Sample viewer

vx.netlux.org/Virus.DOS.Weed.5850.f

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:41.563622916Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.56989523Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:41.575787638Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.581552453Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:41.587797953Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.598224534Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:41.608830879Z 98 PC: 1c134 | Get current PSP
2018-12-17T22:48:41.610952329Z 26 PC: 12cbb | Set disk transfer address
2018-12-17T22:48:41.612077481Z 78 PC: 12ccd | Find first file
2018-12-17T22:48:41.62326342Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:41.62932443Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.645903978Z 61 PC: 13606 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:48:41.652680476Z 63 PC: 136a8 | Read file or device (Read 5850 bytes on handle 5)
2018-12-17T22:48:41.660868504Z 62 PC: 136ee | Close file
2018-12-17T22:48:41.663291343Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.674486324Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.685806225Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:41.692606304Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.698421281Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:41.704311449Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.710866519Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:41.721434039Z 26 PC: 13095 | Set disk transfer address
2018-12-17T22:48:41.722481087Z 78 PC: 130ad | Find first file
2018-12-17T22:48:41.735023786Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:41.745988656Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.755861959Z 61 PC: 138b1 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:48:41.766510772Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:41.768267955Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.774570837Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.779937598Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.782465875Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.785004283Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.796121995Z 62 PC: 13a4a | Close file
2018-12-17T22:48:41.797932123Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:41.798963304Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:41.802092534Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.80770481Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:41.81341569Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.82046117Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:41.826440381Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.832207578Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:41.838887671Z 26 PC: 13095 | Set disk transfer address
2018-12-17T22:48:41.840711119Z 78 PC: 130ad | Find first file
2018-12-17T22:48:41.84697294Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:41.853067769Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.863760916Z 61 PC: 138b1 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:41.870537356Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:41.872248664Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.879887126Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.883415435Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.886207989Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.889875689Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.899373904Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:41.901286122Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:41.903647864Z 62 PC: 13a4a | Close file
2018-12-17T22:48:41.905229304Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:41.906336458Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:41.910604875Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:41.916111397Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.92575794Z 61 PC: 138b1 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:48:41.933003388Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:41.934575561Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.936492421Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.939489851Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.941401247Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:41.943417532Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.955268632Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:41.963411583Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:41.965050379Z 62 PC: 13a4a | Close file
2018-12-17T22:48:41.967806064Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:41.969242199Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:41.972310073Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:41.980440558Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:41.990463493Z 61 PC: 138b1 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:48:41.997293449Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.000236646Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.006982024Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.009787077Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.012783845Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.016096748Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.027070865Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.028732445Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.031769737Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.033667209Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.036263132Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.039695118Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.045303881Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.055060716Z 61 PC: 138b1 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:48:42.062171485Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.063605546Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.070145365Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.07449977Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.076484769Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.078469939Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.088955695Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.090283341Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.091704394Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.093985824Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.094920278Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.09836787Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.104025134Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.113509181Z 61 PC: 138b1 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:48:42.119868816Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.121246575Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.127685462Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.129806077Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.132475182Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.134671718Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.144602373Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.14656205Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.147972386Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.149965219Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.151612904Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.154341741Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.160124966Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.170842006Z 61 PC: 138b1 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:48:42.177700146Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.179253948Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.186062025Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.1887259Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.191485611Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.195170013Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.205070882Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.206714614Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.209365164Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.211183209Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.212169572Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.215366478Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.220880647Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.230884995Z 61 PC: 138b1 | Open file (Filename = 'PAH.COM')
2018-12-17T22:48:42.238011493Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.239502157Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.246010748Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.248949328Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.250862536Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.252814192Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.263281554Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.264793567Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.266397197Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.269073921Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.270057825Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.272443128Z 98 PC: 1c16b | Get current PSP
