ref: 0040328B
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: File$AllocAttributesCountCreateGlobalModuleNameSizeTick
                                                                • String ID: C:\Users\user\AppData\Local\Temp\$C:\Users\user\Desktop$C:\Users\user\Desktop\Gwyddion-2.65.win64.exe$Error launching installer$Error writing temporary file. Make sure your temp folder is valid.$Inst$Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author $Null$soft
                                                                • API String ID: 2803837635-2120731755
                                                                • Opcode ID: e541a5f8c6dece2e8afc31f1679abbe6e625a0cbceb2fdcb1154e7c345c65132
                                                                • Instruction ID: 6a7077609e6cbe8902eef3654a796be60faa9129f620d49927b75729aeb44cd1
                                                                • Opcode Fuzzy Hash: e541a5f8c6dece2e8afc31f1679abbe6e625a0cbceb2fdcb1154e7c345c65132
                                                                • Instruction Fuzzy Hash: 74710271A40204ABDB20DFB5DD85B9E3AACAB04315F21457FF901B72D2CB789E418B6D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 707 4066a5-4066b0 708 4066b2-4066c1 707->708 709 4066c3-4066d9 707->709 708->709 710 4066f1-4066fa 709->710 711 4066db-4066e8 709->711 713 406700 710->713 714 4068d5-4068e0 710->714 711->710 712 4066ea-4066ed 711->712 712->710 715 406705-406712 713->715 716 4068e2-4068e6 call 406668 714->716 717 4068eb-4068ec 714->717 715->714 718 406718-406721 715->718 716->717 720 4068b3 718->720 721 406727-406764 718->721 724 4068c1-4068c4 720->724 725 4068b5-4068bf 720->725 722 406857-40685c 721->722 723 40676a-406771 721->723 729 40685e-406864 722->729 730 40688f-406894 722->730 726 406773-406775 723->726 727 406776-406778 723->727 728 4068c6-4068cf 724->728 725->728 726->727 731 4067b5-4067b8 727->731 732 40677a-406798 call 406536 727->732 728->714 735 406702 728->735 736 406874-406880 call 406668 729->736 737 406866-406872 call 4065af 729->737 733 4068a3-4068b1 lstrlenW 730->733 734 406896-40689e call 4066a5 730->734 741 4067c8-4067cb 731->741 742 4067ba-4067c6 GetSystemDirectoryW 731->742 745 40679d-4067a1 732->745 733->728 734->733 735->715 744 406885-40688b 736->744 737->744 747 406834-406836 741->747 748 4067cd-4067db GetWindowsDirectoryW 741->748 746 406838-40683c 742->746 744->733 750 40688d 744->750 752 4067a7-4067b0 call 4066a5 745->752 753 40683e-406842 745->753 746->753 754 40684f-406855 call 4068ef 746->754 747->746 751 4067dd-4067e5 747->751 748->747 750->754 758 4067e7-4067f0 751->758 759 4067fc-406812 SHGetSpecialFolderLocation 751->759 752->746 753->754 756 406844-40684a lstrcatW 753->756 754->733 756->754 764 4067f8-4067fa 758->764 760 406830 759->760 761 406814-40682e SHGetPathFromIDListW CoTaskMemFree 759->761 760->747 761->746 761->760 764->746 764->759
                                                                APIs
                                                                • GetSystemDirectoryW.KERNEL32(00428200,00000400), ref: 004067C0
                                                                • GetWindowsDirectoryW.KERNEL32(00428200,00000400,00000000,Completed,?,00405701,Completed,00000000,00000000,00000000,00000000), ref: 004067D3
                                                                • lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                • lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                                                Strings
                                                                • \Microsoft\Internet Explorer\Quick Launch, xrefs: 00406844
                                                                • Completed, xrefs: 004066CA
                                                                • Software\Microsoft\Windows\CurrentVersion, xrefs: 0040678E
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Directory$SystemWindowslstrcatlstrlen
                                                                • String ID: Completed$Software\Microsoft\Windows\CurrentVersion$\Microsoft\Internet Explorer\Quick Launch
                                                                • API String ID: 4260037668-2193954744
                                                                • Opcode ID: a56a8a4d956183f5ceef7ff9e42496adb417aa599aaeb911d527621cdebcfcc9
                                                                • Instruction ID: 414c90a3e727c3679fd522760d05a71ccfd37451a898d0680c6fb4b4ce958948
                                                                • Opcode Fuzzy Hash: a56a8a4d956183f5ceef7ff9e42496adb417aa599aaeb911d527621cdebcfcc9
                                                                • Instruction Fuzzy Hash: CD61E172A02115EBDB20AF64CD40BAA37A5EF10314F22C13EE946B62D0DB3D49A1CB5D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                APIs
                                                                • GetDlgItem.USER32(?,00000000), ref: 6E211813
                                                                • GetWindowRect.USER32(00000000,?), ref: 6E21181E
                                                                • MapWindowPoints.USER32(00000000,?,?,00000002), ref: 6E21182E
                                                                • CreateDialogParamW.USER32(00000001,?,6E2114D6,00000000), ref: 6E211843
                                                                • SetWindowPos.USER32(00000000,00000000,?,?,?,?,00000014), ref: 6E211876
                                                                • SetWindowLongW.USER32(?,00000004,6E211407), ref: 6E211884
                                                                • GetProcessHeap.KERNEL32(00000008,00000000), ref: 6E21189E
                                                                • HeapAlloc.KERNEL32(00000000), ref: 6E2118A5
                                                                  • Part of subcall function 6E211E9C: GlobalAlloc.KERNEL32(00000040,?,?,6E2110BE,error,?,00000104), ref: 6E211EB2
                                                                  • Part of subcall function 6E211E9C: lstrcpynW.KERNEL32(00000004,?,?,6E2110BE,error,?,00000104), ref: 6E211EC8
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Window$AllocHeap$CreateDialogGlobalItemLongParamPointsProcessRectlstrcpyn
                                                                • String ID: error$p^v
                                                                • API String ID: 1928716940-3986241059
                                                                • Opcode ID: b0fcb9e15ff3fda6b1b991a4b0290de19775fd2b7aa4cef291926ec1b8fcce7b
                                                                • Instruction ID: 073dc91b65fe82781c24f2ee5eb0dc8303462e9182c2dcb0e96ac41b2dbefd9d
                                                                • Opcode Fuzzy Hash: b0fcb9e15ff3fda6b1b991a4b0290de19775fd2b7aa4cef291926ec1b8fcce7b
                                                                • Instruction Fuzzy Hash: 87310372810A18ABCF109FA5C88E9DE7FBBFB0A701B05440DFB05A7A41CBB05644CBA0
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 776 40176f-401794 call 402da6 call 405fae 781 401796-40179c call 406668 776->781 782 40179e-4017b0 call 406668 call 405f37 lstrcatW 776->782 788 4017b5-4017b6 call 4068ef 781->788 782->788 791 4017bb-4017bf 788->791 792 4017c1-4017cb call 40699e 791->792 793 4017f2-4017f5 791->793 801 4017dd-4017ef 792->801 802 4017cd-4017db CompareFileTime 792->802 795 4017f7-4017f8 call 406133 793->795 796 4017fd-401819 call 406158 793->796 795->796 803 40181b-40181e 796->803 804 40188d-4018b6 call 4056ca call 403371 796->804 801->793 802->801 805 401820-40185e call 406668 * 2 call 4066a5 call 406668 call 405cc8 803->805 806 40186f-401879 call 4056ca 803->806 818 4018b8-4018bc 804->818 819 4018be-4018ca SetFileTime 804->819 805->791 840 401864-401865 805->840 816 401882-401888 806->816 820 402c33 816->820 818->819 822 4018d0-4018db FindCloseChangeNotification 818->822 819->822 823 402c35-402c39 820->823 825 4018e1-4018e4 822->825 826 402c2a-402c2d 822->826 828 4018e6-4018f7 call 4066a5 lstrcatW 825->828 829 4018f9-4018fc call 4066a5 825->829 826->820 834 401901-402398 828->834 829->834 838 40239d-4023a2 834->838 839 402398 call 405cc8 834->839 838->823 839->838 840->816 841 401867-401868 840->841 841->806
                                                                APIs
                                                                • lstrcatW.KERNEL32(00000000,00000000), ref: 004017B0
                                                                • CompareFileTime.KERNEL32(-00000014,?,0040A5F8,0040A5F8,00000000,00000000,0040A5F8,C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES,?,?,00000031), ref: 004017D5
                                                                  • Part of subcall function 00406668: lstrcpynW.KERNEL32(?,?,00000400,004037B0,00429260,NSIS Error), ref: 00406675
                                                                  • Part of subcall function 004056CA: lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                  • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                  • Part of subcall function 004056CA: lstrcatW.KERNEL32(Completed,004030A8), ref: 00405725
                                                                  • Part of subcall function 004056CA: SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                Strings
                                                                • C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES, xrefs: 0040179E
                                                                • C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1", xrefs: 00401821, 0040183F
                                                                • C:\Program Files\Gwyddion\uninstall.exe, xrefs: 00401835, 00401851
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend$lstrcatlstrlen$CompareFileTextTimeWindowlstrcpyn
                                                                • String ID: C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1"$C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES$C:\Program Files\Gwyddion\uninstall.exe
                                                                • API String ID: 1941528284-3563039379
                                                                • Opcode ID: 8523f3ae37f4176a2d63e539cb594509097e8e98a7304b2b57234137f625434c
                                                                • Instruction ID: 87dd38174d63fc88252c3cacf76d35d2aef1a13c6195c1d88e2760da23471212
                                                                • Opcode Fuzzy Hash: 8523f3ae37f4176a2d63e539cb594509097e8e98a7304b2b57234137f625434c
                                                                • Instruction Fuzzy Hash: DE41B771500205BACF10BBB5CD85DAE7A75EF45328B20473FF422B21E1D63D89619A2E
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 842 4056ca-4056df 843 4056e5-4056f6 842->843 844 405796-40579a 842->844 845 405701-40570d lstrlenW 843->845 846 4056f8-4056fc call 4066a5 843->846 848 40572a-40572e 845->848 849 40570f-40571f lstrlenW 845->849 846->845 851 405730-405737 SetWindowTextW 848->851 852 40573d-405741 848->852 849->844 850 405721-405725 lstrcatW 849->850 850->848 851->852 853 405743-405785 SendMessageW * 3 852->853 854 405787-405789 852->854 853->854 854->844 855 40578b-40578e 854->855 855->844
                                                                APIs
                                                                • lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                • lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                • lstrcatW.KERNEL32(Completed,004030A8), ref: 00405725
