Sample viewer

vx.netlux.org/Virus.DOS.Drwatson.1503

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:21.344869065Z 61 PC: 12a95 | Open file (Filename = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-17T22:58:21.350874589Z 48 PC: 12aa1 | Get DOS version
2018-12-17T22:58:21.353260425Z 53 PC: 12b58 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:21.354933523Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:58:21.35665651Z 37 PC: 12b7d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:21.359067003Z 53 PC: 12b82 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:21.360863732Z 37 PC: 12b92 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:21.362212307Z 49 PC: 12b9a | Terminate and stay resident (Return code = '0' | Memory size = '112')