Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Animus.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:39.387923404Z 53 PC: 13692 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:39.389535273Z 53 PC: 13692 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:39.390591845Z 53 PC: 13692 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:39.391597289Z 53 PC: 13692 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:39.393525194Z 53 PC: 13692 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:39.394512174Z 53 PC: 13692 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:39.395474427Z 53 PC: 13692 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:39.396666547Z 53 PC: 13692 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:39.397934465Z 53 PC: 13692 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:39.398921694Z 53 PC: 13692 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:39.400197029Z 53 PC: 13692 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:39.401345854Z 53 PC: 13692 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:39.402221471Z 53 PC: 13692 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:39.402974643Z 53 PC: 13692 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:39.404282369Z 53 PC: 13692 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:39.405309515Z 53 PC: 13692 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:39.406264537Z 53 PC: 13692 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:39.407691479Z 53 PC: 13692 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:39.408748934Z 53 PC: 13692 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:39.409726078Z 37 PC: 136a7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:39.411068098Z 37 PC: 136af | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:39.412372438Z 37 PC: 136b7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:39.413657365Z 37 PC: 136bf | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:39.415585197Z 68 PC: 13a2f | I/O control for devices (Set for = '')
2018-12-17T22:02:39.416953784Z 48 PC: 142ee | Get DOS version
2018-12-17T22:02:39.41888927Z 61 PC: 140ae | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:02:39.425636167Z 87 PC: 133e0 | Get or set file date and time
2018-12-17T22:02:39.426962467Z 63 PC: 14181 | Read file or device (Read 7392 bytes on handle 5)
2018-12-17T22:02:39.433968864Z 87 PC: 1340d | Get or set file date and time
2018-12-17T22:02:39.436223012Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.461270898Z 25 PC: 1437b | Get default drive
2018-12-17T22:02:39.462417996Z 71 PC: 1438e | Get current directory
2018-12-17T22:02:39.470794919Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.472118388Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.477549543Z 26 PC: 13461 | Set disk transfer address
2018-12-17T22:02:39.483478158Z 79 PC: 13466 | Find next file
2018-12-17T22:02:39.487473869Z 26 PC: 13461 | Set disk transfer address
2018-12-17T22:02:39.488807152Z 79 PC: 13466 | Find next file
2018-12-17T22:02:39.492937755Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.494052301Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.496012155Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.49707252Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.503865283Z 61 PC: 140ae | Open file (Filename = 'A:\SLEEP.COM')
2018-12-17T22:02:39.510577294Z 63 PC: 14181 | Read file or device (Read 27 bytes on handle 5)
2018-12-17T22:02:39.517351812Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.519892293Z 60 PC: 140ae | Create or truncate file
2018-12-17T22:02:39.531026777Z 67 PC: 1339f | Get or set file attributes
2018-12-17T22:02:39.536563054Z 61 PC: 140ae | Open file (Filename = 'A:\SLEEP.COM')
2018-12-17T22:02:39.544399316Z 64 PC: 14181 | Write file or device (Write 7392 bytes on handle 5)
2018-12-17T22:02:39.552770939Z 63 PC: 14181 | Read file or device (Read 8192 bytes on handle 6)
2018-12-17T22:02:39.555334126Z 64 PC: 14181 | Write file or device (Write 407 bytes on handle 5)
2018-12-17T22:02:39.563367621Z 66 PC: 1424a | Move file pointer
2018-12-17T22:02:39.564664405Z 66 PC: 14258 | Move file pointer
2018-12-17T22:02:39.565964394Z 66 PC: 14266 | Move file pointer
2018-12-17T22:02:39.56828884Z 87 PC: 1340d | Get or set file date and time
2018-12-17T22:02:39.569768566Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.571464162Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.579579971Z 65 PC: 14283 | Delete file (Filename = 'A:\SLEEP.COM')
2018-12-17T22:02:39.590827938Z 86 PC: 142b9 | Rename file
2018-12-17T22:02:39.601597945Z 67 PC: 133c6 | Get or set file attributes
2018-12-17T22:02:39.623762629Z 26 PC: 13461 | Set disk transfer address
2018-12-17T22:02:39.62465684Z 79 PC: 13466 | Find next file
2018-12-17T22:02:39.626883993Z 61 PC: 140ae | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:02:39.631562349Z 63 PC: 14181 | Read file or device (Read 27 bytes on handle 5)
2018-12-17T22:02:39.638110859Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.64086495Z 60 PC: 140ae | Create or truncate file
2018-12-17T22:02:39.652769901Z 67 PC: 1339f | Get or set file attributes
2018-12-17T22:02:39.658630534Z 61 PC: 140ae | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:02:39.665424064Z 64 PC: 14181 | Write file or device (Write 7392 bytes on handle 5)
2018-12-17T22:02:39.677936505Z 63 PC: 14181 | Read file or device (Read 8192 bytes on handle 6)
2018-12-17T22:02:39.68107924Z 64 PC: 14181 | Write file or device (Write 27 bytes on handle 5)
