Sample viewer

vx.netlux.org/Virus.DOS.VCC.Gr.467

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:34.670444078Z 26 PC: 12e45 | Set disk transfer address
2018-12-17T23:02:34.673192625Z 53 PC: 12e4b | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:02:34.675089413Z 53 PC: 12e58 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:02:34.676663532Z 44 PC: 12e63 | Get time 0x12e63: cmp dl, 0xd
0x12e66: jg 0x12e6c
0x12e68: mov al, 0x82
0x12e6a: out 0x21, al
0x12e6c: mov ah, 0x2c
0x12e6e: int 0x21
0x12e70: cmp dl, 0x32
0x12e73: jg 0x12ee2
0x12e75: mov si, 0
0x12e78: xor byte ptr [bp + si + 0x16c], 0x41
0x12e7d: cmp si, 0x11
0x12e80: je 0x12e85
0x12e82: inc si
0x12e83: jmp 0x12e78
0x12e85: mov ah, 9
0x12e87: lea dx, word ptr [bp + 0x16c]
0x12e8b: int 0x21
0x12e8d: mov ah, 0
0x12e8f: int 0x16
0x12e91: jmp 0x12ee2
2018-12-17T23:02:34.679403734Z 44 PC: 12e70 | Get time 0x12e70: cmp dl, 0x32
0x12e73: jg 0x12ee2
0x12e75: mov si, 0
0x12e78: xor byte ptr [bp + si + 0x16c], 0x41
0x12e7d: cmp si, 0x11
0x12e80: je 0x12e85
0x12e82: inc si
0x12e83: jmp 0x12e78
0x12e85: mov ah, 9
0x12e87: lea dx, word ptr [bp + 0x16c]
0x12e8b: int 0x21
0x12e8d: mov ah, 0
0x12e8f: int 0x16
0x12e91: jmp 0x12ee2
0x12e93: nop
0x12e94: and byte ptr [bp + si + 0x75], al
0x12e97: jb 0x12f07
0x12e99: inc bx
0x12e9a: jns 0x12eff
0x12e9c: insb byte ptr es:[di], dx
2018-12-17T23:02:34.683109857Z 78 PC: 12efb | Find first file
2018-12-17T23:02:34.688820518Z 59 PC: 12f63 | Change current directory
2018-12-17T23:02:34.693278573Z 42 PC: 12f6b | Get date 0x12f6b: cmp dh, 0x11
0x12f6e: jl 0x12f8f
0x12f70: cmp dl, 8
0x12f73: jl 0x12f8f
0x12f75: mov ah, 0x19
0x12f77: int 0x21
0x12f79: mov cx, 0x25
0x12f7c: mov dx, 0
0x12f7f: lea bx, word ptr [bp + 0x16c]
0x12f83: push ds
0x12f84: pop es
0x12f85: mov byte ptr [bp + 0x263], 0x26
0x12f8a: int 0x19
0x12f8c: add sp, 2
0x12f8f: mov ah, 0x1a
0x12f91: mov dx, 0x80
0x12f94: int 0x21
0x12f96: call 0x12f99
0x12f99: call 0x12f9c
0x12f9c: call 0x12f9f
2018-12-17T23:02:34.695595799Z 26 PC: 12f96 | Set disk transfer address
2018-12-17T23:02:34.697094741Z 9 PC: 12fb6 | Display string (String= ' �pZp�5p��CON Gp��!AUX Yp���PRN kp��9CLOCK')