Uploaded October 2016 | Updated September 2026, 2 weeks ago
After long time again with various stuff, getting new equipment, installing it and other nuisance, I've finally managed to upload this.
Hopefully it's properly done.
After long time again with various stuff, getting new equipment, installing it and other nuisance, I've finally managed to upload this.
Hopefully it's properly done.


![Virus (DOS): IDEA.6126
Payload of this virus is activated at 15:30 (by that I mean system time), and shows a spinning video effect with text Warning! strong crypto inside.
Additionally, this virus can infect ZIP files when they are accessed by FindFirst/Next DOS commands (like using dir command to list a file) by dropping a infected copy named readme.com. After 6-7 tries to zip and unzip it and whatever, you can see 3 more video effect payloads, containing text:
Da BeSt BoaRd In SPaiN: El GriLLo Loco (34-1-352 24 45)
Downloaded From hxxp://wxx.narkotic.com/~vico (Cant confirm anything about website, not safe at some point.)
* ROADKILL BBS * Call now 028-6621590
Ive added to end of video slowed down versions of first two payloads so that you can see the text properly.
Aliases:
Virus.DOS.IDEA.6126 (Kaspersky Lab)
Virus: Idea.6126 (McAfee)
Idea-6126 (Sophos)
VGEN.51495 (ClamAV)
Spanska.6126 (FPROT)
Virus:DOS/Spanska.6126 (MS(OneCare))
Spanska.6126 (DrWeb)
Spanska.6126 (BitDef7)
Idea-6126 (AVAST)
Virus.DOS.IDEA (Ikarus)
Spanska.6180 (NAV)
Suspicious_Gen2.EHZCE (Norman)
Virus.DOS.IDEA.6126 [AVP] (FSecure)
IDEA.1626-O (TrendMicro) Virus (DOS): IDEA.6126](https://i.ytimg.com/vi/h1wmMYYB1S8/mqdefault.jpg)







