Sample viewer

vx.netlux.org/Virus.DOS.Pixel.739.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:56.347524015Z 26 PC: 12a72 | Set disk transfer address
2018-12-17T22:48:56.349670076Z 78 PC: 12a7c | Find first file
2018-12-17T22:48:56.355869353Z 61 PC: 12a86 | Open file (Filename = '')
2018-12-17T22:48:56.363172677Z 63 PC: 12a97 | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T22:48:56.370240769Z 66 PC: 12aac | Move file pointer
2018-12-17T22:48:56.372637562Z 64 PC: 12abf | Write file or device (Write 1146 bytes on handle 5)
2018-12-17T22:48:56.401547102Z 62 PC: 12ac8 | Close file
2018-12-17T22:48:56.410494732Z 79 PC: 12ad1 | Find next file
2018-12-17T22:48:56.413440566Z 26 PC: 12adb | Set disk transfer address
2018-12-17T22:48:58.47464792Z 72 PC: 8f1b9 | Allocate memory
2018-12-17T22:48:58.476652649Z 72 PC: 8f1bd | Allocate memory
2018-12-17T22:48:58.479687741Z 99 PC: 90858 | Get DBCS lead byte table pointer
2018-12-17T22:48:58.482755697Z 61 PC: 91f88 | Open file (Filename = 'C:\WINDOWS\HIMEM.SYS')
2018-12-17T22:48:58.493044199Z 66 PC: 91f95 | Move file pointer
2018-12-17T22:48:58.49523044Z 62 PC: 91fc1 | Close file
2018-12-17T22:48:58.497531393Z 75 PC: 91fe0 | Execute program
2018-12-17T22:48:58.512522377Z 98 PC: 916f1 | Get current PSP
2018-12-17T22:48:58.514509616Z 9 PC: c605 | Display string (String= '6��r�&;] u')
2018-12-17T22:48:58.52375728Z 48 PC: c609 | Get DOS version
2018-12-17T22:48:58.527024474Z 9 PC: c382 | Display string (String= ' Installed A20 handler number ')
2018-12-17T22:48:58.530931353Z 2 PC: c38c | Character output (Char = '32')
2018-12-17T22:48:58.532356195Z 2 PC: c3a7 | Character output (Char = '2e')
2018-12-17T22:48:58.534588938Z 9 PC: c6d9 | Display string (String= '�����VH�VD���V@��������������_���Ku��t1��������D�����t �� ��������a1��Z�����W���� ������5���|�����(���������Nj�(��������p�^')
2018-12-17T22:48:58.538812632Z 9 PC: c6e0 | Display string (String= '�5���|�����(���������Nj�(��������p�^')
2018-12-17T22:48:58.543454115Z 61 PC: 91f88 | Open file (Filename = 'C:\WINDOWS\SMARTDRV.EXE')
2018-12-17T22:48:58.553609604Z 66 PC: 91f95 | Move file pointer
2018-12-17T22:48:58.555623136Z 62 PC: 91fc1 | Close file
2018-12-17T22:48:58.557689472Z 75 PC: 91fe0 | Execute program
2018-12-17T22:48:58.577938136Z 98 PC: 916f1 | Get current PSP
2018-12-17T22:48:58.581998756Z 82 PC: 13d46 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:48:58.584169074Z 53 PC: 13ac3 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:48:58.585335613Z 37 PC: 13ad6 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:48:58.586434568Z 53 PC: 13ae0 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:48:58.589253615Z 37 PC: 13af3 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:48:58.590964694Z 9 PC: 13a0d | Display string (Could not find end pointer)
2018-12-17T22:48:58.601343262Z 62 PC: 8f8eb | Close file
2018-12-17T22:48:58.604215742Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.605917677Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.607280966Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.609095405Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.610504106Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.611812778Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.613588148Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.61489609Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.616266439Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.619508432Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.620876806Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.622274892Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.626245864Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.627980879Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.629337904Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.631162623Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.632554726Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.633839797Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.635225177Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.636535703Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.637718394Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.639117146Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.640561191Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.64181758Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.643104884Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.644609479Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.646040993Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.647391599Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.648869986Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.650264203Z 62 PC: 8f8f2 | Close file
