Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Deftones.8576

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:02.509567765Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:02.511333487Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:02.513138935Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:02.514658841Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:02.515939484Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:02.518871675Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:02.520506401Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:02.521617877Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:02.523668111Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:02.525475064Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:02.527706698Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:02.534142237Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:02.536604773Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:02.539226453Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:02.542474967Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:02.544204512Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:02.545796398Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:02.547432068Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:02.549097949Z 53 PC: 13b1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:02.550257127Z 37 PC: 13b2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:02.551397629Z 37 PC: 13b37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:02.552629413Z 37 PC: 13b3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:02.553752074Z 37 PC: 13b47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:02.555432937Z 68 PC: 1478c | I/O control for devices (Set for = '')
2018-12-17T22:41:02.679209989Z 37 PC: 1339c | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:02.682373379Z 48 PC: 143a2 | Get DOS version
2018-12-17T22:41:02.685205392Z 61 PC: 141e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:41:02.691626397Z 63 PC: 142b3 | Read file or device (Read 8576 bytes on handle 5)
2018-12-17T22:41:02.69760834Z 62 PC: 14230 | Close file
2018-12-17T22:41:02.700131251Z 26 PC: 13945 | Set disk transfer address
2018-12-17T22:41:02.701867718Z 78 PC: 13951 | Find first file
2018-12-17T22:41:02.707777442Z 60 PC: 141e0 | Create or truncate file
2018-12-17T22:41:02.901826962Z 64 PC: 142b3 | Write file or device (Write 8576 bytes on handle 5)
2018-12-17T22:41:02.91483528Z 62 PC: 14230 | Close file
2018-12-17T22:41:02.935476223Z 60 PC: 14770 | Create or truncate file
2018-12-17T22:41:02.967220216Z 68 PC: 1478c | I/O control for devices (Set for = '�y��������������9')
2018-12-17T22:41:02.972041285Z 64 PC: 13f13 | Write file or device (Write 84 bytes on handle 5)
2018-12-17T22:41:02.976504298Z 62 PC: 13f52 | Close file
2018-12-17T22:41:03.002823512Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.005847149Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.007051689Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.008479171Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.010222166Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.013217783Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.015075316Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.016883998Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.019522367Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.021502171Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.023453537Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.026097884Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.028389573Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.031328308Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.04237587Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.044815466Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.046707168Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.049271175Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.060191826Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.062381737Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.064949857Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.066497442Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.067921797Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.070358721Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.072276339Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.073826702Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.076735491Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.078525465Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.080217081Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.082323984Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.089452336Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.091337071Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.093025996Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.095327758Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.096932338Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.098731306Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.102059769Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.103886321Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.106087693Z 41 PC: 13a48 | Parse filename
2018-12-17T22:41:03.109851089Z 41 PC: 13a56 | Parse filename
2018-12-17T22:41:03.113668182Z 75 PC: 13a61 | Execute program
2018-12-17T22:41:03.12937814Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.132372387Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.135273292Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.137154379Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.14061698Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.143427579Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.14523031Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.147898841Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.149566603Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.151042156Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.153560282Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.155886302Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.157717148Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.159216943Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.162870947Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.164644886Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.166373576Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.169150297Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.170711197Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.17249282Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.17505468Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.177166007Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.180199687Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.184603403Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.18769154Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.190573989Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.194459311Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.198490741Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.20035789Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.202109031Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.204088106Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.205451135Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.206736324Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.208469797Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.209562785Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.210665528Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.212142873Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.213394877Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.214692526Z 65 PC: 14329 | Delete file (Filename = '���������X')
2018-12-17T22:41:03.223753706Z 48 PC: 143a2 | Get DOS version
2018-12-17T22:41:03.22595553Z 48 PC: 143a2 | Get DOS version
2018-12-17T22:41:03.228022316Z 48 PC: 143a2 | Get DOS version
2018-12-17T22:41:03.230821606Z 48 PC: 143a2 | Get DOS version
2018-12-17T22:41:03.233659275Z 86 PC: 1436d | Rename file
2018-12-17T22:41:03.247285612Z 61 PC: 141e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:41:03.255976204Z 63 PC: 142b3 | Read file or device (Read 8576 bytes on handle 5)
2018-12-17T22:41:03.26653271Z 66 PC: 1488b | Move file pointer
2018-12-17T22:41:03.268719525Z 66 PC: 14899 | Move file pointer
2018-12-17T22:41:03.270805036Z 66 PC: 148a7 | Move file pointer
2018-12-17T22:41:03.274103198Z 66 PC: 14312 | Move file pointer
2018-12-17T22:41:03.276241065Z 63 PC: 142b3 | Read file or device (Read 8576 bytes on handle 5)
2018-12-17T22:41:03.285485402Z 66 PC: 1488b | Move file pointer
2018-12-17T22:41:03.288587225Z 66 PC: 14899 | Move file pointer
2018-12-17T22:41:03.290592175Z 66 PC: 148a7 | Move file pointer
2018-12-17T22:41:03.292797037Z 66 PC: 14312 | Move file pointer
2018-12-17T22:41:03.295981312Z 64 PC: 14211 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:41:03.304870373Z 66 PC: 14312 | Move file pointer
2018-12-17T22:41:03.307008653Z 64 PC: 142b3 | Write file or device (Write 8576 bytes on handle 5)
2018-12-17T22:41:03.317916011Z 62 PC: 14230 | Close file
2018-12-17T22:41:03.327809313Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.329663363Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.332328185Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.335365872Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.337153894Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.339800377Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.341955971Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.343768739Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.345712891Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.348157727Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.349921555Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.351682492Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.353842412Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.355319187Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.357766293Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.36110994Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.362719637Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.36440575Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.366532001Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.368379535Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.37036284Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.372895481Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.374836614Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.377347463Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.380848629Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.382868724Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.384746218Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.388096765Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.389761228Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.391595108Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.394177952Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.396118745Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.398096469Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.416381201Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.417892442Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.419461721Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.421671813Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.423353911Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.425312185Z 41 PC: 13a48 | Parse filename
