Sample viewer

vx.netlux.org/Virus.DOS.Yosha.755

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:49.250000095Z 68 PC: 13022 | I/O control for devices (Set for = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-17T22:55:49.256232495Z 2 PC: 12bb1 | Character output (Char = '0d')
2018-12-17T22:55:49.25893088Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.262773165Z 2 PC: 12bb1 | Character output (Char = '09')
2018-12-17T22:55:49.265481158Z 2 PC: 12bb1 | Character output (Char = '09')
2018-12-17T22:55:49.268990748Z 2 PC: 12bb1 | Character output (Char = '49')
2018-12-17T22:55:49.271946006Z 2 PC: 12bb1 | Character output (Char = '6e')
2018-12-17T22:55:49.274705054Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.277993669Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.280686513Z 2 PC: 12bb1 | Character output (Char = '6c')
2018-12-17T22:55:49.283394345Z 2 PC: 12bb1 | Character output (Char = '6c')
2018-12-17T22:55:49.287133868Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.289945956Z 2 PC: 12bb1 | Character output (Char = '67')
2018-12-17T22:55:49.292701027Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.300585374Z 2 PC: 12bb1 | Character output (Char = '6e')
2018-12-17T22:55:49.303654767Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.306647605Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.310348715Z 2 PC: 12bb1 | Character output (Char = '56')
2018-12-17T22:55:49.312927875Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.31532293Z 2 PC: 12bb1 | Character output (Char = '72')
2018-12-17T22:55:49.318606926Z 2 PC: 12bb1 | Character output (Char = '75')
2018-12-17T22:55:49.322232944Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.325133279Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.328075172Z 2 PC: 12bb1 | Character output (Char = '42')
2018-12-17T22:55:49.336583292Z 2 PC: 12bb1 | Character output (Char = '61')
2018-12-17T22:55:49.339223857Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.341859724Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.346071164Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.348921264Z 2 PC: 12bb1 | Character output (Char = '53')
2018-12-17T22:55:49.351670064Z 2 PC: 12bb1 | Character output (Char = '79')
2018-12-17T22:55:49.35524134Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.357925968Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.360454623Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.363458372Z 2 PC: 12bb1 | Character output (Char = '6d')
2018-12-17T22:55:49.366419932Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.368942145Z 2 PC: 12bb1 | Character output (Char = '28')
2018-12-17T22:55:49.371807193Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.374904868Z 2 PC: 12bb1 | Character output (Char = '6d')
2018-12-17T22:55:49.37770786Z 2 PC: 12bb1 | Character output (Char = '29')
2018-12-17T22:55:49.380509097Z 2 PC: 12bb1 | Character output (Char = '2e')
2018-12-17T22:55:49.384281692Z 2 PC: 12bb1 | Character output (Char = '0d')
2018-12-17T22:55:49.386913121Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.391064648Z 2 PC: 12bb1 | Character output (Char = '09')
2018-12-17T22:55:49.396234851Z 2 PC: 12bb1 | Character output (Char = '43')
2018-12-17T22:55:49.398974774Z 2 PC: 12bb1 | Character output (Char = '6f')
2018-12-17T22:55:49.402655686Z 2 PC: 12bb1 | Character output (Char = '70')
2018-12-17T22:55:49.406384709Z 2 PC: 12bb1 | Character output (Char = '79')
2018-12-17T22:55:49.409347992Z 2 PC: 12bb1 | Character output (Char = '72')
2018-12-17T22:55:49.412253355Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.417102595Z 2 PC: 12bb1 | Character output (Char = '67')
2018-12-17T22:55:49.419608507Z 2 PC: 12bb1 | Character output (Char = '68')
2018-12-17T22:55:49.422081117Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.424915908Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.427778382Z 2 PC: 12bb1 | Character output (Char = '28')
2018-12-17T22:55:49.430678696Z 2 PC: 12bb1 | Character output (Char = '63')
2018-12-17T22:55:49.433654672Z 2 PC: 12bb1 | Character output (Char = '29')
2018-12-17T22:55:49.437089352Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.43984832Z 2 PC: 12bb1 | Character output (Char = '43')
2018-12-17T22:55:49.442571681Z 2 PC: 12bb1 | Character output (Char = '6f')
2018-12-17T22:55:49.445439204Z 2 PC: 12bb1 | Character output (Char = '6d')
2018-12-17T22:55:49.447910061Z 2 PC: 12bb1 | Character output (Char = '70')
2018-12-17T22:55:49.450483881Z 2 PC: 12bb1 | Character output (Char = '2d')
2018-12-17T22:55:49.453658301Z 2 PC: 12bb1 | Character output (Char = '56')
