| PId | Image Name | Address | Mutex Name |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x76ee3a34 | RasPbFile |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771ba3ae | _!MSFTHISTORY!_ |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771bc21c | WininetConnectionMutex |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771bc23d | WininetProxyRegistryMutex |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771bc2dd | WininetStartupMutex |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771d9710 | c:!documents and settings!user!cookies! |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771d9710 | c:!documents and settings!user!local settings!history!history.ie5! |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x771d9710 | c:!documents and settings!user!local settings!temporary internet files!content.ie5! |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x777904d3 | WininetStartupMutex |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x77f76e78 | Shell.CMruPidlList |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x7c81a838 | ShimCacheMutex |
| 0x684 | C:\TEST\sample.exe | 0x77f76e78 | _SHuassist.mtx |
| 0x684 | C:\TEST\sample.exe | 0x7c81a838 | ShimCacheMutex |
• Events Created or Opened| PId | Image Name | Address | Event Name |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x769c4ec2 | Global\userenv: User Profile setup event |
| 0x4ec | C:\Program Files\Internet Explorer\iexplore.exe | 0x77de5f48 | Global\SvcctrlStartEvent_A3752DX |
| 0x684 | C:\TEST\sample.exe | 0x769c4ec2 | Global\userenv: User Profile setup event |
| 0x684 | C:\TEST\sample.exe | 0x77a89422 | Global\crypt32LogoffEvent |
| 0x684 | C:\TEST\sample.exe | 0x7ca66917 | ShellCopyEngineRunning |
| 0x684 | C:\TEST\sample.exe | 0x7ca66957 | ShellCopyEngineFinished |
| 0x724 | C:\WINDOWS\system32\360WDtray.exe | 0x7473d2a8 | CTF.ThreadMIConnectionEvent.00000628.00000000.00000005 |
| 0x724 | C:\WINDOWS\system32\360WDtray.exe | 0x7473d2a8 | CTF.ThreadMarshalInterfaceEvent.00000628.00000000.00000005 |
| 0x724 | C:\WINDOWS\system32\360WDtray.exe | 0x7473d2a8 | MSCTF.SendReceive.Event.ICG.IC |
| 0x724 | C:\WINDOWS\system32\360WDtray.exe | 0x7473d2a8 | MSCTF.SendReceiveConection.Event.ICG.IC |