Trojan

How to remove “VHO:Trojan.Win64.CallMeRoot”?

Malware Removal

The VHO:Trojan.Win64.CallMeRoot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan.Win64.CallMeRoot virus can do?

  • Authenticode signature is invalid

How to determine VHO:Trojan.Win64.CallMeRoot?


File Info:

name: 62296765A5DBEF178E28.mlw
path: /opt/CAPEv2/storage/binaries/ba8928404130ec6c3d5c857eb987aa9ec695d3f85e629b07b9c426e23f792667
crc32: 09052C9C
md5: 62296765a5dbef178e28efdec9ba9a5e
sha1: a494fdef344f3167278cf2469e58cd4da2d71ae2
sha256: ba8928404130ec6c3d5c857eb987aa9ec695d3f85e629b07b9c426e23f792667
sha512: 6e62492222700af58bd154aea0ffc9e25fd08a520e43ddfb5db762c79432f06157ac3d3d0fff07f53da7d8c306ff4a9961c76ddeda5903a2704175038b2c83dc
ssdeep: 768:1kcfYSXP82SwaSj/G2lpA7pFBNKKcA3c0vsFb:6IVpa0G2lpIFlc2E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180F34B01B9A5CC36E89102311CB497619B7DBC135AB4E7977BD8238E5EF30E07A14B9B
sha3_384: 5ffee91b7ca80e3e04c0a68474d6dfbe8f205a8f8eef7563c00a642b1fe35487e96c3cff883e12600abe867c9bbb3f14
ep_bytes: e86a120000e97bfeffff3b0d50300400
timestamp: 2018-05-07 21:38:10

Version Info:

0: [No Data]

VHO:Trojan.Win64.CallMeRoot also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.913
FireEyeGeneric.mg.62296765a5dbef17
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Ransom.GandCrab.913
CylanceUnsafe
VIPREGen:Variant.Ransom.GandCrab.913
SangforTrojan.Win32.Save.a
Cybereasonmalicious.5a5dbe
CyrenW32/Kryptik.HKH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GXKS
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win64.CallMeRoot.gen
BitDefenderGen:Variant.Ransom.GandCrab.913
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Ransom.GandCrab.913
EmsisoftGen:Variant.Ransom.GandCrab.913 (B)
ComodoTrojWare.Win32.Chapak.GO@7o85ni
McAfee-GW-EditionGenericRXGI-RO!62296765A5DB
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.515D
MicrosoftTrojan:Win32/Meterpreter!ml
GDataGen:Variant.Ransom.GandCrab.913
GoogleDetected
AhnLab-V3Trojan/Win32.Gandcrab.C2499364
McAfeeGenericRXGI-RO!62296765A5DB
MalwarebytesMalware.AI.1878503659
RisingRansom.GandCrab!8.F355 (TFE:5:uaUAWKpdsLC)
YandexTrojan.GenAsa!sEQ6NA0nfs4
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GXKS!tr
BitDefenderThetaAI:Packer.4CF2BA0D1E
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove VHO:Trojan.Win64.CallMeRoot?

VHO:Trojan.Win64.CallMeRoot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment