Sample viewer

vx.netlux.org/Virus.DOS.HLLP.6384

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:46.899656411Z 53 PC: 1346a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:46.902157283Z 53 PC: 1346a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:46.903639254Z 53 PC: 1346a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:46.905506173Z 53 PC: 1346a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:46.907951501Z 53 PC: 1346a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:46.909273173Z 53 PC: 1346a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:46.910576171Z 53 PC: 1346a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:46.912952205Z 53 PC: 1346a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:46.914829789Z 53 PC: 1346a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:46.916864923Z 53 PC: 1346a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:46.919287737Z 53 PC: 1346a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:46.921289446Z 53 PC: 1346a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:46.923205436Z 53 PC: 1346a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:46.925371538Z 53 PC: 1346a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:46.927930534Z 53 PC: 1346a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:46.930507014Z 53 PC: 1346a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:46.932123433Z 53 PC: 1346a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:46.936477009Z 53 PC: 1346a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:46.942638404Z 53 PC: 1346a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:46.945189085Z 37 PC: 1347f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:46.952989523Z 37 PC: 13487 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:46.954380414Z 37 PC: 1348f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:46.955683836Z 37 PC: 13497 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:46.95768977Z 68 PC: 13fd3 | I/O control for devices (Set for = '')
2018-12-17T22:55:46.959534888Z 25 PC: 13b7c | Get default drive
2018-12-17T22:55:46.960673486Z 71 PC: 13b8f | Get current directory
2018-12-17T22:55:46.965615139Z 42 PC: 13197 | Get date 0x13197: xor ah, ah
0x13199: les di, ptr [bp + 6]
0x1319c: stosw word ptr es:[di], ax
0x1319d: mov al, dl
0x1319f: les di, ptr [bp + 0xa]
0x131a2: stosw word ptr es:[di], ax
0x131a3: mov al, dh
0x131a5: les di, ptr [bp + 0xe]
0x131a8: stosw word ptr es:[di], ax
0x131a9: xchg ax, cx
0x131aa: les di, ptr [bp + 0x12]
0x131ad: stosw word ptr es:[di], ax
0x131ae: pop bp
0x131af: retf 0x10
0x131b2: push bp
0x131b3: mov bp, sp
0x131b5: mov cx, word ptr [bp + 0xa]
0x131b8: mov dh, byte ptr [bp + 8]
0x131bb: mov dl, byte ptr [bp + 6]
0x131be: mov ah, 0x2b
2018-12-17T22:55:46.97003699Z 48 PC: 13aef | Get DOS version
2018-12-17T22:55:46.971737075Z 61 PC: 1392d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:55:46.979285242Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 5)
2018-12-17T22:55:46.989347964Z 62 PC: 1397d | Close file
2018-12-17T22:55:46.993616945Z 60 PC: 1392d | Create or truncate file
2018-12-17T22:55:47.01176357Z 65 PC: 13a76 | Delete file (Filename = '�')
2018-12-17T22:55:47.025671123Z 26 PC: 1326d | Set disk transfer address
2018-12-17T22:55:47.027460376Z 78 PC: 13279 | Find first file
2018-12-17T22:55:47.035997192Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.037374446Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.040563319Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.042577735Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.045683325Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.047089509Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.050950522Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.052626999Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.055736423Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.057342753Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.062374558Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.06375164Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.066853998Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.068874321Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.072124732Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.073513403Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.077537824Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.078902058Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.0817967Z 26 PC: 1326d | Set disk transfer address
2018-12-17T22:55:47.083968695Z 78 PC: 13279 | Find first file
2018-12-17T22:55:47.091474772Z 61 PC: 1392d | Open file (Filename = 'TEST.EXE')
2018-12-17T22:55:47.097999419Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:47.108055649Z 62 PC: 1397d | Close file
2018-12-17T22:55:47.109991833Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.112791211Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.119045546Z 71 PC: 13b8f | Get current directory
2018-12-17T22:55:47.121802028Z 14 PC: 13bd5 | Set default drive (Drive = 'C')
2018-12-17T22:55:47.123483714Z 25 PC: 13bd9 | Get default drive
2018-12-17T22:55:47.12555017Z 59 PC: 13c43 | Change current directory
2018-12-17T22:55:47.129369682Z 26 PC: 1326d | Set disk transfer address
2018-12-17T22:55:47.132164199Z 78 PC: 13279 | Find first file
2018-12-17T22:55:47.139161913Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.14039036Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.144086183Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.145437512Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.149323449Z 59 PC: 13c43 | Change current directory
2018-12-17T22:55:47.155085743Z 26 PC: 1326d | Set disk transfer address
2018-12-17T22:55:47.156129075Z 78 PC: 13279 | Find first file
2018-12-17T22:55:47.165448777Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.166532584Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.169778256Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.173501847Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.17764925Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.178990288Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.183804123Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.185705082Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.189232465Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.19166537Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.195627549Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.196933038Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.201410553Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.202454751Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.211495693Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.215895862Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.233870106Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.2352622Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.239675204Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.240956093Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.244486866Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.245931267Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.24964892Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.250970613Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.254703709Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.256313964Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.259833326Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.26136961Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.265122146Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.266467291Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.270226128Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.275666297Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.29223935Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.293621935Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.297717736Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.29923986Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.302796496Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.304659172Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.308151197Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.309528795Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.313449488Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.314794044Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.31831451Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.320454623Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.32394682Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.325298775Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.329729215Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.331057906Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.334593706Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.336681982Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.340186247Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.341529122Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.34568791Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.346905564Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.350372213Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.35230323Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.35575023Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.35712198Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.36140423Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.363454959Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.366847021Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.368965644Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.372460852Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.373880717Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.380836947Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.382180313Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.385746626Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.387975055Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.391523938Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.392895205Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.396684313Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.397764934Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.401184291Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:47.402631052Z 79 PC: 13296 | Find next file
2018-12-17T22:55:47.40539939Z 26 PC: 1326d | Set disk transfer address
2018-12-17T22:55:47.406516513Z 78 PC: 13279 | Find first file
2018-12-17T22:55:47.412857158Z 61 PC: 1392d | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:55:47.419611752Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:47.432041638Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:47.434544878Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:47.436221066Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.450377508Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.45243622Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.457138068Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.459745797Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.461267632Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.47272554Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.476016438Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.483142066Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.484497039Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.488788866Z 61 PC: 1392d | Open file (Filename = 'CHKDSK.EXE')
2018-12-17T22:55:48.49571351Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.507921249Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.51036815Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.51208565Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.519447743Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.521817945Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.523350712Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.524976332Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.527409952Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.539784554Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.54209086Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.552805064Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.553871255Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.557293177Z 61 PC: 1392d | Open file (Filename = 'DEBUG.EXE')
2018-12-17T22:55:48.56521208Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.578639727Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.580151999Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.582236821Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.589736052Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.590951745Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.593303962Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.594963801Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.59679483Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.607675649Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.609494528Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.618741977Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.621062416Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.624657834Z 61 PC: 1392d | Open file (Filename = 'EXPAND.EXE')
2018-12-17T22:55:48.63133349Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.644796424Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.646206042Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.647571148Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.656265415Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.657579133Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.659356467Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.661611953Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.662952295Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.672621123Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.675006426Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.681801934Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.682837495Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.686856235Z 61 PC: 1392d | Open file (Filename = 'FDISK.EXE')
