.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T23:11:19.271477632Z | 26 | PC: 12f37 | Set disk transfer address |
2018-12-17T23:11:19.27321354Z | 42 | PC: 12f3b | Get date 0x12f3b: cmp dx, 0x801 0x12f3f: jne 0x12f44 0x12f41: call 0x12fe9 0x12f44: mov ah, 0x4e 0x12f46: xor cx, cx 0x12f48: lea dx, word ptr [bp + 0x230] 0x12f4c: int 0x21 0x12f4e: jb 0x12fb9 0x12f50: mov ax, 0x3d02 0x12f53: lea dx, word ptr [bp + 0x2c6] 0x12f57: int 0x21 0x12f59: xchg ax, bx 0x12f5a: call 0x12fdb 0x12f5d: mov ax, word ptr cs:[bp + 0x2c2] 0x12f62: mov cx, word ptr cs:[bp + 0x237] 0x12f67: add cx, 0x1a8 0x12f6b: cmp ax, cx 0x12f6d: je 0x12fb1 0x12f6f: xor al, al 0x12f71: xor dx, dx |
2018-12-17T23:11:19.27594593Z | 78 | PC: 12f4e | Find first file |
2018-12-17T23:11:19.283274296Z | 61 | PC: 12f59 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:11:19.291362382Z | 63 | PC: 12fe8 | Read file or device (Read 3 bytes on handle 5) |
2018-12-17T23:11:19.315906883Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.322129746Z | 63 | PC: 12fe8 | Read file or device (Read 3 bytes on handle 5) |
2018-12-17T23:11:19.325885133Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.328689733Z | 64 | PC: 12fda | Write file or device (Write 1 bytes on handle 5) |
2018-12-17T23:11:19.333074656Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.335075612Z | 64 | PC: 12fa1 | Write file or device (Write 2 bytes on handle 5) |
2018-12-17T23:11:19.339776179Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.342164892Z | 64 | PC: 13042 | Write file or device (Write 421 bytes on handle 5) |
2018-12-17T23:11:19.361356353Z | 62 | PC: 12fb5 | Close file |
2018-12-17T23:11:19.372165657Z | 79 | PC: 12f4e | Find next file |
2018-12-17T23:11:19.375241507Z | 61 | PC: 12f59 | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:11:19.382997239Z | 63 | PC: 12fe8 | Read file or device (Read 3 bytes on handle 5) |
2018-12-17T23:11:19.390517371Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.402304191Z | 63 | PC: 12fe8 | Read file or device (Read 3 bytes on handle 5) |
2018-12-17T23:11:19.40547034Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.40740976Z | 64 | PC: 12fda | Write file or device (Write 1 bytes on handle 5) |
2018-12-17T23:11:19.411667737Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.41379233Z | 64 | PC: 12fa1 | Write file or device (Write 2 bytes on handle 5) |
2018-12-17T23:11:19.417267711Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-17T23:11:19.420298578Z | 64 | PC: 13042 | Write file or device (Write 421 bytes on handle 5) |
2018-12-17T23:11:19.423427953Z | 62 | PC: 12faf | Close file |
2018-12-17T23:11:19.433185452Z | 26 | PC: 12fbf | Set disk transfer address |
2018-12-17T23:11:19.435920617Z | 9 | PC: 12e37 | Display string (String= ' Stoned virus Remover 2.10 (c)1990 David Tinker. Public Domain. ') |
2018-12-17T23:11:19.445526392Z | 9 | PC: 12e2c | Display string (Could not find end pointer) |
2018-12-17T23:11:19.452201483Z | 9 | PC: 12e69 | Display string (String= 'Checking drive A: ') |
2018-12-17T23:11:19.464018307Z | 9 | PC: 12efa | Display string (String= 'Stoned virus not found on disk ') |
