Avalanche

Threat description

Details

CATEGORYMalware
TYPEVirus
ORIGINGermany
OTHERResident, StealthCOM/EXE-files

Summary

This virus stays resident in memory and infects all executed COM and EXE files. Virus is encrypted with a simple 8-bit key. Avalanche uses 386-specific instructions and will crash on a 286 or lower.

Avalanche is a stealth virus, hiding itself from infected files if it is resident in memory. Boot clean before disinfecting.

Avalanche contains the following text:

AVALANCHE/Germany '94...Metal Junkie greets Neurobasher

It will delete the following antivirus programs when they are executed: F-PROT, TBAV, SCAN, MSAV, CPAV, TBMEM, TBFILE, TBSCAN and TBDRIVER.

This virus was reported to be in the wild in USA in March 1996.

There is another 2818 byte variant.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info