Sample viewer

vx.netlux.org/Virus.DOS.HLLP.6256

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:15:45.021125512Z 53 PC: 1342a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:15:45.023155507Z 53 PC: 1342a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:15:45.02461312Z 53 PC: 1342a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:15:45.02604554Z 53 PC: 1342a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:15:45.028441141Z 53 PC: 1342a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:45.029639832Z 53 PC: 1342a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:45.030723237Z 53 PC: 1342a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:15:45.032027977Z 53 PC: 1342a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:15:45.033770196Z 53 PC: 1342a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:15:45.035277341Z 53 PC: 1342a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:15:45.03690277Z 53 PC: 1342a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:15:45.03875567Z 53 PC: 1342a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:15:45.039929972Z 53 PC: 1342a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:15:45.041368164Z 53 PC: 1342a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:15:45.052841329Z 53 PC: 1342a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:15:45.054044502Z 53 PC: 1342a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:15:45.055394533Z 53 PC: 1342a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:15:45.074657592Z 53 PC: 1342a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:15:45.076482988Z 53 PC: 1342a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:15:45.07812989Z 37 PC: 1343f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:15:45.080483423Z 37 PC: 13447 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:45.082144317Z 37 PC: 1344f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:45.083307952Z 37 PC: 13457 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:15:45.089358965Z 68 PC: 13f84 | I/O control for devices (Set for = '')
2018-12-17T22:15:45.091328824Z 25 PC: 13b3c | Get default drive
2018-12-17T22:15:45.092861459Z 71 PC: 13b4f | Get current directory
2018-12-17T22:15:45.096626927Z 42 PC: 13157 | Get date 0x13157: xor ah, ah
0x13159: les di, ptr [bp + 6]
0x1315c: stosw word ptr es:[di], ax
0x1315d: mov al, dl
0x1315f: les di, ptr [bp + 0xa]
0x13162: stosw word ptr es:[di], ax
0x13163: mov al, dh
0x13165: les di, ptr [bp + 0xe]
0x13168: stosw word ptr es:[di], ax
0x13169: xchg ax, cx
0x1316a: les di, ptr [bp + 0x12]
0x1316d: stosw word ptr es:[di], ax
0x1316e: pop bp
0x1316f: retf 0x10
0x13172: push bp
0x13173: mov bp, sp
0x13175: mov cx, word ptr [bp + 0xa]
0x13178: mov dh, byte ptr [bp + 8]
0x1317b: mov dl, byte ptr [bp + 6]
0x1317e: mov ah, 0x2b
2018-12-17T22:15:45.099202956Z 48 PC: 13aaf | Get DOS version
2018-12-17T22:15:45.101391133Z 61 PC: 138ed | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:15:45.110178847Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 5)
2018-12-17T22:15:45.119111921Z 62 PC: 1393d | Close file
2018-12-17T22:15:45.122206688Z 60 PC: 138ed | Create or truncate file
2018-12-17T22:15:45.143191073Z 65 PC: 13a36 | Delete file (Filename = '�')
2018-12-17T22:15:45.153840752Z 26 PC: 1322d | Set disk transfer address
2018-12-17T22:15:45.154903181Z 78 PC: 13239 | Find first file
2018-12-17T22:15:45.188725028Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.198235545Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.200985389Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.203455879Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.206293505Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.207338972Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.210997013Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.212063387Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.214821998Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.216507838Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.219256723Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.220284121Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.223526897Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.224555223Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.227365226Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.229321403Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.232235546Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.234598106Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.238566915Z 26 PC: 1322d | Set disk transfer address
2018-12-17T22:15:45.239707971Z 78 PC: 13239 | Find first file
2018-12-17T22:15:45.246730567Z 61 PC: 138ed | Open file (Filename = 'TEST.EXE')
2018-12-17T22:15:45.254503751Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:45.26275535Z 62 PC: 1393d | Close file
2018-12-17T22:15:45.264860636Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.266923452Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.269835047Z 71 PC: 13b4f | Get current directory
2018-12-17T22:15:45.272709008Z 14 PC: 13b95 | Set default drive (Drive = 'C')
2018-12-17T22:15:45.274852265Z 25 PC: 13b99 | Get default drive
2018-12-17T22:15:45.276182179Z 59 PC: 13c03 | Change current directory
2018-12-17T22:15:45.280124534Z 26 PC: 1322d | Set disk transfer address
2018-12-17T22:15:45.282370985Z 78 PC: 13239 | Find first file
2018-12-17T22:15:45.288375855Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.289859725Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.293628118Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.295171282Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.298579458Z 59 PC: 13c03 | Change current directory
2018-12-17T22:15:45.305687056Z 26 PC: 1322d | Set disk transfer address
2018-12-17T22:15:45.307458743Z 78 PC: 13239 | Find first file
2018-12-17T22:15:45.317424297Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.319342636Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.323291607Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.32490677Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.329177635Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.330760816Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.334378675Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.336476495Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.340081066Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.341492461Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.345606483Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.347015436Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.350613336Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.35290972Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.356473543Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.357927813Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.36211318Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.363126018Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.366661477Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.368821584Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.372604295Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.37389546Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.378141649Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.379708285Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.383248626Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.385347784Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.389063485Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.39031065Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