Sample viewer

vx.netlux.org/Virus.DOS.Zorm.1139

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:26.505281074Z 61 PC: 12ab8 | Open file (Filename = 'Í ÀŸ')
2018-12-17T22:30:26.512914149Z 26 PC: 12ebc | Set disk transfer address
2018-12-17T22:30:26.514501524Z 53 PC: 12b31 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:26.516118305Z 37 PC: 12b41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:26.51838743Z 71 PC: 12b51 | Get current directory
2018-12-17T22:30:26.521879336Z 25 PC: 12b55 | Get default drive
2018-12-17T22:30:26.523390473Z 14 PC: 12b63 | Set default drive (Drive = 'C')
2018-12-17T22:30:26.526381492Z 78 PC: 12e1d | Find first file
2018-12-17T22:30:26.535890573Z 59 PC: 12e2b | Change current directory
2018-12-17T22:30:26.5396729Z 14 PC: 12d9b | Set default drive (Drive = 'A')
2018-12-17T22:30:26.541024558Z 59 PC: 12da8 | Change current directory
2018-12-17T22:30:26.544990482Z 71 PC: 12b51 | Get current directory
2018-12-17T22:30:26.547668216Z 25 PC: 12b55 | Get default drive
2018-12-17T22:30:26.54881176Z 14 PC: 12b63 | Set default drive (Drive = 'C')