Threat Description

Avalanche

Details

Aliases: Avalanche
Category: Malware
Type: Virus
Platform: W32

Summary



This virus stays resident in memory and infects all executed COM and EXE files. Virus is encrypted with a simple 8-bit key. Avalanche uses 386-specific instructions and will crash on a 286 or lower.

Avalanche is a stealth virus, hiding itself from infected files if it is resident in memory. Boot clean before disinfecting.

Avalanche contains the following text:

AVALANCHE/Germany '94...Metal Junkie greets Neurobasher

It will delete the following antivirus programs when they are executed: F-PROT, TBAV, SCAN, MSAV, CPAV, TBMEM, TBFILE, TBSCAN and TBDRIVER.

This virus was reported to be in the wild in USA in March 1996.

There is another 2818 byte variant.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.








Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More