Sample viewer

vx.netlux.org/Virus.DOS.HLLP.GID.8153

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:18.400755271Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:18.402647948Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:18.404477183Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:18.405882926Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:18.40739908Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:18.410460506Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:18.411969169Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:18.413435443Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:18.415861911Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:18.417317134Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:18.418776664Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:18.421182143Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:18.423115285Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:18.42601912Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:18.428886464Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:18.431313735Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:18.43422208Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:18.436714536Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:18.439167618Z 53 PC: 14b1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:18.441347937Z 37 PC: 14b2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:18.443228287Z 37 PC: 14b37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:18.445201935Z 37 PC: 14b3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:18.447064266Z 37 PC: 14b47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:18.449809739Z 68 PC: 15877 | I/O control for devices (Set for = '')
2018-12-17T22:45:18.536153758Z 37 PC: 142a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:18.537393235Z 44 PC: 159ae | Get time 0x159ae: mov word ptr [0x3e], cx
0x159b2: mov word ptr [0x40], dx
0x159b6: retf
0x159b7: call 0x159fe
0x159ba: jb 0x159cb
0x159bc: mov cx, word ptr es:[di + 4]
0x159c0: cmp cx, 1
0x159c3: je 0x159cb
0x159c5: xor bx, bx
0x159c7: push cs
0x159c8: call 0x2553a
0x159cb: retf 4
0x159ce: call 0x159fe
0x159d1: jb 0x159e6
0x159d3: mov ax, cx
0x159d5: mov dx, bx
0x159d7: mov cx, word ptr es:[di + 4]
0x159db: cmp cx, 1
0x159de: je 0x159e6
0x159e0: xor bx, bx
2018-12-17T22:45:18.539313451Z 43 PC: 14852 | Set date
2018-12-17T22:45:18.542244519Z 25 PC: 1542f | Get default drive
2018-12-17T22:45:18.543249209Z 71 PC: 15442 | Get current directory
2018-12-17T22:45:18.545414935Z 14 PC: 15488 | Set default drive (Drive = 'C')
2018-12-17T22:45:18.547161542Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:18.548364785Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:18.549492044Z 78 PC: 14939 | Find first file
2018-12-17T22:45:18.553972487Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:18.559061158Z 78 PC: 14939 | Find first file
2018-12-17T22:45:18.564926389Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:18.566834375Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.139910665Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.148312453Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 6)
2018-12-17T22:45:19.159776289Z 64 PC: 152b3 | Write file or device (Write 8153 bytes on handle 5)
2018-12-17T22:45:19.173859907Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.17589005Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.184762107Z 14 PC: 15488 | Set default drive (Drive = 'D')
2018-12-17T22:45:19.186503047Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.187723081Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.188795986Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.191417657Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.192935369Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.195013658Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.201066196Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.206995589Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.208667109Z 14 PC: 15488 | Set default drive (Drive = 'E')
2018-12-17T22:45:19.210442624Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.211590973Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.212546099Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.214800064Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.216620319Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.21869969Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.22384066Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.229105728Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.230750009Z 14 PC: 15488 | Set default drive (Drive = 'F')
2018-12-17T22:45:19.231957905Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.233545656Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.234532541Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.236797919Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.239373823Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.242406307Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.250471455Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.260301191Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.262709698Z 14 PC: 15488 | Set default drive (Drive = 'G')
2018-12-17T22:45:19.264074612Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.266557568Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.268142858Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.271015684Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.278851461Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.281565364Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.289173338Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.298551276Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.300737212Z 14 PC: 15488 | Set default drive (Drive = 'H')
2018-12-17T22:45:19.302006301Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.303709709Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.306513679Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.308796897Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.310653502Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.313925826Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.324056182Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.332915962Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.336516077Z 14 PC: 15488 | Set default drive (Drive = 'I')
2018-12-17T22:45:19.33792819Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.339442492Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.341154585Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.343840986Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.345700815Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.349576319Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.357076503Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.365259843Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.368562922Z 14 PC: 15488 | Set default drive (Drive = 'J')
2018-12-17T22:45:19.370307956Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.372253583Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.374115525Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.377091299Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.379350076Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.383042523Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.390971567Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.399302183Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.40199181Z 14 PC: 15488 | Set default drive (Drive = 'K')
2018-12-17T22:45:19.404535801Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.406045456Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.407268644Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.410804235Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.412886181Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.415848408Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.424487443Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.43308669Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.435716353Z 14 PC: 15488 | Set default drive (Drive = 'L')
2018-12-17T22:45:19.437772815Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.439674549Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.441260516Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.444351595Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.446386762Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.449337188Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.458537494Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.467213164Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.46989113Z 14 PC: 15488 | Set default drive (Drive = 'M')
2018-12-17T22:45:19.472307668Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.474515625Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.476004811Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.478739062Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.481489089Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.484352973Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.492045928Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.5006867Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.503270429Z 14 PC: 15488 | Set default drive (Drive = 'N')
