Threat Description

Satria

Details

Aliases:Satria, Ilove
Category:Malware
Type:Virus
Platform: W32

Summary



Satria is a typical boot sector virus, which only spreads from a machine to another via floppy disks and propogates when a machine is booted with an infected floppy in drive A:. After this all floppies get infected during access.

Satria activates on the fourth of July. When an infected machine is booted on this date, the virus displays a graphic which says 'I <heart> U'. Otherwise the virus just spreads.

Satria also contains two unencrypted texts which are never displayed: 'My Honey B'day' and 'SATRIA'.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details




Variant:Satria.B

This version displays a slightly different screen when activating. It also overwrites the original MBR without saving a copy of it.





Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More