This is an encrypted resident infector of EXE files. It infects files when run and also stays resident and infects when other files are accessed. Amount of free memory is not decreased.
Virus contains this text:
CLAWS (C)1994-95 WereWolf
Virus is encrypted with a variable 32-bit key. It deletes checksum databases belonging to several different antivirus packages.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
More scanning & removal options
More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.
You may also refer to the Knowledge Base on the F-Secure Community site for more information.
Description Details: Mikko Hypponen, F-Secure