Sample viewer

vx.netlux.org/Virus.DOS.Sisoruen.451

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:17.17746264Z 26 PC: 12a91 | Set disk transfer address
2018-12-17T22:57:17.17888778Z 78 PC: 12a9c | Find first file
2018-12-17T22:57:17.18322363Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.262535375Z 61 PC: 12b18 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:57:17.279477507Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.285810783Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.292097817Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.302458538Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.309375768Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.312057903Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.322517839Z 61 PC: 12b18 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:57:17.329309546Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.3310838Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.337500476Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.339266821Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.346535862Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.349113162Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.359422802Z 61 PC: 12b18 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:57:17.366095151Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.367708039Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.375613496Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.377387867Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.385054371Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.389320926Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.400159296Z 61 PC: 12b18 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:57:17.413871814Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.416684072Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.423636853Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.425629302Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.433321862Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.437630475Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.447725189Z 61 PC: 12b18 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:57:17.454705299Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.457792735Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.464360287Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.466206447Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.474194604Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.477561907Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.487216655Z 61 PC: 12b18 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:57:17.495456117Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.497225719Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.503809885Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.506543447Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.514015494Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.516878125Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.527411785Z 61 PC: 12b18 | Open file (Filename = 'PAH.COM')
2018-12-17T22:57:17.534652079Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.536162532Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.542986297Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.544340459Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.550439036Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.553792319Z 67 PC: 12b12 | Get or set file attributes
2018-12-17T22:57:17.562931274Z 61 PC: 12b18 | Open file (Filename = 'TEST.COM')
2018-12-17T22:57:17.56965934Z 87 PC: 12b1e | Get or set file date and time
2018-12-17T22:57:17.571269998Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:17.5780267Z 87 PC: 12b90 | Get or set file date and time
2018-12-17T22:57:17.579384044Z 62 PC: 12b94 | Close file
2018-12-17T22:57:17.586359648Z 79 PC: 12a9c | Find next file
2018-12-17T22:57:17.589405822Z 59 PC: 12aa6 | Change current directory
2018-12-17T22:57:17.597769635Z 42 PC: 12aac | Get date 0x12aac: cmp al, 6
0x12aae: je 0x12abc
0x12ab0: cmp al, 0
0x12ab2: je 0x12abc
0x12ab4: mov dx, 0x80
0x12ab7: mov ah, 0x1a
0x12ab9: int 0x21
0x12abb: ret
0x12abc: mov ah, 0xe
0x12abe: mov dl, 2
0x12ac0: int 0x21
0x12ac2: mov ah, 0x3b
0x12ac4: lea dx, word ptr [bp + 0x283]
0x12ac8: int 0x21
0x12aca: mov ah, 0x4e
0x12acc: lea dx, word ptr [bp + 0x285]
0x12ad0: mov cx, 3
0x12ad3: int 0x21
0x12ad5: jb 0x12ab4
0x12ad7: lea dx, word ptr [bp + 0x2ba]
2018-12-17T22:57:17.600145099Z 26 PC: 12abb | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12506,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:33.369110185Z 26 PC: 12a91 | Set disk transfer address
2018-12-25T12:35:33.370911775Z 78 PC: 12a9c | Find first file
2018-12-25T12:35:33.376647356Z 67 PC: 12b12 | Get or set file attributes
2018-12-25T12:35:33.392312403Z 61 PC: 12b18 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:35:33.406684577Z 87 PC: 12b1e | Get or set file date and time
2018-12-25T12:35:33.408063764Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:35:33.414123671Z 87 PC: 12b90 | Get or set file date and time
2018-12-25T12:35:33.415824588Z 62 PC: 12b94 | Close file
2018-12-25T12:35:33.427743081Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.430889967Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.448369549Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.453936007Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.455099151Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.459344944Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.461258365Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.468257358Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.471075775Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.482901845Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.487048423Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.48817833Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.493276713Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.494388681Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.501543419Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.505200239Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.515429144Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.522394973Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.525539481Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.532508767Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.534012635Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.541928447Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.544500105Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.554299311Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.566709119Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.56828851Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.574680846Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.576767893Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.583984291Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.586858199Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.59774974Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.604282342Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.605974963Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.612974988Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.615688525Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.622918174Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.625799449Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.639698591Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.646558971Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.648312764Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.655500398Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.657207551Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.664865971Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.668896939Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.679622542Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.68680133Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.689542601Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.6967889Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.698631638Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.706795321Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.717019631Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:35:33.721482553Z 42 PC: 12aac | Get date 0x12aac: cmp al, 6
0x12aae: je 0x12abc
0x12ab0: cmp al, 0
0x12ab2: je 0x12abc
0x12ab4: mov dx, 0x80
0x12ab7: mov ah, 0x1a
0x12ab9: int 0x21
0x12abb: ret
0x12abc: mov ah, 0xe
0x12abe: mov dl, 2
0x12ac0: int 0x21
0x12ac2: mov ah, 0x3b
0x12ac4: lea dx, word ptr [bp + 0x283]
0x12ac8: int 0x21
0x12aca: mov ah, 0x4e
0x12acc: lea dx, word ptr [bp + 0x285]
0x12ad0: mov cx, 3
0x12ad3: int 0x21
0x12ad5: jb 0x12ab4
0x12ad7: lea dx, word ptr [bp + 0x2ba]
2018-12-25T12:35:33.724340901Z 26 PC: 12abb | Set disk transfer address

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12506,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:33.404310091Z 26 PC: 12a91 | Set disk transfer address
2018-12-25T12:35:33.406104921Z 78 PC: 12a9c | Find first file
2018-12-25T12:35:33.412047875Z 67 PC: 12b12 | Get or set file attributes
2018-12-25T12:35:33.428071892Z 61 PC: 12b18 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:35:33.437007473Z 87 PC: 12b1e | Get or set file date and time
2018-12-25T12:35:33.438388598Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:35:33.442888839Z 87 PC: 12b90 | Get or set file date and time
2018-12-25T12:35:33.443904954Z 62 PC: 12b94 | Close file
2018-12-25T12:35:33.45896656Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.462309212Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.472394616Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.477751687Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.479676863Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.48698245Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.49484473Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.501938182Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.504719285Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.517511541Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.524303897Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.525835935Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.532743353Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.534462585Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.54217933Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.545227862Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.555297104Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.562243866Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.564080886Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.569718465Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.571138949Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.580094052Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.582270412Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.592261474Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.605095746Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.607687177Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.623449354Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.625276691Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.633147366Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.63602742Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.645883146Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.653452358Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.655432294Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.661959218Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.66430275Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.671947516Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.674807129Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.685430514Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.692489121Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.69419605Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.701145149Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.703148172Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.71027238Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.713743463Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.723802357Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.735584144Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.7375364Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.743930623Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.74550369Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.752955729Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.756103027Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:35:33.760498495Z 42 PC: 12aac | Get date 0x12aac: cmp al, 6