2018-12-17T22:48:58.651804792Z 61 PC: 8f8ff | Open file (Filename = '')
2018-12-17T22:48:58.656526783Z 62 PC: 8f90e | Close file
2018-12-17T22:48:58.658069955Z 69 PC: 8f915 | Duplicate handle
2018-12-17T22:48:58.659554081Z 69 PC: 8f919 | Duplicate handle
2018-12-17T22:48:58.661130211Z 61 PC: 9387b | Open file (Filename = '')
2018-12-17T22:48:58.665403607Z 68 PC: 9386b | I/O control for devices (Set for = '')
2018-12-17T22:48:58.666538857Z 61 PC: 9387b | Open file (Filename = '')
2018-12-17T22:48:58.671167472Z 68 PC: 9386b | I/O control for devices (Set for = '')
2018-12-17T22:48:58.672526422Z 74 PC: 8f9c4 | Reallocate memory
2018-12-17T22:48:58.673914382Z 72 PC: 8f9e0 | Allocate memory
2018-12-17T22:48:58.675744698Z 72 PC: 8f9e4 | Allocate memory
2018-12-17T22:48:58.677029886Z 74 PC: 8f9fb | Reallocate memory
2018-12-17T22:48:58.678277688Z 72 PC: 8fa02 | Allocate memory
2018-12-17T22:48:58.6801797Z 72 PC: 8fa06 | Allocate memory
2018-12-17T22:48:58.681377689Z 73 PC: 8fa11 | Release memory
2018-12-17T22:48:58.683407304Z 73 PC: 8efea | Release memory
2018-12-17T22:48:58.684825118Z 74 PC: 8f003 | Reallocate memory
2018-12-17T22:48:58.686049315Z 72 PC: 8f054 | Allocate memory
2018-12-17T22:48:58.695480442Z 72 PC: 8f058 | Allocate memory
2018-12-17T22:48:58.696711854Z 73 PC: 8f060 | Release memory
2018-12-17T22:48:58.697663861Z 61 PC: 8f080 | Open file (Filename = 'y��^�u�3���u%�3�B�u�;�!s����=')
2018-12-17T22:48:58.703431202Z 63 PC: 8f095 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:58.706913617Z 66 PC: 8f0ad | Move file pointer
2018-12-17T22:48:58.708025618Z 62 PC: 8f0d1 | Close file
2018-12-17T22:48:58.709371267Z 75 PC: 8f0f2 | Execute program
2018-12-17T22:48:58.724388183Z 80 PC: 12be9 | Set current PSP
2018-12-17T22:48:58.725349378Z 48 PC: 12bee | Get DOS version
2018-12-17T22:48:58.726694588Z 99 PC: 193d0 | Get DBCS lead byte table pointer
2018-12-17T22:48:58.728928582Z 101 PC: 12c74 | Get extended country info
2018-12-17T22:48:58.729916865Z 99 PC: 12c7a | Get DBCS lead byte table pointer
2018-12-17T22:48:58.731038519Z 74 PC: 12cdc | Reallocate memory
2018-12-17T22:48:58.73226906Z 72 PC: 1355d | Allocate memory
2018-12-17T22:48:58.733337583Z 25 PC: 13596 | Get default drive
2018-12-17T22:48:58.734193883Z 71 PC: 135ad | Get current directory
2018-12-17T22:48:58.736157326Z 59 PC: 135ba | Change current directory
2018-12-17T22:48:58.739238698Z 59 PC: 135c8 | Change current directory
2018-12-17T22:48:58.743127675Z 59 PC: 135d3 | Change current directory
2018-12-17T22:48:58.745964629Z 25 PC: 12d13 | Get default drive
2018-12-17T22:48:58.746973521Z 37 PC: 127d3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:48:58.748069999Z 37 PC: 127da | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:58.749373382Z 37 PC: 127e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:58.75092826Z 80 PC: 1301d | Set current PSP
2018-12-17T22:48:58.751836229Z 37 PC: 13041 | Set interrupt vector (Interrupt = '46' AKA 'Set verify flag')
2018-12-17T22:48:58.753497901Z 53 PC: 13362 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:48:58.754652026Z 37 PC: 13383 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:48:58.75612112Z 51 PC: 13417 | Get or set Ctrl-Break
2018-12-17T22:48:58.757977251Z 72 PC: 130ec | Allocate memory
2018-12-17T22:48:58.7594868Z 61 PC: 131b2 | Open file (Filename = '')
2018-12-17T22:48:58.763321465Z 62 PC: 131ba | Close file
2018-12-17T22:48:58.765421605Z 51 PC: 1344c | Get or set Ctrl-Break
2018-12-17T22:48:58.766184519Z 74 PC: 1197c | Reallocate memory
2018-12-17T22:48:58.76724747Z 72 PC: 11991 | Allocate memory
2018-12-17T22:48:58.768893685Z 73 PC: 119b2 | Release memory
2018-12-17T22:48:58.769859184Z 72 PC: 119bd | Allocate memory
2018-12-17T22:48:58.771312375Z 73 PC: 119df | Release memory
2018-12-17T22:48:58.772685265Z 72 PC: 119f5 | Allocate memory
2018-12-17T22:48:58.774234016Z 72 PC: 119fd | Allocate memory