Sample viewer

vx.netlux.org/Virus.DOS.Zorm.1123.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:05.538346853Z 61 PC: 12a4d | Open file (Filename = 'Í ÀŸ')
2018-12-17T22:22:05.546832797Z 26 PC: 12e41 | Set disk transfer address
2018-12-17T22:22:05.548110444Z 53 PC: 12ac6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:05.549248693Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:05.550277709Z 71 PC: 12ae6 | Get current directory
2018-12-17T22:22:05.553661973Z 25 PC: 12aea | Get default drive
2018-12-17T22:22:05.554943085Z 14 PC: 12af8 | Set default drive (Drive = 'C')
2018-12-17T22:22:05.556468454Z 78 PC: 12da2 | Find first file
2018-12-17T22:22:05.56283933Z 59 PC: 12db0 | Change current directory
2018-12-17T22:22:05.567047529Z 14 PC: 12d20 | Set default drive (Drive = 'A')
2018-12-17T22:22:05.568319862Z 59 PC: 12d2d | Change current directory
2018-12-17T22:22:05.58627873Z 71 PC: 12ae6 | Get current directory
2018-12-17T22:22:05.588624833Z 25 PC: 12aea | Get default drive
2018-12-17T22:22:05.589649656Z 14 PC: 12af8 | Set default drive (Drive = 'C')