Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Kollo.7000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:40.588428906Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:40.589993233Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:40.591411127Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:40.593063006Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:40.59489472Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:40.596109377Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:40.597582205Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:40.599044345Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:40.600125427Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:40.601227342Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:40.602712843Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:40.603819265Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:40.604918684Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:40.606540423Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:40.607588149Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:40.608544805Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:40.609988766Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:40.611062066Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:40.612645362Z 53 PC: 13d32 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:40.621400993Z 37 PC: 13d47 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:40.622445972Z 37 PC: 13d4f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:40.623484574Z 37 PC: 13d57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:40.625577077Z 37 PC: 13d5f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:40.627048808Z 68 PC: 14332 | I/O control for devices (Set for = '')
2018-12-17T22:46:40.675665163Z 37 PC: 13755 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:40.682891733Z 42 PC: 13537 | Get date 0x13537: xor ah, ah
0x13539: les di, ptr [bp + 6]
0x1353c: stosw word ptr es:[di], ax
0x1353d: mov al, dl
0x1353f: les di, ptr [bp + 0xa]
0x13542: stosw word ptr es:[di], ax
0x13543: mov al, dh
0x13545: les di, ptr [bp + 0xe]
0x13548: stosw word ptr es:[di], ax
0x13549: xchg ax, cx
0x1354a: les di, ptr [bp + 0x12]
0x1354d: stosw word ptr es:[di], ax
0x1354e: pop bp
0x1354f: retf 0x10
0x13552: push bp
0x13553: mov bp, sp
0x13555: mov cx, word ptr [bp + 0xa]
0x13558: mov dh, byte ptr [bp + 8]
0x1355b: mov dl, byte ptr [bp + 6]
0x1355e: mov ah, 0x2b
2018-12-17T22:46:40.684564324Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:40.686179366Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.687818958Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.691373154Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.692265257Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.694573718Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.695575753Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.697426202Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.698833372Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.700537399Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.701298342Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.703642764Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.704655313Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.707158378Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.708479132Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.711072238Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.712199555Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.715574705Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.716849365Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.723094706Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.724823276Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.726933622Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:40.732924327Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:40.734760718Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:40.735984914Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:40.737265594Z 62 PC: 14a4a | Close file
2018-12-17T22:46:40.739198404Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:40.741432904Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.7423302Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.747809853Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.748781372Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.751240026Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.752546132Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.755070425Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.755990828Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.758536176Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.75946931Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.762027507Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.763332217Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.76578268Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.766689116Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.769531729Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.770626961Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.773621657Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.77513681Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.780628596Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.782224715Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.785144127Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:40.79197456Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:40.794348116Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:40.796260377Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:40.797960632Z 62 PC: 14a4a | Close file
2018-12-17T22:46:40.800726285Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:40.803712859Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.80503303Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.810800145Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.81318491Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.816042812Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.817605764Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.821326627Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.822380099Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.825150213Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.826575389Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.829229051Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.830431976Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.833477847Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.83448272Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.837211161Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.838861346Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.842148527Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.84392948Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.851080871Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.852550323Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.856179287Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:40.862404635Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:40.864231198Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:40.867199792Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:40.868581478Z 62 PC: 14a4a | Close file
2018-12-17T22:46:40.871712379Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:40.875014467Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.876127682Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.882017787Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.884924792Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.887886908Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.889245161Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.893015977Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.89476744Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.897820867Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.899711971Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.902520138Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.903810214Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.908899504Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.909940034Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.912468471Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.914387193Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.916863178Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.91786874Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.924359839Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.925674399Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.928853342Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:40.935768726Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:40.937319044Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:40.938922795Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:40.940881162Z 62 PC: 14a4a | Close file
2018-12-17T22:46:40.942551163Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:40.945567945Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.947478091Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.953553232Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.954578593Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.958171289Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.959162459Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.961782836Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.963336667Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.966816404Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.967916546Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.97091263Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.971898668Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.974963018Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.97631835Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.979390758Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.981592999Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.984573058Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:40.985860318Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:40.991760068Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:40.993188523Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:40.996358384Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.003517872Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.004999702Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.006642149Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.008977784Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.011081027Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.013848814Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.016679982Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.022175372Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.023255509Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.026274607Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.027285487Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.030916115Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.032682541Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.035201985Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.036810902Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.039399696Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.040443103Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.043432658Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.044391783Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.047158305Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.049257032Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.052097337Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.053332432Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.060824912Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.061916997Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.064737296Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.071598499Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.072989926Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.074532659Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.077007684Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.079127058Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