1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Yesmile

ALIAS:Smile
TYPE:Resident Stealth MBR COM/EXE-files

Summary

This is a multipartite virus which infects MBRs on hard drives and COM and EXE files when they are executed. Occasionally the virus tries to play something (probably laughter) from the PC speaker. Yesmile is a stealth virus, so you can't see it in files or boot sectors when it is resident in memory.

There are several variants of this virus. The 5504 variant was distributed in a dropper called LAUGH.EXE in usenet newsgroups in January 1996. Do note that F-Secure anti-virus products do not specifically detect the LAUGH.EXE dropper: you will have to delete it manually.

[Analysis: Mikko Hypponen, F-Secure]