Virus (Windows): Heretic.1986 @Tom.K
Virus (Windows): Heretic.1986  @Tom.K
Uploaded November 2014 | Updated September 2026, 2 weeks ago
It will infect KERNEL32.DLL by copying it to Windows folder, infecting it and then it will register it as update to replace original kernel file.

After reboot, virus will run from actual kernel and it will infect every executed PE (Portable Executable) file by appending its own code to the end of the file.

Infected files will contain following text string:
"[Heretic] by Memory Lapse
For my thug niggaz.. uptown baby, uptown. "

Further description: about-threats.trendmicro.com/us//archive/malware/PE_HERETIC

Virus.Win32.Heretic.1986 (Kaspersky Lab)
Virus: W95/Heretic (McAfee)
W95/Heretic (Sophos)
W32.Heretic.1986 (ClamAV)
W95/Heretic (Panda)
W32/Heretic.1986 (FPROT)
Virus:Win32/Heretic.1986 (MS(OneCare))
Win32.Heretic.1986 (DrWeb)
Win32/Heretic.1986.Damaged virus (Nod32)
Win32.Heretic.1986 (BitDef7)
Win32.Heretic.1986 (VirusBuster)
Win95:Heretic (AVAST)
Win32.Keisan.1719 (Ikarus)
W32/Heretic.1986 (AVIRA)
W32.Heretic (NAV)
W32/Heretic.1986 (Norman)
Win32.Heretic.a (Rising)
Virus.Win32.Heretic.1986 [AVP] (FSecure)
PE_HERETIC (TrendMicro)
Win32.Heretic.1986 (VirusBusterBeta)
Virus (Windows): Heretic.1986Trojan Horse (Windows): KingSolarisVirus (DOS): CroVir.556, 625; Croatia_II.560Trojan Horse (Windows): MacurOld Software Review: Twinkle Bulbs 5.5 (Windows)Macro Virus (Word/Excel 97): Jerk.a (plus other variants)Old Software Review: Emergency Operation! 1.6 by ANTi-Ware (Windows)Windows NT 4.0 HAL Clock - AclockOutlook 2000 Note BugProgram (DOS): CrashTrojan Horse (Windows): HackItOld Malware Experimental Stream
Tom.K |

Virus (Windows): Heretic.1986

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER