Sample viewer

vx.netlux.org/Virus.DOS.AntiPascal.529.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:34.525145633Z 74 PC: 12aa9 | Reallocate memory
2018-12-17T22:32:34.528019973Z 72 PC: 12ab0 | Allocate memory
2018-12-17T22:32:34.530658369Z 37 PC: 12abd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:34.532478178Z 26 PC: 12ac4 | Set disk transfer address
2018-12-17T22:32:34.53417782Z 25 PC: 12ac8 | Get default drive
2018-12-17T22:32:34.536597359Z 78 PC: 12bd5 | Find first file
2018-12-17T22:32:34.54373798Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.546122471Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.550655936Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.554479298Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.558458364Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.561302224Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.565384759Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.568043124Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.571574368Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.573657058Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.57613589Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.577573137Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.581881953Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.58333449Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.585740617Z 61 PC: 12b80 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:34.591935184Z 63 PC: 12b90 | Read file or device (Read 529 bytes on handle 5)
2018-12-17T22:32:34.60074023Z 62 PC: 12c0a | Close file
2018-12-17T22:32:34.603239338Z 79 PC: 12bd5 | Find next file
2018-12-17T22:32:34.606980468Z 78 PC: 12c1a | Find first file
2018-12-17T22:32:34.614025644Z 78 PC: 12c2b | Find first file
2018-12-17T22:32:34.621066491Z 68 PC: 12aef | I/O control for devices (Set for = '*.pas')
2018-12-17T22:32:34.625585704Z 14 PC: 12afd | Set default drive (Drive = 'C')
2018-12-17T22:32:34.627912989Z 78 PC: 12bd5 | Find first file
2018-12-17T22:32:34.635116067Z 61 PC: 12b80 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:32:34.644358775Z 63 PC: 12b90 | Read file or device (Read 529 bytes on handle 5)
2018-12-17T22:32:34.652791897Z 66 PC: 12b68 | Move file pointer
2018-12-17T22:32:34.656495417Z 64 PC: 12bab | Write file or device (Write 529 bytes on handle 5)
2018-12-17T22:32:35.073378332Z 66 PC: 12b68 | Move file pointer
2018-12-17T22:32:35.076913656Z 64 PC: 12c05 | Write file or device (Write 529 bytes on handle 5)
2018-12-17T22:32:35.086086888Z 62 PC: 12c0a | Close file
2018-12-17T22:32:35.099170858Z 14 PC: 12b05 | Set default drive (Drive = 'A')
2018-12-17T22:32:35.104534508Z 73 PC: 12b11 | Release memory
2018-12-17T22:32:35.107850974Z 74 PC: 12b1a | Reallocate memory
2018-12-17T22:32:35.110234356Z 74 PC: 12b1e | Reallocate memory
2018-12-17T22:32:35.113171549Z 26 PC: 12b25 | Set disk transfer address
2018-12-17T22:32:35.115275984Z 37 PC: 12b2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:35.117348028Z 76 PC: 12c51 | Terminate with return code (Return code = '0')