Sample viewer

vx.netlux.org/Virus.DOS.Psyco.804

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:48.179997522Z 53 PC: 12e3e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:48.181727302Z 37 PC: 12e50 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:48.184530208Z 26 PC: 12e58 | Set disk transfer address
2018-12-17T23:02:48.18610143Z 71 PC: 12e62 | Get current directory
2018-12-17T23:02:48.192934559Z 25 PC: 12e66 | Get default drive
2018-12-17T23:02:48.195522171Z 14 PC: 12e74 | Set default drive (Drive = 'C')
2018-12-17T23:02:48.207054218Z 59 PC: 12e7c | Change current directory
2018-12-17T23:02:48.211404843Z 61 PC: 12e85 | Open file (Filename = 'COMMAND.COM')
2018-12-17T23:02:48.21925924Z 63 PC: 12e97 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:02:48.222727867Z 62 PC: 12e9b | Close file
2018-12-17T23:02:48.22515612Z 78 PC: 12f16 | Find first file
2018-12-17T23:02:48.232316613Z 61 PC: 12fa1 | Open file (Filename = 'COMMAND.COM')
2018-12-17T23:02:48.239981865Z 63 PC: 12fb3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:02:48.243265014Z 66 PC: 12fdc | Move file pointer
2018-12-17T23:02:48.244882633Z 62 PC: 12fe1 | Close file
2018-12-17T23:02:48.248001864Z 67 PC: 12ff2 | Get or set file attributes
2018-12-17T23:02:48.67323744Z 61 PC: 12ff7 | Open file (Filename = 'COMMAND.COM')
2018-12-17T23:02:48.68037439Z 64 PC: 13004 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:02:48.684110069Z 66 PC: 1300d | Move file pointer
2018-12-17T23:02:48.685754759Z 64 PC: 13018 | Write file or device (Write 804 bytes on handle 5)
2018-12-17T23:02:48.696182462Z 87 PC: 13025 | Get or set file date and time
2018-12-17T23:02:48.699112216Z 62 PC: 13029 | Close file
2018-12-17T23:02:48.70731063Z 67 PC: 13038 | Get or set file attributes
2018-12-17T23:02:48.718157259Z 14 PC: 13057 | Set default drive (Drive = 'A')
2018-12-17T23:02:48.7311603Z 59 PC: 1305f | Change current directory
2018-12-17T23:02:48.735826778Z 59 PC: 13067 | Change current directory
2018-12-17T23:02:48.738523144Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')