.081907184Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.083658106Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.089350439Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.090752996Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.094303738Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.095647246Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.098829433Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.100805965Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.104182029Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.106778293Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.109628598Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.110804808Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.115426479Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.116928692Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.119871674Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.122124059Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.125242909Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.126293591Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.132623382Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.133726185Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.139703155Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.147292348Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.148889561Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.150617596Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.15266996Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.154666419Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.157403759Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.159328483Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.164862675Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.166323646Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.170192261Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.171542863Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.177622357Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.179598436Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.182501916Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.183919146Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.18732241Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.188345474Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.191682284Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.193588847Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.197273163Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.19934872Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.202911744Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.206567422Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.213235277Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.214458634Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.21725382Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.223991976Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.225547582Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.226915058Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.229254488Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.231032414Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.233724419Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.235278683Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.238829416Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.239837177Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.243451091Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.244458177Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.246673993Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.248102108Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.24998897Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.251297659Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.25411229Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.254973762Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.257483967Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.25831383Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.260167146Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.262025936Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.263968074Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.264838302Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.268892804Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.269767861Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.271675864Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.276061413Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.277069048Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.278663934Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.279727904Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.280968479Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.283890858Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.284797454Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.288211748Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.289696622Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.291495898Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.292353587Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.294742501Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.29554345Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.298050963Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.299025042Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.300826484Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.302453484Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.304368963Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.305277111Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.307818969Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.308686953Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.310570164Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.312102692Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.315520569Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.316592195Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.318811717Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.322591921Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.324301958Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.325360694Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.326440049Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.328294663Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.330594185Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.331937162Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.338401932Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.339776833Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.34265707Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.344932897Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.347897Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.349394077Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.352977773Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.354380954Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.358184896Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.35985406Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.362759262Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.364667019Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.368809947Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.370203864Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.373837271Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.375550133Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.381182017Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.38307916Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.389736601Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.396170186Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.398492755Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.400218546Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.401993513Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.404942951Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.407671973Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.409876444Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.415991934Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.426435403Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.430241683Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.431972073Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.435028878Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.437265926Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.441282732Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.442650115Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.44644792Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.447541655Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.450427748Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.452808286Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.455705402Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.457041047Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.460876097Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.462220001Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.467851463Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.470187519Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.473261206Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.479683302Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.482128472Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.483765208Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.486218709Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.488529215Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.491215214Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.493472149Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.499122893Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.500382499Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.504036351Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.505579944Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.508474327Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.51024943Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.513049667Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.51450004Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.51858347Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.519827231Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.523403384Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.524937355Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.527723557Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.529789305Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.532362578Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.533594346Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.540221408Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.541540963Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.54459612Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.56446124Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.566088246Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.568468872Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.570446064Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.572529304Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.576046662Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.577642482Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.583166361Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.58548578Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.58833936Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.590383452Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.594371859Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.595663833Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.599015453Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.60031878Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.603002819Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.604861082Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.607423088Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.608746727Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.613574694Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