2018-12-17T22:45:19.504876546Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.507260693Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.50868158Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.511075117Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.513906057Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.517324417Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.52652826Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.536705194Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.540178336Z 14 PC: 15488 | Set default drive (Drive = 'O')
2018-12-17T22:45:19.542106507Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.545412232Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.547064812Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.549663013Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.552312956Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.555265723Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.563184308Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.572637549Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.575086863Z 14 PC: 15488 | Set default drive (Drive = 'P')
2018-12-17T22:45:19.576527241Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.578741356Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.580056697Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.582477024Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.585149953Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.588048945Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.596846199Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.605899506Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.608567067Z 14 PC: 15488 | Set default drive (Drive = 'Q')
2018-12-17T22:45:19.610034258Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.612503986Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.614130343Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.616805721Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.619994556Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.623502213Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.631448855Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.641834726Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.644719621Z 14 PC: 15488 | Set default drive (Drive = 'R')
2018-12-17T22:45:19.646725507Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.649450356Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.650733156Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.652979234Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.65551903Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.658103076Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.66529967Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.674377852Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.6765946Z 14 PC: 15488 | Set default drive (Drive = 'S')
2018-12-17T22:45:19.67850148Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.695150406Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.696295168Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.698459509Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.701014642Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.703811766Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.711573957Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.721255986Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.723548292Z 14 PC: 15488 | Set default drive (Drive = 'T')
2018-12-17T22:45:19.724862035Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.726413681Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.727834958Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.730057825Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.731824168Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.734501215Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.742836347Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.751508396Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.754021846Z 14 PC: 15488 | Set default drive (Drive = 'U')
2018-12-17T22:45:19.755316013Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.756915111Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.758346471Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.760675685Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.762591454Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.76552265Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.773298998Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.782101306Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.785242978Z 14 PC: 15488 | Set default drive (Drive = 'V')
2018-12-17T22:45:19.786610903Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.788418727Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.790398663Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.793110933Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.795311489Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.798439473Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.806954978Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.816283295Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.819742956Z 14 PC: 15488 | Set default drive (Drive = 'W')
2018-12-17T22:45:19.821604273Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.823336108Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.826169745Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.828780838Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.830874901Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.834692233Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.842407544Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.851698942Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.855100718Z 14 PC: 15488 | Set default drive (Drive = 'X')
2018-12-17T22:45:19.856520486Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.858029691Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.859961808Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.862222089Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.864150554Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.867580624Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.8811422Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.891667546Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.895438809Z 14 PC: 15488 | Set default drive (Drive = 'Y')
2018-12-17T22:45:19.897487519Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.899632893Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.902810587Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.905467917Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.908177313Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.912085985Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.920009011Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.928915035Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.933148153Z 14 PC: 15488 | Set default drive (Drive = 'Z')
2018-12-17T22:45:19.935334146Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.937326196Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:19.940213904Z 78 PC: 14939 | Find first file
2018-12-17T22:45:19.942934512Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.944877369Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:19.948332701Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:19.957175701Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:19.966237605Z 62 PC: 15230 | Close file
2018-12-17T22:45:19.969244202Z 14 PC: 15488 | Set default drive (Drive = 'A')
2018-12-17T22:45:19.971222448Z 25 PC: 1548c | Get default drive
2018-12-17T22:45:19.972896725Z 59 PC: 154f6 | Change current directory
2018-12-17T22:45:19.978754425Z 54 PC: 148b5 | Get free disk space
2018-12-17T22:45:19.989693797Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:19.992267702Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:20.005129667Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:20.014123237Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 6)
2018-12-17T22:45:20.023811572Z 64 PC: 152b3 | Write file or device (Write 8153 bytes on handle 5)
2018-12-17T22:45:20.038376911Z 62 PC: 15230 | Close file
2018-12-17T22:45:20.041261051Z 62 PC: 15230 | Close file
2018-12-17T22:45:20.050738953Z 44 PC: 159ae | Get time 0x159ae: mov word ptr [0x3e], cx
0x159b2: mov word ptr [0x40], dx
0x159b6: retf
0x159b7: call 0x159fe
0x159ba: jb 0x159cb
0x159bc: mov cx, word ptr es:[di + 4]
0x159c0: cmp cx, 1
0x159c3: je 0x159cb
0x159c5: xor bx, bx
0x159c7: push cs
0x159c8: call 0x2553a
0x159cb: retf 4
0x159ce: call 0x159fe
0x159d1: jb 0x159e6
0x159d3: mov ax, cx
0x159d5: mov dx, bx
0x159d7: mov cx, word ptr es:[di + 4]
0x159db: cmp cx, 1
0x159de: je 0x159e6
0x159e0: xor bx, bx
2018-12-17T22:45:20.053755728Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.056389205Z 25 PC: 1542f | Get default drive
2018-12-17T22:45:20.05798717Z 71 PC: 15442 | Get current directory
2018-12-17T22:45:20.062494326Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:20.065239832Z 78 PC: 14939 | Find first file
2018-12-17T22:45:20.068233401Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.070607118Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:20.072638317Z 78 PC: 14939 | Find first file
