This is an encrypted resident infector of EXE files. It infects files when run and also stays resident and infects when other files are accessed. Amount of free memory is not decreased.
Virus contains this text:
CLAWS (C)1994-95 WereWolf
Virus is encrypted with a variable 32-bit key. It deletes checksum databases belonging to several different antivirus packages.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
More information on scanning and removal options available in your F-Secure product can be found in the Help Center.
You may also refer to the Knowledge Base on the F-Secure Community site for more information.
Description Details: Mikko Hypponen, F-Secure