                                                                • SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                                                • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                • SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                • SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                  • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                  • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSendlstrlen$lstrcat$TextWindow
                                                                • String ID: Completed
                                                                • API String ID: 1495540970-3087654605
                                                                • Opcode ID: da0887550f177a20a5adca650a80eb3065253b4758cf57a6ba66e38fd01475e6
                                                                • Instruction ID: 7f52a71d89202be05388d2ae90ba5930d13dcc1e6093ad3ff4eaa481a322a782
                                                                • Opcode Fuzzy Hash: da0887550f177a20a5adca650a80eb3065253b4758cf57a6ba66e38fd01475e6
                                                                • Instruction Fuzzy Hash: C6217A71900518FACB119FA5DD84A8EBFB8EB45360F10857AF904B62A0D67A4A509F68
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                APIs
                                                                • SendMessageW.USER32(?,0000040D,00000000), ref: 6E211CE6
                                                                • ShowWindow.USER32(00000008), ref: 6E211CF4
                                                                • KiUserCallbackDispatcher.NTDLL(?,00000000,00000000,00000000), ref: 6E211D10
                                                                • IsDialogMessageW.USER32(?), ref: 6E211D20
                                                                • IsDialogMessageW.USER32(?), ref: 6E211D30
                                                                • TranslateMessage.USER32(?), ref: 6E211D3A
                                                                • DispatchMessageW.USER32(?), ref: 6E211D44
                                                                • SetWindowLongW.USER32(?,00000004), ref: 6E211D5E
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Message$DialogWindow$CallbackDispatchDispatcherLongSendShowTranslateUser
                                                                • String ID:
                                                                • API String ID: 4159918924-0
                                                                • Opcode ID: 1cf2e3ba64fbf039c6c6598b1869f10cf352378a0eb4796b511beb928c68ac8c
                                                                • Instruction ID: 3b91c9d98879092740ae42a268eb436504fc54cb14b9d2eeb80800bc92b7716d
                                                                • Opcode Fuzzy Hash: 1cf2e3ba64fbf039c6c6598b1869f10cf352378a0eb4796b511beb928c68ac8c
                                                                • Instruction Fuzzy Hash: 3211F73281090AABCF119BA1DC4EEDE3FBBFB46702B014015EB0192915EB709749CB70
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 864 40302e-40303d 865 403057-40305d 864->865 866 40303f-403046 864->866 869 403067-403073 GetTickCount 865->869 870 40305f-403065 call 406a71 865->870 867 403048-403049 DestroyWindow 866->867 868 40304f-403055 866->868 867->868 871 4030cd-4030cf 868->871 869->871 873 403075-40307b 869->873 870->871 875 4030aa-4030c7 CreateDialogParamW ShowWindow 873->875 876 40307d-403084 873->876 875->871 876->871 877 403086-4030a3 call 403012 wsprintfW call 4056ca 876->877 881 4030a8 877->881 881->871
                                                                APIs
                                                                • DestroyWindow.USER32(00000000,00000000), ref: 00403049
                                                                • GetTickCount.KERNEL32 ref: 00403067
                                                                • wsprintfW.USER32 ref: 00403095
                                                                  • Part of subcall function 004056CA: lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                  • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                  • Part of subcall function 004056CA: lstrcatW.KERNEL32(Completed,004030A8), ref: 00405725
                                                                  • Part of subcall function 004056CA: SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                • CreateDialogParamW.USER32(0000006F,00000000,00402F93,00000000), ref: 004030B9
                                                                • ShowWindow.USER32(00000000,00000005), ref: 004030C7
                                                                  • Part of subcall function 00403012: MulDiv.KERNEL32(00008000,00000064,00006D8C), ref: 00403027
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSendWindow$lstrlen$CountCreateDestroyDialogParamShowTextTicklstrcatwsprintf
                                                                • String ID: ... %d%%
                                                                • API String ID: 722711167-2449383134
                                                                • Opcode ID: a65563718f57099a27635650194dd277da09fbe66beefc8d93bb4be83c5e7891
                                                                • Instruction ID: 5af6bf9b0b70cf9307c1258d0e5a667b07be53d22b58a3258066d7aee54b172b
                                                                • Opcode Fuzzy Hash: a65563718f57099a27635650194dd277da09fbe66beefc8d93bb4be83c5e7891
                                                                • Instruction Fuzzy Hash: E8018E70553614DBC7317F60AE08A5A3EACAB00F06F54457AF841B21E9DAB84645CBAE
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 004069DC
                                                                • wsprintfW.USER32 ref: 00406A17
                                                                • LoadLibraryExW.KERNELBASE(?,00000000,00000008), ref: 00406A2B
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: DirectoryLibraryLoadSystemwsprintf
                                                                • String ID: %s%S.dll$UXTHEME$\
                                                                • API String ID: 2200240437-1946221925
                                                                • Opcode ID: 63130bafcb32548bd4340548baa3f8658423137b3882cd96386db367ad08b740
                                                                • Instruction ID: e2ac2e7087162e0187f8b4d6776822ec24d6e31928394cf94a41c199a4feb156
                                                                • Opcode Fuzzy Hash: 63130bafcb32548bd4340548baa3f8658423137b3882cd96386db367ad08b740
                                                                • Instruction Fuzzy Hash: 3AF096B154121DA7DB14AB68DD0EF9B366CAB00705F11447EA646F20E0EB7CDA68CB98
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GlobalAlloc.KERNELBASE(00000040,?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 004029B1
                                                                • GlobalAlloc.KERNEL32(00000040,?,00000000,?), ref: 004029CD
                                                                • GlobalFree.KERNEL32(?), ref: 00402A06
                                                                • GlobalFree.KERNEL32(00000000), ref: 00402A19
                                                                • CloseHandle.KERNEL32(?,?,?,?,?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 00402A35
                                                                • DeleteFileW.KERNEL32(?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 00402A48
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Global$AllocFree$CloseDeleteFileHandle
                                                                • String ID:
                                                                • API String ID: 2667972263-0
                                                                • Opcode ID: 2421e7d21af3a58438b8f2604f73b0c275452346c617808a2d043735fc6309d0
                                                                • Instruction ID: 78b93316678d616cb595922dcd62a83f4062aa2fb33f08fb70827f98fa9650ab
                                                                • Opcode Fuzzy Hash: 2421e7d21af3a58438b8f2604f73b0c275452346c617808a2d043735fc6309d0
                                                                • Instruction Fuzzy Hash: E131B171D00124BBCF216FA9CE89D9EBE79AF09364F10023AF461762E1CB794D429B58
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenW.KERNEL32(00423748,00423748,?,%u.%u%s%s,00000005,00000000,00000000,?,000000DC,00000000,?,000000DF,00000000,00000400,?), ref: 00404F12
                                                                • wsprintfW.USER32 ref: 00404F1B
                                                                • SetDlgItemTextW.USER32(?,00423748), ref: 00404F2E
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: ItemTextlstrlenwsprintf
                                                                • String ID: %u.%u%s%s$H7B
                                                                • API String ID: 3540041739-107966168
                                                                • Opcode ID: 2edccdcb36c72f9bdce7a586f7ca7ee262dfb9f9a49697097ea36a1117f17e36
                                                                • Instruction ID: 20619224473e8c08b4fba53027c62ddcf1c3fef784a2ba69f514aa474de30786
                                                                • Opcode Fuzzy Hash: 2edccdcb36c72f9bdce7a586f7ca7ee262dfb9f9a49697097ea36a1117f17e36
                                                                • Instruction Fuzzy Hash: 1A11D8736041283BDB00A5ADDC45E9F3298AB81338F150637FA26F61D1EA79882182E8
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CreateDirectoryW.KERNELBASE(?,?,C:\Users\user\AppData\Local\Temp\), ref: 00405BDC
                                                                • GetLastError.KERNEL32 ref: 00405BF0
                                                                • SetFileSecurityW.ADVAPI32(?,80000007,00000001), ref: 00405C05
                                                                • GetLastError.KERNEL32 ref: 00405C0F
                                                                Strings
                                                                • C:\Users\user\AppData\Local\Temp\, xrefs: 00405BBF
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: ErrorLast$CreateDirectoryFileSecurity
                                                                • String ID: C:\Users\user\AppData\Local\Temp\
                                                                • API String ID: 3449924974-3081826266
                                                                • Opcode ID: 4d8c721838b8a92ea27708fe49d100345a2f80ebd1be40878b53e15a1b169c58
                                                                • Instruction ID: 886f74eda6482ab63e8fe18d08a652fea41827dc0a526659a7d7b5e138c44e4e
                                                                • Opcode Fuzzy Hash: 4d8c721838b8a92ea27708fe49d100345a2f80ebd1be40878b53e15a1b169c58
                                                                • Instruction Fuzzy Hash: 95010871D04219EAEF009FA1CD44BEFBBB8EF14314F04403ADA44B6180E7789648CB99
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SendMessageTimeoutW.USER32(00000000,00000000,?,?,?,00000002,?), ref: 00401CB3
                                                                • SendMessageW.USER32(00000000,00000000,?,?), ref: 00401CCB
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend$Timeout
                                                                • String ID: !