2018-12-17T22:48:42.275606649Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.284703895Z 65 PC: 135d8 | Delete file (Filename = 'C:\DOS\anti-vir.dat')
2018-12-17T22:48:42.291044882Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.298487791Z 65 PC: 135d8 | Delete file (Filename = 'C:\DOS\chklist.ms')
2018-12-17T22:48:42.304866986Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.310912323Z 65 PC: 135d8 | Delete file (Filename = 'C:\DOS\chklist.cps')
2018-12-17T22:48:42.317745523Z 26 PC: 13095 | Set disk transfer address
2018-12-17T22:48:42.318727246Z 78 PC: 130ad | Find first file
2018-12-17T22:48:42.325048023Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.331742335Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.681599168Z 61 PC: 138b1 | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:48:42.688789596Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.691773006Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.69756894Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.701154967Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.704423317Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.707268828Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.716946274Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.718634784Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.720039988Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.7217615Z 26 PC: 1330c | Set disk transfer address
2018-12-17T22:48:42.723277353Z 78 PC: 1331e | Find first file
2018-12-17T22:48:42.729303333Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.735185819Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.744593584Z 61 PC: 13606 | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:48:42.751816378Z 87 PC: 134e2 | Get or set file date and time
2018-12-17T22:48:42.753571436Z 63 PC: 136a8 | Read file or device (Read 5850 bytes on handle 5)
2018-12-17T22:48:42.761095898Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:42.762954233Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:42.772025976Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:42.775881336Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:42.786923994Z 87 PC: 13544 | Get or set file date and time
2018-12-17T22:48:42.789928592Z 62 PC: 136ee | Close file
2018-12-17T22:48:42.797421004Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.807191742Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.809709155Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.813153787Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.819594209Z 65 PC: 135d8 | Delete file (Filename = 'C:\DOS\anti-vir.dat')
2018-12-17T22:48:42.828474217Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.836045012Z 65 PC: 135d8 | Delete file (Filename = 'C:\DOS\chklist.ms')
2018-12-17T22:48:42.84279409Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.849801893Z 65 PC: 135d8 | Delete file (Filename = 'C:\DOS\chklist.cps')
2018-12-17T22:48:42.856389004Z 26 PC: 13095 | Set disk transfer address
2018-12-17T22:48:42.857498298Z 78 PC: 130ad | Find first file
2018-12-17T22:48:42.864581818Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.870911417Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.880539043Z 61 PC: 138b1 | Open file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T22:48:42.888153063Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.889892086Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.895529321Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.899040822Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.902457719Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.905191646Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.915599001Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.917100157Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.918779593Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.921727343Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:42.923097621Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:42.926521198Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:42.933955163Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.943533421Z 61 PC: 138b1 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:48:42.950393698Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:42.952875696Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.958451729Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.961825623Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.965242967Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:42.967755653Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:42.978298837Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:42.981247734Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:42.983056046Z 62 PC: 13a4a | Close file
2018-12-17T22:48:42.985197753Z 26 PC: 1330c | Set disk transfer address
2018-12-17T22:48:42.98774189Z 78 PC: 1331e | Find first file
2018-12-17T22:48:42.994212933Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:43.000427501Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.011003819Z 61 PC: 13606 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:48:43.018136662Z 87 PC: 134e2 | Get or set file date and time
2018-12-17T22:48:43.020150107Z 63 PC: 136a8 | Read file or device (Read 5850 bytes on handle 5)
2018-12-17T22:48:43.028731909Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:43.030709573Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:43.038429338Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:43.043521715Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:43.055565779Z 87 PC: 13544 | Get or set file date and time
2018-12-17T22:48:43.05707213Z 62 PC: 136ee | Close file
2018-12-17T22:48:43.064720056Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.075020082Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:43.076326867Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:43.080312688Z 98 PC: 1c16b | Get current PSP
2018-12-17T22:48:43.081980232Z 26 PC: 13c68 | Set disk transfer address
2018-12-17T22:48:43.083564953Z 78 PC: 13c7a | Find first file
2018-12-17T22:48:43.090499577Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:43.096281522Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.106057767Z 61 PC: 13606 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:48:43.11421772Z 87 PC: 134e2 | Get or set file date and time
2018-12-17T22:48:43.115885482Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:43.117836019Z 63 PC: 136a8 | Read file or device (Read 5850 bytes on handle 5)
2018-12-17T22:48:43.12588664Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:43.129364831Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:43.137908936Z 87 PC: 13544 | Get or set file date and time
2018-12-17T22:48:43.13996456Z 62 PC: 136ee | Close file
2018-12-17T22:48:43.147162696Z 61 PC: 13a6e | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:48:43.154039485Z 66 PC: 13aa1 | Move file pointer
2018-12-17T22:48:43.155363774Z 64 PC: 13ada | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:48:43.162636427Z 62 PC: 13afd | Close file
2018-12-17T22:48:43.170628629Z 61 PC: 13606 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:48:43.178081358Z 87 PC: 13544 | Get or set file date and time
2018-12-17T22:48:43.179674876Z 62 PC: 136ee | Close file
2018-12-17T22:48:43.187452667Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.197512082Z 75 PC: 12fd3 | Execute program
2018-12-17T22:48:43.211517491Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.218250218Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:43.2240013Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.234349685Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:43.241164365Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.246669671Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:43.252922266Z 26 PC: 1330c | Set disk transfer address
2018-12-17T22:48:43.258102003Z 78 PC: 1331e | Find first file
2018-12-17T22:48:43.263935375Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:43.269446466Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.27937749Z 61 PC: 13606 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:48:43.286247224Z 87 PC: 134e2 | Get or set file date and time
2018-12-17T22:48:43.288052827Z 63 PC: 136a8 | Read file or device (Read 5850 bytes on handle 5)
2018-12-17T22:48:43.2967419Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:43.298539969Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:43.3081984Z 66 PC: 1bf7b | Move file pointer
2018-12-17T22:48:43.319230136Z 64 PC: 13652 | Write file or device (Write 5850 bytes on handle 5)
