Virus Database


Kela Family

Description Kela Family

These are memory resident parasitic viruses. They hook INT 21h, and write themselves to the end of COM and EXE files that are accessed. Some of the major "Kela" versions are stealth viruses. The "Kela" viruses contain the following text strings:
"Kela.823": KELA lives Don Kr. 1992
"Kela.1171": KELA
"Kela.1735": AIDSTEST KELA-9 lives all times 1992-93 Alien
"Kela.1904": Kela
"Kela.2002": KELA lives all times 1993 ver
"Kela.2010": AIDSTEST KELA-10 lives all times 1992-93 Alien
"Kela.2122": Eddie livesallsomewhere in time! (C) Dread Lord, 1993, 1994
Thanx to the Dark Avenger DDT -- LAME ! FotD -- RULEZ
"Kela.2163": Eddie lives...somewhere in time!
Eddie 2 or Infinite Dreams virus by FotD
(C) Dread Lord, 1993, 1994
Thanx to the Dark Avenger DDT -- LAME ! FotD -- RULEZ

Some of the "Kela" viruses decrypt and display the following messages:
"Kela.690": ? ä"¡ èá_¡á_ - 4 KELA
"Kela.2099": You Are Dead !! Ha Ha Ha KELA-16
"Kela.2530": You Are Dead !! Ha Ha Ha KELA-15

"Kela.690" is a dangerous virus. While executing, it copies itself to the address 9500:0100, and does not fix the MCB list that might halt the computer. That virus infects .COM files only.
"Kela.2010" overwrites files with a string in Russian.
"Kela.2520" also hooks INT 8 (timer), and manifests itself with a video effect: "drops" the letters.
Kela.Chigi
These are very dangerous viruses. "Chigi.2203" also hooks INT 13h, and searches for the string "Adinf" in sectors being read. If this string is found, the virus overwrites this sector. This virus also contains the followingstring:
ChigiVarez Lives SomeWhere in Net ...

"Chigi.2518" on the 24th of any month, exchanges the addresses of INT 25h and INT 26h. This may corrupt data on the disks. The virus also displays a messages in Russian.

Check other viruses! Be aware! Use Antiviral Software

Dieg.1586

Description Dieg.1586

This is a relatively harmless memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of .COM and .EXE files that are executed. The virus contains the ID-string: "DIEG". In August, the virus also hooks INT 1Ch and 28h, and within 15 minutes after installing into the memory, the virus "shifts" the screen to the left.

DieHard2.4000.a

Description DieHard2.4000.a

This is a dangerous memory resident parasitic encrypted stealth virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are accessed. It overwrites the source files with the following strings:
.model small
.code
org 256
s: push cs
pop ds
call t
db '-Ñ$'
t: pop dx
mov ah,9
int 33
mov ah,76
int 33
end s
begin
write('-Ç');
end.

It also contains the following internal text strings:
SW Error
SW DIE HARD 2

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com