2018-12-17T23:11:19.470327346Z | 9 | PC: 12e69 | Display string (String= 'Checking drive B: ') |
2018-12-17T23:11:19.473902527Z | 9 | PC: 12e84 | Display string (String= 'Error reading disk ') |
2018-12-17T23:11:19.481074753Z | 9 | PC: 12e69 | Display string (String= 'Checking drive C: ') |
2018-12-17T23:11:19.486481083Z | 9 | PC: 12efa | Display string (String= 'Stoned virus not found on disk ') |
2018-12-17T23:11:19.491438604Z | 76 | PC: 12f16 | Terminate with return code (Return code = '0') |
.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-25T12:55:02.546995075Z | 26 | PC: 12f37 | Set disk transfer address |
2018-12-25T12:55:02.548579397Z | 42 | PC: 12f3b | Get date 0x12f3b: cmp dx, 0x801 0x12f3f: jne 0x12f44 0x12f41: call 0x12fe9 0x12f44: mov ah, 0x4e 0x12f46: xor cx, cx 0x12f48: lea dx, word ptr [bp + 0x230] 0x12f4c: int 0x21 0x12f4e: jb 0x12fb9 0x12f50: mov ax, 0x3d02 0x12f53: lea dx, word ptr [bp + 0x2c6] 0x12f57: int 0x21 0x12f59: xchg ax, bx 0x12f5a: call 0x12fdb 0x12f5d: mov ax, word ptr cs:[bp + 0x2c2] 0x12f62: mov cx, word ptr cs:[bp + 0x237] 0x12f67: add cx, 0x1a8 0x12f6b: cmp ax, cx 0x12f6d: je 0x12fb1 0x12f6f: xor al, al 0x12f71: xor dx, dx |
2018-12-25T12:55:02.552036674Z | 78 | PC: 12f4e | Find first file |
2018-12-25T12:55:02.559112624Z | 61 | PC: 12f59 | Open file (Filename = 'SLEEP.COM') |
2018-12-25T12:55:02.568190858Z | 63 | PC: 12fe8 | Read file or device (Read 3 bytes on handle 5) |
2018-12-25T12:55:02.573508294Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-25T12:55:02.574997683Z | 63 | PC: 12fe8 | Read file or device (See above) |
2018-12-25T12:55:02.576960145Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.578637184Z | 64 | PC: 12fda | Write file or device (Write 1 bytes on handle 5) |
2018-12-25T12:55:02.580877077Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.582171471Z | 64 | PC: 12fa1 | Write file or device (Write 2 bytes on handle 5) |
2018-12-25T12:55:02.584390106Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.585935449Z | 64 | PC: 13042 | Write file or device (Write 421 bytes on handle 5) |
2018-12-25T12:55:02.598214192Z | 62 | PC: 12fb5 | Close file |
2018-12-25T12:55:02.604562669Z | 79 | PC: 12f4e | Find next file (See above) |
2018-12-25T12:55:02.607059057Z | 61 | PC: 12f59 | Open file (See above) |
2018-12-25T12:55:02.611705086Z | 63 | PC: 12fe8 | Read file or device (See above) |
2018-12-25T12:55:02.61619943Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.618171663Z | 63 | PC: 12fe8 | Read file or device (See above) |
2018-12-25T12:55:02.620107802Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.621339827Z | 64 | PC: 12fda | Write file or device (See above) |
2018-12-25T12:55:02.624123472Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.625402135Z | 64 | PC: 12fa1 | Write file or device (See above) |
2018-12-25T12:55:02.627367719Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:02.629664551Z | 64 | PC: 13042 | Write file or device (See above) |
2018-12-25T12:55:02.632074658Z | 62 | PC: 12faf | Close file |
2018-12-25T12:55:02.637853764Z | 26 | PC: 12fbf | Set disk transfer address |
