KuaiZip

Threat Scorecard

Popularity Rank: 3,003
Threat Level: 10 % (Normal)
Infected Computers: 103,689
First Seen: July 12, 2016
Last Seen: November 17, 2025
OS(es) Affected: Windows

The KuaiZip software comes from China and is offered as an archive utility for users that like the design of Windows 10 and would like to see it incorporated into their apps. The KuaiZip software is promoted at Kuaizip.com to uphold the design principles of Windows 10 and allow users to manage their archived data efficiently and beautifully. The KuaiZip program boasts of featuring high compression ratio, compatibility with a broad range of data containers, and low resource consumption. With a size of 7MB and a sleek interface, KuaiZip may attract many users to install it. You should know that KuaiZip is supported by a large pool of marketers and may show many advertisements on your screen. Additionally, Kuaizip.com is hosted on several IP addresses that are associated with cyber threats like Pinfi and Genome.

The KuaiZip application may enable users to make, edit, move and transform archives in formats like 7Z, ZIP, RAR, ARC, LBR, TAR, BZ2, IZO, GZ, and APK. However, most users may not welcome the KuaiZip app that comes from software developers that fail to protect their Web site. The KuaiZip tool is perceived as a Potentially Unwanted Program (PUP) that may expose users to cyber threats and load unprotected marketing content on their screen. The ads by KuaiZip may include links to blacklisted domains and invite users to install riskware such as GoFastPC and IB Updater Service. The KuaiZip program is similar to ZiperFly and may edit your Registry to become your default archive manager. You may experience difficulties in removing KuaiZip manually because it can run as a background service continuously. You can purge the KuaiZip software with the help of a reliable anti-malware utility easily.

SpyHunter Detects & Remove KuaiZip

File System Details

KuaiZip may create the following file(s):
# File Name MD5 Detections
1. Update.exe dea1ab165c6f0c197cd55b1d1b55d5db 2,331
2. ziptool_wc-9015_setup.exe fd853d06e1d74db68710435655d403ce 1,020
3. KuaiZip_Setup_129823379_zzlm_013.exe 9c72f085a7a0c39234e051f537edb5aa 641
4. kuaizipUpdateChecker.dll 935e39b35010b2aad1d24c284fa52512 24
5. kpzip.exe 791c381daee80035c8309b3c7c94d192 7
More files

Registry Details

KuaiZip may create the following registry entry or registry entries:
CLSID
{2DA6D0F1-13A1-4EC7-BD41-49A545AD326F}
{2FB831EA-DA68-4A66-8E31-A2D976A6296C}
{3DCCD550-7586-40D2-A51D-D2F98EC06B3C}
{3DCCD550-7586-40D2-A51D-D2F98EC06B3D}
{6ADF19E3-77A3-4395-ADB4-9FD7D351EB3E}
{6ADF19E3-77A3-4395-ADB4-9FD7D351EB3F}
{86C4C3BA-4EA4-4CF8-98B9-6B07B477B835}
{9CC34070-3A38-4C7A-89CB-EF8177EF07A1}
{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2}
{AAA0C5B8-933F-4200-93AD-B143D7FFF9F3}
{C9487131-EF4C-40D9-BA70-E85356CAF67E}
{C9487131-EF4C-40D9-BA70-E85356CAF67F}
File name without path
http_www.kuaizip.com_0.localstorage
i.kpzip[1].xml
kpzip[1].xml
KuaiZip.lnk
kuaizipdrive.sys
www.kuaizip[1].xml
Regexp file mask
%TEMP%\KZ7ZData.7z[RANDOM CHARACTERS]
%WINDIR%\System32\drivers\KuaiZipDrive.sys
%WINDIR%\system32\drivers\KuaiZipDrive2.sys
%WINDIR%\System32\Tasks\KuaiZip_Update
SOFTWARE\Classes\*\shellex\ContextMenuHandlers\KuaiZipShlExt
SOFTWARE\Classes\*\shellex\ContextMenuHandlers\KZipShell2Ext
SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{2FB831EA-DA68-4A66-8E31-A2D976A6296C}
SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\KuaiZipShlExt
SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\KuaiZipShlExt
SOFTWARE\Classes\KuaiZipMount_FileAsso.Origin
SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\KZipShell2Ext
SOFTWARE\Classes\ZipTool_FileAsso.Origin
Software\dlr\KuaizipDlr
SOFTWARE\KuaiZip
Software\KuaiZip2
SOFTWARE\KuaiZipSFX
Software\Microsoft\Internet Explorer\DOMStorage\i.kpzip.com
Software\Microsoft\Internet Explorer\DOMStorage\kpzip.com
Software\Microsoft\Internet Explorer\DOMStorage\kuaizip.com
Software\Microsoft\Internet Explorer\DOMStorage\www.kuaizip.com
SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\kuaizip.com
SOFTWARE\Microsoft\Tracing\kpzip_RASAPI32
SOFTWARE\Microsoft\Tracing\kpzip_RASMANCS
SOFTWARE\Microsoft\Tracing\ktpop3_RASAPI32
SOFTWARE\Microsoft\Tracing\ktpop3_RASMANCS
SOFTWARE\Microsoft\Tracing\KuaiZip_RASAPI32
SOFTWARE\Microsoft\Tracing\KuaiZip_RASMANCS
SOFTWARE\Microsoft\Tracing\mininewsxktt_RASAPI32
SOFTWARE\Microsoft\Tracing\mininewsxktt_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KuaiZip_Update
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\kuaizip2updatesvc
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\kuaizipupdatesvc
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\zipsvcs
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apk\OpenWithProgids\KuaiZip.apk
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab\OpenWithProgids\KuaiZip.cab
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithProgids\KuaiZipMount.flac
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids\KuaiZip.zip
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj2
SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\KuaiZip Shell Extension
SOFTWARE\MzipTool
SOFTWARE\Wow6432Node\KuaiZip2
SOFTWARE\Wow6432Node\Microsoft\Tracing\kpzip_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\kpzip_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\ktpop3_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\ktpop3_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\KuaiZip_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\KuaiZip_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\mininewsxktt_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\mininewsxktt_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\kuaizip2updatesvc
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\kuaizipupdatesvc
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\zipsvcs
SOFTWARE\Wow6432Node\ZipTool
Software\ZipTool
SYSTEM\ControlSet001\Enum\Root\LEGACY_KUAIZIPDRIVE
SYSTEM\ControlSet001\Enum\Root\LEGACY_KUAIZIPDRIVE2
SYSTEM\ControlSet001\services\Kuaizip Update Checker
SYSTEM\ControlSet001\Services\KuaiZipDrive
SYSTEM\ControlSet001\services\KuaiZipDrive2
SYSTEM\ControlSet001\Services\KuaizipUpdateChecker
SYSTEM\ControlSet001\services\TheMzipService
SYSTEM\ControlSet001\Services\ziphost
SYSTEM\ControlSet002\Enum\Root\LEGACY_KUAIZIPDRIVE
SYSTEM\ControlSet002\Enum\Root\LEGACY_KUAIZIPDRIVE2
SYSTEM\ControlSet002\services\Kuaizip Update Checker
SYSTEM\ControlSet002\Services\KuaiZipDrive
SYSTEM\ControlSet002\services\KuaiZipDrive2
SYSTEM\ControlSet002\Services\KuaizipUpdateChecker
SYSTEM\ControlSet002\services\TheMzipService
SYSTEM\ControlSet002\Services\ziphost
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_KUAIZIPDRIVE
SYSTEM\CurrentControlSet\Enum\Root\LEGACY_KUAIZIPDRIVE2
SYSTEM\CurrentControlSet\services\Kuaizip Update Checker
SYSTEM\CurrentControlSet\Services\KuaiZipDrive
SYSTEM\CurrentControlSet\services\KuaiZipDrive2
SYSTEM\CurrentControlSet\Services\KuaizipUpdateChecker
SYSTEM\CurrentControlSet\services\TheMzipService
SYSTEM\CurrentControlSet\Services\ziphost

