Uploaded December 2012 | Updated September 2026, 2 weeks ago
Pretty much a generic VB6 skiddie trojan. It will delete CONFIG.SYS, AUTOEXEC.BAT, WIN.COM, and one more, but I can't find which one is it actually. In general, whatever it managed to delete, it causes failure to boot into Windows. I've tried to backup 3 system files to see will it boot, but still nothing. It doesn't even identify HIMEM.SYS in Windows directory, so it's pretty much screwed up. It's not pretty much detailed video, as I want to show some stuff which still work (sort of).
If you click "INSTALL", it would just delete same files and shutdown.
Aliases:
Trojan.Win32.HackIt (Kaspersky Lab)
Trojan: QDel118 (McAfee)
Mal/Generic-A (Sophos)
W32/Trojan2.CPDM (FPROT)
Trojan:Win32/Hackit (MS(OneCare))
Trojan.HackIt.300 (DrWeb)
Win32/Hackit trojan (Nod32)
Trojan.Win32.Hackit.A (BitDef7)
Win32:Trojan-gen {Other} (AVAST)
Trojan.Win32.HackIt (Ikarus)
Generic.FCA (AVG)
TR/Hackit (AVIRA)
Trojan Horse (NAV)
Trojan.Hackit (Rising)
Pretty much a generic VB6 skiddie trojan. It will delete CONFIG.SYS, AUTOEXEC.BAT, WIN.COM, and one more, but I can't find which one is it actually. In general, whatever it managed to delete, it causes failure to boot into Windows. I've tried to backup 3 system files to see will it boot, but still nothing. It doesn't even identify HIMEM.SYS in Windows directory, so it's pretty much screwed up. It's not pretty much detailed video, as I want to show some stuff which still work (sort of).
If you click "INSTALL", it would just delete same files and shutdown.
Aliases:
Trojan.Win32.HackIt (Kaspersky Lab)
Trojan: QDel118 (McAfee)
Mal/Generic-A (Sophos)
W32/Trojan2.CPDM (FPROT)
Trojan:Win32/Hackit (MS(OneCare))
Trojan.HackIt.300 (DrWeb)
Win32/Hackit trojan (Nod32)
Trojan.Win32.Hackit.A (BitDef7)
Win32:Trojan-gen {Other} (AVAST)
Trojan.Win32.HackIt (Ikarus)
Generic.FCA (AVG)
TR/Hackit (AVIRA)
Trojan Horse (NAV)
Trojan.Hackit (Rising)










![E-mail Worm (Visual Basic Script): Timofonica.A
This is a VBS (Visual Basic Script) E-mail worm which sends mail to all contacts and for each contact it sends an SMS to some number through MoviStar service (NOTE: I havent done research about MoviStar service and therefore any info I say about it might be incorrect).
In addition, it drops a trojan horse in System directory named CMOS.COM which destroys CMOS information and information on hard disks. It might be possible that only boot information is deleted and all data should be fine. However, I havent tested that, but as far as I know, there should be no way to destroy hard drive data from Windows which could cause errors (FlashKiller is the only exception in this case, but it may cause BSODs). Therefore, I would consider that only boot information is gone, but everything else should be fine.
There are 2 more variants. Timofonica.B variant is just based on Apache, while Timofonica.C variant removed trojan horse part in code.
Aliases:
Email-Worm.VBS.Timofonica (Kaspersky Lab)
I-Worm.Timofonica (Kaspersky Lab)
Virus: VBS/Generic@MM (McAfee)
VBS/Timo-A (Sophos)
Worm.Timofonica (ClamAV)
VBS/Timofonica (Panda)
VBS/Timofon.B@m (FPROT)
Virus:VBS/Timofon.A (MS(OneCare))
VBS.Timofonica (DrWeb)
Generic.ScriptWorm.B15CB7EF (BitDef7)
VBS.Timofonica (VirusBuster)
VBS:MailWorm-gen [Wrm] (AVAST)
Email-Worm.VBS.Timofonica (Ikarus)
VBS/Timofon.A (AVG)
VBS/Timofonica (AVIRA)
VBS.Timofonica (NAV)
VBS/Timofon.A@mm (Norman)
VBS/Generic@MM (NAI)
VBS_TIMOFONICA (PCCIL)
VBS.Worm.Zokrim.z (Rising)
VBS/Timofon.B@mm [Libra] (FSecure)
VBS_TIMOFONICA (TrendMicro) E-mail Worm (Visual Basic Script): Timofonica.A](https://i.ytimg.com/vi/fMeeK2RA_As/mqdefault.jpg)