2018-12-17T22:55:48.694076501Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.705738981Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.708425587Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.710119308Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.718156353Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.720712299Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.722326529Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.723961098Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.726519738Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.735776259Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.737534065Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.745501948Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.746537195Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.749752639Z 61 PC: 1392d | Open file (Filename = 'MEM.EXE')
2018-12-17T22:55:48.755642216Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.762853385Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.764251761Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.765790499Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.770593598Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.771653567Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.77314538Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.774386595Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.775470533Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.782862986Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.78470736Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.78926585Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.791139889Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.795449862Z 61 PC: 1392d | Open file (Filename = 'NLSFUNC.EXE')
2018-12-17T22:55:48.799771836Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.808847973Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.810353051Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.811752737Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.818403566Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.819751931Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.821052038Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.823233401Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.824614755Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.831284649Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.833912564Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.839172474Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.840186951Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.844202273Z 61 PC: 1392d | Open file (Filename = 'QBASIC.EXE')
2018-12-17T22:55:48.849619508Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.858997077Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.86230437Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.864257087Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.872686861Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.874796408Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.876299521Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.878864533Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.88043589Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.88961164Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.892409992Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.899290843Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.900300631Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.904738007Z 61 PC: 1392d | Open file (Filename = 'REPLACE.EXE')
2018-12-17T22:55:48.911971432Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.924855427Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.92802093Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.930676498Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.938695691Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:48.941265912Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:48.943322965Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:48.945043929Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.947579141Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:48.957131481Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:48.958642516Z 62 PC: 1397d | Close file
2018-12-17T22:55:48.966643012Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:48.968133862Z 79 PC: 13296 | Find next file
2018-12-17T22:55:48.971876829Z 61 PC: 1392d | Open file (Filename = 'RESTORE.EXE')
2018-12-17T22:55:48.980750938Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:48.993284217Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:48.995147233Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:48.997452044Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.005927734Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.007592629Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.009828846Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.011497095Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.014063672Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.02317339Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:49.024690168Z 62 PC: 1397d | Close file
2018-12-17T22:55:49.03268821Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:49.034065565Z 79 PC: 13296 | Find next file
2018-12-17T22:55:49.037700484Z 61 PC: 1392d | Open file (Filename = 'SCANDISK.EXE')
2018-12-17T22:55:49.045252367Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:49.057406517Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:49.05959195Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.062803379Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.071051391Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.073086968Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.074539287Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.075913094Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.078201275Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.088077137Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:49.089962394Z 62 PC: 1397d | Close file
2018-12-17T22:55:49.098704026Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:49.099884361Z 79 PC: 13296 | Find next file
2018-12-17T22:55:49.103139465Z 61 PC: 1392d | Open file (Filename = 'SETUP.EXE')
2018-12-17T22:55:49.110436257Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:49.122169237Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:49.123968654Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.126136534Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.133416446Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.135621782Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.137857976Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.139488366Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.14191147Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.151542495Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:49.153349058Z 62 PC: 1397d | Close file
2018-12-17T22:55:49.161905714Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:49.163038188Z 79 PC: 13296 | Find next file
2018-12-17T22:55:49.1665556Z 61 PC: 1392d | Open file (Filename = 'XCOPY.EXE')
2018-12-17T22:55:49.174959031Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:49.186847874Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:49.188407494Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.191277702Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.19871633Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.200962813Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.202470554Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.204215918Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.206638368Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.216250502Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:49.217814042Z 62 PC: 1397d | Close file