                                                                • API String ID: 1777923405-2657877971
                                                                • Opcode ID: b183ccb6ab3284ced798d12f720e161a9248df31e23c89b80f307d5b894ef539
                                                                • Instruction ID: e1c20d37316975b9b94706f7b3abd8da4b7b3b5136eece5bd2aa3cbae88a6c19
                                                                • Opcode Fuzzy Hash: b183ccb6ab3284ced798d12f720e161a9248df31e23c89b80f307d5b894ef539
                                                                • Instruction Fuzzy Hash: 28219E7190420AEFEF05AFA4D94AAAE7BB4FF44304F14453EF601B61D0D7B88941CB98
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenW.KERNEL32(C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000023,00000011,00000002), ref: 004024D5
                                                                • RegSetValueExW.KERNELBASE(?,?,?,?,C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000000,00000011,00000002), ref: 00402515
                                                                • RegCloseKey.ADVAPI32(?,?,?,C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000000,00000011,00000002), ref: 004025FD
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CloseValuelstrlen
                                                                • String ID: C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1"
                                                                • API String ID: 2655323295-529217095
                                                                • Opcode ID: c23fcdec70e9ceb7831d592374f9d693e5ab08b70c15ca3c3014b4063adf34c4
                                                                • Instruction ID: a516967871aadb8e7373f7254d3c24ec0cdbd982f2b4049ed7d94b0996b6da2b
                                                                • Opcode Fuzzy Hash: c23fcdec70e9ceb7831d592374f9d693e5ab08b70c15ca3c3014b4063adf34c4
                                                                • Instruction Fuzzy Hash: 4011AF71E00108BEEF10AFA1CE49EAEB6B8EB44354F11443AF404B61C1DBB98D409658
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetTickCount.KERNEL32 ref: 004061A5
                                                                • GetTempFileNameW.KERNELBASE(?,?,00000000,?,?,?,?,0040363E,1033,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 004061C0
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CountFileNameTempTick
                                                                • String ID: C:\Users\user\AppData\Local\Temp\$nsa
                                                                • API String ID: 1716503409-678247507
                                                                • Opcode ID: 6315ab6e6f8253ba2c88c9b6803a176270f8621abb800126aa0f3c3b7b9ef66c
                                                                • Instruction ID: 21b676f9b33da427d45e0b2d6905a63b6509bf3d89a4e990effff8b21c6fdcbe
                                                                • Opcode Fuzzy Hash: 6315ab6e6f8253ba2c88c9b6803a176270f8621abb800126aa0f3c3b7b9ef66c
                                                                • Instruction Fuzzy Hash: C3F09076700214BFEB008F59DD05E9AB7BCEBA1710F11803AEE05EB180E6B0A9648768
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetModuleHandleW.KERNELBASE(00000000,00000001,000000F0), ref: 00402103
                                                                • LoadLibraryExW.KERNELBASE(00000000,?,00000008,00000001,000000F0), ref: 00402114
                                                                • KiUserCallbackDispatcher.NTDLL(?,00000400,?,0040CE58,0040A000,?,00000008,00000001,000000F0), ref: 00402164
                                                                  • Part of subcall function 004056CA: lstrlenW.KERNEL32(Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                  • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Completed,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                  • Part of subcall function 004056CA: lstrcatW.KERNEL32(Completed,004030A8), ref: 00405725
                                                                  • Part of subcall function 004056CA: SetWindowTextW.USER32(Completed,Completed), ref: 00405737
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                  • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                • FreeLibrary.KERNEL32(?,?,000000F7,?,?,00000008,00000001,000000F0), ref: 00402191
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend$Librarylstrlen$CallbackDispatcherFreeHandleLoadModuleTextUserWindowlstrcat
                                                                • String ID:
                                                                • API String ID: 719239633-0
                                                                • Opcode ID: c0fc562415b006524e612b10bc8b4f19115c3b5e74acc175c6571b6fb39ea03e
                                                                • Instruction ID: 1e7e134340f86907485d462c64894228b35b3344cd4f3d252167f9901203d809
                                                                • Opcode Fuzzy Hash: c0fc562415b006524e612b10bc8b4f19115c3b5e74acc175c6571b6fb39ea03e
                                                                • Instruction Fuzzy Hash: C521C231904104FADF11AFA5CF48A9D7A70BF48354F60413BF605B91E0DBBD8A929A5D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                  • Part of subcall function 00405FE2: CharNextW.USER32(?,?,00425F50,?,00406056,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0,00000000), ref: 00405FF0
                                                                  • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 00405FF5
                                                                  • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 0040600D
                                                                • GetFileAttributesW.KERNELBASE(?,?,00000000,0000005C,00000000,000000F0), ref: 0040161A
                                                                  • Part of subcall function 00405B99: CreateDirectoryW.KERNELBASE(?,?,C:\Users\user\AppData\Local\Temp\), ref: 00405BDC
                                                                • SetCurrentDirectoryW.KERNELBASE(?,C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES,?,00000000,000000F0), ref: 0040164D
                                                                Strings
                                                                • C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES, xrefs: 00401640
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CharNext$Directory$AttributesCreateCurrentFile
                                                                • String ID: C:\Program Files\Gwyddion\share\locale\es\LC_MESSAGES
                                                                • API String ID: 1892508949-923977919
                                                                • Opcode ID: 5100f8edfc5c73fcce05ecfe13f7e88f84c01c09c33b7a9b27ef58f2b5b0e964
                                                                • Instruction ID: a0118e7b9b939ef3ea3e51add98df8039a5aa70d3b8e99a19be4f9c31e9f39fe
                                                                • Opcode Fuzzy Hash: 5100f8edfc5c73fcce05ecfe13f7e88f84c01c09c33b7a9b27ef58f2b5b0e964
                                                                • Instruction Fuzzy Hash: 04112231508105EBCF30AFA0CD4099E36A0EF15329B28493BF901B22F1DB3E4982DB5E
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                  • Part of subcall function 00406668: lstrcpynW.KERNEL32(?,?,00000400,004037B0,00429260,NSIS Error), ref: 00406675
                                                                  • Part of subcall function 00405FE2: CharNextW.USER32(?,?,00425F50,?,00406056,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0,00000000), ref: 00405FF0
                                                                  • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 00405FF5
                                                                  • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 0040600D
                                                                • lstrlenW.KERNEL32(00425F50,00000000,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0,00000000), ref: 00406098
                                                                • GetFileAttributesW.KERNELBASE(00425F50,00425F50,00425F50,00425F50,00425F50,00425F50,00000000,00425F50,00425F50,74DF3420,?,74DF2EE0,00405D94,?,74DF3420,74DF2EE0), ref: 004060A8
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CharNext$AttributesFilelstrcpynlstrlen
                                                                • String ID: P_B
                                                                • API String ID: 3248276644-906794629
                                                                • Opcode ID: 900e3a3aedd828ccf636743a116f58552bc6887dcb5d3e9637a901da882d1290
                                                                • Instruction ID: df110f430b83b9381375b5fd3fa67f6c4419d4890c6468873e0fced3c2676832
                                                                • Opcode Fuzzy Hash: 900e3a3aedd828ccf636743a116f58552bc6887dcb5d3e9637a901da882d1290
                                                                • Instruction Fuzzy Hash: 0DF07826144A1216E622B23A0C05BAF05098F82354B07063FFC93B22E1DF3C8973C43E
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 9f3cc98df1e3ecd253cf91825a4064c55af45d063240f038e3dc270cc3f81a7c
                                                                • Instruction ID: 10cc2cc0f2c892254e5285b7a8bac4c216a70fda8fb68dfa7c3680dd08f727d3
                                                                • Opcode Fuzzy Hash: 9f3cc98df1e3ecd253cf91825a4064c55af45d063240f038e3dc270cc3f81a7c
                                                                • Instruction Fuzzy Hash: 55A15571E04228DBDF28CFA8C8547ADBBB1FF44305F10842AD856BB281D778A986DF45
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 97748a737734167d5846b9d8dd4738ada3f75d0b833fdafa89234df63502b4a5
                                                                • Instruction ID: d49815ad38d406b3cd0a1a90ea7be1526168d9e39684835ffa6a026ef1ef4849
                                                                • Opcode Fuzzy Hash: 97748a737734167d5846b9d8dd4738ada3f75d0b833fdafa89234df63502b4a5
                                                                • Instruction Fuzzy Hash: 91913270D04228DBEF28CF98C8547ADBBB1FF44305F14816AD856BB281D778A986DF45
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 93c083d05bcdf6195ca23c2a54f1652f9efbc2f2339d63ff2f761c89645e7c92
                                                                • Instruction ID: 0a676f48c9952aad729ccf503b6a86ce95496029d8c73069f89f3073be052f6e
                                                                • Opcode Fuzzy Hash: 93c083d05bcdf6195ca23c2a54f1652f9efbc2f2339d63ff2f761c89645e7c92
                                                                • Instruction Fuzzy Hash: C3813471D08228DFDF24CFA8C8847ADBBB1FB44305F24816AD456BB281D778A986DF05
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 42fe04b556333c9da529a864bcd0db0a91825228453d2ef5331aa29539740558
                                                                • Instruction ID: 41bbaa2e3590000dceee7c9791d291245bc26db239967492cd44d063337b5de0
                                                                • Opcode Fuzzy Hash: 42fe04b556333c9da529a864bcd0db0a91825228453d2ef5331aa29539740558
                                                                • Instruction Fuzzy Hash: 3E814831D08228DBEF28CFA8C8447ADBBB1FF44305F14816AD856B7281D778A986DF45
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 7ccf24f4e081119859c9f0e48baaaa1d38e3934f3a3b1d8a87677b84cb71901f
                                                                • Instruction ID: 4a3513360c1d1cc4287bdabe5afcaa460628bed3c0d7ae87261646ca99be8a9f
                                                                • Opcode Fuzzy Hash: 7ccf24f4e081119859c9f0e48baaaa1d38e3934f3a3b1d8a87677b84cb71901f
                                                                • Instruction Fuzzy Hash: 0D711271D04228DBEF28CF98C9947ADBBF1FB44305F14806AD856B7280D738A986DF05
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: c68610f165bc536a6a66ce61bc987e677a2aaa57ebbfa987bd426c3fc0f92c56
                                                                • Instruction ID: aecab3f40db1f9fc07a3dc9ea3777efa7aa3d7dc23f88bc09ddd959c6243594a
                                                                • Opcode Fuzzy Hash: c68610f165bc536a6a66ce61bc987e677a2aaa57ebbfa987bd426c3fc0f92c56
                                                                • Instruction Fuzzy Hash: 2B711571D04228DBEF28CF98C8547ADBBB1FF44305F14806AD856BB281D778A986DF05
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: b33066b9a67caffcdb2859c2a3d237c195f810e8b6f417b46283b98aba377de3
                                                                • Instruction ID: 947ff9f4813c08031b822263453b6bbc7859602ae013fffc9a74d3363ad91bbb
