Threat Description

Yesmile

Details

Aliases:Yesmile, Smile
Category:Malware
Type:Virus
Platform:W32

Summary



This is a multipartite virus which infects MBRs on hard drives and COM and EXE files when they are executed. Occasionally the virus tries to play something (probably laughter) from the PC speaker. Yesmile is a stealth virus, so you can't see it in files or boot sectors when it is resident in memory.

There are several variants of this virus. The 5504 variant was distributed in a dropper called LAUGH.EXE in usenet newsgroups in January 1996. Do note that F-Secure anti-virus products do not specifically detect the LAUGH.EXE dropper: you will have to delete it manually.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.








Description Created: Mikko Hypponen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More