Sample viewer

vx.netlux.org/Virus.DOS.Zorm.1863

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:07.271157992Z 61 PC: 12ae2 | Open file (Filename = 'Í ÀŸ')
2018-12-17T22:47:07.275258572Z 105 PC: 12b0f | Get or set media id
2018-12-17T22:47:07.276867596Z 37 PC: 12b8d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:07.278288619Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.279914403Z 9 PC: 12a47 | Display string (String= 'HOOPS! i m afraid your puter is now infected by zorm-d virus')
2018-12-17T22:47:07.28392161Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.284924469Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:47:07.286170539Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.2880309Z 72 PC: 12174 | Allocate memory
2018-12-17T22:47:07.289513908Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.290636784Z 72 PC: 1218d | Allocate memory
2018-12-17T22:47:07.293003872Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.294213444Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:47:07.295300796Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.297139186Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:07.298067186Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.299319238Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.301088934Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.302051386Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.303161035Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.305002034Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:47:07.306477741Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.307992763Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.310035431Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.311272674Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.312743858Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.31466113Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:47:07.316295231Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.317728745Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.319630957Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.320823412Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.322208731Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.324129778Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 7)
2018-12-17T22:47:07.325784077Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.327153656Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.329063997Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.330485805Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.33163818Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.333154559Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 8)
2018-12-17T22:47:07.334315189Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.335390341Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.336872099Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.337857474Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.338917915Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.340974652Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 9)
2018-12-17T22:47:07.342182053Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.34320569Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.344365657Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.345426668Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.346372117Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.347577424Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 10)
2018-12-17T22:47:07.354842025Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.356107363Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.357956409Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.363675125Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.365691019Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.367499759Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 11)
2018-12-17T22:47:07.369592921Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.371024474Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.37231342Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.374385252Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.375724968Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.377069823Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 12)
2018-12-17T22:47:07.380131684Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.382185569Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.38390451Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.385760364Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.387133772Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.388513827Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 13)
2018-12-17T22:47:07.390801197Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.392433149Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.393908332Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.3956295Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.397254397Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.398676022Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 14)
2018-12-17T22:47:07.400667411Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.402077103Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.403446076Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.409534525Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.410909873Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.412294538Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 15)
2018-12-17T22:47:07.414249805Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.415608712Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.417020656Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.418741084Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.420076415Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.421385055Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 16)
2018-12-17T22:47:07.424006512Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.425079907Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.426533375Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.428197102Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.429667293Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.430990014Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 17)
2018-12-17T22:47:07.432662845Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.434083959Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.435450342Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.43776932Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.439859073Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.44183242Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 18)
2018-12-17T22:47:07.444805327Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.446716644Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.448321485Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.450126197Z 66 PC: 9efb7 | Move file pointer
2018-12-17T22:47:07.45164164Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.453247929Z 63 PC: 9efb7 | Read file or device (Read 28 bytes on handle 19)
2018-12-17T22:47:07.455492159Z 87 PC: 9efb7 | Get or set file date and time
2018-12-17T22:47:07.457425072Z 62 PC: 122ab | Close file
2018-12-17T22:47:07.460806949Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.463633033Z 99 PC: 99647 | Get DBCS lead byte table pointer
2018-12-17T22:47:07.465433284Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.467116229Z 56 PC: 93e69 | Get or set country info
2018-12-17T22:47:07.470358779Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.471504668Z 64 PC: 998b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:47:07.476610669Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.478322107Z 25 PC: 93ed2 | Get default drive
2018-12-17T22:47:07.479924085Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.481114777Z 71 PC: 9614d | Get current directory
2018-12-17T22:47:07.493481426Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.495057959Z 64 PC: 998b8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:47:07.498535967Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.501008387Z 2 PC: 96122 | Character output (Char = '3e')
2018-12-17T22:47:07.503194541Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.504291675Z 93 PC: 93f90 | File sharing functions
2018-12-17T22:47:07.506367525Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.507481609Z 93 PC: 93f97 | File sharing functions
2018-12-17T22:47:07.509205732Z 37 PC: 9efb7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:07.511117608Z 10 PC: 93fa9 | Buffered keyboard input