                                                                • Opcode Fuzzy Hash: b33066b9a67caffcdb2859c2a3d237c195f810e8b6f417b46283b98aba377de3
                                                                • Instruction Fuzzy Hash: FE713471E04228DBEF28CF98C8547ADBBB1FF44305F15806AD856BB281C778A986DF45
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetTickCount.KERNEL32 ref: 0040348D
                                                                  • Part of subcall function 004035F8: SetFilePointer.KERNELBASE(00000000,00000000,00000000,004032F6,?), ref: 00403606
                                                                • SetFilePointer.KERNELBASE(00000000,00000000,?,00000000,004033A3,00000004,00000000,00000000,?,?,0040331D,000000FF,00000000,00000000,?,?), ref: 004034C0
                                                                • SetFilePointer.KERNELBASE(06D84C40,00000000,00000000,00414EF0,00004000,?,00000000,004033A3,00000004,00000000,00000000,?,?,0040331D,000000FF,00000000), ref: 004035BB
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FilePointer$CountTick
                                                                • String ID:
                                                                • API String ID: 1092082344-0
                                                                • Opcode ID: ce02fe222e12e83d877d3b7aabf99e7a2bcb53596278d9d285b37d8023f85d8e
                                                                • Instruction ID: 4a0f782daef8a724a5dada35133bb9654e3c612a62d69fcdf17392b9264be50a
                                                                • Opcode Fuzzy Hash: ce02fe222e12e83d877d3b7aabf99e7a2bcb53596278d9d285b37d8023f85d8e
                                                                • Instruction Fuzzy Hash: 3A31AEB2650205EFC7209F29EE848263BADF70475A755023BE900B22F1C7B59D42DB9D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SendMessageW.USER32(00000408,?,00000000,004041FC), ref: 004045BB
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend
                                                                • String ID: x
                                                                • API String ID: 3850602802-2363233923
                                                                • Opcode ID: a4e2778218c9fdeab8ae4952123a6e605dd424a78c20075fb3486bdcc909a4f1
                                                                • Instruction ID: 271d720e87c3080f9bc4c684b425461430c88a900e0fa794081ec75d4c8aeb56
                                                                • Opcode Fuzzy Hash: a4e2778218c9fdeab8ae4952123a6e605dd424a78c20075fb3486bdcc909a4f1
                                                                • Instruction Fuzzy Hash: 58C01271646200FBCB208B00EE00F067A21B7A4B02F2088B9FB81240B48A314822DB2D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SetFilePointer.KERNELBASE(?,00000000,00000000,00000000,00000000,?,?,0040331D,000000FF,00000000,00000000,?,?), ref: 00403396
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FilePointer
                                                                • String ID:
                                                                • API String ID: 973152223-0
                                                                • Opcode ID: 9659739b35da8af7fb285d31f71ea9b2402f124514f270f9d6eabe2ecb184dd4
                                                                • Instruction ID: 963a71f16df831595788c30304fa9cedbf2cad19eb63879c1ada4fe15c9ed8fa
                                                                • Opcode Fuzzy Hash: 9659739b35da8af7fb285d31f71ea9b2402f124514f270f9d6eabe2ecb184dd4
                                                                • Instruction Fuzzy Hash: 93319F70200219EFDB129F65ED84E9A3FA8FF00355B10443AF905EA1A1D778CE51DBA9
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • RegQueryValueExW.ADVAPI32(00000000,00000000,?,?,?,?,?,?,?,?,00000033), ref: 0040255B
                                                                • RegCloseKey.ADVAPI32(?,?,?,C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1",00000000,00000011,00000002), ref: 004025FD
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CloseQueryValue
                                                                • String ID:
                                                                • API String ID: 3356406503-0
                                                                • Opcode ID: 65252af27aff81f363bfff3291cf17b609d6a402d488cd426901fcd094bf1953
                                                                • Instruction ID: eaee0c709954dca67eb2d1c59e66f6ca2c08a593dad46a4828cc6951ae7b5872
                                                                • Opcode Fuzzy Hash: 65252af27aff81f363bfff3291cf17b609d6a402d488cd426901fcd094bf1953
                                                                • Instruction Fuzzy Hash: 5C116D71900219EBDF14DFA4DE589AE7774FF04345B20443BE401B62D0E7B88A45EB5D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • RegQueryValueExW.KERNELBASE(00000020,00000020,00000000,00000000,00428200,00000800,00000000,?,00000000,00000020,00000020,00428200,?,?,0040679D,80000002), ref: 0040657C
                                                                • RegCloseKey.KERNELBASE(00000020,?,0040679D,80000002,Software\Microsoft\Windows\CurrentVersion,00000020,00428200,00000020,00000000,Completed), ref: 00406587
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CloseQueryValue
                                                                • String ID:
                                                                • API String ID: 3356406503-0
                                                                • Opcode ID: 5e421e957683aa7155fe1e1f393967b6404614e05e15b89e99e168e2dc4a01c3
                                                                • Instruction ID: 52dd0fe420a7c1e2827d1a164217834099ee72e945ce70567094b216899e5676
                                                                • Opcode Fuzzy Hash: 5e421e957683aa7155fe1e1f393967b6404614e05e15b89e99e168e2dc4a01c3
                                                                • Instruction Fuzzy Hash: C4017C72500209FADF21CF51DD09EDB3BA8EF54364F01803AFD1AA2190D738D964DBA4
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • MulDiv.KERNEL32(00007530,00000000,00000000), ref: 004013E4
                                                                • SendMessageW.USER32(?,00000402,00000000), ref: 004013F4
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend
                                                                • String ID:
                                                                • API String ID: 3850602802-0
                                                                • Opcode ID: 09e122a9c5ca6d14e20a0c17f6d9bb0c47d9e5f073d0cae9cf8d248ab6fa9320
                                                                • Instruction ID: af17251ef12b8b272b5eaf8d1bef107274ce64b6e67bb2dd4604cf2723900e86
                                                                • Opcode Fuzzy Hash: 09e122a9c5ca6d14e20a0c17f6d9bb0c47d9e5f073d0cae9cf8d248ab6fa9320
                                                                • Instruction Fuzzy Hash: 6F012831724220EBEB295B389D05B6A3698E710714F10857FF855F76F1E678CC029B6D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • OleInitialize.OLE32(00000000), ref: 004057AD
                                                                  • Part of subcall function 00404610: SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                                                • OleUninitialize.OLE32(00000404,00000000,?,00000000,?), ref: 004057F9
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: InitializeMessageSendUninitialize
                                                                • String ID:
                                                                • API String ID: 2896919175-0
                                                                • Opcode ID: b14588aebbadd05bc97f1dd14ffe2b6982532d9bfcd69c4411fdff16e8679f7d
                                                                • Instruction ID: 683c9d360a8619809caff371317e20043972a5eac84f98be19084c03997f3dfe
                                                                • Opcode Fuzzy Hash: b14588aebbadd05bc97f1dd14ffe2b6982532d9bfcd69c4411fdff16e8679f7d
                                                                • Instruction Fuzzy Hash: 84F09072600600CBD6215B54AD01B17B764EB84304F45447FFF89732F0DB7A48529A6E
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetModuleHandleA.KERNEL32(?,00000020,?,00403750,0000000B), ref: 00406A47
                                                                • GetProcAddress.KERNEL32(00000000,?), ref: 00406A62
                                                                  • Part of subcall function 004069C5: GetSystemDirectoryW.KERNEL32(?,00000104), ref: 004069DC
                                                                  • Part of subcall function 004069C5: wsprintfW.USER32 ref: 00406A17
                                                                  • Part of subcall function 004069C5: LoadLibraryExW.KERNELBASE(?,00000000,00000008), ref: 00406A2B
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: AddressDirectoryHandleLibraryLoadModuleProcSystemwsprintf
                                                                • String ID:
                                                                • API String ID: 2547128583-0
                                                                • Opcode ID: a89557e88259ac32882439a66efe2bded2b7fe37332f597cb2162f61758b0433
                                                                • Instruction ID: 0464b4a7853edb7079d0776797c383171681067eb8499b99987f1e8ea9f8efb8
                                                                • Opcode Fuzzy Hash: a89557e88259ac32882439a66efe2bded2b7fe37332f597cb2162f61758b0433
                                                                • Instruction Fuzzy Hash: E0E086727042106AD210A6745D08D3773E8ABC6711307883EF557F2040D738DC359A79
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,80000000,00000003), ref: 0040615C
                                                                • CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: File$AttributesCreate
                                                                • String ID:
                                                                • API String ID: 415043291-0
                                                                • Opcode ID: bc48b18717e6d0ecb647aea7fc0ab07bebcbb2e2e3a0bd9572a83b91cd6509df
                                                                • Instruction ID: 0e1b57c135d9ed337dcee0f1630d7a3ffd6699826ab823f4ff8c6da5104765b0
                                                                • Opcode Fuzzy Hash: bc48b18717e6d0ecb647aea7fc0ab07bebcbb2e2e3a0bd9572a83b91cd6509df
                                                                • Instruction Fuzzy Hash: DCD09E71254201AFEF0D8F20DF16F2E7AA2EB94B04F11952CB682940E1DAB15C15AB19
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetFileAttributesW.KERNELBASE(?,?,00405D38,?,?,00000000,00405F0E,?,?,?,?), ref: 00406138
                                                                • SetFileAttributesW.KERNEL32(?,00000000), ref: 0040614C
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: AttributesFile
                                                                • String ID:
                                                                • API String ID: 3188754299-0
                                                                • Opcode ID: a764032cc0ce64e7f87df91ab84dfb27e8fca44cfd77f22972d2dc2d25b91850
                                                                • Instruction ID: 3e6336b5c460747e2e1e0fbe3c4db8defb42c0044e1a92967a1d29a512d2a4bc
                                                                • Opcode Fuzzy Hash: a764032cc0ce64e7f87df91ab84dfb27e8fca44cfd77f22972d2dc2d25b91850
                                                                • Instruction Fuzzy Hash: 73D0C972514130ABC2102728AE0889ABB56EB64271B014A35F9A5A62B0CB304C628A98
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CreateDirectoryW.KERNELBASE(?,00000000,00403633,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405C1C
                                                                • GetLastError.KERNEL32 ref: 00405C2A
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CreateDirectoryErrorLast
                                                                • String ID:
                                                                • API String ID: 1375471231-0
                                                                • Opcode ID: 3d774f31bfc7c5d70b6f8c035fc875d1b29c99f0800ffc9da4ab7b914865a185
                                                                • Instruction ID: 66e62c5d6c7775ff4cea72667941029308d228c48495a605f612c1d2d9e1fc74
                                                                • Opcode Fuzzy Hash: 3d774f31bfc7c5d70b6f8c035fc875d1b29c99f0800ffc9da4ab7b914865a185
