Sample viewer

vx.netlux.org/Trojan.DOS.ScanScreen

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:14.153939984Z 74 PC: 12ac5 | Reallocate memory
2018-12-17T23:07:14.156818957Z 74 PC: 12ad2 | Reallocate memory
2018-12-17T23:07:14.162761681Z 72 PC: 12ade | Allocate memory
2018-12-17T23:07:14.172306393Z 9 PC: 154a8 | Display string (String= 'Keyboard driver installed. (C) 1988,1989 A.Strakhov, AcademySoft. ')
2018-12-17T23:07:14.180680234Z 9 PC: 15957 | Display string (String= 'Switch RUS/LAT modes : ')
2018-12-17T23:07:14.184315363Z 9 PC: 15965 | Display string (String= '+')
2018-12-17T23:07:14.187496787Z 9 PC: 1596c | Display string (String= ' ')
2018-12-17T23:07:14.193007757Z 9 PC: 15957 | Display string (String= 'Switch IBM/RUS modes : ')
2018-12-17T23:07:14.197801288Z 9 PC: 15965 | Display string (String= '++')
2018-12-17T23:07:14.201093779Z 9 PC: 1596c | Display string (String= ' ')
2018-12-17T23:07:14.206241265Z 49 PC: 154d3 | Terminate and stay resident (Return code = '0' | Memory size = '685')