Sample viewer

vx.netlux.org/Virus.DOS.HLLW.Wurm.9948

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:13.214507302Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.217780692Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.220705263Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.223730128Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.227820218Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.231332116Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.234442615Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.237709147Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.241659926Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.24445938Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.247335948Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.257900132Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.261024573Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.264175254Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.269196362Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.272667837Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.27561422Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.279360358Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.28217172Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.284934946Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.288192715Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.295836839Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.299127929Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.302896676Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.306039427Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.309168231Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.312134432Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.315552028Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.318807076Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.322083113Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.325850029Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.328895179Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.331983878Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.33581211Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.339688942Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.342756829Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.346685715Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.350499104Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.353302497Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.357151994Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.360132945Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.363216919Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.366916746Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.373757273Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.376711845Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.37995107Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.382741356Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.385580905Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.389363628Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.392424676Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.395246075Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.398567652Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.401624283Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.404672039Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.408347132Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.41141724Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.41442252Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.417845244Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.420880832Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.424377737Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.428664661Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.432601548Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.436373331Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.439633009Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.442788604Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.446312663Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.449464269Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.452320178Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.455227571Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.458784371Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.461387491Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.464219802Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.467836092Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.47087151Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.473966096Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.477968199Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.480806903Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.483271134Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.485395472Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.487385591Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.489232228Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.491459404Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.495039814Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.497816803Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.501166347Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.504502927Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.507234365Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.510884641Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.51381379Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.516473062Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.519704018Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.522438491Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.525041072Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.528189833Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.530967401Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.533813774Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.53711554Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.540085964Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.543094174Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.546690853Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.549709243Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.552686422Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.556362151Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.559373676Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.562366888Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.566244719Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.569072007Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.572594842Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.576465086Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.579547281Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.582338851Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.585660542Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.588589069Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.591293526Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.594772337Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.597504384Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.600209308Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.603852209Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.606759106Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.609597616Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.613351403Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.616095579Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.618809518Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.622526652Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.625340803Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.628113999Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.630988497Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.63465777Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.637401195Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.64007704Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.643694692Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.646953915Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.649632463Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.65370774Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.656410539Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.659080293Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.663217366Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.666057381Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.668717843Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.672822008Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.675765109Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.678662435Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.682526297Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.685409401Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.688294366Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.692479917Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.695195846Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.697902614Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.701983968Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.704939964Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.708110031Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.712470131Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.715493196Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.718555521Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.722190171Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.725795959Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.728741124Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.732449149Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.735595951Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.73853248Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.742185982Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.745433917Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.748384696Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.751074785Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.75300671Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.754852348Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.757175339Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.759191016Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.76095242Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.762890144Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.765081656Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.766912032Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.769178322Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.771168198Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.773020633Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.77545357Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.777300754Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.779154785Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.781535547Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.783506384Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.78538741Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.787861087Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.78988577Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.791837648Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.794331908Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.796338731Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.798344038Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.801331027Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.803353589Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.805292737Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