                                                                • Instruction Fuzzy Hash: FBC04C31218605AEE7605B219F0CB177A94DB50741F114839E186F40A0DA788455D92D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GlobalFree.KERNEL32(00000000), ref: 00401C0B
                                                                • GlobalAlloc.KERNELBASE(00000040,00000804), ref: 00401C1D
                                                                  • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                  • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Global$AllocFreelstrcatlstrlen
                                                                • String ID:
                                                                • API String ID: 3292104215-0
                                                                • Opcode ID: 8fff9c0e4c5b0ae78a96e2b6671f0d610947169ea12ed52eae8356a764bd9261
                                                                • Instruction ID: d74cddccbdd50a14e5bf5e3e63826a63b2a65df0fd836753f00777670cd3b466
                                                                • Opcode Fuzzy Hash: 8fff9c0e4c5b0ae78a96e2b6671f0d610947169ea12ed52eae8356a764bd9261
                                                                • Instruction Fuzzy Hash: 5321D872904210DBDB20EFA4DEC4E5E73A4AB047157150A3BF542F72D0D6BD9C518BAD
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • RegCreateKeyExW.KERNELBASE(00000000,?,00000000,00000000,00000000,?,00000000,?,00000000,?,?,?,00402E57,00000000,?,?), ref: 0040652C
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Create
                                                                • String ID:
                                                                • API String ID: 2289755597-0
                                                                • Opcode ID: f0170b29b94a961cdf0cc122a920c286c7e5b726b195fdee8f598fb45efbb6e4
                                                                • Instruction ID: 390987c888b9fe28ccc3a202ccefe0e129b8fdbaba7b34d45eb5723cdb444700
                                                                • Opcode Fuzzy Hash: f0170b29b94a961cdf0cc122a920c286c7e5b726b195fdee8f598fb45efbb6e4
                                                                • Instruction Fuzzy Hash: C1E0ECB2010109BEEF099F90EC0ADBB372DEB04704F41492EF907E4091E6B5AE70AA34
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • WriteFile.KERNELBASE(?,00000000,00000000,00000000,00000000,0040DD57,0040CEF0,00403579,0040CEF0,0040DD57,00414EF0,00004000,?,00000000,004033A3,00000004), ref: 0040621E
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FileWrite
                                                                • String ID:
                                                                • API String ID: 3934441357-0
                                                                • Opcode ID: 3dec9289c2e50997f5b7f42c7d661c3d3292bfbb80aff78175bf8fde073ef60e
                                                                • Instruction ID: 398385dbb58ca0a44fa402a726e0ab0b2131cea3ae709c8a1b666252059dd88a
                                                                • Opcode Fuzzy Hash: 3dec9289c2e50997f5b7f42c7d661c3d3292bfbb80aff78175bf8fde073ef60e
                                                                • Instruction Fuzzy Hash: F6E08632141129EBCF10AE548C00EEB375CFB01350F014476F955E3040D330E93087A5
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • ReadFile.KERNELBASE(?,00000000,00000000,00000000,00000000,00414EF0,0040CEF0,004035F5,?,?,004034F9,00414EF0,00004000,?,00000000,004033A3), ref: 004061EF
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FileRead
                                                                • String ID:
                                                                • API String ID: 2738559852-0
                                                                • Opcode ID: 0024165f2f5d2011be9120f41fe866c54f7b8e58de784a1218c53157080e4b8c
                                                                • Instruction ID: 689b8facb1381159ac92aeccc4703b7db47ce2620db9a14c340ec3ef8a35c8b1
                                                                • Opcode Fuzzy Hash: 0024165f2f5d2011be9120f41fe866c54f7b8e58de784a1218c53157080e4b8c
                                                                • Instruction Fuzzy Hash: C1E0863250021AABDF10AE518C04AEB375CEB01360F014477F922E2150D230E82187E8
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,00000020,00428200,?,00000020,?,00406563,?,00000000,00000020,00000020,00428200,?), ref: 004064F9
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Open
                                                                • String ID:
                                                                • API String ID: 71445658-0
                                                                • Opcode ID: 759d75b29ffd137612e455953a298f0698f5beae901813cd77d6ec234b014f3e
                                                                • Instruction ID: 5036765eb4ab6e58186d81024f5778724aa2024cd81e2e1d5ca813995cf5404a
                                                                • Opcode Fuzzy Hash: 759d75b29ffd137612e455953a298f0698f5beae901813cd77d6ec234b014f3e
                                                                • Instruction Fuzzy Hash: BAD0123210020DBBDF115F90AD01FAB375DAB08310F018426FE06A4092D775D534A728
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                  • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                  • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                                                • SetDlgItemTextW.USER32(?,?,00000000), ref: 004045DE
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: ItemTextlstrcatlstrlen
                                                                • String ID:
                                                                • API String ID: 281422827-0
                                                                • Opcode ID: 73b3e70f26523695344aa313222f8106b15ff01fe64d2e6c86eba35ea0453547
                                                                • Instruction ID: ac81fd1055ba0297197cac3df011722fda0f302089e5b839fe348bc6695a069d
                                                                • Opcode Fuzzy Hash: 73b3e70f26523695344aa313222f8106b15ff01fe64d2e6c86eba35ea0453547
                                                                • Instruction Fuzzy Hash: 77C04C7554C300BFE641A755CC42F1FB799EF94319F04C92EB19DE11D1C63984309A2A
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend
                                                                • String ID:
                                                                • API String ID: 3850602802-0
                                                                • Opcode ID: 8557fc69485774ba4641c6a2d2b4437b1a5152abf7221d5f63999a85994ee7b6
                                                                • Instruction ID: 1d0f09303225af8c469e983b8f6ba21d59f3f36861eec243a4bc5be8392dea83
                                                                • Opcode Fuzzy Hash: 8557fc69485774ba4641c6a2d2b4437b1a5152abf7221d5f63999a85994ee7b6
                                                                • Instruction Fuzzy Hash: 9EC09B71741700FBDE209B509F45F077794A754701F154979B741F60E0D775D410D62D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SetFilePointer.KERNELBASE(00000000,00000000,00000000,004032F6,?), ref: 00403606
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FilePointer
                                                                • String ID:
                                                                • API String ID: 973152223-0
                                                                • Opcode ID: e1e4f0b9cbde4cef3e4374ef9de0ac4f9a9ec0cef6a377cf2568efe91b529ef4
                                                                • Instruction ID: 036c8468b6dd2e012b37e6e875261c5f60c7cf4634656b07e897873a541603b6
                                                                • Opcode Fuzzy Hash: e1e4f0b9cbde4cef3e4374ef9de0ac4f9a9ec0cef6a377cf2568efe91b529ef4
                                                                • Instruction Fuzzy Hash: 1FB01231140304BFDA214F10DF09F067B21BB94700F20C034B384380F086711435EB0D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend
                                                                • String ID:
                                                                • API String ID: 3850602802-0
                                                                • Opcode ID: 70666cfd2db8a5712e0e3ed728d50a5e19955e25533eceda6abdc0f56bdf790a
                                                                • Instruction ID: 26063d6d883ff380d2e1d7f9fe2b9d631bf033e6200e0a233fd0d302f8c02db7
                                                                • Opcode Fuzzy Hash: 70666cfd2db8a5712e0e3ed728d50a5e19955e25533eceda6abdc0f56bdf790a
                                                                • Instruction Fuzzy Hash: 5BB01235286A00FBDE614B00DE09F457E62F764B01F048078F741240F0CAB300B5DF19
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • KiUserCallbackDispatcher.NTDLL(?,004043BD), ref: 004045F0
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CallbackDispatcherUser
                                                                • String ID:
                                                                • API String ID: 2492992576-0
                                                                • Opcode ID: b9cabee76f1705efe6df0b682491f715d60f75bd340f366a7093c5de42737780
                                                                • Instruction ID: 97f05af551d2e904d84950d91e3a9b28448307360fbef328a82585e9573e9e03
                                                                • Opcode Fuzzy Hash: b9cabee76f1705efe6df0b682491f715d60f75bd340f366a7093c5de42737780
                                                                • Instruction Fuzzy Hash: DBA001B6604500ABDE129F61EF09D0ABB72EBA4B02B418579A28590034CA365961FB1D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • FindFirstFileW.KERNEL32(00000000,?,00000002), ref: 0040291A
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: FileFindFirst
                                                                • String ID:
                                                                • API String ID: 1974802433-0
                                                                • Opcode ID: b2f27a8a5f9b700f187602bb898c1293859530a573ae52e9df8ecc114fa703e5
                                                                • Instruction ID: b84bdfeecc4e8c0803ac0e71b8711fc90ef1d688bdc4be786e729a17b55638d3
                                                                • Opcode Fuzzy Hash: b2f27a8a5f9b700f187602bb898c1293859530a573ae52e9df8ecc114fa703e5
                                                                • Instruction Fuzzy Hash: 47F05E71A04105EBDB01DBB4EE49AAEB378EF14314F60457BE101F21D0E7B88E529B29
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetDlgItem.USER32(?,000003F9), ref: 00405049
                                                                • GetDlgItem.USER32(?,00000408), ref: 00405054
                                                                • GlobalAlloc.KERNEL32(00000040,?), ref: 0040509E
                                                                • LoadImageW.USER32(0000006E,00000000,00000000,00000000,00000000), ref: 004050B5
                                                                • SetWindowLongW.USER32(?,000000FC,0040563E), ref: 004050CE
                                                                • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000006,00000000), ref: 004050E2
                                                                • ImageList_AddMasked.COMCTL32(00000000,00000000,00FF00FF), ref: 004050F4
                                                                • SendMessageW.USER32(?,00001109,00000002), ref: 0040510A
                                                                • SendMessageW.USER32(?,0000111C,00000000,00000000), ref: 00405116
                                                                • SendMessageW.USER32(?,0000111B,00000010,00000000), ref: 00405128
                                                                • DeleteObject.GDI32(00000000), ref: 0040512B
                                                                • SendMessageW.USER32(?,00000143,00000000,00000000), ref: 00405156
                                                                • SendMessageW.USER32(?,00000151,00000000,00000000), ref: 00405162
                                                                • SendMessageW.USER32(?,00001132,00000000,?), ref: 004051FD
                                                                • SendMessageW.USER32(?,0000110A,00000003,00000110), ref: 0040522D
                                                                  • Part of subcall function 004045F9: SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                                                • SendMessageW.USER32(?,00001132,00000000,?), ref: 00405241
