Sample viewer

vx.netlux.org/Virus.DOS.AMSV.443

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:47.557035798Z 48 PC: 13612 | Get DOS version
2018-12-17T22:45:47.558755485Z 53 PC: 13643 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:47.561677335Z 37 PC: 13653 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:47.562845843Z 9 PC: 135fb | Display string (String= ' ANSI v1.0 (c) 1990 The Nutty Professor. �For Personal Use only.� ')
2018-12-17T22:45:47.568879258Z 9 PC: 135fb | Display string (Could not find end pointer)
2018-12-17T22:45:47.577100804Z 9 PC: 135fb | Display string (String= 'Status: ')
2018-12-17T22:45:47.578843176Z 2 PC: 135fb | Character output (Char = '4f')
2018-12-17T22:45:47.580604444Z 2 PC: 135fb | Character output (Char = '4e')
2018-12-17T22:45:47.590814927Z 2 PC: 135fb | Character output (Char = '20')
2018-12-17T22:45:47.592729871Z 2 PC: 135fb | Character output (Char = '20')
2018-12-17T22:45:47.594328881Z 2 PC: 135fb | Character output (Char = '46')
2018-12-17T22:45:47.596588761Z 2 PC: 135fb | Character output (Char = '41')
2018-12-17T22:45:47.60977269Z 2 PC: 135fb | Character output (Char = '53')
2018-12-17T22:45:47.611336225Z 2 PC: 135fb | Character output (Char = '54')
2018-12-17T22:45:47.612794684Z 9 PC: 135fb | Display string (String= ' Buffer size: ')
2018-12-17T22:45:47.616653121Z 2 PC: 135fb | Character output (Char = '32')
2018-12-17T22:45:47.618299499Z 2 PC: 135fb | Character output (Char = '30')
2018-12-17T22:45:47.619878336Z 2 PC: 135fb | Character output (Char = '30')
2018-12-17T22:45:47.622074413Z 9 PC: 135fb | Display string (String= ' Bytes free: ')
2018-12-17T22:45:47.624820873Z 2 PC: 135fb | Character output (Char = '32')
2018-12-17T22:45:47.627377253Z 2 PC: 135fb | Character output (Char = '30')
2018-12-17T22:45:47.630243322Z 2 PC: 135fb | Character output (Char = '30')
2018-12-17T22:45:47.632503793Z 9 PC: 135fb | Display string (String= ' ')
2018-12-17T22:45:47.638703084Z 53 PC: 13469 | Get interrupt vector (Interrupt = '41' AKA 'Parse filename')
2018-12-17T22:45:47.640658201Z 37 PC: 13489 | Set interrupt vector (Interrupt = '41' AKA 'Parse filename')
2018-12-17T22:45:47.641642059Z 53 PC: 1348e | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:45:47.642692877Z 37 PC: 1349e | Set interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:45:47.643977457Z 53 PC: 134a3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:47.645153707Z 37 PC: 134b3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:47.646182721Z 73 PC: 134bc | Release memory
2018-12-17T22:45:47.647290084Z 9 PC: 135fb | Display string (String= 'r my instructions only. /U = Uninstall ')
2018-12-17T22:45:47.650193011Z 49 PC: 134d0 | Terminate and stay resident (Return code = '0' | Memory size = '159')