Sample viewer

vx.netlux.org/Virus.DOS.Zhengxi.7271

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:44.708523252Z 37 PC: 12ad4 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:19:44.711817263Z 51 PC: 13041 | Get or set Ctrl-Break
2018-12-17T22:19:44.712738527Z 47 PC: 1305f | Get disk transfer address
2018-12-17T22:19:44.713855749Z 26 PC: 1306a | Set disk transfer address
2018-12-17T22:19:44.716045185Z 81 PC: 13a24 | Get current PSP
2018-12-17T22:19:44.71696388Z 78 PC: 13071 | Find first file
2018-12-17T22:19:44.722884297Z 26 PC: 13077 | Set disk transfer address
2018-12-17T22:19:44.732899935Z 42 PC: 1307b | Get date 0x1307b: xor dx, word ptr [bp + 0x3d]
0x1307e: and dx, 0x18
0x13081: je 0x13059
0x13083: mov ah, 0x51
0x13085: int 0x21
0x13087: mov es, bx
0x13089: dec bx
0x1308a: mov ds, bx
0x1308c: mov bx, word ptr [3]
0x13090: sub bh, 7
0x13093: mov ah, 0x4a
0x13095: int 0x21
0x13097: mov ah, 0x48
0x13099: mov bx, 0x6ff
0x1309c: int 0x21
0x1309e: jb 0x13059
0x130a0: cmp word ptr es:[0], 0x20cd
0x130a7: jne 0x130af
0x130a9: sub byte ptr es:[3], 8
0x130af: dec ax
2018-12-17T22:19:44.744666528Z 9 PC: 12bdd | Display string (String= 'ؙnnFvQ X.] .e .] .&_ ..c Abnormal program termination ')
2018-12-17T22:19:44.751789468Z 76 PC: 12be1 | Terminate with return code (Return code = '36')