                                                                • GetWindowLongW.USER32(?,000000F0), ref: 0040526F
                                                                • SetWindowLongW.USER32(?,000000F0,00000000), ref: 0040527D
                                                                • ShowWindow.USER32(?,00000005), ref: 0040528D
                                                                • SendMessageW.USER32(?,00000419,00000000,?), ref: 00405388
                                                                • SendMessageW.USER32(?,00000147,00000000,00000000), ref: 004053ED
                                                                • SendMessageW.USER32(?,00000150,00000000,00000000), ref: 00405402
                                                                • SendMessageW.USER32(?,00000420,00000000,00000020), ref: 00405426
                                                                • SendMessageW.USER32(?,00000200,00000000,00000000), ref: 00405446
                                                                • ImageList_Destroy.COMCTL32(?), ref: 0040545B
                                                                • GlobalFree.KERNEL32(?), ref: 0040546B
                                                                • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 004054E4
                                                                • SendMessageW.USER32(?,00001102,?,?), ref: 0040558D
                                                                • SendMessageW.USER32(?,0000113F,00000000,00000008), ref: 0040559C
                                                                • InvalidateRect.USER32(?,00000000,00000001), ref: 004055C7
                                                                • ShowWindow.USER32(?,00000000), ref: 00405615
                                                                • GetDlgItem.USER32(?,000003FE), ref: 00405620
                                                                • ShowWindow.USER32(00000000), ref: 00405627
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: MessageSend$Window$Image$ItemList_LongShow$Global$AllocCreateDeleteDestroyFreeInvalidateLoadMaskedObjectRect
                                                                • String ID: $M$N
                                                                • API String ID: 2564846305-813528018
                                                                • Opcode ID: 950969970af6d10ef62121ad67a768569704eb6391eae900e1ce4f9d1827afee
                                                                • Instruction ID: a1eb65f7683e17450fca8d4cb4c1055b074660be5b1b810df034ff690b7f681c
                                                                • Opcode Fuzzy Hash: 950969970af6d10ef62121ad67a768569704eb6391eae900e1ce4f9d1827afee
                                                                • Instruction Fuzzy Hash: 2A025CB0900609EFDF20DF65CD45AAE7BB5FB44315F10817AEA10BA2E1D7798A52CF18
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                  • Part of subcall function 6E211E4E: lstrcpynW.KERNEL32(6E211054,?,?,?,6E211054,?), ref: 6E211E7B
                                                                  • Part of subcall function 6E211E4E: GlobalFree.KERNEL32 ref: 6E211E8B
                                                                • lstrcmpiW.KERNEL32(?,save,6E214920,00000400,6E215128,00000400,?,00000005), ref: 6E211168
                                                                • GetFileAttributesW.KERNEL32(6E215128), ref: 6E21117A
                                                                • lstrcpyW.KERNEL32(6E215928,6E215128), ref: 6E211193
                                                                • lstrcpyW.KERNEL32(6E214920,All Files|*.*), ref: 6E2111B8
                                                                • CharNextW.USER32(6E214920), ref: 6E2111D9
                                                                • GetCurrentDirectoryW.KERNEL32(00000400,6E214120), ref: 6E2111F1
                                                                • GetSaveFileNameW.COMDLG32(0000004C), ref: 6E211205
                                                                • GetOpenFileNameW.COMDLG32(0000004C), ref: 6E21120D
                                                                • CommDlgExtendedError.COMDLG32 ref: 6E211213
                                                                • GetSaveFileNameW.COMDLG32(0000004C), ref: 6E211230
                                                                • GetOpenFileNameW.COMDLG32(0000004C), ref: 6E211238
                                                                • SetCurrentDirectoryW.KERNEL32(6E214120,6E215128), ref: 6E211250
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: File$Name$CurrentDirectoryOpenSavelstrcpy$AttributesCharCommErrorExtendedFreeGlobalNextlstrcmpilstrcpyn
                                                                • String ID: A!n$ I!n$(Q!n$(Y!n$All Files|*.*$L$save
                                                                • API String ID: 3853173656-2056385730
                                                                • Opcode ID: 43bd716d4f2327950939fe569e6b74c60920503cbc0eed04ef26b18a9dcf2a14
                                                                • Instruction ID: 76eff207a3308ca8249bc93e6fe339ca9f11e68fe915255d7fe4a10f04c587c1
                                                                • Opcode Fuzzy Hash: 43bd716d4f2327950939fe569e6b74c60920503cbc0eed04ef26b18a9dcf2a14
                                                                • Instruction Fuzzy Hash: E141917190820DABDB009FD4C84DACE7BFBBB1A316B154119EB15D6640DB748B89CA71
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CloseHandle.KERNEL32(00000000,?,00000000,00000001,?,00000000,?,?,00406449,?,?), ref: 004062E9
                                                                • GetShortPathNameW.KERNEL32(?,00426DE8,00000400), ref: 004062F2
                                                                  • Part of subcall function 004060BD: lstrlenA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060CD
                                                                  • Part of subcall function 004060BD: lstrlenA.KERNEL32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060FF
                                                                • GetShortPathNameW.KERNEL32(?,004275E8,00000400), ref: 0040630F
                                                                • wsprintfA.USER32 ref: 0040632D
                                                                • GetFileSize.KERNEL32(00000000,00000000,004275E8,C0000000,00000004,004275E8,?,?,?,?,?), ref: 00406368
                                                                • GlobalAlloc.KERNEL32(00000040,0000000A,?,?,?,?), ref: 00406377
                                                                • lstrcpyA.KERNEL32(00000000,[Rename],00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004063AF
                                                                • SetFilePointer.KERNEL32(0040A5B0,00000000,00000000,00000000,00000000,004269E8,00000000,-0000000A,0040A5B0,00000000,[Rename],00000000,00000000,00000000), ref: 00406405
                                                                • GlobalFree.KERNEL32(00000000), ref: 00406416
                                                                • CloseHandle.KERNEL32(00000000,?,?,?,?), ref: 0040641D
                                                                  • Part of subcall function 00406158: GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,80000000,00000003), ref: 0040615C
                                                                  • Part of subcall function 00406158: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: File$CloseGlobalHandleNamePathShortlstrlen$AllocAttributesCreateFreePointerSizelstrcpywsprintf
                                                                • String ID: %ls=%ls$[Rename]$mB$uB$uB
                                                                • API String ID: 2171350718-2295842750
                                                                • Opcode ID: b2067825d6455a5a6fbc0e1ac0a55e75a76fa2936571f052824e5b49ab30fb97
                                                                • Instruction ID: df9b4e9fb9d32bd4c250032a1d399944af7a2e4c2f0bdec2b7d3959d12e60cc8
                                                                • Opcode Fuzzy Hash: b2067825d6455a5a6fbc0e1ac0a55e75a76fa2936571f052824e5b49ab30fb97
                                                                • Instruction Fuzzy Hash: B8314331200315BBD2206B619D49F5B3AACEF85704F16003BFD02FA2C2EA7DD82186BD
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • DefWindowProcW.USER32(?,00000046,?,?), ref: 0040102C
                                                                • BeginPaint.USER32(?,?), ref: 00401047
                                                                • GetClientRect.USER32(?,?), ref: 0040105B
                                                                • CreateBrushIndirect.GDI32(00000000), ref: 004010CF
                                                                • FillRect.USER32(00000000,?,00000000), ref: 004010E4
                                                                • DeleteObject.GDI32(?), ref: 004010ED
                                                                • CreateFontIndirectW.GDI32(?), ref: 00401105
                                                                • SetBkMode.GDI32(00000000,00000001), ref: 00401126
                                                                • SetTextColor.GDI32(00000000,000000FF), ref: 00401130
                                                                • SelectObject.GDI32(00000000,?), ref: 00401140
                                                                • DrawTextW.USER32(00000000,00429260,000000FF,00000010,00000820), ref: 00401156
                                                                • SelectObject.GDI32(00000000,00000000), ref: 00401160
                                                                • DeleteObject.GDI32(?), ref: 00401165
                                                                • EndPaint.USER32(?,?), ref: 0040116E
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Object$CreateDeleteIndirectPaintRectSelectText$BeginBrushClientColorDrawFillFontModeProcWindow
                                                                • String ID: F
                                                                • API String ID: 941294808-1304234792
                                                                • Opcode ID: 8da9fae8b34351ceae2931000ebd9f39a308799c7d87b7a6dbcfe72b45b7384c
                                                                • Instruction ID: e2f9fea5dfd6f059ba8eeb08e8d10ac227d01a2162b8a260283931f50cd0bfbf
                                                                • Opcode Fuzzy Hash: 8da9fae8b34351ceae2931000ebd9f39a308799c7d87b7a6dbcfe72b45b7384c
                                                                • Instruction Fuzzy Hash: 33418B71800209EFCF058FA5DE459AF7BB9FF45315F00802AF991AA2A0C7349A55DFA4
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SendMessageW.USER32(?,?,?), ref: 6E211531
                                                                • GetDlgItem.USER32(?,?), ref: 6E211544
                                                                • SetWindowLongW.USER32(?,00000000,00000000), ref: 6E211659
                                                                • GetWindowTextW.USER32(?,00000000,00000400), ref: 6E2116B0
                                                                • DrawTextW.USER32(?,00000000,000000FF,?,00000414), ref: 6E2116D1
                                                                • GetWindowLongW.USER32(?,000000EB), ref: 6E21171C
                                                                • SetTextColor.GDI32(?,00000000), ref: 6E21172F
                                                                • DrawTextW.USER32(?,00000000,000000FF,00000000,?), ref: 6E211749
                                                                • DrawFocusRect.USER32(?,00000010), ref: 6E21176A
                                                                • RemovePropW.USER32(00000000,NSIS: nsControl pointer property), ref: 6E21178E
                                                                Strings
                                                                • NSIS: nsControl pointer property, xrefs: 6E211786
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Text$DrawWindow$Long$ColorFocusItemMessagePropRectRemoveSend
                                                                • String ID: NSIS: nsControl pointer property
                                                                • API String ID: 2008169532-1714965683
                                                                • Opcode ID: 486f86a111aef5758827d93bfacda89a146dab683dfade72a538fddacfea3e79
                                                                • Instruction ID: 5239c401536ac38a2673795d6035cf1103fd7d7bbab62db46947233049323206
