Malware Wiki


1,336pages on
this wiki
Add New Page
Comments2 Share

Virus.DOS.Ha1.1383, also known as Ha!, is a memory resident parasitic encrypted DOS virus.


When the virus is loaded into memory, it hooks INT 21h and writes itself into the end of the executables that are run.

The infection size varies in different files, it is in a range of 1,458 to 1,472 bytes.

Memory usage

The exact memory usage is 1,456 bytes.


On every 8th day, it also hooks onto INT 16h (keyboard) and switches the symbol "!" and space key when they are typed.

On every 16th day, this virus hooks onto INT 9 (keyboard interrupt) and when CTRL-ALT-DEL is pressed, the virus displays an ASCII art shifting "ha!" plus a message:

☼☼☼☼                    ☼☼☼
 ►►►                   ►►►►►
 ◄◄◄                   ◄◄◄◄◄
 ↕↕↕  ↕↕↕    ↕↕↕↕↕     ↕↕↕↕↕
 ‼‼‼‼‼ ‼‼‼       ‼‼‼    ‼‼‼
 ¶¶¶   ¶¶¶   ¶¶¶¶¶¶¶     ¶ 
 §§§   §§§  §§§  §§§
 ▬▬▬   ▬▬▬  ▬▬▬  ▬▬▬    ▬▬▬  
↨↨↨↨   ↨↨↨   ↨↨↨↨ ↨↨↨   ↨↨↨

          version A

Other details

For any leap year, the virus skips February 29th and count the day as average year. Say simpler, for March 5th in any year, the virus activates with the big "ha!" payload, it does not activate on March 4th in leap year even it is another 16th day in a year.

The virus contains the internal text string:

ha! version A

Additionally, not to be confused with the Ha virus, which has 2 variants: Ha.311 and Ha.709, are simply file infector viruses, programs infected by them may fail to run and cause a system crash.




Ha1 virus review by Alles Sandro

Ad blocker interference detected!

Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.