Sample viewer

vx.netlux.org/Virus.DOS.AVCS.276

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:51.982195784Z 26 PC: 1410a | Set disk transfer address
2018-12-17T22:53:51.983903642Z 78 PC: 1411e | Find first file
2018-12-17T22:53:51.990636409Z 61 PC: 14153 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:51.998023365Z 63 PC: 14163 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:52.005481464Z 66 PC: 141c3 | Move file pointer
2018-12-17T22:53:52.008318534Z 64 PC: 14197 | Write file or device (Write 276 bytes on handle 5)
2018-12-17T22:53:52.022784677Z 66 PC: 141c3 | Move file pointer
2018-12-17T22:53:52.024406453Z 64 PC: 141a8 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:53:52.03250206Z 87 PC: 141af | Get or set file date and time
2018-12-17T22:53:52.034745865Z 62 PC: 141b3 | Close file
2018-12-17T22:53:52.043583756Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.0484092Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.05134238Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.054021943Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.057524132Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.061111069Z 61 PC: 14153 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:53:52.068519375Z 63 PC: 14163 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:52.078330154Z 66 PC: 141c3 | Move file pointer
2018-12-17T22:53:52.080066606Z 64 PC: 14197 | Write file or device (Write 276 bytes on handle 5)
2018-12-17T22:53:52.088534342Z 66 PC: 141c3 | Move file pointer
2018-12-17T22:53:52.09803122Z 64 PC: 141a8 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:53:52.105388891Z 87 PC: 141af | Get or set file date and time
2018-12-17T22:53:52.1072195Z 62 PC: 141b3 | Close file
2018-12-17T22:53:52.116596374Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.119739968Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.122731548Z 61 PC: 14153 | Open file (Filename = 'TEST.COM')
2018-12-17T22:53:52.130769066Z 63 PC: 14163 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:52.135059185Z 66 PC: 141c3 | Move file pointer
2018-12-17T22:53:52.137223941Z 64 PC: 14197 | Write file or device (Write 276 bytes on handle 5)
2018-12-17T22:53:52.146499584Z 66 PC: 141c3 | Move file pointer
2018-12-17T22:53:52.149108504Z 64 PC: 141a8 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:53:52.152680434Z 87 PC: 141af | Get or set file date and time
2018-12-17T22:53:52.154842305Z 62 PC: 141b3 | Close file
2018-12-17T22:53:52.164895158Z 79 PC: 1411e | Find next file
2018-12-17T22:53:52.168160242Z 26 PC: 141bc | Set disk transfer address
2018-12-17T22:53:52.169548971Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:53:52.171760975Z 9 PC: 12a7a | Display string (String= ' --=[ Selfchecking AntiStealth Goat COM/EXE file, 01/06/01 ]=------------------ (c) 1995-2001 by ROSE SWE, Dipl.-Ing. Ralph Roth - Version 1.18 - Freeware ')
2018-12-17T22:53:52.182488065Z 61 PC: 12cb7 | Open file (Filename = '')
2018-12-17T22:53:52.190287195Z 9 PC: 12a88 | Display string (String= 'Self test: ')
2018-12-17T22:53:52.194550573Z 93 PC: 12b24 | File sharing functions
2018-12-17T22:53:52.196961082Z 9 PC: 12b03 | Display string (String= 'Size change=+0228h/00552d. Virus might be activ? ')
2018-12-17T22:53:52.204309515Z 76 PC: 12b09 | Terminate with return code (Return code = '1')