Sample viewer

vx.netlux.org/Virus.DOS.Selectron.1258

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:07.885755927Z 246 PC: 13c7b | UNKNOWN!
2018-12-17T23:02:07.887640763Z 48 PC: 13c8a | Get DOS version
2018-12-17T23:02:07.88877539Z 82 PC: 13c95 | Get DOS internal pointers (SYSVARS)
2018-12-17T23:02:07.890141453Z 53 PC: 13d50 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:02:07.891561664Z 37 PC: 13d5f | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:02:07.894987359Z 53 PC: 13d64 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:07.896448158Z 37 PC: 13d73 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:07.897964843Z 42 PC: 13cdf | Get date 0x13cdf: or al, al
0x13ce1: jne 0x13ce8
0x13ce3: push dx
0x13ce4: call 0x13d1a
0x13ce7: pop dx
0x13ce8: and dl, 1
0x13ceb: jne 0x13cf0
0x13ced: call 0x13d2f
0x13cf0: push cs
0x13cf1: pop ds
0x13cf2: mov ax, cs
0x13cf4: sub ax, word ptr ds:[bp + 0x4e4]
0x13cf9: mov bx, word ptr ds:[bp + 0x4e6]
0x13cfe: add bx, ax
0x13d00: mov ax, word ptr ds:[bp + 0x4e8]
0x13d05: pop es
0x13d06: pop ds
0x13d07: push bx
0x13d08: push ax
0x13d09: retf
2018-12-17T23:02:07.915516663Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T23:02:07.921451828Z 76 PC: 12a61 | Terminate with return code (Return code = '0')