Virus.DOS.Hydra is a memory resident parasitic virus on DOS.

There are 2 variants:

  • Virus.DOS.Hydra.1162
  • Virus.DOS.Hydra.1649


When the virus is loaded into memory, the virus infects EXE executables that are run. The infection size varies in different files.


This variant mainly infects goat files, and not every file could be infected by this variant. And it might crash the system on infecting files having specified file size.


This variant infects every file that is run, but it does not infect files smaller than 1,000 bytes.

Advanced details

The following table shows the TSR memory usage of the variants.

Variant Memory usage in bytes
Hydra.1162 1,504
Hydra.1649 1,984

MD5 hashes:

Variant Hash
Hydra.1162 aac172d12959770758fa4abf3d9fe9d2
Hydra.1649 895de923868f83baa214976f604270ff


Hydra activates on January 1st, the payload runs once only on every section.


This variant displays the following message:

This is Hydra v1.0.
Don`t panic, I will not destroy your data.


When an infected program is run, the virus scrambles characters on screen like inside a washing machine, and they move away to right when a key is pressed.

After that it displays the following message:

This is Hydra v1.1.
Don`t panic, I will not destroy your data.

Hydra.1649 in action

Other details

When an infected goat file is run on non-activation day, the system may crash by memory allocation error or run into an invalid part of memory.