2018-12-17T22:41:03.427710219Z 41 PC: 13a56 | Parse filename
2018-12-17T22:41:03.430457893Z 75 PC: 13a61 | Execute program
2018-12-17T22:41:03.464702313Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.467528696Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.479609652Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.481158697Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.483086531Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.485498713Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.4870809Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.488927651Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.491591757Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.493337285Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.494987723Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.498682611Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.500376223Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.501885317Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.504634234Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.506322643Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.508272127Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.510443001Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.511830495Z 53 PC: 1c4da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.513305717Z 37 PC: 1c4ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.51551597Z 37 PC: 1c4f7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.51775273Z 37 PC: 1c4ff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.520170038Z 37 PC: 1c507 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.524647563Z 68 PC: 1d14c | I/O control for devices (Set for = '')
2018-12-17T22:41:03.682558475Z 37 PC: 1bd5c | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.684575931Z 48 PC: 1cd62 | Get DOS version
2018-12-17T22:41:03.687032885Z 61 PC: 1cba0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:41:03.69535893Z 63 PC: 1cc73 | Read file or device (Read 8576 bytes on handle 5)
2018-12-17T22:41:03.706161938Z 62 PC: 1cbf0 | Close file
2018-12-17T22:41:03.710085126Z 26 PC: 1c305 | Set disk transfer address
2018-12-17T22:41:03.711766071Z 78 PC: 1c311 | Find first file
2018-12-17T22:41:03.716179481Z 48 PC: 1cd62 | Get DOS version
2018-12-17T22:41:03.718151569Z 48 PC: 1cd62 | Get DOS version
2018-12-17T22:41:03.719385358Z 48 PC: 1cd62 | Get DOS version
2018-12-17T22:41:03.720564671Z 48 PC: 1cd62 | Get DOS version
2018-12-17T22:41:03.722761856Z 86 PC: 1cd2d | Rename file
2018-12-17T22:41:03.727525288Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.728570248Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.730301851Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.731350685Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.732357016Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.73398917Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.735359062Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.736398938Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.738041585Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.739050164Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.740043266Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.741664049Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.742784558Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.743817158Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.745531619Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.746614369Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.747676415Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.749395978Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.750575076Z 37 PC: 1c631 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.752223675Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.766565568Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.768653075Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.770591519Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.77337015Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.775367375Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.776980619Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.779414409Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.78149669Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.783265866Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.785671814Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.787371028Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.788932643Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.791261921Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.792964692Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.794557869Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.797178052Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.800167916Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.801891563Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.805241005Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.807153909Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.809760106Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.812198174Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.813896189Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.815722274Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.818114713Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.819935927Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.821639768Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.824069291Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.825718798Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.827367006Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.82967647Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.831930507Z 6 PC: 1c6b8 | Direct console I/O
2018-12-17T22:41:03.834359491Z 76 PC: 1c670 | Terminate with return code (Return code = '2')
2018-12-17T22:41:03.837155388Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.838271781Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.839740658Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.841840007Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.843100496Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.844200486Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.845985652Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.847062216Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.848100346Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.849694511Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.850716786Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.852524573Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.854017081Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.855187463Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.856847824Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.85798025Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.859048501Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.860816897Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.861961461Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.863273514Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.865096024Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.866256541Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.867319211Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.869150729Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.870278295Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.871428157Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.873034823Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.874151782Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.875169925Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.877139168Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.878248267Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.879289759Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.88122718Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.882394759Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.883682896Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.885481696Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.886585203Z 53 PC: 13a91 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.887692799Z 37 PC: 13a9a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.889640025Z 86 PC: 1436d | Rename file
2018-12-17T22:41:03.906572749Z 61 PC: 141e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:41:03.912035312Z 63 PC: 142b3 | Read file or device (Read 8576 bytes on handle 5)
2018-12-17T22:41:03.918977571Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:03.920232358Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:03.921434572Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:03.923614104Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:03.924904331Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:03.926171604Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:03.928411658Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:03.930019675Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:03.931332849Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:03.933356336Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:03.93462676Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:03.935840839Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:03.937647755Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:03.938983335Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:03.940145811Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:03.942204832Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:03.943340019Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:03.944380543Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:03.946528364Z 37 PC: 13c71 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:03.947606838Z 76 PC: 13cb0 | Terminate with return code (Return code = '0')