2018-12-17T22:55:49.455882985Z 2 PC: 12bb1 | Character output (Char = '49')
2018-12-17T22:55:49.459984197Z 2 PC: 12bb1 | Character output (Char = '52')
2018-12-17T22:55:49.463396785Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.465803902Z 2 PC: 12bb1 | Character output (Char = '49')
2018-12-17T22:55:49.468182966Z 2 PC: 12bb1 | Character output (Char = '6e')
2018-12-17T22:55:49.471938338Z 2 PC: 12bb1 | Character output (Char = '63')
2018-12-17T22:55:49.474589153Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.477191778Z 2 PC: 12bb1 | Character output (Char = '31')
2018-12-17T22:55:49.480595338Z 2 PC: 12bb1 | Character output (Char = '39')
2018-12-17T22:55:49.483453573Z 2 PC: 12bb1 | Character output (Char = '39')
2018-12-17T22:55:49.486069663Z 2 PC: 12bb1 | Character output (Char = '36')
2018-12-17T22:55:49.48892871Z 2 PC: 12bb1 | Character output (Char = '2c')
2018-12-17T22:55:49.491916318Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.495800603Z 2 PC: 12bb1 | Character output (Char = '41')
2018-12-17T22:55:49.498183845Z 2 PC: 12bb1 | Character output (Char = '6c')
2018-12-17T22:55:49.500958242Z 2 PC: 12bb1 | Character output (Char = '6c')
2018-12-17T22:55:49.503323741Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.505677127Z 2 PC: 12bb1 | Character output (Char = '72')
2018-12-17T22:55:49.509187238Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.511816622Z 2 PC: 12bb1 | Character output (Char = '67')
2018-12-17T22:55:49.514459412Z 2 PC: 12bb1 | Character output (Char = '68')
2018-12-17T22:55:49.518173207Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.520827067Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.523236248Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.526621544Z 2 PC: 12bb1 | Character output (Char = '72')
2018-12-17T22:55:49.529303699Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.531781789Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.535446931Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.537852726Z 2 PC: 12bb1 | Character output (Char = '76')
2018-12-17T22:55:49.540236097Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.54284827Z 2 PC: 12bb1 | Character output (Char = '72')
2018-12-17T22:55:49.545675447Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.547948582Z 2 PC: 12bb1 | Character output (Char = '64')
2018-12-17T22:55:49.550387739Z 2 PC: 12bb1 | Character output (Char = '21')
2018-12-17T22:55:49.553809323Z 2 PC: 12bb1 | Character output (Char = '0d')
2018-12-17T22:55:49.556225968Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.569165783Z 2 PC: 12bb1 | Character output (Char = '09')
2018-12-17T22:55:49.575094331Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.578144297Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.587963834Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.591644866Z 2 PC: 12bb1 | Character output (Char = '42')
2018-12-17T22:55:49.594298687Z 2 PC: 12bb1 | Character output (Char = '61')
2018-12-17T22:55:49.596950574Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.600258255Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.602854217Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.605822729Z 2 PC: 12bb1 | Character output (Char = '66')
2018-12-17T22:55:49.608891771Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.612149356Z 2 PC: 12bb1 | Character output (Char = '6c')
2018-12-17T22:55:49.61484187Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.61785688Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.621968362Z 2 PC: 12bb1 | Character output (Char = '23')
2018-12-17T22:55:49.62496111Z 2 PC: 12bb1 | Character output (Char = '32')
2018-12-17T22:55:49.627833342Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.631733747Z 2 PC: 12bb1 | Character output (Char = '28')
2018-12-17T22:55:49.634498937Z 2 PC: 12bb1 | Character output (Char = '2e')
2018-12-17T22:55:49.637188605Z 2 PC: 12bb1 | Character output (Char = '45')
2018-12-17T22:55:49.64092933Z 2 PC: 12bb1 | Character output (Char = '58')
2018-12-17T22:55:49.643964327Z 2 PC: 12bb1 | Character output (Char = '45')
2018-12-17T22:55:49.646696555Z 2 PC: 12bb1 | Character output (Char = '29')
2018-12-17T22:55:49.649989388Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.653797689Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.656410604Z 2 PC: 12bb1 | Character output (Char = '4f')
2018-12-17T22:55:49.659041622Z 2 PC: 12bb1 | Character output (Char = '72')
2018-12-17T22:55:49.66288552Z 2 PC: 12bb1 | Character output (Char = '67')
2018-12-17T22:55:49.665614172Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.668333987Z 2 PC: 12bb1 | Character output (Char = '6e')