.394687287Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.396692977Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.400142092Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.401418138Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.408882184Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.410136336Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.413621282Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.415857434Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.419314627Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.420563971Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.42494634Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.426086425Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.429301456Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.43119483Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.43449096Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.435586402Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.439752766Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.441215349Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.444772779Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.450469247Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.453822482Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.454881675Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.458988799Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.460512572Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.463954724Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.465968737Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.470048455Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.471065897Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.475093266Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.47639426Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.479745182Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.481671096Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.48509076Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.486262329Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.490435069Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.491739924Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.498064519Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.499683499Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.503158047Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.504443315Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.508509396Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.50982612Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.513296161Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.515368875Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.518967844Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.520255299Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.524144027Z 26 PC: 1322d | Set disk transfer address
2018-12-17T22:15:45.525733916Z 78 PC: 13239 | Find first file
2018-12-17T22:15:45.532061646Z 61 PC: 138ed | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:15:45.538575237Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:45.54751668Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:45.549098576Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:45.551505062Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:45.90564279Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:45.907490037Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:45.910049744Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:45.912198478Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:45.913959613Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:45.925672314Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:45.928189545Z 62 PC: 1393d | Close file
2018-12-17T22:15:45.935522722Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:45.937770827Z 79 PC: 13256 | Find next file
2018-12-17T22:15:45.941743728Z 61 PC: 138ed | Open file (Filename = 'CHKDSK.EXE')
2018-12-17T22:15:45.948764998Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:45.958441134Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:45.960684405Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:45.962478995Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:45.970911026Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:45.973001881Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:45.974717496Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:45.977482036Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:45.979637195Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:45.992005789Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:45.994736159Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.002443393Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.003836196Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.008362901Z 61 PC: 138ed | Open file (Filename = 'DEBUG.EXE')
2018-12-17T22:15:46.015781372Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.023816249Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.026449214Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.029319261Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.036805556Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.039125747Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.040537651Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.042058257Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.044772721Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.054375167Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.056315534Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.073055245Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.074663817Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.078267508Z 61 PC: 138ed | Open file (Filename = 'EXPAND.EXE')
2018-12-17T22:15:46.086090159Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.095426818Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.097231751Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.099837807Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.10785818Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.109576154Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.112113891Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.113970861Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.115315256Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.124878412Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.126720806Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.134150854Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.13625736Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.139778678Z 61 PC: 138ed | Open file (Filename = 'FDISK.EXE')
2018-12-17T22:15:46.146729706Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.155662795Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.157128066Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.159058538Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.168542533Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.16993474Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.171264028Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.173485267Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.174901386Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.183605418Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.185976692Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.193114707Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.194518943Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.19881678Z 61 PC: 138ed | Open file (Filename = 'MEM.EXE')
