How to remove tunmirror.exe

tunmirror.exe

The module tunmirror.exe has been detected as Hack.KMS

tunmirror.exe
Product Name:

TunMirror

MD5: fb5f055633e4f7890004972e108a07cd
Size: 14 KB
First Published: 2017-05-21 05:04:04 (7 years ago)
Latest Published: 2024-08-06 23:06:00 (4 months ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2024-08-06 23:06:00 (4 months ago)
Signed By: WZT
Status: Valid
%commonappdata%\kmsautos\bin
%commonappdata%\kmsauto\bin
%appdata%\zhp\quarantine\kmsautos\bin
%sysdrive%\windows.old\programdata\kmsauto\bin
%appdata%\zhp\quarantine\kmsautos\kmsautos\bin
%sysdrive%\$recycle.bin\s-1-5-21-257334955-1849367147-1897638829-1000
%sysdrive%\windows.old\programdata\kmsautos\bin
%sysdrive%\$recycle.bin\s-1-5-21-2275429643-1357250638-3055656149-1001\$rjaj0uu\bin
%commonappdata%\kmsautos
%commonappdata%\kmsauto
TunMirror.exe
tunmirror.exe
$R5721CQ.exe
16.2%
12.0%
7.5%
7.3%
7.0%
5.0%
2.8%
2.6%
2.3%
2.1%
2.0%
2.0%
1.9%
1.8%
1.7%
1.5%
1.4%
1.4%
1.4%
1.3%
1.2%
1.1%
1.0%
0.9%
0.9%
0.9%
0.9%
0.7%
0.6%
0.6%
0.6%
0.6%
0.5%
0.5%
0.5%
0.4%
0.4%
0.4%
0.4%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
Windows 10 77.0%
Windows 7 13.3%
Windows 8.1 8.4%
Windows 8 1.1%
Windows Vista 0.2%
Windows Server 2012 R2 0.1%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00003e6e

.NET Info:

MVID: d18b1277-6c9f-4c98-9f00-7b3c5edb3ecd
Typelib ID: 6a1f4016-f16e-41bc-80fb-0642c8a34893

PE Sections:

Name Size of data MD5
.text 8192 70f97254cab34ebef5f38c294e796e47
.rsrc 1536 5dfa487d9ed8f03e2f14811a0d0f9429
.reloc 512 e9fa315a001f5a9c37d66a41fde0fed5

More information:

Download GridinSoft Anti-Malware - Removal tool for tunmirror.exe