2018-12-17T22:02:39.684149632Z 66 PC: 1424a | Move file pointer
2018-12-17T22:02:39.687352648Z 66 PC: 14258 | Move file pointer
2018-12-17T22:02:39.688954829Z 66 PC: 14266 | Move file pointer
2018-12-17T22:02:39.690622068Z 87 PC: 1340d | Get or set file date and time
2018-12-17T22:02:39.693227439Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.695269843Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.702918409Z 65 PC: 14283 | Delete file (Filename = 'A:\PRINT.COM')
2018-12-17T22:02:39.71475137Z 86 PC: 142b9 | Rename file
2018-12-17T22:02:39.726224734Z 67 PC: 133c6 | Get or set file attributes
2018-12-17T22:02:39.73896088Z 26 PC: 13461 | Set disk transfer address
2018-12-17T22:02:39.741199181Z 79 PC: 13466 | Find next file
2018-12-17T22:02:39.745143324Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.746433935Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.754008837Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.755227757Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.76214199Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.764284838Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.770292188Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.771492046Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.781259353Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.782488755Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.791055099Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.792609694Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.802542094Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.80375379Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.812241317Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.814225413Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.820437847Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.821783594Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.829797549Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.830884381Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.833426867Z 26 PC: 1343d | Set disk transfer address
2018-12-17T22:02:39.835001145Z 78 PC: 13449 | Find first file
2018-12-17T22:02:39.837375505Z 61 PC: 140ae | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:02:39.844745849Z 87 PC: 133e0 | Get or set file date and time
2018-12-17T22:02:39.847021877Z 60 PC: 140ae | Create or truncate file
2018-12-17T22:02:39.859175507Z 66 PC: 141e0 | Move file pointer
2018-12-17T22:02:39.860653846Z 63 PC: 14181 | Read file or device (Read 8192 bytes on handle 5)
2018-12-17T22:02:39.868928293Z 64 PC: 14181 | Write file or device (Write 100 bytes on handle 6)
2018-12-17T22:02:39.873128439Z 66 PC: 1424a | Move file pointer
2018-12-17T22:02:39.874496307Z 66 PC: 14258 | Move file pointer
2018-12-17T22:02:39.876880606Z 66 PC: 14266 | Move file pointer
2018-12-17T22:02:39.878982087Z 87 PC: 1340d | Get or set file date and time
2018-12-17T22:02:39.880432322Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.883076464Z 62 PC: 140fe | Close file
2018-12-17T22:02:39.890621079Z 44 PC: 1402f | Get time 0x1402f: mov word ptr [0x42], cx
0x14033: mov word ptr [0x44], dx
0x14037: retf
0x14038: mov bx, sp
0x1403a: push ds
0x1403b: les di, ptr ss:[bx + 8]
0x1403f: lds si, ptr ss:[bx + 4]
0x14043: cld
0x14044: xor ax, ax
0x14046: stosw word ptr es:[di], ax
0x14047: mov ax, 0xd7b0
0x1404a: stosw word ptr es:[di], ax
0x1404b: xor ax, ax
0x1404d: mov cx, 0x16
0x14050: rep stosd dword ptr es:[di], eax
0x14052: lodsb al, byte ptr [si]
0x14053: cmp al, 0x4f
0x14055: jbe 0x14059
0x14057: mov al, 0x4f
0x14059: mov cl, al
2018-12-17T22:02:39.893080208Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:39.895071721Z 37 PC: 134ad | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:39.8961171Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:39.897198322Z 37 PC: 134ad | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:39.899261458Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:39.900349499Z 37 PC: 134ad | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:39.901323014Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:39.903577904Z 37 PC: 134ad | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:39.904670387Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:39.905796495Z 37 PC: 134ad | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:39.908109523Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:39.909225461Z 37 PC: 134ad | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:39.91031087Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:39.91270852Z 37 PC: 134ad | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:39.913787098Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:39.915377018Z 37 PC: 134ad | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:39.917683462Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:39.919147168Z 37 PC: 134ad | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:39.920400487Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:39.921984351Z 37 PC: 134ad | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:39.924005069Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:39.925330975Z 37 PC: 134ad | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:39.926589638Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:39.928621337Z 37 PC: 134ad | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:39.929707672Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:39.930835469Z 37 PC: 134ad | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:39.933415795Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:39.934713567Z 37 PC: 134ad | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:39.935955389Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:39.938362818Z 37 PC: 134ad | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:39.939721555Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:39.941325786Z 37 PC: 134ad | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:39.94398544Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:39.945297354Z 37 PC: 134ad | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:39.946566664Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:39.948404291Z 37 PC: 134ad | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:39.950167322Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:39.951449175Z 37 PC: 134ad | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:39.954093613Z 41 PC: 1352d | Parse filename
2018-12-17T22:02:39.955428053Z 41 PC: 1353b | Parse filename
2018-12-17T22:02:39.956849762Z 75 PC: 13546 | Execute program
2018-12-17T22:02:39.967764751Z 9 PC: 23e22 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-17T22:02:39.974569358Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:39.976753919Z 37 PC: 134ad | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:39.978011035Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:39.979173363Z 37 PC: 134ad | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:39.980527867Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:39.982124364Z 37 PC: 134ad | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:39.983348706Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:39.984603505Z 37 PC: 134ad | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:39.986336732Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:39.987674668Z 37 PC: 134ad | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:39.988973183Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:39.990701065Z 37 PC: 134ad | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:39.99177567Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:39.992850735Z 37 PC: 134ad | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:39.994291988Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:39.995404059Z 37 PC: 134ad | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:39.996661231Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:39.998219797Z 37 PC: 134ad | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:39.999318879Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:40.001206395Z 37 PC: 134ad | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:40.002296647Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:40.003352551Z 37 PC: 134ad | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:40.005231619Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:40.006318897Z 37 PC: 134ad | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:40.007306873Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:40.008836595Z 37 PC: 134ad | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:40.009835886Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:40.010864188Z 37 PC: 134ad | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:40.012472615Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:40.013580704Z 37 PC: 134ad | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:40.014584466Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:40.016159687Z 37 PC: 134ad | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:40.017031093Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:40.01804826Z 37 PC: 134ad | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:40.019480478Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:40.020483253Z 37 PC: 134ad | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:40.021461724Z 53 PC: 134a4 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:40.02287599Z 37 PC: 134ad | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:40.024129775Z 65 PC: 14283 | Delete file (Filename = 'A:\Animus.exe')
2018-12-17T22:02:40.039740322Z 64 PC: 13b32 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:02:40.041788879Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:40.042788742Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:40.044328253Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:40.045372994Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:40.046409911Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:40.047917348Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:40.048909745Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:40.049921041Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:40.0517956Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:40.052819141Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:40.053800471Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:40.055381466Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:40.056332805Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:40.057587831Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:40.059011207Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:40.059997807Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:40.06096814Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:40.063064548Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:40.064035781Z 37 PC: 137a6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:40.065008673Z 76 PC: 137e5 | Terminate with return code (Return code = '0')