Time Syscall Op Syscall Name
2018-12-17T21:53:19.520747538Z 44 PC: 1410e | Get time 0x1410e: mov bl, dl
0x14110: mov ah, 0xb
0x14112: int 0x21
0x14114: cmp ah, 0
0x14117: jne 0x14120
0x14119: add bx, bp
0x1411b: cmp al, byte ptr cs:[bx]
0x1411e: je 0x14173
0x14120: push ds
0x14121: push es
0x14122: mov ah, 0x4a
0x14124: mov bx, 0xffff
0x14127: int 0x21
0x14129: sub bx, 0x26
0x1412d: mov ax, 0x4a00
0x14130: int 0x21
0x14132: mov ax, 0x4800
0x14135: mov bx, 0x25
0x14138: int 0x21
0x1413a: mov es, ax
2018-12-17T21:53:19.523859298Z 11 PC: 14114 | Get input status
2018-12-17T21:53:19.526512228Z 74 PC: 14129 | Reallocate memory
2018-12-17T21:53:19.528361153Z 74 PC: 14132 | Reallocate memory
2018-12-17T21:53:19.530469219Z 72 PC: 1413a | Allocate memory
2018-12-17T21:53:19.532973632Z 37 PC: 14171 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:19.534993837Z 48 PC: 12a6d | Get DOS version
2018-12-17T21:53:19.537226463Z 9 PC: 12a84 | Display string (Could not find end pointer)
2018-12-17T21:53:19.546712545Z 61 PC: 12cc4 | Open file (Filename = '')
2018-12-17T21:53:19.553555339Z 9 PC: 12a92 | Display string (Could not find end pointer)
2018-12-17T21:53:19.55629353Z 93 PC: 12b31 | File sharing functions
2018-12-17T21:53:19.559195313Z 9 PC: 12b10 | Display string (String= 'Size change=+022Ch/00556d. Virus might be activ? ')
2018-12-17T21:53:19.564670377Z 76 PC: 12b16 | Terminate with return code (Return code = '1')