Sample viewer

vx.netlux.org/Virus.DOS.BackFormat.2000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:08.541714573Z 61 PC: 13c58 | Open file
2018-12-17T22:34:08.548359078Z 63 PC: 13c6a | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:34:08.551196343Z 66 PC: 13c8e | Move file pointer
2018-12-17T22:34:08.552765313Z 63 PC: 13c9d | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:34:08.562103966Z 87 PC: 13ccb | Get or set file date and time
2018-12-17T22:34:08.572364184Z 66 PC: 13cdc | Move file pointer
2018-12-17T22:34:08.574222537Z 66 PC: 13cff | Move file pointer
2018-12-17T22:34:08.57607569Z 98 PC: 13d05 | Get current PSP
2018-12-17T22:34:08.578088628Z 48 PC: 13d1b | Get DOS version
2018-12-17T22:34:08.57938291Z 82 PC: 13d32 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:34:08.580804732Z 64 PC: 13d6a | Write file or device (Write 1855 bytes on handle 5)
2018-12-17T22:34:08.92437808Z 66 PC: 13d76 | Move file pointer
2018-12-17T22:34:08.92602668Z 64 PC: 13d80 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:34:08.929164823Z 87 PC: 13d8d | Get or set file date and time
2018-12-17T22:34:08.931398199Z 62 PC: 13da1 | Close file
2018-12-17T22:34:08.93627236Z 74 PC: 12c7e | Reallocate memory
2018-12-17T22:34:08.937474842Z 82 PC: 12c82 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:34:08.939481312Z 73 PC: 12cae | Release memory
2018-12-17T22:34:08.940717288Z 75 PC: 12d11 | Execute program
2018-12-17T22:34:08.951444588Z 76 PC: 145d8 | Terminate with return code (Return code = '0')
2018-12-17T22:34:08.955144011Z 77 PC: 12d15 | Get program return code
2018-12-17T22:34:08.956448593Z 76 PC: 12d2a | Terminate with return code (Return code = '0')
2018-12-17T22:34:08.959736873Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:34:08.961486145Z 72 PC: 12174 | Allocate memory
2018-12-17T22:34:08.963411018Z 72 PC: 1218d | Allocate memory
2018-12-17T22:34:08.964999079Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:34:08.96643973Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:08.976148858Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:08.977632305Z 66 PC: 12eac | Move file pointer
2018-12-17T22:34:08.979451161Z 87 PC: 12ecd | Get or set file date and time
2018-12-17T22:34:08.981700223Z 63 PC: 12ee0 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:34:08.983581181Z 66 PC: 12f40 | Move file pointer
2018-12-17T22:34:08.985410815Z 66 PC: 12f7b | Move file pointer
2018-12-17T22:34:08.987648949Z 64 PC: 12f8b | Write file or device (Write 1990 bytes on handle 5)
2018-12-17T22:34:08.989518308Z 66 PC: 12f97 | Move file pointer
2018-12-17T22:34:08.991299661Z 64 PC: 12fa1 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:34:08.994071339Z 87 PC: 1310e | Get or set file date and time
2018-12-17T22:34:08.995518733Z 62 PC: 122ab | Close file
2018-12-17T22:34:08.997806117Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.000023304Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.001669317Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.003444492Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.008594181Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.01013141Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.011577082Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.014175598Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.015637004Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.017129575Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.019342404Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.020859536Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.022283328Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.024285048Z 62 PC: 122ab | Close file
2018-12-17T22:34:09.027320026Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:34:09.028859815Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:34:09.037918935Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:34:09.042300385Z 25 PC: 94e62 | Get default drive
2018-12-17T22:34:09.043839081Z 71 PC: 970dd | Get current directory
2018-12-17T22:34:09.048415332Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:34:09.051763677Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:34:09.055002035Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:34:09.057362951Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:34:09.059378412Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:34:23.516490445Z 0 PC: 0 | Program terminate
2018-12-17T22:34:24.870722586Z 0 PC: 0 | Program terminate
2018-12-17T22:34:24.972976176Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:34:24.979759907Z 41 PC: 94fae | Parse filename
2018-12-17T22:34:24.981597555Z 41 PC: 9502f | Parse filename
2018-12-17T22:34:24.983416132Z 41 PC: 9504c | Parse filename
2018-12-17T22:34:24.987753069Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:34:24.990040656Z 71 PC: 986f3 | Get current directory
2018-12-17T22:34:24.998150523Z 78 PC: 986fe | Find first file
2018-12-17T22:34:25.008581295Z 71 PC: 9856c | Get current directory
2018-12-17T22:34:25.012453169Z 73 PC: 97c09 | Release memory
2018-12-17T22:34:25.014166458Z 75 PC: 11821 | Execute program
2018-12-17T22:34:25.031282605Z 9 PC: 13457 | Display string (String= 'Hello, World! ')
2018-12-17T22:34:25.035087041Z 76 PC: 1345b | Terminate with return code (Return code = '36')