How to remove tunmirror.exe

tunmirror.exe

The module tunmirror.exe has been detected as Hack.KMS

tunmirror.exe
Product Name:

TunMirror

MD5: fb5f055633e4f7890004972e108a07cd
Size: 14 KB
First Published: 2017-05-21 05:04:04 (8 years ago)
Latest Published: 2024-08-06 23:06:00 (a year ago)
Status: Hack.KMS (on last analysis)
Analysis Date: 2024-08-06 23:06:00 (a year ago)
Signed By: WZT
Status: Valid
%commonappdata%\kmsautos\bin
%commonappdata%\kmsauto\bin
%appdata%\zhp\quarantine\kmsautos\bin
%sysdrive%\windows.old\programdata\kmsauto\bin
%appdata%\zhp\quarantine\kmsautos\kmsautos\bin
%sysdrive%\$recycle.bin\s-1-5-21-257334955-1849367147-1897638829-1000
%sysdrive%\windows.old\programdata\kmsautos\bin
%sysdrive%\$recycle.bin\s-1-5-21-2275429643-1357250638-3055656149-1001\$rjaj0uu\bin
%commonappdata%\kmsautos
%commonappdata%\kmsauto
TunMirror.exe
tunmirror.exe
$R5721CQ.exe
Ukraine 16.2%
Russia 12.0%
Indonesia 7.5%
Iran 7.3%
South Korea 7.0%
Vietnam 5.0%
Turkey 2.8%
Egypt 2.6%
Mexico 2.3%
Taiwan 2.1%
France 2.0%
United States 2.0%
Spain 1.9%
Italy 1.8%
Belarus 1.7%
Poland 1.5%
Israel 1.4%
Saudi Arabia 1.4%
Germany 1.4%
Bulgaria 1.3%
Algeria 1.2%
Thailand 1.1%
Ecuador 1.0%
Romania 0.9%
Brazil 0.9%
Colombia 0.9%
Tunisia 0.9%
Sweden 0.7%
Iraq 0.6%
Venezuela 0.6%
Philippines 0.6%
Czech Republic 0.6%
United Kingdom 0.5%
Chile 0.5%
Kyrgyzstan 0.5%
Moldova 0.4%
Morocco 0.4%
Kazakhstan 0.4%
Canada 0.4%
Estonia 0.3%
Netherlands 0.3%
Croatia 0.3%
Argentina 0.3%
Portugal 0.3%
Pakistan 0.3%
China 0.3%
India 0.3%
Georgia 0.2%
Yemen 0.2%
Hong Kong 0.2%
Palestine 0.2%
Dominican Republic 0.2%
Azerbaijan 0.2%
Jordan 0.2%
Panama 0.2%
Bolivia 0.1%
United Arab Emirates 0.1%
Guatemala 0.1%
Lithuania 0.1%
Tajikistan 0.1%
Former Yugoslav Republic of Macedonia 0.1%
Serbia 0.1%
Greece 0.1%
Ghana 0.1%
Belgium 0.1%
New Zealand 0.1%
Latvia 0.1%
Bosnia and Herzegovina 0.1%
Sudan 0.1%
Slovenia 0.1%
Madagascar 0.1%
Paraguay 0.1%
Afghanistan 0.1%
Bahrain 0.1%
Nicaragua 0.1%
Sri Lanka 0.1%
Windows 10 77.0%
Windows 7 13.3%
Windows 8.1 8.4%
Windows 8 1.1%
Windows Vista 0.2%
Windows Server 2012 R2 0.1%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00003e6e

.NET Info:

MVID: d18b1277-6c9f-4c98-9f00-7b3c5edb3ecd
Typelib ID: 6a1f4016-f16e-41bc-80fb-0642c8a34893

PE Sections:

Name Size of data MD5
.text 8192 70f97254cab34ebef5f38c294e796e47
.rsrc 1536 5dfa487d9ed8f03e2f14811a0d0f9429
.reloc 512 e9fa315a001f5a9c37d66a41fde0fed5

More information:

Download GridinSoft Anti-Malware - Removal tool for tunmirror.exe
­