Threat Description



Aliases: HLLP.4676, Hooters
Category: Malware
Type: Virus
Platform: W32


This virus adds itself to the end of infected files and encrypts the full file after that.


Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Technical Details

When run, the virus decrypts the original program and writes it to the file called HOOTERS.EXE. Then it executes this file and finally deletes it - sometimes leaving a zero byte HOOTERS.EXE behind.

A side-effect of this is that the memory map might list - for example - an infected mouse driver as HOOTERS.EXE instead of MOUSE.EXE.

Hooters was found in the wild in Australia in September 1996. It has been spread over the internet.

Description Created: Mikko Hypponen, F-Secure


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More