Sample viewer

vx.netlux.org/Virus.DOS.Weed.4080.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:20.709538946Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.716564916Z 65 PC: 132c0 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:01:20.722497993Z 98 PC: 18a84 | Get current PSP
2018-12-17T22:01:20.724018499Z 26 PC: 12b4e | Set disk transfer address
2018-12-17T22:01:20.725977664Z 78 PC: 12b60 | Find first file
2018-12-17T22:01:20.731834682Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:20.737766588Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.755618361Z 61 PC: 132ee | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:20.775798324Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:20.785472877Z 62 PC: 133d6 | Close file
2018-12-17T22:01:20.787665645Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.799159571Z 47 PC: 18be5 | Get disk transfer address
2018-12-17T22:01:20.800407379Z 26 PC: 18bf0 | Set disk transfer address
2018-12-17T22:01:20.802107246Z 78 PC: 18bfc | Find first file
2018-12-17T22:01:20.809541475Z 26 PC: 18c0e | Set disk transfer address
2018-12-17T22:01:20.811214279Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:20.816760937Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.827642993Z 61 PC: 13531 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:01:20.834890726Z 66 PC: 13561 | Move file pointer
2018-12-17T22:01:20.836658126Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.840166856Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.843640522Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.846645788Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.850292736Z 62 PC: 1360e | Close file
2018-12-17T22:01:20.852137657Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.864507222Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:20.866421348Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:20.869198773Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:20.871685005Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:20.873330288Z 47 PC: 18be5 | Get disk transfer address
2018-12-17T22:01:20.876000626Z 26 PC: 18bf0 | Set disk transfer address
2018-12-17T22:01:20.877646227Z 78 PC: 18bfc | Find first file
2018-12-17T22:01:20.884360852Z 26 PC: 18c0e | Set disk transfer address
2018-12-17T22:01:20.888092357Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:20.894278658Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.906875196Z 61 PC: 13531 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:01:20.914939035Z 66 PC: 13561 | Move file pointer
2018-12-17T22:01:20.916852285Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.931773254Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.935495356Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.939441012Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:20.942789043Z 62 PC: 1360e | Close file
2018-12-17T22:01:20.946247832Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.956747969Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:20.95838788Z 78 PC: 1301d | Find first file
2018-12-17T22:01:20.964677002Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:20.970571619Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:20.980334189Z 61 PC: 132ee | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:01:20.98709654Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:20.988824621Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:20.99194486Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:20.994326037Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.004989801Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.013714456Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.022719224Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:21.02496061Z 62 PC: 133d6 | Close file
2018-12-17T22:01:21.033352584Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.044210807Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:21.046690808Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:21.048254281Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:21.051498808Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:21.054471607Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.060696416Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.070819032Z 61 PC: 13531 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:01:21.078704843Z 66 PC: 13561 | Move file pointer
2018-12-17T22:01:21.080348587Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.082499073Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.085576671Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.087712658Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.089815203Z 62 PC: 1360e | Close file
2018-12-17T22:01:21.092789458Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.102814211Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:21.103999977Z 78 PC: 1301d | Find first file
2018-12-17T22:01:21.110427123Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.116020557Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.125679947Z 61 PC: 132ee | Open file (Filename = 'PRINT.COM')
2018-12-17T22:01:21.133010202Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:21.134681405Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:21.141725893Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.144611781Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.153846868Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.162635165Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.172330808Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:21.174315673Z 62 PC: 133d6 | Close file
2018-12-17T22:01:21.18208379Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.192743549Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:21.19445606Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:21.195770585Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:21.19888544Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:21.201555018Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.208018934Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.217659296Z 61 PC: 13531 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:01:21.225065029Z 66 PC: 13561 | Move file pointer
2018-12-17T22:01:21.226330059Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.232558901Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.235616954Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.238370154Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.241123799Z 62 PC: 1360e | Close file
2018-12-17T22:01:21.244043549Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.254181363Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:21.255551265Z 78 PC: 1301d | Find first file
2018-12-17T22:01:21.262298228Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.268160139Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.278246273Z 61 PC: 132ee | Open file (Filename = 'HELLO.COM')
2018-12-17T22:01:21.285729403Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:21.287742218Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:21.290796607Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.293817094Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.302986958Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.311948651Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.322087184Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:21.324517894Z 62 PC: 133d6 | Close file
2018-12-17T22:01:21.332448956Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.343588077Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:21.345411025Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:21.350399374Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:21.354099129Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:21.356398759Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.362372156Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.372404664Z 61 PC: 13531 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:01:21.379909984Z 66 PC: 13561 | Move file pointer
2018-12-17T22:01:21.381538303Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.388189534Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.391549003Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.39382256Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.396041985Z 62 PC: 1360e | Close file
2018-12-17T22:01:21.39958858Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.411076796Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:21.41241954Z 78 PC: 1301d | Find first file
2018-12-17T22:01:21.419951469Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.426331874Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.436922966Z 61 PC: 132ee | Open file (Filename = 'PHANG.COM')
2018-12-17T22:01:21.445013544Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:21.447152474Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:21.450442806Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.453624309Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.462989926Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.472076691Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.482652312Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:21.485342468Z 62 PC: 133d6 | Close file
