Threat Description

Avalanche

Details

Aliases:Avalanche
Category:Malware
Type:Virus
Platform: W32

Summary



This virus stays resident in memory and infects all executed COM and EXE files. Virus is encrypted with a simple 8-bit key. Avalanche uses 386-specific instructions and will crash on a 286 or lower.

Avalanche is a stealth virus, hiding itself from infected files if it is resident in memory. Boot clean before disinfecting.

Avalanche contains the following text:

AVALANCHE/Germany '94...Metal Junkie greets Neurobasher

It will delete the following antivirus programs when they are executed: F-PROT, TBAV, SCAN, MSAV, CPAV, TBMEM, TBFILE, TBSCAN and TBDRIVER.

This virus was reported to be in the wild in USA in March 1996.

There is another 2818 byte variant.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.








Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More