Sample viewer

vx.netlux.org/Virus.DOS.HLLP.TMS.11712

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:24.688380628Z 53 PC: 1450a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:24.690032444Z 53 PC: 1450a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:24.691233981Z 53 PC: 1450a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:24.692373291Z 53 PC: 1450a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:58:24.693946142Z 53 PC: 1450a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:24.69511489Z 53 PC: 1450a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:24.696296918Z 53 PC: 1450a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:24.69791648Z 53 PC: 1450a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:24.699045055Z 53 PC: 1450a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:24.700057151Z 53 PC: 1450a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:24.701544484Z 53 PC: 1450a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:24.702513155Z 53 PC: 1450a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:24.703824048Z 53 PC: 1450a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:24.70594057Z 53 PC: 1450a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:24.707213267Z 53 PC: 1450a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:24.708396812Z 53 PC: 1450a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:24.709902085Z 53 PC: 1450a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:24.711074396Z 53 PC: 1450a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:24.712219831Z 53 PC: 1450a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:24.714028438Z 37 PC: 1451f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:24.715129207Z 37 PC: 14527 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:24.716233613Z 37 PC: 1452f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:24.717698988Z 37 PC: 14537 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:24.719130995Z 68 PC: 1516a | I/O control for devices (Set for = '')
2018-12-17T21:58:24.790784922Z 37 PC: 13f31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:24.792726883Z 25 PC: 13ce7 | Get default drive
2018-12-17T21:58:24.794439666Z 71 PC: 13d03 | Get current directory
2018-12-17T21:58:24.797132219Z 48 PC: 14d92 | Get DOS version
2018-12-17T21:58:24.79932256Z 26 PC: 13bc2 | Set disk transfer address
2018-12-17T21:58:24.800980709Z 78 PC: 13b97 | Find first file
2018-12-17T21:58:24.805023758Z 67 PC: 13bab | Get or set file attributes
2018-12-17T21:58:24.821495722Z 61 PC: 14bd0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:58:24.828784988Z 66 PC: 14d02 | Move file pointer
2018-12-17T21:58:24.830245198Z 64 PC: 14ca3 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T21:58:24.837179577Z 61 PC: 14bd0 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:58:24.844043456Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T21:58:24.846923458Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.849068521Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.857203227Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:24.859143705Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:24.86187515Z 14 PC: 14e78 | Set default drive (Drive = 'C')
2018-12-17T21:58:24.863187837Z 25 PC: 14e7c | Get default drive
2018-12-17T21:58:24.864499555Z 59 PC: 14ee6 | Change current directory
2018-12-17T21:58:24.870602071Z 26 PC: 13bc2 | Set disk transfer address
2018-12-17T21:58:24.87393451Z 78 PC: 13b97 | Find first file
2018-12-17T21:58:24.883295634Z 61 PC: 14bd0 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T21:58:24.890225035Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:24.895965083Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.897936331Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:24.898934933Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:24.90274225Z 61 PC: 14bd0 | Open file (Filename = 'CHKDSK.EXE')
2018-12-17T21:58:24.909540262Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:24.915137536Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.917748458Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:24.918960394Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:24.922539054Z 61 PC: 14bd0 | Open file (Filename = 'DEBUG.EXE')
2018-12-17T21:58:24.930473406Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:24.936306236Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.938596702Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:24.940389961Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:24.944343881Z 61 PC: 14bd0 | Open file (Filename = 'EXPAND.EXE')
2018-12-17T21:58:24.951084793Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:24.957314471Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.95959638Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:24.960974848Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:24.965184606Z 61 PC: 14bd0 | Open file (Filename = 'FDISK.EXE')
2018-12-17T21:58:24.971985877Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:24.977741819Z 62 PC: 14c20 | Close file
2018-12-17T21:58:24.980600278Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:24.981819014Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:24.985613427Z 61 PC: 14bd0 | Open file (Filename = 'MEM.EXE')
2018-12-17T21:58:24.993571826Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:24.999250564Z 62 PC: 14c20 | Close file
2018-12-17T21:58:25.001350788Z 67 PC: 13bab | Get or set file attributes
2018-12-17T21:58:25.343999123Z 67 PC: 13bab | Get or set file attributes
2018-12-17T21:58:25.367642941Z 61 PC: 14bd0 | Open file (Filename = 'MEM.EXE')
2018-12-17T21:58:25.376404498Z 61 PC: 14bd0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:58:25.385946737Z 60 PC: 14bd0 | Create or truncate file
2018-12-17T21:58:25.397450893Z 63 PC: 14ca3 | Read file or device (Read 11712 bytes on handle 6)
2018-12-17T21:58:25.405685785Z 64 PC: 14ca3 | Write file or device (Write 11712 bytes on handle 7)