2018-12-17T22:48:43.328065002Z 87 PC: 13544 | Get or set file date and time
2018-12-17T22:48:43.330253669Z 62 PC: 136ee | Close file
2018-12-17T22:48:43.338388756Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.348648448Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.355567711Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:43.361948988Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.372986072Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:43.380910835Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.387006434Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:43.393278288Z 26 PC: 13095 | Set disk transfer address
2018-12-17T22:48:43.39548999Z 78 PC: 130ad | Find first file
2018-12-17T22:48:43.401856121Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:43.412692343Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.483527466Z 61 PC: 138b1 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:48:43.489674788Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:43.491198087Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.497852436Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.500388426Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.503760337Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.506798391Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.552340488Z 62 PC: 13a4a | Close file
2018-12-17T22:48:43.555069595Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:43.556503241Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:43.559384311Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.566532094Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:43.573319179Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.578966538Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:43.586237067Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.591954255Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:43.597748999Z 26 PC: 13095 | Set disk transfer address
2018-12-17T22:48:43.599531998Z 78 PC: 130ad | Find first file
2018-12-17T22:48:43.605453017Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:43.611279755Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.670159001Z 61 PC: 138b1 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:43.674300526Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:43.675985185Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.682555601Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.685159367Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.688025016Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:43.690602791Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:43.971128744Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:43.974036802Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:43.976287973Z 62 PC: 13a4a | Close file
2018-12-17T22:48:43.978455676Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:43.980980036Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:43.984181472Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:43.990342988Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:44.795855938Z 61 PC: 138b1 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:48:44.802575712Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:44.80567376Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:44.807449004Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:44.809303474Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:44.81197168Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:44.813870174Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:44.989201287Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:44.992095986Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:44.993615839Z 62 PC: 13a4a | Close file
2018-12-17T22:48:44.995430976Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:44.997189469Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:44.999149328Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:45.002713647Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.123004521Z 61 PC: 138b1 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:48:45.130825564Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:45.132928175Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.145916993Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.148876854Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.152677029Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.156794858Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.167095042Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:45.169468108Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:45.170686782Z 62 PC: 13a4a | Close file
2018-12-17T22:48:45.172202284Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:45.1738382Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:45.176399114Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:45.182191439Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.192710375Z 61 PC: 138b1 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:48:45.19847427Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:45.199694029Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.204513825Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.206094937Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.207810253Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.210597997Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.227395951Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:45.230266806Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:45.235239304Z 62 PC: 13a4a | Close file
2018-12-17T22:48:45.237251496Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:45.239020496Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:45.241834309Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:45.247787335Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.257944297Z 61 PC: 138b1 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:48:45.264495858Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:45.265869954Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.272478059Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.274560866Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.276906279Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.29509524Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.306647609Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:45.309210357Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:45.310556839Z 62 PC: 13a4a | Close file
2018-12-17T22:48:45.31223568Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:45.314805693Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:45.317581685Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:45.323562888Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.333662819Z 61 PC: 138b1 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:48:45.34008548Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:45.341410112Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.34861762Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.351180169Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.354447204Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.35697541Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.368200767Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:45.370159583Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:45.371649299Z 62 PC: 13a4a | Close file
2018-12-17T22:48:45.374158684Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:45.375755051Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:45.378479024Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:48:45.38404028Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.394277654Z 61 PC: 138b1 | Open file (Filename = 'PAH.COM')
2018-12-17T22:48:45.400791987Z 66 PC: 138e1 | Move file pointer
2018-12-17T22:48:45.403328908Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.41040419Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.412493979Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.415425465Z 63 PC: 13916 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:48:45.41746527Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.722629696Z 66 PC: 139c5 | Move file pointer
2018-12-17T22:48:45.725829017Z 66 PC: 139f2 | Move file pointer
2018-12-17T22:48:45.728118508Z 62 PC: 13a4a | Close file
2018-12-17T22:48:45.730935922Z 26 PC: 131d4 | Set disk transfer address
2018-12-17T22:48:45.732920584Z 79 PC: 131e2 | Find next file
2018-12-17T22:48:45.735643267Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.741285555Z 65 PC: 135d8 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:48:45.752930561Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.759057726Z 65 PC: 135d8 | Delete file (Filename = 'chklist.ms')
2018-12-17T22:48:45.765723712Z 67 PC: 1345e | Get or set file attributes
2018-12-17T22:48:45.774559588Z 65 PC: 135d8 | Delete file (Filename = 'chklist.cps')
2018-12-17T22:48:45.779410079Z 76 PC: 13050 | Terminate with return code (Return code = '0')