Uploaded April 2014 | Updated September 2026, 2 weeks ago
This is a VBS (Visual Basic Script) E-mail worm which sends mail to all contacts and for each contact it sends an SMS to some number through MoviStar service (NOTE: I haven't done research about MoviStar service and therefore any info I say about it might be incorrect).
In addition, it drops a trojan horse in System directory named "CMOS.COM" which destroys CMOS information and information on hard disks. It might be possible that only boot information is deleted and all data should be fine. However, I haven't tested that, but as far as I know, there should be no way to destroy hard drive data from Windows which could cause errors (FlashKiller is the only exception in this case, but it may cause BSODs). Therefore, I would consider that only boot information is gone, but everything else should be fine.
There are 2 more variants. Timofonica.B variant is just based on Apache, while Timofonica.C variant removed trojan horse part in code.
Aliases:
Email-Worm.VBS.Timofonica (Kaspersky Lab)
I-Worm.Timofonica (Kaspersky Lab)
Virus: VBS/Generic@MM (McAfee)
VBS/Timo-A (Sophos)
Worm.Timofonica (ClamAV)
VBS/Timofonica (Panda)
VBS/Timofon.B@m (FPROT)
Virus:VBS/Timofon.A (MS(OneCare))
VBS.Timofonica (DrWeb)
Generic.ScriptWorm.B15CB7EF (BitDef7)
VBS.Timofonica (VirusBuster)
VBS:MailWorm-gen [Wrm] (AVAST)
Email-Worm.VBS.Timofonica (Ikarus)
VBS/Timofon.A (AVG)
VBS/Timofonica (AVIRA)
VBS.Timofonica (NAV)
VBS/Timofon.A@mm (Norman)
VBS/Generic@MM (NAI)
VBS_TIMOFONICA (PCCIL)
VBS.Worm.Zokrim.z (Rising)
VBS/Timofon.B@mm [Libra] (FSecure)
VBS_TIMOFONICA (TrendMicro)
This is a VBS (Visual Basic Script) E-mail worm which sends mail to all contacts and for each contact it sends an SMS to some number through MoviStar service (NOTE: I haven't done research about MoviStar service and therefore any info I say about it might be incorrect).
In addition, it drops a trojan horse in System directory named "CMOS.COM" which destroys CMOS information and information on hard disks. It might be possible that only boot information is deleted and all data should be fine. However, I haven't tested that, but as far as I know, there should be no way to destroy hard drive data from Windows which could cause errors (FlashKiller is the only exception in this case, but it may cause BSODs). Therefore, I would consider that only boot information is gone, but everything else should be fine.
There are 2 more variants. Timofonica.B variant is just based on Apache, while Timofonica.C variant removed trojan horse part in code.
Aliases:
Email-Worm.VBS.Timofonica (Kaspersky Lab)
I-Worm.Timofonica (Kaspersky Lab)
Virus: VBS/Generic@MM (McAfee)
VBS/Timo-A (Sophos)
Worm.Timofonica (ClamAV)
VBS/Timofonica (Panda)
VBS/Timofon.B@m (FPROT)
Virus:VBS/Timofon.A (MS(OneCare))
VBS.Timofonica (DrWeb)
Generic.ScriptWorm.B15CB7EF (BitDef7)
VBS.Timofonica (VirusBuster)
VBS:MailWorm-gen [Wrm] (AVAST)
Email-Worm.VBS.Timofonica (Ikarus)
VBS/Timofon.A (AVG)
VBS/Timofonica (AVIRA)
VBS.Timofonica (NAV)
VBS/Timofon.A@mm (Norman)
VBS/Generic@MM (NAI)
VBS_TIMOFONICA (PCCIL)
VBS.Worm.Zokrim.z (Rising)
VBS/Timofon.B@mm [Libra] (FSecure)
VBS_TIMOFONICA (TrendMicro)



![Virus (DOS): IDEA.6126
Payload of this virus is activated at 15:30 (by that I mean system time), and shows a spinning video effect with text Warning! strong crypto inside.
Additionally, this virus can infect ZIP files when they are accessed by FindFirst/Next DOS commands (like using dir command to list a file) by dropping a infected copy named readme.com. After 6-7 tries to zip and unzip it and whatever, you can see 3 more video effect payloads, containing text:
Da BeSt BoaRd In SPaiN: El GriLLo Loco (34-1-352 24 45)
Downloaded From hxxp://wxx.narkotic.com/~vico (Cant confirm anything about website, not safe at some point.)
* ROADKILL BBS * Call now 028-6621590
Ive added to end of video slowed down versions of first two payloads so that you can see the text properly.
Aliases:
Virus.DOS.IDEA.6126 (Kaspersky Lab)
Virus: Idea.6126 (McAfee)
Idea-6126 (Sophos)
VGEN.51495 (ClamAV)
Spanska.6126 (FPROT)
Virus:DOS/Spanska.6126 (MS(OneCare))
Spanska.6126 (DrWeb)
Spanska.6126 (BitDef7)
Idea-6126 (AVAST)
Virus.DOS.IDEA (Ikarus)
Spanska.6180 (NAV)
Suspicious_Gen2.EHZCE (Norman)
Virus.DOS.IDEA.6126 [AVP] (FSecure)
IDEA.1626-O (TrendMicro) Virus (DOS): IDEA.6126](https://i.ytimg.com/vi/h1wmMYYB1S8/mqdefault.jpg)






