oohivfy.exe

The executable oohivfy.exe has been detected as malware by 7 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “Oohivfy”.
MD5:
e1e6929b004d0fb3b558df5130e7084b

SHA-1:
bed9b708fd5ee2ee46a0f9917e785abc1e0a4014

SHA-256:
140b4a1a6e86a34121925c669763439d39f664393723c3c59b2ea0b29f8e8332

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2026 10:12:25 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
150602-1

Dr.Web
BACKDOOR.Trojan
9.0.1.0183

Emsisoft Anti-Malware
Rootkit.74613
8.15.07.04.03

F-Secure
Rootkit.74613
11.2015-04-07_7

Norman
Rootkit.74613
11.20150704

Panda Antivirus
Trj/Genetic.gen
15.07.02.04

Reason Heuristics
Threat.Win.Reputation.IMP
15.7.3.23

File size:
2 MB (2,075,648 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\iwajulse\oohivfy.exe

File PE Metadata
Compilation timestamp:
6/21/2015 7:23:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:kYVmIGvP9vwHVJ7byEPCj+KpPayw/Ei5FM3x3tTUxIBz9Pn4VJtjB4zmikGHowdX:zme7bB6SPom3NkZd3cfJTt/p/tUn7

Entry address:
0x14F67C

Entry point:
E8, 8E, C3, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, E8, 0B, 5E, 00, E8, 7E, 1A, 00, 00, E8, 67, 70, 00, 00, 0F, B7, F0, 6A, 02, E8, C2, 63, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 53, 49, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
1.5 MB (1,547,776 bytes)

Service
Display name:
Oohivfy

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove oohivfy.exe - Powered by Reason Core Security