Sample viewer

vx.netlux.org/Virus.DOS.Lemming.2144.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:21.569188085Z 255 PC: 12a66 | UNKNOWN!
2018-12-17T21:59:21.57078621Z 82 PC: 12b59 | Get DOS internal pointers (SYSVARS)
2018-12-17T21:59:21.572010631Z 88 PC: 12a91 | case 0xGet or set allocation strateg:
2018-12-17T21:59:21.573046012Z 88 PC: 12a9b | case 0xGet or set allocation strateg:
2018-12-17T21:59:21.574680734Z 53 PC: 130ec | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:59:21.575843464Z 37 PC: 130f9 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:59:21.576812721Z 53 PC: 1311f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T21:59:21.577685389Z 37 PC: 1312f | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:59:21.579149615Z 76 PC: 12a46 | Terminate with return code (Return code = '0')
2018-12-17T21:59:21.581965671Z 77 PC: 11fe0 | Get program return code
2018-12-17T21:59:21.583011555Z 72 PC: 12174 | Allocate memory
2018-12-17T21:59:21.585154738Z 72 PC: 1218d | Allocate memory
2018-12-17T21:59:21.587132093Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:59:21.58808478Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:21.589461226Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.590459941Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.591394412Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.59362145Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.594612501Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.595931374Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.597288942Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.598971272Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.599896547Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.601793464Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.602692614Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.604008598Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.605348396Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.608230755Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.61026731Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.612643909Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.613921233Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.615421644Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.617183469Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.618935809Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.62007771Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.62175399Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.623449532Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.625508795Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.626776904Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.628858546Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.630028508Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.631705131Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.633520072Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.635062433Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.636120844Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.638362564Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.639411827Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.640846324Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.642381095Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.643976294Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.645202646Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.647363416Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.64832635Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.6500322Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.651953674Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.653393771Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.654359341Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.656809572Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.65793341Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.659369125Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.661149075Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.662935307Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.664004554Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.66603902Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.667199236Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.669075402Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.67060401Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.672334424Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.673523422Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.676355801Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.677565605Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.679745576Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.682032597Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.683729954Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:21.684760708Z 62 PC: 122ab | Close file
2018-12-17T21:59:21.688159282Z 99 PC: 994d7 | Get DBCS lead byte table pointer
2018-12-17T21:59:21.689512368Z 56 PC: 93cf9 | Get or set country info
2018-12-17T21:59:21.691298207Z 64 PC: 99748 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:59:21.696082379Z 25 PC: 93d62 | Get default drive
2018-12-17T21:59:21.697598971Z 71 PC: 95fdd | Get current directory
2018-12-17T21:59:21.701344471Z 64 PC: 99748 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:59:21.704925867Z 2 PC: 95fb2 | Character output (Char = '3e')
2018-12-17T21:59:21.706913322Z 93 PC: 93e20 | File sharing functions
2018-12-17T21:59:21.708760598Z 93 PC: 93e27 | File sharing functions
2018-12-17T21:59:21.711180754Z 10 PC: 93e39 | Buffered keyboard input
2018-12-17T21:59:36.562145321Z 0 PC: 0 | Program terminate
2018-12-17T21:59:37.917139008Z 0 PC: 0 | Program terminate
2018-12-17T21:59:38.019837736Z 64 PC: 99748 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:59:38.025865454Z 41 PC: 93eae | Parse filename
2018-12-17T21:59:38.028539997Z 41 PC: 93f2f | Parse filename
2018-12-17T21:59:38.030438936Z 41 PC: 93f4c | Parse filename
2018-12-17T21:59:38.034221144Z 26 PC: 973f7 | Set disk transfer address
2018-12-17T21:59:38.037705499Z 71 PC: 975f3 | Get current directory
2018-12-17T21:59:38.046175683Z 78 PC: 9ee49 | Find first file
2018-12-17T21:59:38.055504586Z 47 PC: 9ee58 | Get disk transfer address
2018-12-17T21:59:38.062957468Z 71 PC: 9746c | Get current directory
2018-12-17T21:59:38.066490328Z 73 PC: 96b09 | Release memory
2018-12-17T21:59:38.068821694Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.07143022Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.072970917Z 61 PC: 9f167 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T21:59:38.08026551Z 87 PC: 9f167 | Get or set file date and time
2018-12-17T21:59:38.083032087Z 66 PC: 9f167 | Move file pointer
2018-12-17T21:59:38.085141936Z 63 PC: 9f167 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T21:59:38.092072433Z 66 PC: 9f167 | Move file pointer
2018-12-17T21:59:38.095955238Z 64 PC: 9f167 | Write file or device (Write 2160 bytes on handle 5)
2018-12-17T21:59:38.117592758Z 66 PC: 9f167 | Move file pointer
2018-12-17T21:59:38.120700845Z 64 PC: 9f167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:38.129538851Z 87 PC: 9f167 | Get or set file date and time
2018-12-17T21:59:38.131739255Z 62 PC: 9f167 | Close file
2018-12-17T21:59:38.142977524Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.145299153Z 75 PC: 11821 | Execute program
2018-12-17T21:59:38.17393995Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T21:59:38.178247403Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T21:59:38.190038414Z 77 PC: 11fe0 | Get program return code
2018-12-17T21:59:38.192502505Z 72 PC: 12174 | Allocate memory
2018-12-17T21:59:38.194620226Z 72 PC: 1218d | Allocate memory
2018-12-17T21:59:38.196608862Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:59:38.199033466Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:38.200173801Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.201537937Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.203683156Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.205533388Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.206704818Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.209172463Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.220463123Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.222501782Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.224862766Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.23780838Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.240147662Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.243625899Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.245546851Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.247408098Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.251255692Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.253305934Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.254846418Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.258331319Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.260251495Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.263591631Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.266668609Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.268631127Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.270257604Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.272986483Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.274819557Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.277593868Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.27997414Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.282233991Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.283948443Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.287100516Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.28877845Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.291029699Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.293761121Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.295990868Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.297639719Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.301086661Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.302502694Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.304261779Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.307543394Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.311353593Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.312661363Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.314642882Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.316896059Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.318891901Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.320305821Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.323144869Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.32466255Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.326803754Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.329306773Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.33118014Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.332678296Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.335780458Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.337220873Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.339088259Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.341467518Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.34349504Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.344917717Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.34776088Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.349231584Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.351212559Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:38.353595073Z 62 PC: 122ab | Close file
2018-12-17T21:59:38.356747245Z 99 PC: 994d7 | Get DBCS lead byte table pointer
2018-12-17T21:59:38.35913826Z 56 PC: 93cf9 | Get or set country info
2018-12-17T21:59:38.362405687Z 64 PC: 99748 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:59:38.367526501Z 25 PC: 93d62 | Get default drive
2018-12-17T21:59:38.369315789Z 71 PC: 95fdd | Get current directory
2018-12-17T21:59:38.37725926Z 64 PC: 99748 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:59:38.380525841Z 2 PC: 95fb2 | Character output (Char = '3e')
2018-12-17T21:59:38.383744154Z 93 PC: 93e20 | File sharing functions
2018-12-17T21:59:38.38664393Z 93 PC: 93e27 | File sharing functions
2018-12-17T21:59:38.388660786Z 10 PC: 93e39 | Buffered keyboard input