2018-12-17T22:01:21.493331204Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.504112317Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:21.505990331Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:21.507511097Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:21.511574925Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:21.514084189Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.520319775Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.531299534Z 61 PC: 13531 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:01:21.543400578Z 66 PC: 13561 | Move file pointer
2018-12-17T22:01:21.545212585Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.55186516Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.555164157Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.557483722Z 63 PC: 13596 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:21.559820468Z 62 PC: 1360e | Close file
2018-12-17T22:01:21.563466853Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.574063827Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:21.575623146Z 78 PC: 1301d | Find first file
2018-12-17T22:01:21.582886614Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.588914586Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.598852047Z 61 PC: 132ee | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:01:21.611731535Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:21.613973173Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:21.620747971Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.623827219Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.633162634Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:21.642055214Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:21.652687293Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:21.65476529Z 62 PC: 133d6 | Close file
2018-12-17T22:01:21.662513022Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.674277688Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:21.675837507Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:21.677181329Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:21.680225584Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:21.682688883Z 98 PC: 18abb | Get current PSP
2018-12-17T22:01:21.684869346Z 47 PC: 18be5 | Get disk transfer address
2018-12-17T22:01:21.686247791Z 26 PC: 18bf0 | Set disk transfer address
2018-12-17T22:01:21.688551963Z 78 PC: 18bfc | Find first file
2018-12-17T22:01:21.697464091Z 26 PC: 18c0e | Set disk transfer address
2018-12-17T22:01:21.69930372Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.706299156Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.71212748Z 61 PC: 13531 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:01:21.718545833Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:21.725419595Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:21.726729733Z 78 PC: 1301d | Find first file
2018-12-17T22:01:21.733121651Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:21.740071798Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.4262265Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:01:22.433182693Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:22.436024768Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:22.443467291Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.445701985Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.453873229Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.463100559Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.473205727Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:22.475667888Z 62 PC: 133d6 | Close file
2018-12-17T22:01:22.483382064Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.497716473Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:22.509848007Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:22.518322134Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:22.526707316Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:22.529517839Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.536050709Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.542065009Z 61 PC: 13531 | Open file (Filename = 'CHKDSK.EXE')
2018-12-17T22:01:22.549697983Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.555768125Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:22.557141342Z 78 PC: 1301d | Find first file
2018-12-17T22:01:22.564062847Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.570400765Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.580927018Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T22:01:22.589520586Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:22.591145934Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:22.598454771Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.601157918Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.609428791Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.618375354Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.628996574Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:22.631253853Z 62 PC: 133d6 | Close file
2018-12-17T22:01:22.63839306Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.648797417Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:22.649998991Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:22.65104255Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:22.654784894Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:22.656392208Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.662157827Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.668406678Z 61 PC: 13531 | Open file (Filename = 'DEBUG.EXE')
2018-12-17T22:01:22.674844306Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.681583539Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:22.683877881Z 78 PC: 1301d | Find first file
2018-12-17T22:01:22.690544429Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.696782461Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.707092536Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T22:01:22.714822649Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:22.716624239Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:22.724572945Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.726449931Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.733686065Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.744073284Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.755999199Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:22.757615629Z 62 PC: 133d6 | Close file
2018-12-17T22:01:22.765846673Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.775743331Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:22.776915606Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:22.779206813Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:22.78253385Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:22.784445697Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.791354908Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.797249561Z 61 PC: 13531 | Open file (Filename = 'EXPAND.EXE')
2018-12-17T22:01:22.803703154Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.811012289Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:22.812260219Z 78 PC: 1301d | Find first file
2018-12-17T22:01:22.818618791Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.825303999Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.834878939Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T22:01:22.841806164Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:22.844062058Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:22.851046004Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.853010748Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.861399591Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.870078591Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.879431594Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:22.882038902Z 62 PC: 133d6 | Close file
2018-12-17T22:01:22.889005284Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.898711369Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:22.900715926Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:22.901827745Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:22.904920901Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:22.907255397Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.912905792Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.91830157Z 61 PC: 13531 | Open file (Filename = 'FDISK.EXE')
2018-12-17T22:01:22.924782804Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.930389243Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:22.932400417Z 78 PC: 1301d | Find first file
