Sample viewer

vx.netlux.org/Virus.DOS.HLLO.5424

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:57.161331284Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:57.163802435Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:57.165031951Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:57.166290803Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:57.168213902Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:57.16963645Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:57.171139387Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:57.172630583Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:57.174338261Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:57.175513048Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:57.176715486Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:57.178916246Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:57.180295479Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:57.181650405Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:57.18362638Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:57.185002511Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:57.186379486Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:57.188133187Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:57.189613166Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:57.191187987Z 37 PC: 1300f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:57.192685518Z 37 PC: 13017 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:57.197954422Z 37 PC: 1301f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:57.199077886Z 37 PC: 13027 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:57.200548031Z 68 PC: 13cde | I/O control for devices (Set for = '&���&�G &�f %:��&�G&:F�������')
2018-12-17T22:20:57.202661652Z 64 PC: 13418 | Write file or device (Write 23 bytes on handle 1)
2018-12-17T22:20:57.207779914Z 26 PC: 12e6d | Set disk transfer address
2018-12-17T22:20:57.209102654Z 78 PC: 12e79 | Find first file
2018-12-17T22:20:57.223262673Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:57.242943131Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.261987618Z 61 PC: 136c0 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:20:57.269441452Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:57.271345514Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:57.272965844Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:57.279680691Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.281277446Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.282647108Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.284257741Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.302251306Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.304000771Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.306041308Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:57.313929608Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:57.321727232Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.323862784Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:57.326287659Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.333454063Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.343607582Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:57.345814544Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:57.348941836Z 25 PC: 1389b | Get default drive
2018-12-17T22:20:57.350238821Z 71 PC: 138ae | Get current directory
2018-12-17T22:20:57.35473171Z 14 PC: 138f4 | Set default drive (Drive = 'C')
2018-12-17T22:20:57.356488353Z 25 PC: 138f8 | Get default drive
2018-12-17T22:20:57.357839966Z 59 PC: 13962 | Change current directory
2018-12-17T22:20:57.364368101Z 26 PC: 12e6d | Set disk transfer address
2018-12-17T22:20:57.365833457Z 78 PC: 12e79 | Find first file
2018-12-17T22:20:57.374568181Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:57.380628866Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.736646943Z 61 PC: 136c0 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:20:57.743577147Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:57.745410403Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:57.747781392Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:57.75553865Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.757187483Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.759453443Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.76120171Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.762827361Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.76565274Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.767813939Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:57.77665103Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:57.785827144Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.788316641Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:57.790512624Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.797839986Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.809000821Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:57.810410604Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:57.815192227Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:57.822124584Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.831802669Z 61 PC: 136c0 | Open file (Filename = 'CHKDSK.EXE')
2018-12-17T22:20:57.840386993Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:57.842410528Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:57.844404003Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:57.852150356Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.853586813Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.854954708Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.857172012Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.858575673Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.859958247Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.862186318Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:57.869332381Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:57.87715839Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.879835427Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:57.88166868Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.888155249Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.898651886Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:57.900062241Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:57.903551681Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:57.909834092Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.919278246Z 61 PC: 136c0 | Open file (Filename = 'DEBUG.EXE')
2018-12-17T22:20:57.926603902Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:57.92881271Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:57.930298588Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:57.936852943Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.939092549Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.940442576Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.941850961Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:57.943466743Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:57.944934886Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:57.946310927Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:57.95514618Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:57.963712918Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.9658696Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:57.967839191Z 62 PC: 13710 | Close file
2018-12-17T22:20:57.975566512Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:57.984564525Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:57.985496826Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:57.989441879Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:57.995127321Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.00476238Z 61 PC: 136c0 | Open file (Filename = 'EXPAND.EXE')
2018-12-17T22:20:58.012187924Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.01360953Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.015003203Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.022172925Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.023664814Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.026200307Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.028688721Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.030860588Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.032568304Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.034981432Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.043153844Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.057558854Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.060816242Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.062843338Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.069800417Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.080480052Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.081972862Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.085823332Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.092732364Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.102724429Z 61 PC: 136c0 | Open file (Filename = 'FDISK.EXE')
2018-12-17T22:20:58.109200003Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.111685883Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.11308194Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.11960083Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.122403168Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.12374532Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.125503124Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.128014985Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.129825965Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.131560435Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.139667921Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.14760731Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.14944266Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.151783135Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.158246801Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.168936121Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.170688696Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.174234603Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.180152546Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.190426905Z 61 PC: 136c0 | Open file (Filename = 'MEM.EXE')
2018-12-17T22:20:58.197612325Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.199031812Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.201406316Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.208478461Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.209807281Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.211807051Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.213282146Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.214543214Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.216019147Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.21793102Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.224968277Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.234258241Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.236996302Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.238869676Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.24568812Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.255821257Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.257095128Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.263907283Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.271378074Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.281241757Z 61 PC: 136c0 | Open file (Filename = 'NLSFUNC.EXE')
2018-12-17T22:20:58.289021033Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.291839837Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.293514749Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.300986552Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.303705359Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.305370303Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.307019183Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.309658554Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.311363385Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.313534082Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.32225331Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.337818902Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.340000621Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.342658536Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.349621022Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.360099711Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.361922748Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.366031247Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.374004805Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.384523044Z 61 PC: 136c0 | Open file (Filename = 'QBASIC.EXE')
