Sample viewer

vx.netlux.org/Virus.DOS.Sirius.Alive.2000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:41.181849768Z 254 PC: 1a97e | UNKNOWN!
2018-12-17T22:23:41.186320124Z 61 PC: 1a9fe | Open file (Filename = 'c:\dos\doskey.com')
2018-12-17T22:23:41.193037674Z 48 PC: 1841e | Get DOS version
2018-12-17T22:23:41.194985122Z 74 PC: 18480 | Reallocate memory
2018-12-17T22:23:41.198150371Z 48 PC: 16912 | Get DOS version
2018-12-17T22:23:41.199785917Z 53 PC: 1691a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:41.201574993Z 37 PC: 1692c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:41.204170009Z 68 PC: 169b0 | I/O control for devices (Set for = '��F �}G�V����')
2018-12-17T22:23:41.206109087Z 68 PC: 169b0 | I/O control for devices (Set for = '| OFF] W ECHO [message] Type ECHO without parameters to display the current echo setting. GDirects MS-DOS to a labelled line in a batch progra��')
2018-12-17T22:23:41.208087792Z 68 PC: 169b0 | I/O control for devices (Set for = '')
2018-12-17T22:23:41.210224041Z 68 PC: 169b0 | I/O control for devices (Set for = '')
2018-12-17T22:23:41.213267113Z 68 PC: 169b0 | I/O control for devices (Set for = '')
2018-12-17T22:23:41.215830023Z 99 PC: 18758 | Get DBCS lead byte table pointer
2018-12-17T22:23:41.217399092Z 68 PC: 18772 | I/O control for devices (Set for = '')
2018-12-17T22:23:41.222651156Z 68 PC: 1877d | I/O control for devices (Set for = '')
2018-12-17T22:23:41.224376606Z 68 PC: 18788 | I/O control for devices (Set for = '')
2018-12-17T22:23:41.226187069Z 68 PC: 18790 | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T22:23:41.229340761Z 48 PC: 18795 | Get DOS version
2018-12-17T22:23:41.231431049Z 64 PC: 18a10 | Write file or device (Write 21 bytes on handle 2)
2018-12-17T22:23:41.236850907Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:41.238802757Z 76 PC: 16a2e | Terminate with return code (Return code = '1')