This is an encrypted resident infector of EXE files. It infects files when run and also stays resident and infects when other files are accessed. Amount of free memory is not decreased.
Virus contains this text:
CLAWS (C)1994-95 WereWolf
Virus is encrypted with a variable 32-bit key. It deletes checksum databases belonging to several different antivirus packages.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.
You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.
Description Details: Mikko Hypponen, F-Secure