Uploaded April 2023 | Updated September 2026, 3 weeks ago
Crypto graphs are running. Explosion is a substance of jumping force. Get coin for return prediction.
Crypto graphs are running. Explosion is a substance of jumping force. Get coin for return prediction.


![Virus (DOS): Sidewinder.2048
Aliases:
Virus.DOS.Sidewinder.2048.b (Kaspersky Lab)
Kyokushi.mp.2048.c (McAfee)
Sidewinder-b (Sophos)
Sidewinder.2048.B (ClamAV)
Kyokushinkai.C (Panda)
Kyokushinkai.2048 (FPROT)
Virus:DOS/Kyokushinkai_2048.D (MS(OneCare))
Kyokushi.2048 (DrWeb)
Kysia.2048.C virus (Nod32)
Kyokushinkai.2048.D (BitDef7)
Kyokushinkai.2048.D (VirusBuster)
SideWinder-1819 (AVAST)
Virus.DOS.Kyokushinkai_2048.D (Ikarus)
VGEN/2694.512 (AVIRA)
Kyokushinkai.2048.C (NAV)
Kyokushinkai.2048.C (Norman)
DosExe.Virus.Sidewinder.2048.b (Rising)
Virus.DOS.Sidewinder.2048.b [AVP] (FSecure)
SIDEWINB (TrendMicro)
Kyokushinkai.2048.D (VirusBusterBeta)
Its supposed to infect EXE files in background, but it seems to fail at that. Therefore, only payload is shown.
On 21st of April, it will show a Pac-Man eating your screen.
Dan did record this virus, but Ive managed to slow it down for better quality.
Dans footage: https://www.youtube.com/watch?v=n3veMP8k-I0 Virus (DOS): Sidewinder.2048](https://i.ytimg.com/vi/ZB23Y1QXCBs/mqdefault.jpg)




![Virus (Windows): Heretic.1986
It will infect KERNEL32.DLL by copying it to Windows folder, infecting it and then it will register it as update to replace original kernel file.
After reboot, virus will run from actual kernel and it will infect every executed PE (Portable Executable) file by appending its own code to the end of the file.
Infected files will contain following text string:
[Heretic] by Memory Lapse
For my thug niggaz.. uptown baby, uptown.
Further description: http://about-threats.trendmicro.com/us//archive/malware/PE_HERETIC
Virus.Win32.Heretic.1986 (Kaspersky Lab)
Virus: W95/Heretic (McAfee)
W95/Heretic (Sophos)
W32.Heretic.1986 (ClamAV)
W95/Heretic (Panda)
W32/Heretic.1986 (FPROT)
Virus:Win32/Heretic.1986 (MS(OneCare))
Win32.Heretic.1986 (DrWeb)
Win32/Heretic.1986.Damaged virus (Nod32)
Win32.Heretic.1986 (BitDef7)
Win32.Heretic.1986 (VirusBuster)
Win95:Heretic (AVAST)
Win32.Keisan.1719 (Ikarus)
W32/Heretic.1986 (AVIRA)
W32.Heretic (NAV)
W32/Heretic.1986 (Norman)
Win32.Heretic.a (Rising)
Virus.Win32.Heretic.1986 [AVP] (FSecure)
PE_HERETIC (TrendMicro)
Win32.Heretic.1986 (VirusBusterBeta) Virus (Windows): Heretic.1986](https://i.ytimg.com/vi/Ziq0b_qP6u8/mqdefault.jpg)


![Trojan Horse (Windows): Macur
In general it drops itself to %windir% with filename pic.exe, edits a line in Win.ini to load that file at every boot (load=pic.exe), and then it creates about 1,410 folders named with zeros, ones, twos, threes, fours and fives, and it keeps stacking number by number using this pattern:
0
00
000
...
00000000000000000000000000000000... (Its pretty much difficult to count...)
After it came to maximum, it continues to next number (1):
1
11
111
...
Another interesting thing is that it checks the folder name of current folder with specific pattern. If the 1st letter is W or 5th letter is O and 6th letter is W, it will not show fake error message. Note that it does check even parent folders as far its noticed when trojan was launched on desktop.
Aliases:
Trojan.Win32.Macur (Kaspersky Lab)
Trojan: Macur (McAfee)
Troj/Macur (Sophos)
Trj/Macur (Panda)
W32/Trojan!028f (FPROT)
Trojan:Win32/Macur (MS(OneCare))
Trojan.Macur (DrWeb)
Win32/Macur trojan (Nod32)
Trojan.Win32.Macur (BitDef7)
Trojan.Macur.B (VirusBuster)
Win32:Trojan-gen (AVAST)
Trojan.Win32.Macur (Ikarus)
Generic.KSI (AVG)
TR/Macur.A (AVIRA)
Trojan.Macur (NAV)
W32/Macur.A (Norman)
Macur (NAI)
TROJ_MACUR.A (PCCIL)
Trojan.Macur (Rising)
Trojan.Win32.Macur [AVP] (FSecure)
TROJ_MACUR.A (TrendMicro)
Trojan.Macur.B (VirusBusterBeta) Trojan Horse (Windows): Macur](https://i.ytimg.com/vi/_apjJyW5TSc/mqdefault.jpg)