2018-12-17T22:15:46.205735665Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.21381592Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.21600181Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.217736319Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.225316421Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.227558324Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.229220196Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.230933276Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.233038062Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.242719336Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.244741043Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.252578199Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.253912268Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.261011649Z 61 PC: 138ed | Open file (Filename = 'NLSFUNC.EXE')
2018-12-17T22:15:46.267852207Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.275887929Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.277722987Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.279030636Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.290549466Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.292239307Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.293464198Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.294740261Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.296581219Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.3059441Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.307500101Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.314647996Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.315806626Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.319589708Z 61 PC: 138ed | Open file (Filename = 'QBASIC.EXE')
2018-12-17T22:15:46.326150512Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.334153176Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.336402124Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.338207333Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.616098241Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.618632076Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.620675966Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.622127581Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.624163411Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.678979443Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.68083063Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.688243758Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.6899567Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.693161024Z 61 PC: 138ed | Open file (Filename = 'REPLACE.EXE')
2018-12-17T22:15:46.700288247Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.708287004Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.710035329Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.71212145Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.719456357Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.721349816Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.723042886Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.724759397Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.727245589Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.73632236Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.737774469Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.746277897Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.747575326Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.751277393Z 61 PC: 138ed | Open file (Filename = 'RESTORE.EXE')
2018-12-17T22:15:46.759541292Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.767596386Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.769031944Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.771122909Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.779186705Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.782066188Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.784023557Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.785980176Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.787606907Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.795887263Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.797325334Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.80470214Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.805656414Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.808794723Z 61 PC: 138ed | Open file (Filename = 'SCANDISK.EXE')
2018-12-17T22:15:46.815767304Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.823483579Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.824817719Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.827049257Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.834721396Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.836879764Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.83823483Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.839548543Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.841353385Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.850329829Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.851861335Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.859297216Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.860100006Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.862338313Z 61 PC: 138ed | Open file (Filename = 'SETUP.EXE')
2018-12-17T22:15:46.867065068Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.872082185Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.873304525Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.874760347Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.879619465Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.881180165Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.88232898Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.88342112Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.885026989Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.89084386Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.892124892Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.897432373Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.898340545Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.900579632Z 61 PC: 138ed | Open file (Filename = 'XCOPY.EXE')
2018-12-17T22:15:46.905320167Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.910588984Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.912287387Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.913374547Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.918412281Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.92023597Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.921425719Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.922793328Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.924566999Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.930810561Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.932321682Z 62 PC: 1393d | Close file
2018-12-17T22:15:46.937514003Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:46.938436107Z 79 PC: 13256 | Find next file
2018-12-17T22:15:46.941510723Z 61 PC: 138ed | Open file (Filename = 'DEFRAG.EXE')
2018-12-17T22:15:46.94578736Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:46.954115837Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:46.956222817Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.957657174Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.964684118Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:46.978028915Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:46.980043366Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:46.981367891Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:46.983161425Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:46.992207577Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:46.994214672Z 62 PC: 1393d | Close file