0x12aae: je 0x12abc
0x12ab0: cmp al, 0
0x12ab2: je 0x12abc
0x12ab4: mov dx, 0x80
0x12ab7: mov ah, 0x1a
0x12ab9: int 0x21
0x12abb: ret
0x12abc: mov ah, 0xe
0x12abe: mov dl, 2
0x12ac0: int 0x21
0x12ac2: mov ah, 0x3b
0x12ac4: lea dx, word ptr [bp + 0x283]
0x12ac8: int 0x21
0x12aca: mov ah, 0x4e
0x12acc: lea dx, word ptr [bp + 0x285]
0x12ad0: mov cx, 3
0x12ad3: int 0x21
0x12ad5: jb 0x12ab4
0x12ad7: lea dx, word ptr [bp + 0x2ba]
2018-12-25T12:35:33.76438903Z 14 PC: 12ac2 | Set default drive (Drive = 'C')
2018-12-25T12:35:33.766118012Z 59 PC: 12aca | Change current directory
2018-12-25T12:35:33.769915547Z 78 PC: 12ad5 | Find first file
2018-12-25T12:35:33.776171341Z 67 PC: 12ae3 | Get or set file attributes
2018-12-25T12:35:34.102656464Z 61 PC: 12ae8 | Open file (Filename = 'AUTOEXEC.BAT')
2018-12-25T12:35:34.109258823Z 66 PC: 12ba1 | Move file pointer
2018-12-25T12:35:34.111078937Z 64 PC: 12af7 | Write file or device (Write 30 bytes on handle 5)
2018-12-25T12:35:34.115446364Z 67 PC: 12b00 | Get or set file attributes
2018-12-25T12:35:34.131883589Z 62 PC: 12b04 | Close file
2018-12-25T12:35:34.142555852Z 26 PC: 12abb | Set disk transfer address

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12506,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:33.557219727Z 26 PC: 12a91 | Set disk transfer address
2018-12-25T12:35:33.558908296Z 78 PC: 12a9c | Find first file
2018-12-25T12:35:33.564771188Z 67 PC: 12b12 | Get or set file attributes
2018-12-25T12:35:33.580942587Z 61 PC: 12b18 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:35:33.595467247Z 87 PC: 12b1e | Get or set file date and time
2018-12-25T12:35:33.597496959Z 63 PC: 12b2b | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:35:33.603868244Z 87 PC: 12b90 | Get or set file date and time
2018-12-25T12:35:33.605474304Z 62 PC: 12b94 | Close file
2018-12-25T12:35:33.613393642Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.6163771Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.62662275Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.634451011Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.63589686Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.653008451Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.655563483Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.662863943Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.665751268Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.67663528Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.683331016Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.68500467Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.692442786Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.694681108Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.701946082Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.70562077Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.718070256Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.725357729Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.727357498Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.734749124Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.736577409Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.743827926Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.747926577Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.758341738Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.764757164Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.767372487Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:33.774502837Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:33.776026926Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:33.783824376Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:33.791022059Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:33.989109193Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:33.994845813Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:33.996581864Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:34.003735555Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:34.006530065Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:34.102255222Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:34.105288586Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:34.117152141Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:34.126864526Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:34.128141258Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:34.151343384Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:34.153632957Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:34.160711705Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:34.163556098Z 67 PC: 12b12 | Get or set file attributes (See above)
2018-12-25T12:35:34.175163714Z 61 PC: 12b18 | Open file (See above)
2018-12-25T12:35:34.181728427Z 87 PC: 12b1e | Get or set file date and time (See above)
2018-12-25T12:35:34.183213829Z 63 PC: 12b2b | Read file or device (See above)
2018-12-25T12:35:34.190377803Z 87 PC: 12b90 | Get or set file date and time (See above)
2018-12-25T12:35:34.195807949Z 62 PC: 12b94 | Close file (See above)
2018-12-25T12:35:34.21062596Z 79 PC: 12a9c | Find next file (See above)
2018-12-25T12:35:34.218840085Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:35:34.223690341Z 42 PC: 12aac | Get date 0x12aac: cmp al, 6
0x12aae: je 0x12abc
0x12ab0: cmp al, 0
0x12ab2: je 0x12abc
0x12ab4: mov dx, 0x80
0x12ab7: mov ah, 0x1a
0x12ab9: int 0x21
0x12abb: ret
0x12abc: mov ah, 0xe
0x12abe: mov dl, 2
0x12ac0: int 0x21
0x12ac2: mov ah, 0x3b
0x12ac4: lea dx, word ptr [bp + 0x283]
0x12ac8: int 0x21
0x12aca: mov ah, 0x4e
0x12acc: lea dx, word ptr [bp + 0x285]
0x12ad0: mov cx, 3
0x12ad3: int 0x21
0x12ad5: jb 0x12ab4
0x12ad7: lea dx, word ptr [bp + 0x2ba]
2018-12-25T12:35:34.22583717Z 14 PC: 12ac2 | Set default drive (Drive = 'C')
2018-12-25T12:35:34.22775933Z 59 PC: 12aca | Change current directory
2018-12-25T12:35:34.231280773Z 78 PC: 12ad5 | Find first file
2018-12-25T12:35:34.239922975Z 67 PC: 12ae3 | Get or set file attributes
2018-12-25T12:35:34.571144432Z 61 PC: 12ae8 | Open file (Filename = 'AUTOEXEC.BAT')
2018-12-25T12:35:34.577474885Z 66 PC: 12ba1 | Move file pointer
2018-12-25T12:35:34.57906385Z 64 PC: 12af7 | Write file or device (Write 30 bytes on handle 5)
2018-12-25T12:35:34.582960837Z 67 PC: 12b00 | Get or set file attributes
2018-12-25T12:35:34.592817601Z 62 PC: 12b04 | Close file
2018-12-25T12:35:34.599490856Z 26 PC: 12abb | Set disk transfer address