2018-12-25T12:55:02.644139914Z | 9 | PC: 12e37 | Display string (String= ' Stoned virus Remover 2.10 (c)1990 David Tinker. Public Domain. ') |
2018-12-25T12:55:02.649603114Z | 9 | PC: 12e2c | Display string (Could not find end pointer) |
2018-12-25T12:55:02.653043991Z | 9 | PC: 12e69 | Display string (String= 'Checking drive A: ') |
2018-12-25T12:55:02.679563893Z | 9 | PC: 12efa | Display string (String= 'Stoned virus not found on disk ') |
2018-12-25T12:55:02.684232825Z | 9 | PC: 12e69 | Display string (See above) |
2018-12-25T12:55:02.688855518Z | 9 | PC: 12e84 | Display string (String= 'Error reading disk ') |
2018-12-25T12:55:02.693586953Z | 9 | PC: 12e69 | Display string (See above) |
2018-12-25T12:55:02.698952746Z | 9 | PC: 12efa | Display string (See above) |
2018-12-25T12:55:02.70510345Z | 76 | PC: 12f16 | Terminate with return code (Return code = '0') |
.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-25T12:55:03.114747717Z | 26 | PC: 12f37 | Set disk transfer address |
2018-12-25T12:55:03.116581809Z | 42 | PC: 12f3b | Get date 0x12f3b: cmp dx, 0x801 0x12f3f: jne 0x12f44 0x12f41: call 0x12fe9 0x12f44: mov ah, 0x4e 0x12f46: xor cx, cx 0x12f48: lea dx, word ptr [bp + 0x230] 0x12f4c: int 0x21 0x12f4e: jb 0x12fb9 0x12f50: mov ax, 0x3d02 0x12f53: lea dx, word ptr [bp + 0x2c6] 0x12f57: int 0x21 0x12f59: xchg ax, bx 0x12f5a: call 0x12fdb 0x12f5d: mov ax, word ptr cs:[bp + 0x2c2] 0x12f62: mov cx, word ptr cs:[bp + 0x237] 0x12f67: add cx, 0x1a8 0x12f6b: cmp ax, cx 0x12f6d: je 0x12fb1 0x12f6f: xor al, al 0x12f71: xor dx, dx |
2018-12-25T12:55:03.129203697Z | 9 | PC: 1300b | Display string (String= '** Today Is The Birthday Of The Phantom Programmer! **') |
2018-12-25T12:55:03.133816828Z | 9 | PC: 13021 | Display string (String= ' --- Files Infected by the Destructor Virus ! ---') |
2018-12-25T12:55:03.138377392Z | 8 | PC: 1302c | Console input without echo |
.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-25T12:55:03.649874466Z | 26 | PC: 12f37 | Set disk transfer address |
2018-12-25T12:55:03.651099173Z | 42 | PC: 12f3b | Get date 0x12f3b: cmp dx, 0x801 0x12f3f: jne 0x12f44 0x12f41: call 0x12fe9 0x12f44: mov ah, 0x4e 0x12f46: xor cx, cx 0x12f48: lea dx, word ptr [bp + 0x230] 0x12f4c: int 0x21 0x12f4e: jb 0x12fb9 0x12f50: mov ax, 0x3d02 0x12f53: lea dx, word ptr [bp + 0x2c6] 0x12f57: int 0x21 0x12f59: xchg ax, bx 0x12f5a: call 0x12fdb 0x12f5d: mov ax, word ptr cs:[bp + 0x2c2] 0x12f62: mov cx, word ptr cs:[bp + 0x237] 0x12f67: add cx, 0x1a8 0x12f6b: cmp ax, cx 0x12f6d: je 0x12fb1 0x12f6f: xor al, al 0x12f71: xor dx, dx |
2018-12-25T12:55:03.65452491Z | 78 | PC: 12f4e | Find first file |
2018-12-25T12:55:03.661574712Z | 61 | PC: 12f59 | Open file (Filename = 'SLEEP.COM') |
2018-12-25T12:55:03.669287339Z | 63 | PC: 12fe8 | Read file or device (Read 3 bytes on handle 5) |
2018-12-25T12:55:03.677085652Z | 66 | PC: 12fc6 | Move file pointer |
2018-12-25T12:55:03.678965813Z | 63 | PC: 12fe8 | Read file or device (See above) |
2018-12-25T12:55:03.682137229Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.684743311Z | 64 | PC: 12fda | Write file or device (Write 1 bytes on handle 5) |
2018-12-25T12:55:03.686716587Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.687933336Z | 64 | PC: 12fa1 | Write file or device (Write 2 bytes on handle 5) |