2018-12-17T22:15:47.000986338Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:47.00191234Z 79 PC: 13256 | Find next file
2018-12-17T22:15:47.008805989Z 61 PC: 138ed | Open file (Filename = 'EMM386.EXE')
2018-12-17T22:15:47.019717996Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 6)
2018-12-17T22:15:47.027855127Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:47.030865618Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:47.032229554Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:47.039731117Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:47.041416594Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:47.042917344Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:47.045838812Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:47.04742461Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 6)
2018-12-17T22:15:47.056646525Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:47.060119101Z 62 PC: 1393d | Close file
2018-12-17T22:15:47.068111228Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:47.069364936Z 79 PC: 13256 | Find next file
2018-12-17T22:15:47.073834833Z 59 PC: 13c03 | Change current directory
2018-12-17T22:15:47.078108758Z 26 PC: 13251 | Set disk transfer address
2018-12-17T22:15:47.079554318Z 79 PC: 13256 | Find next file
2018-12-17T22:15:47.086429127Z 59 PC: 13c03 | Change current directory
2018-12-17T22:15:47.090288029Z 60 PC: 138ed | Create or truncate file
2018-12-17T22:15:47.100579519Z 65 PC: 13a36 | Delete file (Filename = '�')
2018-12-17T22:15:47.115580514Z 26 PC: 1322d | Set disk transfer address
2018-12-17T22:15:47.116689413Z 78 PC: 13239 | Find first file
2018-12-17T22:15:47.123114518Z 14 PC: 13b95 | Set default drive (Drive = 'C')
2018-12-17T22:15:47.124347981Z 25 PC: 13b99 | Get default drive
2018-12-17T22:15:47.127176644Z 59 PC: 13c03 | Change current directory
2018-12-17T22:15:47.13278662Z 14 PC: 13b95 | Set default drive (Drive = 'A')
2018-12-17T22:15:47.134818044Z 25 PC: 13b99 | Get default drive
2018-12-17T22:15:47.136286568Z 59 PC: 13c03 | Change current directory
2018-12-17T22:15:47.141620847Z 61 PC: 138ed | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:15:47.151859499Z 87 PC: 131d0 | Get or set file date and time
2018-12-17T22:15:47.15399848Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:47.156762313Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:47.15847249Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:47.160259616Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:47.162895765Z 63 PC: 139c0 | Read file or device (Read 6256 bytes on handle 7)
2018-12-17T22:15:47.171251978Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:47.173065966Z 64 PC: 139c0 | Write file or device (Write 6256 bytes on handle 7)
2018-12-17T22:15:47.183821864Z 66 PC: 14083 | Move file pointer
2018-12-17T22:15:47.185628103Z 66 PC: 14091 | Move file pointer
2018-12-17T22:15:47.1876056Z 66 PC: 1409f | Move file pointer
2018-12-17T22:15:47.190389268Z 66 PC: 13a1f | Move file pointer
2018-12-17T22:15:47.19218644Z 64 PC: 1391e | Write file or device (Write 0 bytes on handle 7)
2018-12-17T22:15:47.20135591Z 87 PC: 131fd | Get or set file date and time
2018-12-17T22:15:47.203627749Z 62 PC: 1393d | Close file
2018-12-17T22:15:47.21074694Z 53 PC: 1339c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:15:47.212991557Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:15:47.214260688Z 53 PC: 1339c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:15:47.215798135Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:15:47.218082949Z 53 PC: 1339c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:15:47.219210208Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:15:47.22027532Z 53 PC: 1339c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:15:47.222226228Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:15:47.223345045Z 53 PC: 1339c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:47.224441503Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:47.22648334Z 53 PC: 1339c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:47.227896777Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:47.229372429Z 53 PC: 1339c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:15:47.231175146Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:15:47.232562896Z 53 PC: 1339c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:15:47.234504367Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:15:47.236326291Z 53 PC: 1339c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:15:47.237682606Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:15:47.240063521Z 53 PC: 1339c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:15:47.24141709Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:15:47.242301051Z 53 PC: 1339c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:15:47.244051867Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:15:47.244964609Z 53 PC: 1339c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:15:47.246568355Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:15:47.247518772Z 53 PC: 1339c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:15:47.248431645Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:15:47.249909691Z 53 PC: 1339c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:15:47.250812071Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:15:47.251661605Z 53 PC: 1339c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:15:47.254319612Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:15:47.255424077Z 53 PC: 1339c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:15:47.257094047Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:15:47.258223516Z 53 PC: 1339c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:15:47.259454306Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:15:47.26372766Z 53 PC: 1339c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:15:47.266276619Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:15:47.268268017Z 53 PC: 1339c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:15:47.272265522Z 37 PC: 133a5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:15:47.274623462Z 41 PC: 13353 | Parse filename
2018-12-17T22:15:47.277345917Z 41 PC: 13361 | Parse filename
2018-12-17T22:15:47.278811858Z 75 PC: 1336c | Execute program
2018-12-17T22:15:47.296270773Z 80 PC: 1cf29 | Set current PSP
2018-12-17T22:15:47.298060742Z 48 PC: 1cf2e | Get DOS version
2018-12-17T22:15:47.299193026Z 99 PC: 23710 | Get DBCS lead byte table pointer
2018-12-17T22:15:47.300905638Z 101 PC: 1cfb4 | Get extended country info
2018-12-17T22:15:47.302777761Z 99 PC: 1cfba | Get DBCS lead byte table pointer
2018-12-17T22:15:47.303759445Z 74 PC: 1d01c | Reallocate memory
2018-12-17T22:15:47.304799382Z 25 PC: 1d053 | Get default drive
2018-12-17T22:15:47.306198249Z 37 PC: 1cb13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:15:47.307077016Z 37 PC: 1cb1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:47.308623058Z 37 PC: 1cb21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:47.311404526Z 74 PC: 1bcbc | Reallocate memory
2018-12-17T22:15:47.312529893Z 72 PC: 1bcfd | Allocate memory
2018-12-17T22:15:47.315485268Z 72 PC: 1bd35 | Allocate memory
2018-12-17T22:15:47.317100679Z 72 PC: 1bd3d | Allocate memory