2018-12-17T22:55:49.672139844Z 2 PC: 12bb1 | Character output (Char = '61')
2018-12-17T22:55:49.675262396Z 2 PC: 12bb1 | Character output (Char = '6c')
2018-12-17T22:55:49.678092649Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.681274513Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.684086751Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.68669736Z 2 PC: 12bb1 | Character output (Char = '7a')
2018-12-17T22:55:49.689768206Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.692335533Z 2 PC: 12bb1 | Character output (Char = '3a')
2018-12-17T22:55:49.695264852Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.698955884Z 2 PC: 12bb1 | Character output (Char = '32')
2018-12-17T22:55:49.702471545Z 2 PC: 12bb1 | Character output (Char = '30')
2018-12-17T22:55:49.705445107Z 2 PC: 12bb1 | Character output (Char = '30')
2018-12-17T22:55:49.70858374Z 2 PC: 12bb1 | Character output (Char = '30')
2018-12-17T22:55:49.711468154Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.714064436Z 2 PC: 12bb1 | Character output (Char = '62')
2018-12-17T22:55:49.717853222Z 2 PC: 12bb1 | Character output (Char = '79')
2018-12-17T22:55:49.720434707Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.722907196Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.725885837Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.728678249Z 2 PC: 12bb1 | Character output (Char = '0d')
2018-12-17T22:55:49.731168512Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.735947239Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.740234091Z 61 PC: 12a6c | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:55:49.747476861Z 63 PC: 12a6c | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:55:49.755865928Z 62 PC: 12a6c | Close file
2018-12-17T22:55:49.770454212Z 2 PC: 12bb1 | Character output (Char = '56')
2018-12-17T22:55:49.773937392Z 2 PC: 12bb1 | Character output (Char = '49')
2018-12-17T22:55:49.776675752Z 2 PC: 12bb1 | Character output (Char = '52')
2018-12-17T22:55:49.780834834Z 2 PC: 12bb1 | Character output (Char = '55')
2018-12-17T22:55:49.783579185Z 2 PC: 12bb1 | Character output (Char = '53')
2018-12-17T22:55:49.786727686Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.79092525Z 2 PC: 12bb1 | Character output (Char = '52')
2018-12-17T22:55:49.79577532Z 2 PC: 12bb1 | Character output (Char = '45')
2018-12-17T22:55:49.798950672Z 2 PC: 12bb1 | Character output (Char = '4c')
2018-12-17T22:55:49.804089196Z 2 PC: 12bb1 | Character output (Char = '45')
2018-12-17T22:55:49.807127399Z 2 PC: 12bb1 | Character output (Char = '41')
2018-12-17T22:55:49.809849789Z 2 PC: 12bb1 | Character output (Char = '53')
2018-12-17T22:55:49.813281462Z 2 PC: 12bb1 | Character output (Char = '45')
2018-12-17T22:55:49.816302253Z 2 PC: 12bb1 | Character output (Char = '44')
2018-12-17T22:55:49.81917183Z 2 PC: 12bb1 | Character output (Char = '21')
2018-12-17T22:55:49.823325611Z 2 PC: 12bb1 | Character output (Char = '21')
2018-12-17T22:55:49.826064051Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.828820956Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.832644556Z 2 PC: 12bb1 | Character output (Char = '49')
2018-12-17T22:55:49.835352619Z 2 PC: 12bb1 | Character output (Char = '74')
2018-12-17T22:55:49.838523432Z 2 PC: 12bb1 | Character output (Char = '27')
2018-12-17T22:55:49.842774056Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.846373895Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.848839903Z 2 PC: 12bb1 | Character output (Char = '6e')
2018-12-17T22:55:49.852083613Z 2 PC: 12bb1 | Character output (Char = '61')
2018-12-17T22:55:49.854747272Z 2 PC: 12bb1 | Character output (Char = '6d')
2018-12-17T22:55:49.857270127Z 2 PC: 12bb1 | Character output (Char = '65')
2018-12-17T22:55:49.859986646Z 2 PC: 12bb1 | Character output (Char = '20')
2018-12-17T22:55:49.863228482Z 2 PC: 12bb1 | Character output (Char = '69')
2018-12-17T22:55:49.865603218Z 2 PC: 12bb1 | Character output (Char = '73')
2018-12-17T22:55:49.86818884Z 2 PC: 12bb1 | Character output (Char = '3a')
2018-12-17T22:55:49.871537918Z 2 PC: 12bb1 | Character output (Char = '0d')
2018-12-17T22:55:49.874095568Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.878209124Z 2 PC: 12bb1 | Character output (Char = '0a')
2018-12-17T22:55:49.88538548Z 2 PC: 12bb1 | Character output (Char = '07')
2018-12-17T22:55:49.887983015Z 9 PC: 12b96 | Display string (String= 'This file has not had the INJECT.EXE run on it to load the Virus name into it ')
2018-12-17T22:55:49.894065183Z 76 PC: 12a6c | Terminate with return code (Return code = '1')