2018-12-17T21:58:25.421448192Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.431483926Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.440059191Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.451237962Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.4605683Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.470413229Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.479687768Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.488849325Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.497515678Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.509428916Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.51739677Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.526589601Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.535330537Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.54443688Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.553021451Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.564566447Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.573252789Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.582309363Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.591511122Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.601040008Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.608949239Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.61879204Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.62727204Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.637274908Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.645525777Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.655990531Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.664078687Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.673957363Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.696243676Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.705079399Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:25.713572894Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.721102355Z 64 PC: 14ca3 | Write file or device (Write 1782 bytes on handle 7)
2018-12-17T21:58:25.729380831Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:25.7318246Z 62 PC: 14c20 | Close file
2018-12-17T21:58:25.734828023Z 60 PC: 14bd0 | Create or truncate file
2018-12-17T21:58:25.748752537Z 62 PC: 14c20 | Close file
2018-12-17T21:58:25.762032881Z 61 PC: 14bd0 | Open file (Filename = 'uhczzeku.tmp')
2018-12-17T21:58:25.770697431Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.794018053Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.800633019Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.808097956Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.815372476Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.8215624Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.829746069Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.836646555Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.843659037Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.850641605Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.856798125Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.86078617Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.872568137Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.879680984Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.886852011Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.893580633Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.899724966Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.903827381Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.910221418Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.914433896Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.919272923Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.924583425Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.929345303Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.933418072Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.93888524Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.943303256Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.949399241Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.954042001Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.959139882Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.964421211Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.972528947Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.978885849Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:25.986016528Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:25.993158235Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.000768446Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.007137448Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.014540126Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.022514561Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.02966521Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.035996276Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.044816534Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.05407112Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.062736852Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.070138443Z 64 PC: 14ca3 | Write file or device (Write 1206 bytes on handle 5)
2018-12-17T21:58:26.079221227Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.081265219Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.090457998Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.092608292Z 65 PC: 14d19 | Delete file (Filename = 'uhczzeku.tmp')
2018-12-17T21:58:26.103894048Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.106927385Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:26.108287292Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:26.112463589Z 61 PC: 14bd0 | Open file (Filename = 'NLSFUNC.EXE')
2018-12-17T21:58:26.12012176Z 63 PC: 14ca3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:58:26.126138475Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.128547623Z 67 PC: 13bab | Get or set file attributes
2018-12-17T21:58:26.139508993Z 67 PC: 13bab | Get or set file attributes
2018-12-17T21:58:26.145825118Z 61 PC: 14bd0 | Open file (Filename = 'NLSFUNC.EXE')
2018-12-17T21:58:26.15460759Z 61 PC: 14bd0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:58:26.166976128Z 60 PC: 14bd0 | Create or truncate file
2018-12-17T21:58:26.178311019Z 63 PC: 14ca3 | Read file or device (Read 11712 bytes on handle 6)
2018-12-17T21:58:26.186741374Z 64 PC: 14ca3 | Write file or device (Write 11712 bytes on handle 7)
2018-12-17T21:58:26.201471098Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.218223862Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:26.226847181Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.237810675Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:26.246337305Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.256181381Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 7)