2018-12-17T22:55:49.225887623Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:49.226929931Z 79 PC: 13296 | Find next file
2018-12-17T22:55:49.230283206Z 61 PC: 1392d | Open file (Filename = 'DEFRAG.EXE')
2018-12-17T22:55:49.238162609Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 6)
2018-12-17T22:55:49.2498981Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:49.251364937Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.256389873Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.265130843Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.266501478Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.268915488Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.270338504Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.271768065Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 6)
2018-12-17T22:55:49.282779213Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:49.284361141Z 62 PC: 1397d | Close file
2018-12-17T22:55:49.292657628Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:49.294296216Z 79 PC: 13296 | Find next file
2018-12-17T22:55:49.300839111Z 59 PC: 13c43 | Change current directory
2018-12-17T22:55:49.305956464Z 26 PC: 13291 | Set disk transfer address
2018-12-17T22:55:49.30726285Z 79 PC: 13296 | Find next file
2018-12-17T22:55:49.313291514Z 59 PC: 13c43 | Change current directory
2018-12-17T22:55:49.317998082Z 60 PC: 1392d | Create or truncate file
2018-12-17T22:55:49.328456362Z 65 PC: 13a76 | Delete file (Filename = '�')
2018-12-17T22:55:49.335566337Z 26 PC: 1326d | Set disk transfer address
2018-12-17T22:55:49.336974832Z 78 PC: 13279 | Find first file
2018-12-17T22:55:49.341193419Z 14 PC: 13bd5 | Set default drive (Drive = 'C')
2018-12-17T22:55:49.342195704Z 25 PC: 13bd9 | Get default drive
2018-12-17T22:55:49.344406337Z 59 PC: 13c43 | Change current directory
2018-12-17T22:55:49.347057559Z 14 PC: 13bd5 | Set default drive (Drive = 'A')
2018-12-17T22:55:49.34804251Z 25 PC: 13bd9 | Get default drive
2018-12-17T22:55:49.349465784Z 59 PC: 13c43 | Change current directory
2018-12-17T22:55:49.353304325Z 61 PC: 1392d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:55:49.364716615Z 87 PC: 13210 | Get or set file date and time
2018-12-17T22:55:49.368388113Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.370425175Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.373422372Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.375399234Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.377308174Z 63 PC: 13a00 | Read file or device (Read 6384 bytes on handle 7)
2018-12-17T22:55:49.390081207Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.391570055Z 64 PC: 13a00 | Write file or device (Write 6384 bytes on handle 7)
2018-12-17T22:55:49.400590485Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:55:49.403339615Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:49.404816727Z 66 PC: 140ee | Move file pointer
2018-12-17T22:55:49.406705648Z 66 PC: 13a5f | Move file pointer
2018-12-17T22:55:49.408435312Z 64 PC: 1395e | Write file or device (Write 0 bytes on handle 7)
2018-12-17T22:55:49.416123162Z 87 PC: 1323d | Get or set file date and time
2018-12-17T22:55:49.41829919Z 62 PC: 1397d | Close file
2018-12-17T22:55:49.425100918Z 53 PC: 133dc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:49.426200788Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:49.428060639Z 53 PC: 133dc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:49.429175639Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:49.430282688Z 53 PC: 133dc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:49.432245901Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:49.433953439Z 53 PC: 133dc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:49.435186193Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:49.436632296Z 53 PC: 133dc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:49.437863822Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:49.439677856Z 53 PC: 133dc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:49.441098461Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:49.442422897Z 53 PC: 133dc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:49.444194443Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:49.445322916Z 53 PC: 133dc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:49.446667534Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:49.448697367Z 53 PC: 133dc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:49.45007422Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:49.451594551Z 53 PC: 133dc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:49.453077723Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:49.454310839Z 53 PC: 133dc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:49.45620975Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:49.457252792Z 53 PC: 133dc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:49.460829162Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:49.462575506Z 53 PC: 133dc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:49.463650106Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:49.464575693Z 53 PC: 133dc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:49.465864395Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:49.466790191Z 53 PC: 133dc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:49.468295114Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:49.469237966Z 53 PC: 133dc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:49.470256885Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:49.471784068Z 53 PC: 133dc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:49.473044901Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:49.473981743Z 53 PC: 133dc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:49.475518647Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:49.476653687Z 53 PC: 133dc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:49.477763224Z 37 PC: 133e5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:49.479811088Z 41 PC: 13393 | Parse filename
2018-12-17T22:55:49.481093055Z 41 PC: 133a1 | Parse filename
2018-12-17T22:55:49.482770025Z 75 PC: 133ac | Execute program
2018-12-17T22:55:49.503938577Z 80 PC: 1cff9 | Set current PSP
2018-12-17T22:55:49.504706779Z 48 PC: 1cffe | Get DOS version
2018-12-17T22:55:49.506714759Z 99 PC: 237e0 | Get DBCS lead byte table pointer
2018-12-17T22:55:49.509573904Z 101 PC: 1d084 | Get extended country info
2018-12-17T22:55:49.510691934Z 99 PC: 1d08a | Get DBCS lead byte table pointer
2018-12-17T22:55:49.512764894Z 74 PC: 1d0ec | Reallocate memory
2018-12-17T22:55:49.515039695Z 25 PC: 1d123 | Get default drive
2018-12-17T22:55:49.516490235Z 37 PC: 1cbe3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:55:49.517755616Z 37 PC: 1cbea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:49.518601679Z 37 PC: 1cbf1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:49.523240661Z 74 PC: 1bd8c | Reallocate memory
2018-12-17T22:55:49.524617925Z 72 PC: 1bdcd | Allocate memory
2018-12-17T22:55:49.526229737Z 72 PC: 1be05 | Allocate memory
2018-12-17T22:55:49.529087316Z 72 PC: 1be0d | Allocate memory