Sample viewer

vx.netlux.org/Virus.DOS.Zhengxi.7313.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:16:43.826433468Z 37 PC: 12ba4 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:16:43.829739623Z 51 PC: 1310f | Get or set Ctrl-Break
2018-12-17T22:16:43.830911651Z 47 PC: 1312d | Get disk transfer address
2018-12-17T22:16:43.832276128Z 26 PC: 13138 | Set disk transfer address
2018-12-17T22:16:43.834461802Z 81 PC: 13bc4 | Get current PSP
2018-12-17T22:16:43.835819661Z 78 PC: 1313f | Find first file
2018-12-17T22:16:43.841975631Z 26 PC: 13145 | Set disk transfer address
2018-12-17T22:16:43.843305819Z 42 PC: 13149 | Get date 0x13149: xor dx, word ptr [bp + 0x3d]
0x1314c: and dx, 0x18
0x1314f: je 0x13127
0x13151: mov ah, 0x51
0x13153: int 0x21
0x13155: mov es, bx
0x13157: dec bx
0x13158: mov ds, bx
0x1315a: mov bx, word ptr [3]
0x1315e: sub bh, 7
0x13161: mov ah, 0x4a
0x13163: int 0x21
0x13165: mov ah, 0x48
0x13167: mov bx, 0x6ff
0x1316a: int 0x21
0x1316c: jb 0x13127
0x1316e: cmp word ptr es:[0], 0x20cd
0x13175: jne 0x1317d
0x13177: sub byte ptr es:[3], 8
0x1317d: dec ax
2018-12-17T22:16:43.848359549Z 9 PC: 12caa | Display string (Could not find end pointer)
2018-12-17T22:16:43.852482479Z 76 PC: 12cae | Terminate with return code (Return code = '36')