.614972201Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.62253034Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.624239305Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.629549234Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.631000672Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.633830947Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.640566264Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.642760096Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.644360986Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.654683274Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.657114203Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.659806225Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.661899741Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.668398494Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.669857614Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.673718721Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.675384305Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.678495699Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.680782598Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.683705532Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.68509014Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.688784648Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.690173791Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.694032868Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.695339556Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.698294218Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.700506799Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.703514181Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.704918167Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.711449562Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.712782829Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.716046764Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.722554146Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.724156841Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.726562856Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.728289359Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.730209048Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.733350863Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.734476354Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.740459999Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.741659133Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.745030502Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.747189291Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.749903231Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.750940735Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.754511493Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.755555389Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.758185474Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.760122738Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.762660099Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.764684591Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.767595698Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.769061675Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.773230361Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.775020081Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.780683975Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.783846459Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.786823454Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.792765506Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.794750768Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.796241248Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.798713672Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.800897249Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.803702865Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.805950849Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.811596537Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.813259057Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.816469962Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.817836752Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.821642619Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.823233577Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.825964269Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.82856421Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.832242072Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.833631899Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.837613999Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.83914048Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.842557969Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.843976082Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.846829932Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.849087195Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.854502636Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.855562349Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.859799094Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.866055052Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.867893695Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.870046203Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.87176659Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.874600911Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.877564508Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.878894656Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.885544827Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.886677151Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.889467909Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.891587233Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.894533321Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.896636979Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.899766772Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.90104206Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.904780309Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.906363607Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.909945176Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.912266413Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.915081933Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.916565111Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.919808762Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.920828591Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.927258518Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.928931872Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.932127614Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:41.939959648Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:41.941873585Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:41.943629045Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:41.946342122Z 62 PC: 14a4a | Close file
2018-12-17T22:46:41.948546152Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:41.951842286Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.953480916Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:41.959119737Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.961275404Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.964317336Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.965704129Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.969341869Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.970615632Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.973655691Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.975356007Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.978210402Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.980471456Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.983137361Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.984396072Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.987878997Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:41.989124999Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:41.993618325Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:41.994752175Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:42.000324055Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.002467872Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.005849298Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:42.012050228Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:42.014503394Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:42.016241607Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:42.018377495Z 62 PC: 14a4a | Close file
2018-12-17T22:46:42.021239158Z 44 PC: 1497b | Get time 0x1497b: mov word ptr [0x3e], cx
0x1497f: mov word ptr [0x40], dx
0x14983: retf
0x14984: mov bx, sp
0x14986: push ds
0x14987: les di, ptr ss:[bx + 8]
0x1498b: lds si, ptr ss:[bx + 4]
0x1498f: cld
0x14990: xor ax, ax
0x14992: stosw word ptr es:[di], ax
0x14993: mov ax, 0xd7b0
0x14996: stosw word ptr es:[di], ax
0x14997: xor ax, ax
0x14999: mov cx, 0x16
0x1499c: rep stosd dword ptr es:[di], eax
0x1499e: lodsb al, byte ptr [si]
0x1499f: cmp al, 0x4f
0x149a1: jbe 0x149a5
0x149a3: mov al, 0x4f
0x149a5: mov cl, al
2018-12-17T22:46:42.023844423Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:42.03746329Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:42.043044896Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.044363481Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.048069123Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.049349124Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.052443611Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.054410277Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.057199268Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.059492296Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.062414618Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.063636526Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.066947165Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.068099403Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.074935147Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.076366746Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.083211756Z 26 PC: 135c7 | Set disk transfer address
2018-12-17T22:46:42.085284542Z 78 PC: 135d3 | Find first file
2018-12-17T22:46:42.090910067Z 26 PC: 135eb | Set disk transfer address
2018-12-17T22:46:42.092219427Z 79 PC: 135f0 | Find next file
2018-12-17T22:46:42.096001611Z 61 PC: 149fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:46:42.10270796Z 66 PC: 14b96 | Move file pointer
2018-12-17T22:46:42.104515245Z 66 PC: 14ba4 | Move file pointer
2018-12-17T22:46:42.10654172Z 66 PC: 14bb2 | Move file pointer
2018-12-17T22:46:42.108513108Z 62 PC: 14a4a | Close file
2018-12-17T22:46:42.111389458Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:42.112733722Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:42.114294027Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:42.116268766Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:42.117605899Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:42.119759793Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:42.12145333Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:42.122807236Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:42.125272561Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:42.126645784Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:42.128868706Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:42.130540832Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:42.131913838Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:42.134375857Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:42.135744318Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:42.137294146Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:42.139577735Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:42.140980032Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:42.143208176Z 37 PC: 13e46 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:42.144856373Z 76 PC: 13e85 | Terminate with return code (Return code = '0')