.807766851Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.80976913Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.811762763Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.814230781Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.816262493Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.818234852Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.820704377Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.822738098Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.824747646Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.828448431Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.831457808Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.8345205Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.838345295Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.841371265Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.844371148Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.847857563Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.850851713Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.853881298Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.85768212Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.860657915Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.863641576Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.86727099Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.870030915Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.872692601Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.877026107Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.879676714Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.882254425Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.885620956Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.888295739Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.891036351Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.893827546Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.896440756Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.899032162Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.901948769Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.904641581Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.907423263Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.911109428Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.91382537Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.917649334Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.920836439Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.923769159Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.926529481Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.93055028Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.933224827Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.936090944Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.939649806Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.942359082Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.945620279Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.949402349Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.952146313Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.956257688Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.959007535Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.961700623Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.965726241Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.968649387Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.97160977Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.975259607Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.978221242Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.98116945Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.984472287Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.987577319Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.990471035Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.994689259Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:13.998138951Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.001158837Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.005088133Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.007999879Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.010898989Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.014994204Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.018097113Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.021090319Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.025724137Z 11 PC: 14e46 | Get input status
2018-12-17T22:23:14.032897937Z 74 PC: 136e9 | Reallocate memory
2018-12-17T22:23:14.034513414Z 48 PC: 13721 | Get DOS version
2018-12-17T22:23:14.037464872Z 74 PC: 14618 | Reallocate memory
2018-12-17T22:23:14.041040043Z 74 PC: 14618 | Reallocate memory
2018-12-17T22:23:14.044153406Z 74 PC: 14618 | Reallocate memory
2018-12-17T22:23:14.047413557Z 42 PC: 13cfc | Get date 0x13cfc: sub cx, 0x76c
0x13d00: mov ch, al
0x13d02: mov al, cl
0x13d04: xor ah, ah
0x13d06: mov word ptr [bp - 2], dx
0x13d09: mov word ptr [bx + 0xa], ax
0x13d0c: mov al, byte ptr [bp - 1]
0x13d0f: dec ax
0x13d10: mov word ptr [bx + 8], ax
0x13d13: mov al, byte ptr [bp - 2]
0x13d16: xor ah, ah
0x13d18: mov word ptr [bx + 6], ax
0x13d1b: mov ah, 0x2c
0x13d1d: int 0x21
0x13d1f: mov al, ch
0x13d21: xor ah, ah
0x13d23: mov word ptr [bx + 4], ax
0x13d26: mov al, cl
0x13d28: mov word ptr [bx + 2], ax
0x13d2b: mov al, dh
2018-12-17T22:23:14.049620689Z 44 PC: 13d1f | Get time 0x13d1f: mov al, ch
0x13d21: xor ah, ah
0x13d23: mov word ptr [bx + 4], ax
0x13d26: mov al, cl
0x13d28: mov word ptr [bx + 2], ax
0x13d2b: mov al, dh
0x13d2d: xor dh, dh
0x13d2f: mov si, dx
0x13d31: shl si, 1
0x13d33: shl si, 1
0x13d35: mov word ptr [bx], ax
0x13d37: add si, dx
0x13d39: mov ah, 0x2a
0x13d3b: int 0x21
0x13d3d: sub cx, 0x76c
0x13d41: mov ch, al
0x13d43: shl si, 1
0x13d45: mov ax, dx
0x13d47: cmp dl, byte ptr [bp - 2]
0x13d4a: je 0x13d64
2018-12-17T22:23:14.051638404Z 42 PC: 13d3d | Get date 0x13d3d: sub cx, 0x76c
0x13d41: mov ch, al
0x13d43: shl si, 1
0x13d45: mov ax, dx
0x13d47: cmp dl, byte ptr [bp - 2]
0x13d4a: je 0x13d64
0x13d4c: cmp word ptr [bx + 4], 0x17
0x13d50: je 0x13d64
0x13d52: mov dl, cl
0x13d54: xor dh, dh
0x13d56: mov word ptr [bx + 0xa], dx
0x13d59: mov dl, ah
0x13d5b: dec dx
0x13d5c: xor ah, ah
0x13d5e: mov word ptr [bx + 8], dx
0x13d61: mov word ptr [bx + 6], ax
0x13d64: mov ax, si
0x13d66: mov word ptr [bx + 0x10], 0xffff
0x13d6b: mov sp, bp
0x13d6d: pop bp
2018-12-17T22:23:14.056182228Z 61 PC: 12ee5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:23:14.062829885Z 68 PC: 1384a | I/O control for devices (Set for = '')
2018-12-17T22:23:14.064134213Z 68 PC: 1384a | I/O control for devices (Set for = '�����r_.�� �uW.�� �uO.�`�t< wCu2�.�a�t < t r/<w+��.�� �u!��.�� �u��.�� �u ��[^������[^�����.�U� ')
2018-12-17T22:23:14.066324044Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.068208565Z 74 PC: 14618 | Reallocate memory
2018-12-17T22:23:14.070178301Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.072415803Z 63 PC: 13190 | Read file or device (Read 9948 bytes on handle 5)
2018-12-17T22:23:14.080432487Z 62 PC: 13c9b | Close file
2018-12-17T22:23:14.082996631Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.085317451Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.091047091Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.092391056Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.096893687Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.098175396Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.101299317Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.103508697Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.109280271Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.110330554Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.113803804Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.114852497Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.117791868Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.11981058Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.124909989Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.125960861Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.129422111Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.130373158Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.133938741Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.136224734Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.141663042Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.142925233Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.14639997Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.147735738Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.152014462Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.153140468Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.158440549Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.160706409Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.163178811Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.167921518Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.17256495Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.174024881Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.179916409Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.182087432Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.185141333Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.186435938Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.190420449Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.192046019Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.195800045Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.197044803Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.198799021Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.199726715Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.20210506Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.203315123Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.206819795Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.207705812Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.209672143Z 26 PC: 13474 | Set disk transfer address
2018-12-17T22:23:14.210858517Z 78 PC: 1347a | Find first file
2018-12-17T22:23:14.216561982Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.217230705Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.219513683Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.220230968Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.222000409Z 26 PC: 13489 | Set disk transfer address
2018-12-17T22:23:14.223157651Z 79 PC: 1348d | Find next file
2018-12-17T22:23:14.225234789Z 61 PC: 12ee5 | Open file (Filename = 'C:\WINDOWS\OACKAGER.EXE')
2018-12-17T22:23:14.231695729Z 60 PC: 12f92 | Create or truncate file
2018-12-17T22:23:14.576986301Z 68 PC: 1384a | I/O control for devices (Set for = '�����r_.�� �uW.�� �uO.�`�t< wCu2�.�a�t < t r/<w+��.�� �u!��.�� �u��.�� �u ��[^������[^�����.�U� ')
2018-12-17T22:23:14.579095507Z 64 PC: 132e6 | Write file or device (Write 9948 bytes on handle 5)
2018-12-17T22:23:14.602813487Z 62 PC: 13c9b | Close file
2018-12-17T22:23:14.611098856Z 67 PC: 135a7 | Get or set file attributes
2018-12-17T22:23:14.619776767Z 67 PC: 135bb | Get or set file attributes
2018-12-17T22:23:14.63744144Z 65 PC: 1434e | Delete file (Filename = 'A:\TEST.EXE')
2018-12-17T22:23:14.651072605Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.652890928Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.656644811Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.658486456Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.660488109Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.662855415Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.664508439Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.666252Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.668495679Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.66975583Z 66 PC: 13087 | Move file pointer
2018-12-17T22:23:14.672583003Z 76 PC: 1381c | Terminate with return code (Return code = '0')