Sample viewer

vx.netlux.org/Virus.DOS.Avalgasil.666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:16:00.796342929Z 118 PC: 17fd9 | UNKNOWN!
2018-12-17T22:16:00.798108843Z 73 PC: 17fe4 | Release memory
2018-12-17T22:16:00.799536613Z 72 PC: 17fed | Allocate memory
2018-12-17T22:16:00.801041449Z 74 PC: 17ffc | Reallocate memory
2018-12-17T22:16:00.803306661Z 74 PC: 1800b | Reallocate memory
2018-12-17T22:16:00.805012961Z 53 PC: 18023 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:16:00.806144481Z 82 PC: 18051 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:16:00.809790165Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:16:00.810845605Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:16:00.812000445Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:16:00.814759199Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:16:00.815838938Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:16:00.817045679Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:00.818679175Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:16:00.820734068Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:16:00.821931621Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:16:00.823567936Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:16:00.825208435Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:16:00.826731899Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:16:00.828456642Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:16:00.82983576Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:16:00.831445469Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:16:00.832966298Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:16:00.834337047Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:16:00.835485426Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:16:00.837898071Z 53 PC: 16cc2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:16:00.839255299Z 37 PC: 16cd7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:16:00.8403431Z 37 PC: 16cdf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:16:00.84170061Z 37 PC: 16ce7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:00.843319993Z 37 PC: 16cef | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:16:00.844936318Z 68 PC: 17366 | I/O control for devices (Set for = '')
2018-12-17T22:16:00.93230455Z 37 PC: 12f15 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:16:00.937880295Z 53 PC: 9f938 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:00.939900922Z 37 PC: 9f938 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:00.941483066Z 46 PC: 9f938 | Set verify flag
2018-12-17T22:16:00.944148265Z 61 PC: 9f938 | Open file (Filename = '‹ʀ')
2018-12-17T22:16:00.950989193Z 37 PC: 9f938 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:00.953066926Z 61 PC: 17af7 | Open file (Filename = 'EGAVGA.BGI')
2018-12-17T22:16:00.965870424Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:16:00.967371913Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:16:00.968869502Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:16:00.970639802Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:16:00.971849412Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:16:00.973123007Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:00.975323659Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:16:00.976713692Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:16:00.978152875Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:16:00.980123804Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:16:00.981551803Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:16:00.98277683Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:16:00.984406458Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:16:00.985443486Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:16:00.986538661Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:16:00.988257905Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:16:00.989192459Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:16:00.993385014Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:16:00.995091215Z 37 PC: 16dd6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:16:00.996228357Z 76 PC: 16e15 | Terminate with return code (Return code = '1')