Sample viewer

vx.netlux.org/Virus.DOS.Tourist.1871

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:35.45517481Z 42 PC: 13853 | Get date 0x13853: pop bx
0x13854: cmp cx, 0x7c9
0x13858: jb 0x1387e
0x1385a: cmp dh, 6
0x1385d: jne 0x1387e
0x1385f: cmp dl, 9
0x13862: jne 0x1387e
0x13864: push bx
0x13865: call 0x1391e
0x13868: mov ah, 0
0x1386a: int 0x16
0x1386c: mov ah, 0
0x1386e: mov al, 3
0x13870: int 0x10
0x13872: xor ax, ax
0x13874: mov es, ax
0x13876: mov ax, 0x1357
0x13879: mov word ptr es:[0x353], ax
0x1387d: pop bx
0x1387e: push cs
2018-12-17T22:38:35.461030607Z 25 PC: 13885 | Get default drive
2018-12-17T22:38:35.464872261Z 26 PC: 138a8 | Set disk transfer address
2018-12-17T22:38:35.466859894Z 78 PC: 138b6 | Find first file
2018-12-17T22:38:35.479460102Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.482844525Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.486675559Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.490486275Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.493007623Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.495427419Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.500866943Z 79 PC: 138dd | Find next file
2018-12-17T22:38:35.503811568Z 61 PC: 13478 | Open file (Filename = '')
2018-12-17T22:38:35.509625756Z 66 PC: 13493 | Move file pointer
2018-12-17T22:38:35.511853712Z 37 PC: 134a5 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:38:35.513879587Z 37 PC: 134b2 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:38:35.516981898Z 74 PC: 134bd | Reallocate memory
2018-12-17T22:38:35.520580825Z 72 PC: 134cb | Allocate memory
2018-12-17T22:38:35.524754655Z 63 PC: 134f1 | Read file or device (Read 4416 bytes on handle 5)
2018-12-17T22:38:35.534395529Z 66 PC: 13685 | Move file pointer
2018-12-17T22:38:35.537025893Z 64 PC: 136b5 | Write file or device (Write 6301 bytes on handle 5)
2018-12-17T22:38:35.553263089Z 87 PC: 136d8 | Get or set file date and time
2018-12-17T22:38:35.555012222Z 73 PC: 136e6 | Release memory
2018-12-17T22:38:35.556670245Z 62 PC: 136f4 | Close file
2018-12-17T22:38:35.56510624Z 74 PC: 12c4b | Reallocate memory
2018-12-17T22:38:35.567014293Z 61 PC: 131c1 | Open file (Filename = '')
2018-12-17T22:38:35.570173924Z 9 PC: 133d4 | Display string (String= ' COMPARE 1.0 (C) 1988 Ziff Communications Co. PC Magazine � Michael J. Mefford Syntax: COMPARE filespec filespec[/B][/W] /B = Binary /W = WordStar')
2018-12-17T22:38:35.582025771Z 9 PC: 133d4 | Display string (String= ' Enter first file name ')
2018-12-17T22:38:35.589824647Z 10 PC: 13355 | Buffered keyboard input