                                                                • Opcode Fuzzy Hash: 486f86a111aef5758827d93bfacda89a146dab683dfade72a538fddacfea3e79
                                                                • Instruction Fuzzy Hash: A381B07180820E9FDF51CF94CC88BEA7BEBFB11301F044565EA5096295CBB1CACACB60
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetWindowLongW.USER32(?,000000EB), ref: 00404648
                                                                • GetSysColor.USER32(00000000), ref: 00404686
                                                                • SetTextColor.GDI32(?,00000000), ref: 00404692
                                                                • SetBkMode.GDI32(?,?), ref: 0040469E
                                                                • GetSysColor.USER32(?), ref: 004046B1
                                                                • SetBkColor.GDI32(?,?), ref: 004046C1
                                                                • DeleteObject.GDI32(?), ref: 004046DB
                                                                • CreateBrushIndirect.GDI32(?), ref: 004046E5
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Color$BrushCreateDeleteIndirectLongModeObjectTextWindow
                                                                • String ID:
                                                                • API String ID: 2320649405-0
                                                                • Opcode ID: f4fe220c79686689299554ac50abea47664d32920eac269e7a43003585d3568b
                                                                • Instruction ID: e78b8cc9c8042372c9a7340b9b8aa9b23ded286a9f8ddc7240a2e2d8bd1f46c0
                                                                • Opcode Fuzzy Hash: f4fe220c79686689299554ac50abea47664d32920eac269e7a43003585d3568b
                                                                • Instruction Fuzzy Hash: DE2197715007049FC7309F28D908B5BBBF8AF42714F008D2EE992A22E1D739D944DB58
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • ReadFile.KERNEL32(?,?,?,?), ref: 00402758
                                                                • MultiByteToWideChar.KERNEL32(?,00000008,?,?,?,00000001), ref: 00402793
                                                                • SetFilePointer.KERNEL32(?,?,?,00000001,?,00000008,?,?,?,00000001), ref: 004027B6
                                                                • MultiByteToWideChar.KERNEL32(?,00000008,?,00000000,?,00000001,?,00000001,?,00000008,?,?,?,00000001), ref: 004027CC
                                                                  • Part of subcall function 00406239: SetFilePointer.KERNEL32(?,00000000,00000000,00000001), ref: 0040624F
                                                                • SetFilePointer.KERNEL32(?,?,?,00000001,?,?,00000002), ref: 00402878
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: File$Pointer$ByteCharMultiWide$Read
                                                                • String ID: 9
                                                                • API String ID: 163830602-2366072709
                                                                • Opcode ID: c494a9c5f1831dca55446a6dfc25bb45b63b896379fbbdb0ec38153142a3ac1c
                                                                • Instruction ID: 581cf2785626502de532f206a1de9da9d9b8d20bcd24121b7f7bd1133decb9a2
                                                                • Opcode Fuzzy Hash: c494a9c5f1831dca55446a6dfc25bb45b63b896379fbbdb0ec38153142a3ac1c
                                                                • Instruction Fuzzy Hash: CE51FB75D00219AADF20EF95CA88AAEBB75FF04304F50417BE541B62D4D7B49D82CB58
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CharNextW.USER32(?,*?|<>/":,00000000,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406952
                                                                • CharNextW.USER32(?,?,?,00000000,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406961
                                                                • CharNextW.USER32(?,00000000,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406966
                                                                • CharPrevW.USER32(?,?,74DF3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406979
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Char$Next$Prev
                                                                • String ID: *?|<>/":$C:\Users\user\AppData\Local\Temp\
                                                                • API String ID: 589700163-4010320282
                                                                • Opcode ID: 4a25a2118415850d7bb15acf585ec7f7b5de772317bec8c7d00468289de3f440
                                                                • Instruction ID: d28fb8c2eefe6f61a155ceb01790bbf8b21f4710aa7989e54d8eeb8481a577c9
                                                                • Opcode Fuzzy Hash: 4a25a2118415850d7bb15acf585ec7f7b5de772317bec8c7d00468289de3f440
                                                                • Instruction Fuzzy Hash: 2611089580061295DB303B18CC40BB762F8AF99B50F12403FE98A776C1E77C4C9286BD
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                  • Part of subcall function 6E211E4E: lstrcpynW.KERNEL32(6E211054,?,?,?,6E211054,?), ref: 6E211E7B
                                                                  • Part of subcall function 6E211E4E: GlobalFree.KERNEL32 ref: 6E211E8B
                                                                • SHBrowseForFolderW.SHELL32(?), ref: 6E2110A8
                                                                • SHGetPathFromIDListW.SHELL32(00000000,?), ref: 6E2110C8
                                                                • CoTaskMemFree.OLE32(00000000,error), ref: 6E2110E6
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Free$BrowseFolderFromGlobalListPathTasklstrcpyn
                                                                • String ID: 0vu$E$error
                                                                • API String ID: 1728609016-1006580955
                                                                • Opcode ID: e2f33d63bc6b9aec36d02c58ab4aeacfc08bc2276595ee2df64f333a1df86ef2
                                                                • Instruction ID: 42950de4a45cf981c1d3905701a143ea65727b1a74f91d31b159438c46848656
                                                                • Opcode Fuzzy Hash: e2f33d63bc6b9aec36d02c58ab4aeacfc08bc2276595ee2df64f333a1df86ef2
                                                                • Instruction Fuzzy Hash: 70214CB5D2821DABCB50DFD0C849BDE77F9AB09345F004159DB04E2200EBB49B88CFA5
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00404F9A
                                                                • GetMessagePos.USER32 ref: 00404FA2
                                                                • ScreenToClient.USER32(?,?), ref: 00404FBC
                                                                • SendMessageW.USER32(?,00001111,00000000,?), ref: 00404FCE
                                                                • SendMessageW.USER32(?,0000113E,00000000,?), ref: 00404FF4
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Message$Send$ClientScreen
                                                                • String ID: f
                                                                • API String ID: 41195575-1993550816
                                                                • Opcode ID: b2affdf3b53bee8738e3b61904ea6c87bda347b462d3853a737802ef9deed65a
                                                                • Instruction ID: ce4c7d6d39dceca23aa6ebdb29af7737867007859e7bede0b388bd4d525dd41f
                                                                • Opcode Fuzzy Hash: b2affdf3b53bee8738e3b61904ea6c87bda347b462d3853a737802ef9deed65a
                                                                • Instruction Fuzzy Hash: 3C014C71940219BADB00DBA4DD85BFEBBB8AF54711F10012BBB50B61C0D6B49A058BA5
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetDC.USER32(?), ref: 00401E51
                                                                • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00401E6B
                                                                • MulDiv.KERNEL32(00000000,00000000), ref: 00401E73
                                                                • ReleaseDC.USER32(?,00000000), ref: 00401E84
                                                                  • Part of subcall function 004066A5: lstrcatW.KERNEL32(00428200,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                  • Part of subcall function 004066A5: lstrlenW.KERNEL32(00428200,00000000,Completed,?,00405701,Completed,00000000), ref: 004068A4
                                                                • CreateFontIndirectW.GDI32(0040CDF8), ref: 00401ED3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CapsCreateDeviceFontIndirectReleaselstrcatlstrlen
                                                                • String ID: MS Shell Dlg
                                                                • API String ID: 2584051700-76309092
                                                                • Opcode ID: e128970cf71a0b284ce18b21917758e509e5717976d06807f88455f58f814df6
                                                                • Instruction ID: b9cc094806d22c325402cb6ccb5f5134c2025175c414775df3ff87de861ccae2
                                                                • Opcode Fuzzy Hash: e128970cf71a0b284ce18b21917758e509e5717976d06807f88455f58f814df6
                                                                • Instruction Fuzzy Hash: 8401B571900241EFEB005BB4EE89A9A3FB0AB15301F208939F541B71D2C6B904459BED
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • SetTimer.USER32(?,00000001,000000FA,00000000), ref: 00402FB1
                                                                • wsprintfW.USER32 ref: 00402FE5
                                                                • SetWindowTextW.USER32(?,?), ref: 00402FF5
                                                                • SetDlgItemTextW.USER32(?,00000406,?), ref: 00403007
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Text$ItemTimerWindowwsprintf
                                                                • String ID: unpacking data: %d%%$verifying installer: %d%%
                                                                • API String ID: 1451636040-1158693248
                                                                • Opcode ID: b65fa6b26e28fa793ab4966251e07a6fe500b79f9b1e2f9c66e5bc42e84335f7
                                                                • Instruction ID: 34ad84b97f90b05cf42cbebec4ee1aaae98efe268bf46a139428006d78f28757
                                                                • Opcode Fuzzy Hash: b65fa6b26e28fa793ab4966251e07a6fe500b79f9b1e2f9c66e5bc42e84335f7
                                                                • Instruction Fuzzy Hash: 25F0497050020DABEF246F60DD49BEA3B69FB00309F00803AFA05B51D0DFBD9A559F59
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • RegEnumValueW.ADVAPI32(?,00000000,?,?,00000000,00000000,00000000,00000000,?,?,00100020,?,?,?), ref: 00402EFD
                                                                • RegEnumKeyW.ADVAPI32(?,00000000,?,00000105), ref: 00402F49
                                                                • RegCloseKey.ADVAPI32(?,?,?), ref: 00402F52
                                                                • RegDeleteKeyW.ADVAPI32(?,?), ref: 00402F69
                                                                • RegCloseKey.ADVAPI32(?,?,?), ref: 00402F74
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CloseEnum$DeleteValue
                                                                • String ID:
                                                                • API String ID: 1354259210-0
                                                                • Opcode ID: 2f5760c81b9bdb573da93a40119b3bcbbfe2770e9a6cbc48a05e82d61b54c679
                                                                • Instruction ID: 37c7ba0f9c491dd7f389852fcb35a119484072d927876f68e32cbd91f0a54eef
                                                                • Opcode Fuzzy Hash: 2f5760c81b9bdb573da93a40119b3bcbbfe2770e9a6cbc48a05e82d61b54c679
                                                                • Instruction Fuzzy Hash: 6D216B7150010ABBDF11AF94CE89EEF7B7DEB50384F110076F909B21E0D7B49E54AA68
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • GetDlgItem.USER32(?,?), ref: 00401D9A
                                                                • GetClientRect.USER32(?,?), ref: 00401DE5
                                                                • LoadImageW.USER32(?,?,?,?,?,?), ref: 00401E15
                                                                • SendMessageW.USER32(?,00000172,?,00000000), ref: 00401E29
                                                                • DeleteObject.GDI32(00000000), ref: 00401E39