2018-12-17T22:01:22.938891386Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:22.945574188Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:22.956241653Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T22:01:22.963111059Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:22.964946671Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:22.973676929Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.975438837Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:22.982669115Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:22.992113162Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.001048065Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.00264103Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.011365775Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.02153928Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:23.022817117Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:23.024953731Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:23.028102567Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:23.029879034Z 47 PC: 18be5 | Get disk transfer address
2018-12-17T22:01:23.032092945Z 26 PC: 18bf0 | Set disk transfer address
2018-12-17T22:01:23.033196684Z 78 PC: 18bfc | Find first file
2018-12-17T22:01:23.039427459Z 26 PC: 18c0e | Set disk transfer address
2018-12-17T22:01:23.041789698Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.047978677Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.054174615Z 61 PC: 13531 | Open file (Filename = 'EDIT.COM')
2018-12-17T22:01:23.06107672Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.067078095Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:23.069088707Z 78 PC: 1301d | Find first file
2018-12-17T22:01:23.075205529Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.081808112Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.088582173Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T22:01:23.092823013Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:23.093944494Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:23.098379184Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.099735224Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.105033008Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.110394318Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.120516825Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.122122172Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.131379242Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.140809295Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:23.14256536Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:23.144243741Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:23.147138392Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:23.148656092Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.155013875Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.160533323Z 61 PC: 13531 | Open file (Filename = 'FORMAT.COM')
2018-12-17T22:01:23.168304267Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.173922983Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:23.175084752Z 78 PC: 1301d | Find first file
2018-12-17T22:01:23.182193068Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.1883835Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.198004967Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:01:23.20516674Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:23.206713063Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:23.214419323Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.217523715Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.224780822Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.233548889Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.243306481Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.245121947Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.25221213Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.262771938Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:23.264143693Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:23.265479285Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:23.268889646Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:23.270556257Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.278037724Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.290486009Z 61 PC: 13531 | Open file (Filename = 'KEYB.COM')
2018-12-17T22:01:23.296768531Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.303122024Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:23.304275348Z 78 PC: 1301d | Find first file
2018-12-17T22:01:23.310516837Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.316938388Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.326821092Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T22:01:23.334033198Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:23.337393412Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:23.344424968Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.346351298Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.354682228Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.363715041Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.373071821Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.375218111Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.38226066Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.392507162Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:23.393746048Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:23.394791709Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:23.403464589Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:23.405050729Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.411605329Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.418638777Z 61 PC: 13531 | Open file (Filename = 'SYS.COM')
2018-12-17T22:01:23.4255303Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.431620875Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:23.434236991Z 78 PC: 1301d | Find first file
2018-12-17T22:01:23.44061144Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.446806862Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.456851141Z 61 PC: 132ee | Open file (Filename = 'C:\DOS\SYS.COM')
2018-12-17T22:01:23.46410631Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:23.466261789Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:23.474744928Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.476896149Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.485088651Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.494327717Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.503095502Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.50500799Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.512621989Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.522237425Z 47 PC: 18c22 | Get disk transfer address
2018-12-17T22:01:23.524397517Z 26 PC: 18c2d | Set disk transfer address
2018-12-17T22:01:23.525496455Z 79 PC: 18c31 | Find next file
2018-12-17T22:01:23.53148905Z 26 PC: 18c41 | Set disk transfer address
2018-12-17T22:01:23.533724691Z 98 PC: 18abb | Get current PSP
2018-12-17T22:01:23.535942462Z 26 PC: 12d8f | Set disk transfer address
2018-12-17T22:01:23.537198954Z 78 PC: 12da1 | Find first file
2018-12-17T22:01:23.54390664Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.550005885Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.560444305Z 61 PC: 132ee | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:23.567307819Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:23.569160266Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.572083274Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:23.574247081Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.582968769Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)
2018-12-17T22:01:23.592362493Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.593973127Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.601517875Z 61 PC: 13664 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:23.608966909Z 66 PC: 13697 | Move file pointer
2018-12-17T22:01:23.61033828Z 64 PC: 136d0 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:01:23.611881523Z 62 PC: 136f3 | Close file
2018-12-17T22:01:23.614334953Z 61 PC: 132ee | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:23.620654832Z 87 PC: 1327c | Get or set file date and time
2018-12-17T22:01:23.622234811Z 62 PC: 133d6 | Close file
2018-12-17T22:01:23.629053335Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.638564527Z 75 PC: 12ea2 | Execute program
2018-12-17T22:01:23.656452498Z 26 PC: 1f3b9 | Set disk transfer address
2018-12-17T22:01:23.666582634Z 77 PC: 12eb8 | Get program return code
2018-12-17T22:01:23.668669787Z 26 PC: 1300b | Set disk transfer address
2018-12-17T22:01:23.67086612Z 78 PC: 1301d | Find first file
2018-12-17T22:01:23.676909615Z 67 PC: 13120 | Get or set file attributes
2018-12-17T22:01:23.682548469Z 67 PC: 13157 | Get or set file attributes
2018-12-17T22:01:23.693051274Z 61 PC: 132ee | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:23.699483281Z 87 PC: 1321a | Get or set file date and time
2018-12-17T22:01:23.700896078Z 63 PC: 13390 | Read file or device (Read 4080 bytes on handle 5)
2018-12-17T22:01:23.709817424Z 66 PC: 188cb | Move file pointer
2018-12-17T22:01:23.714005856Z 64 PC: 1333a | Write file or device (Write 4080 bytes on handle 5)