Sample viewer

vx.netlux.org/Virus.DOS.Vanish.1635

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:14.279257658Z 48 PC: 1ced4 | Get DOS version
2018-12-17T23:02:14.280828812Z 82 PC: 1cf28 | Get DOS internal pointers (SYSVARS)
2018-12-17T23:02:14.290830442Z 48 PC: 18800 | Get DOS version
2018-12-17T23:02:14.29208166Z 74 PC: 18879 | Reallocate memory
2018-12-17T23:02:14.294918711Z 53 PC: 188f7 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:14.296108061Z 37 PC: 18909 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:14.297049826Z 68 PC: 18999 | I/O control for devices
2018-12-17T23:02:14.299145852Z 68 PC: 18999 | I/O control for devices (Set for = '^�')
2018-12-17T23:02:14.300497911Z 68 PC: 18999 | I/O control for devices (Set for = 'F�@�F��v��')
2018-12-17T23:02:14.301947707Z 68 PC: 18999 | I/O control for devices (Set for = '��� RQ�N���RQ�N��RQ�r��v��')
2018-12-17T23:02:14.304110434Z 68 PC: 18999 | I/O control for devices (Set for = '��� RQ�N���RQ�N��RQ�r��v��')
2018-12-17T23:02:14.316166927Z 56 PC: 18e06 | Get or set country info
2018-12-17T23:02:14.318493023Z 68 PC: 16d11 | I/O control for devices (Set for = '���=�ZҼ߱�(ڭ27��ʺ9U*C�Z �����T���:�z�{$���@� W`y��㨆 p��w�q��. �[Ɍ44R��R�~��')
2018-12-17T23:02:14.320745533Z 68 PC: 16d26 | I/O control for devices (Set for = '*eg?\I8�`�{9U��jl��˝sWkb��bh��+"`g�>�:�e��=��R2h��h�!�܅���N��S"޿DY��ug�y���y��r����0eqUŢm8u1��P���N�~l'��d�N��s�a�+�j����')
2018-12-17T23:02:14.32216062Z 84 PC: 174f7 | Get verify flag
2018-12-17T23:02:14.323171842Z 51 PC: 174ff | Get or set Ctrl-Break
2018-12-17T23:02:14.324627143Z 51 PC: 1750a | Get or set Ctrl-Break
2018-12-17T23:02:14.325473712Z 37 PC: 17514 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:14.32764325Z 53 PC: 17046 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:14.330227791Z 37 PC: 17056 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:14.332420778Z 55 PC: 16d4c | Get or set switch character
2018-12-17T23:02:14.334397955Z 43 PC: 174db | Set date
2018-12-17T23:02:14.337768968Z 61 PC: 18f65 | Open file (Filename = '�:*O�k')
2018-12-17T23:02:14.344929921Z 61 PC: 18f65 | Open file (Filename = 'A:/PKZIP.CFG')
2018-12-17T23:02:14.351426414Z 68 PC: 169f5 | I/O control for devices (Set for = '!')
2018-12-17T23:02:14.368371273Z 61 PC: 17292 | Open file (Filename = '�LNf��ƚ�juF�D�� �iU�U���t��e���N�P��/���g/!��"w��9>��N�gfW�c�LEg�qOv�����ӷ �ص����A��1M���Y��A3�t���Q]*�?��ˇ9��CB�'��,�a�7�5�CÄ#�9t�4�� ֌_c��p�c���2����Q�ia/��
2018-12-17T23:02:14.376031454Z 227 PC: 16df6 | UNKNOWN!
2018-12-17T23:02:14.377264649Z 96 PC: 16dac | Qualify filename
2018-12-17T23:02:14.38355549Z 64 PC: 17184 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:02:14.389071499Z 64 PC: 17184 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:02:14.421173377Z 12 PC: 18e06 | Flush input buffer and input