2018-12-25T12:55:03.690138983Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.691500807Z | 64 | PC: 13042 | Write file or device (Write 421 bytes on handle 5) |
2018-12-25T12:55:03.702584876Z | 62 | PC: 12fb5 | Close file |
2018-12-25T12:55:03.709392959Z | 79 | PC: 12f4e | Find next file (See above) |
2018-12-25T12:55:03.711782212Z | 61 | PC: 12f59 | Open file (See above) |
2018-12-25T12:55:03.71742118Z | 63 | PC: 12fe8 | Read file or device (See above) |
2018-12-25T12:55:03.740400499Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.742703625Z | 63 | PC: 12fe8 | Read file or device (See above) |
2018-12-25T12:55:03.745540351Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.74700152Z | 64 | PC: 12fda | Write file or device (See above) |
2018-12-25T12:55:03.75049377Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.751959276Z | 64 | PC: 12fa1 | Write file or device (See above) |
2018-12-25T12:55:03.755037884Z | 66 | PC: 12fc6 | Move file pointer (See above) |
2018-12-25T12:55:03.760598952Z | 64 | PC: 13042 | Write file or device (See above) |
2018-12-25T12:55:03.763782734Z | 62 | PC: 12faf | Close file |
2018-12-25T12:55:03.772545326Z | 26 | PC: 12fbf | Set disk transfer address |
2018-12-25T12:55:03.775337507Z | 9 | PC: 12e37 | Display string (String= ' Stoned virus Remover 2.10 (c)1990 David Tinker. Public Domain. ') |
2018-12-25T12:55:03.784655298Z | 9 | PC: 12e2c | Display string (Could not find end pointer) |
2018-12-25T12:55:03.791853768Z | 9 | PC: 12e69 | Display string (String= 'Checking drive A: ') |
2018-12-25T12:55:03.79862898Z | 9 | PC: 12efa | Display string (String= 'Stoned virus not found on disk ') |
2018-12-25T12:55:03.803947676Z | 9 | PC: 12e69 | Display string (See above) |
2018-12-25T12:55:03.808795304Z | 9 | PC: 12e84 | Display string (String= 'Error reading disk ') |
2018-12-25T12:55:03.813578393Z | 9 | PC: 12e69 | Display string (See above) |
2018-12-25T12:55:03.828532069Z | 9 | PC: 12efa | Display string (See above) |
2018-12-25T12:55:03.835014467Z | 76 | PC: 12f16 | Terminate with return code (Return code = '0') |
.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-25T12:55:04.72597194Z | 26 | PC: 12f37 | Set disk transfer address |
2018-12-25T12:55:04.727548262Z | 42 | PC: 12f3b | Get date 0x12f3b: cmp dx, 0x801 0x12f3f: jne 0x12f44 0x12f41: call 0x12fe9 0x12f44: mov ah, 0x4e 0x12f46: xor cx, cx 0x12f48: lea dx, word ptr [bp + 0x230] 0x12f4c: int 0x21 0x12f4e: jb 0x12fb9 0x12f50: mov ax, 0x3d02 0x12f53: lea dx, word ptr [bp + 0x2c6] 0x12f57: int 0x21 0x12f59: xchg ax, bx 0x12f5a: call 0x12fdb 0x12f5d: mov ax, word ptr cs:[bp + 0x2c2] 0x12f62: mov cx, word ptr cs:[bp + 0x237] 0x12f67: add cx, 0x1a8 0x12f6b: cmp ax, cx 0x12f6d: je 0x12fb1 0x12f6f: xor al, al 0x12f71: xor dx, dx |
2018-12-25T12:55:04.731773524Z | 9 | PC: 1300b | Display string (String= '** Today Is The Birthday Of The Phantom Programmer! **') |
2018-12-25T12:55:04.735984305Z | 9 | PC: 13021 | Display string (String= ' --- Files Infected by the Destructor Virus ! ---') |
2018-12-25T12:55:04.740459225Z | 8 | PC: 1302c | Console input without echo |