F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Yesmile





NAME:Yesmile
ALIAS:Smile
TYPE:Resident Stealth MBR COM/EXE-files

This is a multipartite virus which infects MBRs on hard drives and COM and EXE files when they are executed. Occasionally the virus tries to play something (probably laughter) from the PC speaker. Yesmile is a stealth virus, so you can't see it in files or boot sectors when it is resident in memory.

There are several variants of this virus. The 5504 variant was distributed in a dropper called LAUGH.EXE in usenet newsgroups in January 1996. Do note that F-Secure anti-virus products do not specifically detect the LAUGH.EXE dropper: you will have to delete it manually.

[Analysis: Mikko Hypponen, F-Secure]