2018-12-17T21:58:26.265389423Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.272267515Z 64 PC: 14ca3 | Write file or device (Write 892 bytes on handle 7)
2018-12-17T21:58:26.281624809Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.285231327Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.287562159Z 60 PC: 14bd0 | Create or truncate file
2018-12-17T21:58:26.301269092Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.309942557Z 61 PC: 14bd0 | Open file (Filename = 'uhczzeku.tmp')
2018-12-17T21:58:26.317941721Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.325535111Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.334649542Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.341811517Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.350206557Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.357675185Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.365432067Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.372078015Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.380676034Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.387380526Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.395074817Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.402475453Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.410613235Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.417535795Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.425527188Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.432168988Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.440250897Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.453256688Z 64 PC: 14ca3 | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T21:58:26.473724572Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.478343773Z 64 PC: 14ca3 | Write file or device (Write 316 bytes on handle 5)
2018-12-17T21:58:26.482178263Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 7)
2018-12-17T21:58:26.487746906Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.495995998Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.498329962Z 65 PC: 14d19 | Delete file (Filename = 'uhczzeku.tmp')
2018-12-17T21:58:26.50979815Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.512669391Z 26 PC: 13be4 | Set disk transfer address
2018-12-17T21:58:26.514031038Z 79 PC: 13be9 | Find next file
2018-12-17T21:58:26.517603838Z 14 PC: 13d2d | Set default drive (Drive = 'A')
2018-12-17T21:58:26.51979273Z 25 PC: 13d31 | Get default drive
2018-12-17T21:58:26.521140095Z 59 PC: 13b97 | Change current directory
2018-12-17T21:58:26.525402777Z 44 PC: 152a1 | Get time 0x152a1: mov word ptr [0x38c], cx
0x152a5: mov word ptr [0x38e], dx
0x152a9: retf
0x152aa: mov di, 0x3a0
0x152ad: push ds
0x152ae: pop es
0x152af: mov cx, 0x442e
0x152b2: sub cx, di
0x152b4: shr cx, 1
0x152b6: xor ax, ax
0x152b8: cld
0x152b9: rep stosd dword ptr es:[di], eax
0x152bb: ret
0x152bc: add byte ptr [bx + si], al
0x152be: add byte ptr [bx + si], al
0x152c0: add byte ptr [bx + si], al
0x152c2: sub ch, byte ptr [0x7865]
0x152c6: add byte ptr gs:[bp + si], bh
0x152c9: xor ch, byte ptr [bp + si]
0x152cb: and bl, byte ptr [bp + si]
2018-12-17T21:58:26.528943827Z 67 PC: 13bab | Get or set file attributes
2018-12-17T21:58:26.535391668Z 61 PC: 14bd0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:58:26.542852831Z 60 PC: 14bd0 | Create or truncate file
2018-12-17T21:58:26.554229095Z 66 PC: 14d02 | Move file pointer
2018-12-17T21:58:26.556013867Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.563251696Z 64 PC: 14ca3 | Write file or device (Write 192 bytes on handle 6)
2018-12-17T21:58:26.568240596Z 63 PC: 14ca3 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T21:58:26.570842255Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.572949022Z 62 PC: 14c20 | Close file
2018-12-17T21:58:26.58208642Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:26.583564949Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:26.585223806Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:26.587391544Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:26.588839014Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:26.590513912Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:26.592640973Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:58:26.59411266Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:58:26.595801396Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:26.597950782Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:26.599381636Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:26.601130954Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:26.602586398Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:26.604026294Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:26.606147538Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:26.607755925Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:26.609093898Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:26.611031262Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:26.612458116Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:26.613886462Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:26.616755476Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:26.617974309Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:26.618974997Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:26.620663461Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:26.621667764Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:26.622971529Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:26.624520898Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:26.625494387Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:26.626316373Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:26.62786096Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:26.62889359Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:26.629822934Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:26.631037882Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:26.632036669Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:26.63302825Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:26.634784339Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:26.635855482Z 53 PC: 13e68 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:26.637004694Z 37 PC: 13e71 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:26.63867432Z 41 PC: 13e1f | Parse filename
2018-12-17T21:58:26.639942403Z 41 PC: 13e2d | Parse filename
2018-12-17T21:58:26.641035911Z 75 PC: 13e38 | Execute program