Uploaded June 2024 | Updated September 2026, 2 weeks ago
Warning: Some sections contain suddenly loud noises and intensive video effects!
Some content is most likely going to be muted due to songs!
Trying to check out some old bootleg operating systems.
Warning: Some sections contain suddenly loud noises and intensive video effects!
Some content is most likely going to be muted due to songs!
Trying to check out some old bootleg operating systems.
![Virus (Windows): Heretic.1986
It will infect KERNEL32.DLL by copying it to Windows folder, infecting it and then it will register it as update to replace original kernel file.
After reboot, virus will run from actual kernel and it will infect every executed PE (Portable Executable) file by appending its own code to the end of the file.
Infected files will contain following text string:
[Heretic] by Memory Lapse
For my thug niggaz.. uptown baby, uptown.
Further description: http://about-threats.trendmicro.com/us//archive/malware/PE_HERETIC
Virus.Win32.Heretic.1986 (Kaspersky Lab)
Virus: W95/Heretic (McAfee)
W95/Heretic (Sophos)
W32.Heretic.1986 (ClamAV)
W95/Heretic (Panda)
W32/Heretic.1986 (FPROT)
Virus:Win32/Heretic.1986 (MS(OneCare))
Win32.Heretic.1986 (DrWeb)
Win32/Heretic.1986.Damaged virus (Nod32)
Win32.Heretic.1986 (BitDef7)
Win32.Heretic.1986 (VirusBuster)
Win95:Heretic (AVAST)
Win32.Keisan.1719 (Ikarus)
W32/Heretic.1986 (AVIRA)
W32.Heretic (NAV)
W32/Heretic.1986 (Norman)
Win32.Heretic.a (Rising)
Virus.Win32.Heretic.1986 [AVP] (FSecure)
PE_HERETIC (TrendMicro)
Win32.Heretic.1986 (VirusBusterBeta) Virus (Windows): Heretic.1986](https://i.ytimg.com/vi/Ziq0b_qP6u8/mqdefault.jpg)


![Trojan Horse (Windows): Macur
In general it drops itself to %windir% with filename pic.exe, edits a line in Win.ini to load that file at every boot (load=pic.exe), and then it creates about 1,410 folders named with zeros, ones, twos, threes, fours and fives, and it keeps stacking number by number using this pattern:
0
00
000
...
00000000000000000000000000000000... (Its pretty much difficult to count...)
After it came to maximum, it continues to next number (1):
1
11
111
...
Another interesting thing is that it checks the folder name of current folder with specific pattern. If the 1st letter is W or 5th letter is O and 6th letter is W, it will not show fake error message. Note that it does check even parent folders as far its noticed when trojan was launched on desktop.
Aliases:
Trojan.Win32.Macur (Kaspersky Lab)
Trojan: Macur (McAfee)
Troj/Macur (Sophos)
Trj/Macur (Panda)
W32/Trojan!028f (FPROT)
Trojan:Win32/Macur (MS(OneCare))
Trojan.Macur (DrWeb)
Win32/Macur trojan (Nod32)
Trojan.Win32.Macur (BitDef7)
Trojan.Macur.B (VirusBuster)
Win32:Trojan-gen (AVAST)
Trojan.Win32.Macur (Ikarus)
Generic.KSI (AVG)
TR/Macur.A (AVIRA)
Trojan.Macur (NAV)
W32/Macur.A (Norman)
Macur (NAI)
TROJ_MACUR.A (PCCIL)
Trojan.Macur (Rising)
Trojan.Win32.Macur [AVP] (FSecure)
TROJ_MACUR.A (TrendMicro)
Trojan.Macur.B (VirusBusterBeta) Trojan Horse (Windows): Macur](https://i.ytimg.com/vi/_apjJyW5TSc/mqdefault.jpg)






