Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Wonder.7424.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:33.721416007Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:28:33.724572813Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:33.727319229Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:33.729037154Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:28:33.730762917Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:28:33.732768831Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:33.734569082Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:28:33.737206148Z 68 PC: 13c81 | I/O control for devices (Set for = '�3 ')
2018-12-17T22:28:33.739925101Z 68 PC: 13c81 | I/O control for devices (Set for = '�3 ')
2018-12-17T22:28:33.742680647Z 61 PC: 13f34 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:28:33.750676925Z 68 PC: 13c25 | I/O control for devices (Set for = '+ - Copyright 1990 Borland Intl.')
2018-12-17T22:28:33.753081696Z 68 PC: 13c81 | I/O control for devices
2018-12-17T22:28:33.75546402Z 63 PC: 1401d | Read file or device (Read 7168 bytes on handle 5)
2018-12-17T22:28:33.764123445Z 63 PC: 1401d | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:28:33.783058238Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.785533696Z 47 PC: 13a7e | Get disk transfer address
2018-12-17T22:28:33.786784449Z 26 PC: 13a87 | Set disk transfer address
2018-12-17T22:28:33.789251122Z 78 PC: 13a91 | Find first file
2018-12-17T22:28:33.800605025Z 26 PC: 13a99 | Set disk transfer address
2018-12-17T22:28:33.802760602Z 61 PC: 13f34 | Open file (Filename = '�%�z')
2018-12-17T22:28:33.811299784Z 68 PC: 13c25 | I/O control for devices (Set for = '�!�.')
2018-12-17T22:28:33.813029443Z 68 PC: 13c81 | I/O control for devices (Set for = 'e in drive %1 has no label Volume in drive %1 is %2 Volume Serial Number is %1-%2 'Duplicate file name or file not found Invalid path or file name Out of environment space File creation error Batch file missing  Insert disk with batch file')
2018-12-17T22:28:33.816195166Z 63 PC: 1401d | Read file or device (Read 7168 bytes on handle 5)
2018-12-17T22:28:33.824939713Z 63 PC: 1401d | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:28:33.832985368Z 47 PC: 13ab0 | Get disk transfer address
2018-12-17T22:28:33.834395573Z 26 PC: 13ab9 | Set disk transfer address
2018-12-17T22:28:33.835916859Z 79 PC: 13abd | Find next file
2018-12-17T22:28:33.840351974Z 26 PC: 13ac5 | Set disk transfer address
2018-12-17T22:28:33.842541649Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.844828398Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.848106535Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.85079643Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.853341972Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.857033242Z 62 PC: 139fa | Close file
2018-12-17T22:28:33.859453908Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:33.861002063Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:33.863304865Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:28:33.865183764Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:28:33.866741682Z 76 PC: 12b9c | Terminate with return code (Return code = '0')