Sample viewer




Time Syscall Op Syscall Name
2018-12-17T22:44:53.009472639Z 25 PC: 12ba6 | Get default drive
2018-12-17T22:44:53.010798537Z 71 PC: 12bb8 | Get current directory
2018-12-17T22:44:53.014946651Z 26 PC: 12bc0 | Set disk transfer address
2018-12-17T22:44:53.016630031Z 78 PC: 12bf6 | Find first file
2018-12-17T22:44:53.023788675Z 61 PC: 12c14 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:44:53.032164064Z 63 PC: 12c23 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:44:53.035349522Z 62 PC: 12c27 | Close file
2018-12-17T22:44:53.037770986Z 67 PC: 12c3d | Get or set file attributes
2018-12-17T22:44:53.055828073Z 61 PC: 12c4b | Open file (Filename = 'TEST.EXE')
2018-12-17T22:44:53.068993794Z 63 PC: 12c5b | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:44:53.07679984Z 66 PC: 12c83 | Move file pointer
2018-12-17T22:44:53.078984617Z 64 PC: 12c8e | Write file or device (Write 888 bytes on handle 5)
2018-12-17T22:44:53.089599653Z 66 PC: 12ccf | Move file pointer
2018-12-17T22:44:53.093626306Z 66 PC: 12ce5 | Move file pointer
2018-12-17T22:44:53.103717815Z 64 PC: 12cf0 | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:44:53.10823478Z 87 PC: 12d03 | Get or set file date and time
2018-12-17T22:44:53.109933446Z 62 PC: 12d07 | Close file
2018-12-17T22:44:53.125173112Z 67 PC: 12d16 | Get or set file attributes
2018-12-17T22:44:53.152607609Z 59 PC: 12d49 | Change current directory
2018-12-17T22:44:53.157898393Z 9 PC: 12d44 | Display string (String= ' ******************************************************* * yO!!! I could have made some mischief to you but I * * lEfT it out. I'm the #Nomad Virus# - Mikee's World * ******************************************************* ')
2018-12-17T22:44:53.174666606Z 59 PC: 12d1f | Change current directory
2018-12-17T22:44:53.179886994Z 26 PC: 12d2e | Set disk transfer address
2018-12-17T22:44:53.181346344Z 9 PC: 12ac8 | Display string (Could not find end pointer)
2018-12-17T22:44:53.198410167Z 76 PC: 12acc | Terminate with return code (Return code = '36')