Virus.DOS.Zohra is a memory resident parasitic encrypted DOS virus, written by Wintermute in 29A.

There are 5 variants in 3 versions, represented by the following:

  • Virus.DOS.Zohra.4160
  • Virus.DOS.Zohra.4382
  • Virus.DOS.Zohra.4488


This virus first checks the version of the operating system, if it is later than 5.0, the virus simply exits and nothing will be installed or infected.

When the virus is loaded into memory, it hooks INT 21h and writes itself to the end of executables that are run.

The virus does not infect files which their filename contains any of these substrings:


The virus hides its TSR code when MEM.EXE is run, this will make the program to show there is only 48 bytes less in system free memory. But if MEM is renamed to other filename and run, the actual memory usage will be shown.

The virus removes itself from memory when WIN.EXE is run.

This virus use a quite complex way to get original address of INT 21h handler, it disassembles code of INT 21h handlers up to the original handler in DOS kernel.

Advanced details

The TSR memory usage of the variants:

Variant Memory usage in bytes
Zohra.4160 7,856
Zohra.4382 8,304
Zohra.4488 8,528
Zohra.4516 8,592
Zohra.4525 8,592

MD5 hashes:

Variant Hash
Zohra.4160 a69253acc8923d732d6e07ec72ccc8da
Zohra.4382 f10b3eb29a917315020c8c28b0384a28
Zohra.4488 f848a81f7622e01f40d6e1679d0b7d60
Zohra.4516 ceffad8627790b082088102f08b73651
Zohra.4525 94018d6b2c402383b38e3e2cad921440



This variant does not manifest itself.

Zohra.4382, 4488, 4516 and 4525

On April 14th, when the virus is already in the memory, it waits for a program execution, when triggered it shifts the characters on screen quickly. After a while the virus clears the screen line by line from the top and bottom to the center of the screen, and then it displays the message in green color, followed by hanging the system.


Zohra Crack (c) SunSoft

Zohra.4488, 4516 and 4525:

Zohra will live forever ! Necromancy with her...


This family has 5 variants in total:

  • Virus.DOS.Zohra.4160
  • Virus.DOS.Zohra.4382
  • Virus.DOS.Zohra.4488
  • Virus.DOS.Zohra.4516
  • Virus.DOS.Zohra.4525

Other details

Zohra.4160 and 4382 belong to other creator(s).

Zohra.4382 contains the encrypted internal text strings:

[Zohra] Crack (c) SunSoft
Ralph Roth

Zohra.4488, 4516 and 4525 contain the encrypted internal text strings:

[Zohra] virus by Wintermute/29A, dedicated to the best Necromancer of the
Forgotten Realms,... I assure you will live forever, my love... ;)


  1. List of variants of the Zohra virus on VX Heaven


Zohra DOS Virus Simulator on MS-DOS 6.22 and DOSBox 0

Zohra DOS Virus Simulator on MS-DOS 6.22 and DOSBox 0.73

Payload simulation of the Zohra virus

Community content is available under CC-BY-SA unless otherwise noted.