Sample viewer

vx.netlux.org/Virus.DOS.Gotcha.627.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:59.707374956Z 218 PC: 12a8b | UNKNOWN!
2018-12-17T21:51:59.709019823Z 48 PC: 12a95 | Get DOS version
2018-12-17T21:51:59.710586763Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:59.714062652Z 77 PC: 11fe0 | Get program return code
2018-12-17T21:51:59.71619475Z 72 PC: 12174 | Allocate memory
2018-12-17T21:51:59.718318777Z 72 PC: 1218d | Allocate memory
2018-12-17T21:51:59.720870231Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:51:59.723536504Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:59.724896739Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:59.726356585Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.728525328Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.730640863Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.73228174Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.734418449Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.735971786Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.737514571Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.739401702Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.74302369Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.745747011Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.747639735Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.749731918Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.751519324Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.753405948Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.755699362Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.757436051Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.759103007Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.761299496Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.762533041Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.76377962Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.766653964Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.767951564Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.770088005Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.773137976Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.774876043Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.77661096Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.778836839Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.781162536Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.78293539Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:51:59.7866556Z 62 PC: 122ab | Close file
2018-12-17T21:51:59.789732399Z 99 PC: 9a0a7 | Get DBCS lead byte table pointer
2018-12-17T21:51:59.791652302Z 56 PC: 948c9 | Get or set country info
2018-12-17T21:51:59.794262252Z 64 PC: 9a318 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:51:59.797886354Z 25 PC: 94932 | Get default drive
2018-12-17T21:51:59.801115406Z 71 PC: 96bad | Get current directory
2018-12-17T21:51:59.809003133Z 64 PC: 9a318 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:51:59.81314335Z 2 PC: 96b82 | Character output (Char = '3e')
2018-12-17T21:51:59.815569029Z 93 PC: 949f0 | File sharing functions
2018-12-17T21:51:59.817485395Z 93 PC: 949f7 | File sharing functions
2018-12-17T21:51:59.820095285Z 10 PC: 94a09 | Buffered keyboard input
2018-12-17T21:52:14.698280623Z 0 PC: 0 | Program terminate
2018-12-17T21:52:16.053033539Z 0 PC: 0 | Program terminate
2018-12-17T21:52:16.155364141Z 64 PC: 9a318 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:52:16.161181869Z 41 PC: 94a7e | Parse filename
2018-12-17T21:52:16.16405151Z 41 PC: 94aff | Parse filename
2018-12-17T21:52:16.166610219Z 41 PC: 94b1c | Parse filename
2018-12-17T21:52:16.17018381Z 26 PC: 97fc7 | Set disk transfer address
2018-12-17T21:52:16.173305619Z 71 PC: 981c3 | Get current directory
2018-12-17T21:52:16.18134982Z 78 PC: 981ce | Find first file
2018-12-17T21:52:16.190445549Z 71 PC: 9803c | Get current directory
2018-12-17T21:52:16.194372708Z 73 PC: 976d9 | Release memory
2018-12-17T21:52:16.195936971Z 61 PC: 9f889 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T21:52:16.202584515Z 98 PC: 9f8b0 | Get current PSP
2018-12-17T21:52:16.20939883Z 51 PC: 9f8d7 | Get or set Ctrl-Break
2018-12-17T21:52:16.210532904Z 51 PC: 9f8dd | Get or set Ctrl-Break
2018-12-17T21:52:16.21152716Z 53 PC: 9f8e4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:16.213704081Z 37 PC: 9f8f2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:16.215711344Z 63 PC: 9f966 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:52:16.22229874Z 63 PC: 9f977 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T21:52:16.225345022Z 62 PC: 9f8a9 | Close file
2018-12-17T21:52:16.229978808Z 37 PC: 9f9ff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:16.231042238Z 51 PC: 9fa03 | Get or set Ctrl-Break
2018-12-17T21:52:16.232028786Z 75 PC: 11821 | Execute program
2018-12-17T21:52:16.240821747Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T21:52:16.243837957Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T21:52:16.246455764Z 77 PC: 11fe0 | Get program return code
2018-12-17T21:52:16.24792562Z 72 PC: 12174 | Allocate memory
2018-12-17T21:52:16.249166614Z 72 PC: 1218d | Allocate memory
2018-12-17T21:52:16.250403293Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:52:16.251892933Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:16.25283156Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:16.253826566Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.255572907Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.256760584Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.257950871Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.259768205Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.261177775Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.262260382Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.263941765Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.265056105Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.266160438Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.267602777Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.268624743Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.269715205Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.273403078Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.277558364Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.279259624Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.281199073Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.282999398Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.285167974Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.287723404Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.28936098Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.290802889Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.292712494Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.293981437Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.295187696Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.297539601Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.299680141Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.301375494Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.30589728Z 69 PC: 9f889 | Duplicate handle
2018-12-17T21:52:16.307385728Z 62 PC: 122ab | Close file
2018-12-17T21:52:16.310110535Z 99 PC: 9a0a7 | Get DBCS lead byte table pointer
2018-12-17T21:52:16.311884149Z 56 PC: 948c9 | Get or set country info
2018-12-17T21:52:16.313484822Z 64 PC: 9a318 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:52:16.317038718Z 25 PC: 94932 | Get default drive
2018-12-17T21:52:16.318691734Z 71 PC: 96bad | Get current directory
2018-12-17T21:52:16.321239858Z 64 PC: 9a318 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:52:16.323606567Z 2 PC: 96b82 | Character output (Char = '3e')
2018-12-17T21:52:16.325455272Z 93 PC: 949f0 | File sharing functions
2018-12-17T21:52:16.326790886Z 93 PC: 949f7 | File sharing functions
2018-12-17T21:52:16.32850699Z 10 PC: 94a09 | Buffered keyboard input