Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Russian_Flag


Aliases:


Russian_Flag
Ekaterinburg, Slydell

Malware
Virus
W32

Summary

This is a typical boot sector virus. It activates when a machine is booted on the 19th of August, displaying a Russian flag on the screen. In 1991, this was the date of the communist military coup attempt in Russia.

The virus also contains the string "Ekaterinburg" at offset 17Ah in an infected boot sector. The text is encrypted.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.









Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.