Tonya Virus (31-July-1993) Entry...............: Tonya Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: Summer 1993 where.: Melbourne, Australia Classification......: File virus (COM infector), memory resident, variably encrypted Length of Virus.....: 1.Length (Byte) on media: 971 Bytes 2.Length (Byte) in RAM: 2016 Bytes --------------------- Preconditions ------------------------------------ Operating System(s).: MSDOS Version/Release.....: Computer model(s)...: IBM PCs and Compatibles --------------------- Attributes --------------------------------------- Easy Identification.: Virus is variably encrypted, no signature possible (after decryption, text may be identified) Type of infection...: File infection: COM files are infected upon opening (INT 21/3D) or loading for execution (INT 21/4B), if not too short (<50) or too long (>64,303). Upon detecting an yet uninfected COM file with proper size, virus appends it's code at the end and restores date, time and attributes previously saved. Length of COM files increase by 971 bytes. Self-Identification in files: Stealth: Virus is variably encrypted. Virus inter- cepts DOS functions OpenFile and Load&Execute, and it saves date&time attributes, to avoid detection. System infection: When an infected COM file is executed, virus after decryption first tries to make itself memory resident, using a non- standard DOS function; if not yet resident, virus loads itself to top-of-memory, reducing available memory by 2016 bytes. Self-Identification in memory: checking register value of an undocumented DOS function. Infection Trigger...: Executing an infected file, or (when virus is memory resident) invoking DOS functions Open File or Load&Execute, as long as 50 Documentation by....: Roger Riordan Klaus Brunnstein (CVC entry) Date................: 31-July-1993 Information Source..: Analysis of Virus .