| PId | Image Name | Address | Function ( Parameters ) | Return Value |
| 0x208 | C:\WINDOWS\system32\oruyb.exe | 0x4027d1 | CreateServiceA(hSCManager: 0x1523b8, lpServiceName: "DSPLALER", lpDisplayName: "DCOM Server Process Lookup and Launcher", dwDesiredAccess: 0xf01ff, dwServiceType: 0x10, dwStartType: 0x2, dwErrorControl: 0x1, lpBinaryPathName: "C:\WINDOWS\system32\oruyb.exe", lpLoadOrderGroup: "(null)", lpdwTagId: 0x0, lpDependencies: 0x408278, lpServiceStartName: "(null)", lpPassword: 0x0)|0x152280 |
• DNS Queries| PId | Image Name | Address | Mutex Name |
| 0x380 | C:\WINDOWS\system32\rundll32.exe | 0x928acf | USMSVC_CLICK555 |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x76ee3a34 | RasPbFile |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771ba3ae | _!MSFTHISTORY!_ |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771bc21c | WininetConnectionMutex |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771bc23d | WininetProxyRegistryMutex |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771bc2dd | WininetStartupMutex |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771d96e1 | c:!documents and settings!localservice!cookies! |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771d96e1 | c:!documents and settings!localservice!local settings!history!history.ie5! |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x771d96e1 | c:!documents and settings!localservice!local settings!temporary internet files!content.ie5! |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x77267e1b | ZonesCacheCounterMutex |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x77267e1b | ZonesLockedCacheCounterMutex |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x772689fc | ZonesCounterMutex |
| 0x560 | C:\WINDOWS\system32\rundll32.exe | 0x928acf | USMSVC_CLICK555 |
• Events Created or Opened| PId | Image Name | Address | Event Name |
| 0x208 | C:\WINDOWS\system32\oruyb.exe | 0x77de5f48 | Global\SvcctrlStartEvent_A3752DX |
| 0x380 | C:\WINDOWS\system32\rundll32.exe | 0x77a89410 | Global\crypt32LogoffEvent |
| 0x3e4 | C:\WINDOWS\system32\net1.exe | 0x77de5f48 | Global\SvcctrlStartEvent_A3752DX |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x76b443c5 | DINPUTWINMM |
| 0x3f4 | C:\WINDOWS\system32\oruyb.exe | 0x77de5f48 | Global\SvcctrlStartEvent_A3752DX |
| 0x560 | C:\WINDOWS\system32\rundll32.exe | 0x77a89422 | Global\crypt32LogoffEvent |