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: ClientDeleteImageItemLoadMessageObjectRectSend
                                                                • String ID:
                                                                • API String ID: 1849352358-0
                                                                • Opcode ID: 100b3177012869429c2005611ce111630833f28d1ab152a2d5a2575cfc39775b
                                                                • Instruction ID: 4d725fdcf847a80329c23b38d7164c003567f542edd6fcacfb34c9ebeef40da9
                                                                • Opcode Fuzzy Hash: 100b3177012869429c2005611ce111630833f28d1ab152a2d5a2575cfc39775b
                                                                • Instruction Fuzzy Hash: 67212672904119AFCB05CBA4DE45AEEBBB5EF08304F14003AF945F62A0CB389951DB98
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                  • Part of subcall function 6E2113D2: GetPropW.USER32(?,NSIS: nsControl pointer property), ref: 6E2113DB
                                                                • LoadCursorW.USER32(00000000,00007F89), ref: 6E2114A8
                                                                • SetCursor.USER32(00000000,?,?,?), ref: 6E2114AF
                                                                • CallWindowProcW.USER32(?,?,00000020,?,?), ref: 6E2114CC
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Cursor$CallLoadProcPropWindow
                                                                • String ID:
                                                                • API String ID: 1635134901-3916222277
                                                                • Opcode ID: 31fbe3fc736c431347e17c7eff10e8bd8e587e17cff37292bdb523c0f4f321f6
                                                                • Instruction ID: d16f957f278a5b0efe914441bd5374aa7b21beb66734b4d1d37e037e5ffdd863
                                                                • Opcode Fuzzy Hash: 31fbe3fc736c431347e17c7eff10e8bd8e587e17cff37292bdb523c0f4f321f6
                                                                • Instruction Fuzzy Hash: AFE0C93614810EBBDF015FD1CC09DD93BABBB19762F018424FB1994460CBB686A4DB61
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenW.KERNEL32(?,C:\Users\user\AppData\Local\Temp\,0040362D,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405F3D
                                                                • CharPrevW.USER32(?,00000000,?,C:\Users\user\AppData\Local\Temp\,0040362D,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405F47
                                                                • lstrcatW.KERNEL32(?,0040A014), ref: 00405F59
                                                                Strings
                                                                • C:\Users\user\AppData\Local\Temp\, xrefs: 00405F37
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CharPrevlstrcatlstrlen
                                                                • String ID: C:\Users\user\AppData\Local\Temp\
                                                                • API String ID: 2659869361-3081826266
                                                                • Opcode ID: 7317fb0b60a0da6156192e69c80d181f5022b3d5f83b8f009beaa75eacd33bdb
                                                                • Instruction ID: 9007417a49851ea4d61da9c71e51c63d156abd36d345156a737e00ee84923012
                                                                • Opcode Fuzzy Hash: 7317fb0b60a0da6156192e69c80d181f5022b3d5f83b8f009beaa75eacd33bdb
                                                                • Instruction Fuzzy Hash: 59D05E611019246AC111AB548D04DDB63ACAE85304742046AF601B60A0CB7E196287ED
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenA.KERNEL32(C:\Program Files\Gwyddion\uninstall.exe), ref: 00402695
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: lstrlen
                                                                • String ID: C:\Program Files\Gwyddion\bin\gwyddion.exe --remote-new "%1"$C:\Program Files\Gwyddion\uninstall.exe
                                                                • API String ID: 1659193697-875172512
                                                                • Opcode ID: 3cd7dd4fa08ce330ceb9fc547222c09b9309161f54410083866a53871864bccb
                                                                • Instruction ID: f1e3379d491753f9d96dc3c217618d2e64da59e9cc8309568291ba5d2d488428
                                                                • Opcode Fuzzy Hash: 3cd7dd4fa08ce330ceb9fc547222c09b9309161f54410083866a53871864bccb
                                                                • Instruction Fuzzy Hash: D511C472A00205EBCB10BBB18E4AA9E76619F44758F21483FE402B61C1DAFD8891965F
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenW.KERNEL32(74DEF380,?,00000400,00000400,?,74DEF380,00000000), ref: 6E21133E
                                                                • CharPrevW.USER32(74DEF380,00000000,?,74DEF380,00000000), ref: 6E211349
                                                                • MulDiv.KERNEL32(?,00000000,00000064), ref: 6E21136D
                                                                • MapDialogRect.USER32(74DEF380,74DEF380), ref: 6E211393
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2905444464.000000006E211000.00000020.00000001.01000000.00000006.sdmp, Offset: 6E210000, based on PE: true
                                                                • Associated: 00000000.00000002.2905281859.000000006E210000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905581266.000000006E213000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905702064.000000006E214000.00000008.00000001.01000000.00000006.sdmpDownload File
                                                                • Associated: 00000000.00000002.2905844819.000000006E218000.00000002.00000001.01000000.00000006.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_6e210000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CharDialogPrevRectlstrlen
                                                                • String ID:
                                                                • API String ID: 3411278111-0
                                                                • Opcode ID: 1862a66c9aa3a8131df9dadc3211e3c399f1b11a3b9e4352b4154996539e376f
                                                                • Instruction ID: 987ad04b35629e83573f9a0344f97b91c2e97fff9a654fd429af548002178afb
                                                                • Opcode Fuzzy Hash: 1862a66c9aa3a8131df9dadc3211e3c399f1b11a3b9e4352b4154996539e376f
                                                                • Instruction Fuzzy Hash: 8211B135D1852EEF8B209F89C808ECEB7FBEF51700B014416EA14A7608E7719B88CB94
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • CloseHandle.KERNEL32(000002F0,C:\Users\user\AppData\Local\Temp\,00403B71,?), ref: 00403C37
                                                                • CloseHandle.KERNEL32(000002C4,C:\Users\user\AppData\Local\Temp\,00403B71,?), ref: 00403C4B
                                                                Strings
                                                                • C:\Users\user\AppData\Local\Temp\, xrefs: 00403C2A
                                                                • C:\Users\user\AppData\Local\Temp\nsmFD66.tmp, xrefs: 00403C5B
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CloseHandle
                                                                • String ID: C:\Users\user\AppData\Local\Temp\$C:\Users\user\AppData\Local\Temp\nsmFD66.tmp
                                                                • API String ID: 2962429428-1866907244
                                                                • Opcode ID: 3450910aa3eb4a83e9339ad550daa728f038e8843dee50fd20da138f79135bda
                                                                • Instruction ID: ab9e488bef71b432d29da19662b82269d7b8f1628316f3e3d8f7e3aa77a32ace
                                                                • Opcode Fuzzy Hash: 3450910aa3eb4a83e9339ad550daa728f038e8843dee50fd20da138f79135bda
                                                                • Instruction Fuzzy Hash: 3BE0863244471496E5246F7DAF4D9853B285F413357248726F178F60F0C7389A9B4A9D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • IsWindowVisible.USER32(?), ref: 0040566D
                                                                • CallWindowProcW.USER32(?,?,?,?), ref: 004056BE
                                                                  • Part of subcall function 00404610: SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: Window$CallMessageProcSendVisible
                                                                • String ID:
                                                                • API String ID: 3748168415-3916222277
                                                                • Opcode ID: a73dc4e993bde12ea44745026bd4b5676165c6f206d332bc9731ab0fc1b08652
                                                                • Instruction ID: 537e1cae7e4c88fb21f4f8cfd237bdd46b0b38e99f2a5e053ca6ba0093d9a5c8
                                                                • Opcode Fuzzy Hash: a73dc4e993bde12ea44745026bd4b5676165c6f206d332bc9731ab0fc1b08652
                                                                • Instruction Fuzzy Hash: 4401B171200608AFEF205F11DD84A6B3A35EB84361F904837FA08752E0D77F8D929E6D
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenW.KERNEL32(80000000,C:\Users\user\Desktop,0040313C,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,80000000,00000003), ref: 00405F89
                                                                • CharPrevW.USER32(80000000,00000000,80000000,C:\Users\user\Desktop,0040313C,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,C:\Users\user\Desktop\Gwyddion-2.65.win64.exe,80000000,00000003), ref: 00405F99
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: CharPrevlstrlen
                                                                • String ID: C:\Users\user\Desktop
                                                                • API String ID: 2709904686-224404859
                                                                • Opcode ID: 176def5b2db9ef34a9f22db2929791273b03e08e07d7b66f37effa829582f156
                                                                • Instruction ID: bd974b3f77e4b05eb9372a1ad14375fba7b947cfa10dd8d614d5bb7090e452f7
                                                                • Opcode Fuzzy Hash: 176def5b2db9ef34a9f22db2929791273b03e08e07d7b66f37effa829582f156
                                                                • Instruction Fuzzy Hash: 6CD05EB2401D219EC3126B04DC00D9F63ACEF51301B4A4866E441AB1A0DB7C5D9186A9
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%

                                                                APIs
                                                                • lstrlenA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060CD
                                                                • lstrcmpiA.KERNEL32(00000000,00000000), ref: 004060E5
                                                                • CharNextA.USER32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060F6
                                                                • lstrlenA.KERNEL32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060FF
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.2897393940.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                • Associated: 00000000.00000002.2897370851.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897439927.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897524045.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                • Associated: 00000000.00000002.2897687470.000000000044D000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_400000_Gwyddion-2.jbxd
                                                                Similarity
                                                                • API ID: lstrlen$CharNextlstrcmpi
                                                                • String ID:
                                                                • API String ID: 190613189-0
                                                                • Opcode ID: 4f145c51a58837bd7eda372618efc6ab74ada67201017ca859b4805a40dfc06b
                                                                • Instruction ID: 2f06b96f93541eceebcae48a9adfe7aedd37cb678349478f8cad11de2473fd3e
                                                                • Opcode Fuzzy Hash: 4f145c51a58837bd7eda372618efc6ab74ada67201017ca859b4805a40dfc06b
                                                                • Instruction Fuzzy Hash: 0BF0F631104054FFDB12DFA4CD00D9EBBA8EF06350B2640BAE841FB321D674DE11A798
                                                                Uniqueness

                                                                Uniqueness Score: -1.00%