2018-12-17T22:20:58.391754116Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.393776578Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.396212014Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.404820088Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.406263699Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.408543553Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.410098516Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.412220634Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.414477971Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.416041116Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.417817693Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.420061164Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.426215213Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.435647659Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.437856842Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.441320742Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.447913474Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.458735198Z 61 PC: 136c0 | Open file (Filename = 'REPLACE.EXE')
2018-12-17T22:20:58.465628475Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.467415363Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.469591427Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.47639868Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.478071729Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.480382895Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.482131567Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.483776676Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.485703381Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.487415538Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.495026316Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.503460002Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.505296395Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.507647162Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.515114778Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.524765884Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.527140571Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.531142667Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.537298547Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.547604796Z 61 PC: 136c0 | Open file (Filename = 'RESTORE.EXE')
2018-12-17T22:20:58.554823466Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.556310928Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.558649144Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.565414078Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.566809413Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.56885609Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.570305386Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.571642824Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.573872313Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.575306988Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.58246583Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.592509359Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.594374892Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.596125987Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.604253712Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.614217934Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.615794021Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.620567938Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.626766036Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.636199086Z 61 PC: 136c0 | Open file (Filename = 'SCANDISK.EXE')
2018-12-17T22:20:58.644678348Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.646614012Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.648123548Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.652901975Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.65400553Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.655158507Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.656751527Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.657831137Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.659354421Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.661228853Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.665988395Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.67121223Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.673066585Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.674272832Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.67870972Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.685038342Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.686113521Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.690014325Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.695701931Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.704842391Z 61 PC: 136c0 | Open file (Filename = 'SETUP.EXE')
2018-12-17T22:20:58.712939399Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:58.714373947Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:58.715737785Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:58.723667083Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.7250743Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.726427005Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.730695239Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:58.732360879Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:58.734013809Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:58.736123665Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:58.743674244Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:58.751564664Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.753913546Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:58.755419244Z 62 PC: 13710 | Close file
2018-12-17T22:20:58.761868548Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:58.77128243Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:58.772197123Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:58.781222591Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:58.787102264Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.091582958Z 61 PC: 136c0 | Open file (Filename = 'XCOPY.EXE')
2018-12-17T22:20:59.100187862Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:59.102396824Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:59.104151096Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:59.111845457Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.113848118Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.115499046Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.117998634Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.119901816Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.121391729Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.123320793Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:59.13071454Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:59.139073527Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.141425904Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:59.142885294Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.149144686Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.158343813Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:59.159247814Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:59.162970304Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:59.169419524Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.178444435Z 61 PC: 136c0 | Open file (Filename = 'DEFRAG.EXE')
2018-12-17T22:20:59.185595365Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:59.187112352Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:59.188648585Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:59.196361004Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.197917936Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.199466305Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.201615895Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.20332466Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.205236705Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.207285666Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:59.215287937Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:59.223914902Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.225916829Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:59.227667358Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.23558209Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.242437219Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:59.243433927Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:59.248930588Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:59.25283766Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.259642533Z 61 PC: 136c0 | Open file (Filename = 'EMM386.EXE')
2018-12-17T22:20:59.26757203Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:59.269146242Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:59.270707716Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:59.278362221Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.280119955Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.281777405Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.284127269Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.286184674Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.288470708Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.290883942Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:59.298570156Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:59.308531388Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.310824305Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:59.31248076Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.320445944Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.329836059Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:59.33115332Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:59.335528161Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:20:59.341522241Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.3511735Z 61 PC: 136c0 | Open file (Filename = 'MSCDEX.EXE')
2018-12-17T22:20:59.35858924Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:20:59.360275405Z 48 PC: 1380e | Get DOS version
2018-12-17T22:20:59.361864093Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:59.369869573Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.371391186Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.374135014Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.375714504Z 66 PC: 13ddd | Move file pointer
2018-12-17T22:20:59.377873736Z 66 PC: 13deb | Move file pointer
2018-12-17T22:20:59.380329142Z 66 PC: 13df9 | Move file pointer
2018-12-17T22:20:59.381938035Z 63 PC: 13793 | Read file or device (Read 4282 bytes on handle 6)
2018-12-17T22:20:59.389402027Z 64 PC: 13793 | Write file or device (Write 4282 bytes on handle 5)
2018-12-17T22:20:59.398187874Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.399954415Z 87 PC: 12e3d | Get or set file date and time
2018-12-17T22:20:59.40158408Z 62 PC: 13710 | Close file
2018-12-17T22:20:59.408598332Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:20:59.417955868Z 26 PC: 12e91 | Set disk transfer address
2018-12-17T22:20:59.41927803Z 79 PC: 12e96 | Find next file
2018-12-17T22:20:59.423579658Z 14 PC: 138f4 | Set default drive (Drive = 'A')
2018-12-17T22:20:59.42502952Z 25 PC: 138f8 | Get default drive
2018-12-17T22:20:59.426362955Z 59 PC: 13962 | Change current directory
2018-12-17T22:20:59.431820258Z 64 PC: 13418 | Write file or device (Write 33 bytes on handle 1)
2018-12-17T22:20:59.437276273Z 64 PC: 13418 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:20:59.439116751Z 37 PC: 13151 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:59.440737627Z 37 PC: 13151 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:59.441876369Z 37 PC: 13151 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:59.44367848Z 37 PC: 13151 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:59.444754631Z 37 PC: 13151 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:59.445875534Z 37 PC: 13151 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:59.447908805Z 37 PC: 13151 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:59.44898829Z 37 PC: 13151 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:59.450050072Z 37 PC: 13151 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:59.451903518Z 37 PC: 13151 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:59.45308818Z 37 PC: 13151 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:59.454167394Z 37 PC: 13151 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:59.45601696Z 37 PC: 13151 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:59.457816911Z 37 PC: 13151 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:59.45892369Z 37 PC: 13151 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:59.460953465Z 37 PC: 13151 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:59.462261597Z 37 PC: 13151 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:59.463590861Z 37 PC: 13151 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:59.465794382Z 37 PC: 13151 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:59.466923787Z 76 PC: 13190 | Terminate with return code (Return code = '0')