2018-12-17T22:45:20.079480985Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.081632107Z 86 PC: 1536d | Rename file
2018-12-17T22:45:20.102358114Z 67 PC: 148d5 | Get or set file attributes
2018-12-17T22:45:20.118607544Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.129774984Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.OLD')
2018-12-17T22:45:20.136861106Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.138243694Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:20.145707726Z 66 PC: 15312 | Move file pointer
2018-12-17T22:45:20.147395384Z 63 PC: 152b3 | Read file or device (Read 4000 bytes on handle 5)
2018-12-17T22:45:20.148929208Z 62 PC: 15230 | Close file
2018-12-17T22:45:20.150542921Z 62 PC: 15230 | Close file
2018-12-17T22:45:20.152542392Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.153725471Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.162727235Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.164347629Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.165740789Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:20.16814352Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:20.17017037Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:20.171856326Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:20.174578123Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:20.175976776Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:20.177530136Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:20.180307812Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:20.18207616Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.183792669Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.186749405Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:20.188466623Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:20.19013549Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:20.192900286Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:20.194597659Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:20.196271522Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:20.199085129Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:20.205396051Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:20.212919764Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:20.215454482Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:20.216778147Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:20.218131961Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:20.220511673Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:20.221881239Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:20.223556464Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:20.226326244Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:20.228018024Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:20.229708325Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:20.232440089Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:20.234155385Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:20.235805418Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:20.238564881Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:20.240216341Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:20.24190895Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:20.2444239Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:20.245767318Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:20.24711259Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.24957134Z 41 PC: 14a49 | Parse filename
2018-12-17T22:45:20.251314885Z 41 PC: 14a57 | Parse filename
2018-12-17T22:45:20.252921905Z 75 PC: 14a62 | Execute program
2018-12-17T22:45:20.264307351Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.265663953Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.266991259Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:20.269478647Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:20.270961112Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:20.272279874Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:20.27449789Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:20.275848648Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:20.277141513Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:20.279619958Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:20.280920622Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.282244196Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.284607317Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:20.285952309Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:20.287247118Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:20.289850514Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:20.29143573Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:20.293046979Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:20.296277382Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:20.297900478Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:20.299468834Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:20.302227251Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:20.303801404Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:20.305317047Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:20.307719186Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:20.309510254Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:20.311271001Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:20.3140678Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:20.315921657Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:20.317779606Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:20.320158084Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:20.322011524Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:20.323768326Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:20.325941467Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:20.327796641Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:20.329865234Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:20.331914019Z 53 PC: 14a92 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:20.333835658Z 37 PC: 14a9b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:20.336868107Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.338813601Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:20.340234929Z 78 PC: 14939 | Find first file
2018-12-17T22:45:20.347820696Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.359215341Z 65 PC: 15329 | Delete file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:20.371686637Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.374523592Z 86 PC: 1536d | Rename file
2018-12-17T22:45:20.387487684Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.389461781Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.402537398Z 26 PC: 1492d | Set disk transfer address
2018-12-17T22:45:20.403808954Z 78 PC: 14939 | Find first file
2018-12-17T22:45:20.418592902Z 86 PC: 1536d | Rename file
2018-12-17T22:45:20.425746161Z 60 PC: 151e0 | Create or truncate file
2018-12-17T22:45:20.43132345Z 48 PC: 153a2 | Get DOS version
2018-12-17T22:45:20.433142337Z 67 PC: 148d5 | Get or set file attributes
2018-12-17T22:45:20.441276596Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.452744545Z 61 PC: 151e0 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:20.460667941Z 63 PC: 152b3 | Read file or device (Read 8153 bytes on handle 5)
2018-12-17T22:45:20.471136407Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.478579104Z 61 PC: 151e0 | Open file (Filename = 'GID_v5.$w$')
2018-12-17T22:45:20.487474738Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.493515034Z 62 PC: 15230 | Close file
2018-12-17T22:45:20.495853923Z 67 PC: 148fc | Get or set file attributes
2018-12-17T22:45:20.508333133Z 65 PC: 15329 | Delete file (Filename = 'GID_v5.$w$')
2018-12-17T22:45:20.515150036Z 54 PC: 148b5 | Get free disk space
2018-12-17T22:45:20.525799841Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.527530939Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:20.528880807Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:20.530097542Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:20.532674659Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:20.534006628Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.535312172Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:20.537762761Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:20.539063876Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:20.540276091Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:20.542447727Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:20.544387642Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:20.546647851Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:20.548427435Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:20.549660864Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:20.554058455Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:20.555720151Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:20.557318755Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:20.560874373Z 37 PC: 14c71 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:20.562368159Z 76 PC: 14cb0 | Terminate with return code (Return code = '0')