Uploaded October 2018 | Updated September 2026, 2 weeks ago
Seizure & Loud Noise Warning! This footage may contain loud noise and content that may cause epilepsy! This isn't the typical software review where I try to explain every single part, so take note of that.
This program is extremely great for going crazy with drawing. No need to say more about this, it pretty much shows what it can do by itself.
Downloads:
archive.org/details/pixel-whimsy-1.3.0.1 (unfortunately broken for me on VM)
archive.org/details/pixelwhimsy_1.2.0 (works in VM with XP SP3)
Captions author: Tramplefoot (youtube.com/channel/UCiYoVO0WA0jznbldHCbEJng)
Seizure & Loud Noise Warning! This footage may contain loud noise and content that may cause epilepsy! This isn't the typical software review where I try to explain every single part, so take note of that.
This program is extremely great for going crazy with drawing. No need to say more about this, it pretty much shows what it can do by itself.
Downloads:
archive.org/details/pixel-whimsy-1.3.0.1 (unfortunately broken for me on VM)
archive.org/details/pixelwhimsy_1.2.0 (works in VM with XP SP3)
Captions author: Tramplefoot (youtube.com/channel/UCiYoVO0WA0jznbldHCbEJng)

![Virus (Windows): Heretic.1986
It will infect KERNEL32.DLL by copying it to Windows folder, infecting it and then it will register it as update to replace original kernel file.
After reboot, virus will run from actual kernel and it will infect every executed PE (Portable Executable) file by appending its own code to the end of the file.
Infected files will contain following text string:
[Heretic] by Memory Lapse
For my thug niggaz.. uptown baby, uptown.
Further description: http://about-threats.trendmicro.com/us//archive/malware/PE_HERETIC
Virus.Win32.Heretic.1986 (Kaspersky Lab)
Virus: W95/Heretic (McAfee)
W95/Heretic (Sophos)
W32.Heretic.1986 (ClamAV)
W95/Heretic (Panda)
W32/Heretic.1986 (FPROT)
Virus:Win32/Heretic.1986 (MS(OneCare))
Win32.Heretic.1986 (DrWeb)
Win32/Heretic.1986.Damaged virus (Nod32)
Win32.Heretic.1986 (BitDef7)
Win32.Heretic.1986 (VirusBuster)
Win95:Heretic (AVAST)
Win32.Keisan.1719 (Ikarus)
W32/Heretic.1986 (AVIRA)
W32.Heretic (NAV)
W32/Heretic.1986 (Norman)
Win32.Heretic.a (Rising)
Virus.Win32.Heretic.1986 [AVP] (FSecure)
PE_HERETIC (TrendMicro)
Win32.Heretic.1986 (VirusBusterBeta) Virus (Windows): Heretic.1986](https://i.ytimg.com/vi/Ziq0b_qP6u8/mqdefault.jpg)


![Trojan Horse (Windows): Macur
In general it drops itself to %windir% with filename pic.exe, edits a line in Win.ini to load that file at every boot (load=pic.exe), and then it creates about 1,410 folders named with zeros, ones, twos, threes, fours and fives, and it keeps stacking number by number using this pattern:
0
00
000
...
00000000000000000000000000000000... (Its pretty much difficult to count...)
After it came to maximum, it continues to next number (1):
1
11
111
...
Another interesting thing is that it checks the folder name of current folder with specific pattern. If the 1st letter is W or 5th letter is O and 6th letter is W, it will not show fake error message. Note that it does check even parent folders as far its noticed when trojan was launched on desktop.
Aliases:
Trojan.Win32.Macur (Kaspersky Lab)
Trojan: Macur (McAfee)
Troj/Macur (Sophos)
Trj/Macur (Panda)
W32/Trojan!028f (FPROT)
Trojan:Win32/Macur (MS(OneCare))
Trojan.Macur (DrWeb)
Win32/Macur trojan (Nod32)
Trojan.Win32.Macur (BitDef7)
Trojan.Macur.B (VirusBuster)
Win32:Trojan-gen (AVAST)
Trojan.Win32.Macur (Ikarus)
Generic.KSI (AVG)
TR/Macur.A (AVIRA)
Trojan.Macur (NAV)
W32/Macur.A (Norman)
Macur (NAI)
TROJ_MACUR.A (PCCIL)
Trojan.Macur (Rising)
Trojan.Win32.Macur [AVP] (FSecure)
TROJ_MACUR.A (TrendMicro)
Trojan.Macur.B (VirusBusterBeta) Trojan Horse (Windows): Macur](https://i.ytimg.com/vi/_apjJyW5TSc/mqdefault.jpg)