Directories

KuaiZip may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Compress
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\KuaiZip
%APPDATA%\Heinote
%APPDATA%\Kuaizip
%APPDATA%\Microsoft\Windows\Start Menu\Programs\KuaiZip
%APPDATA%\abckantutips
%APPDATA%\klzip
%APPDATA%\ksrjzs
%APPDATA%\kuaiya
%APPDATA%\快压
%HOMEDRIVE%\tools\快压
%LOCALAPPDATA%\KuaiZip
%LOCALAPPDATA%\finder
%LOCALAPPDATA%\zm\finder
%PROGRAMFILES%\Heinote
%PROGRAMFILES%\KuaiZip
%PROGRAMFILES%\MzipTool
%PROGRAMFILES%\ZipTool
%PROGRAMFILES%\k52zip
%PROGRAMFILES%\kuai8
%PROGRAMFILES%\kuaiya
%PROGRAMFILES%\¿ìѹ
%PROGRAMFILES%\快压
%PROGRAMFILES%\快压x86
%PROGRAMFILES%\辦揤
%PROGRAMFILES(x86)%\Heinote
%PROGRAMFILES(x86)%\KuaiZip
%PROGRAMFILES(x86)%\MzipTool
%PROGRAMFILES(x86)%\kuai8
%PROGRAMFILES(x86)%\kuaiya
%PROGRAMFILES(x86)%\快压
%PROGRAMFILES(x86)%\快压x86
%TEMP%\KuaiZip
%USERPROFILE%\Local Settings\Application Data\KuaiZip
%WINDIR%\system32\config\systemprofile\appdata\roaming\快压
%WINDIR%\syswow64\config\systemprofile\appdata\roaming\快压
%appdata%\photoviewer
%appdata%\xiaoyu
%appdata%\雷神压缩
%localappdata%\快压
%programfiles%\QiaoZip
%windir%\SysWOW64\config\systemprofile\AppData\Roaming\ZipTool
%windir%\System32\config\systemprofile\AppData\Roaming\ZipTool

Analysis Report

General information

Family Name: PUP.Kuaizip
Signature status: Self Signed

Known Samples

MD5: 64d25c958f813a62f2c2833e3441143b
SHA1: 2d36c526a9deab397c3d0016fd9953924f4b1f69
SHA256: 59219D398861372C9B099173C2332D2C36A5DC79E5D99790DB45B23C4688E44B
File Size: 1.40 MB, 1400376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name 风尚云起文化传媒(北京)有限公司
File Description About.exe
File Version 1.0.3.230511
Internal Name About.exe
Legal Copyright Copyright(C)2023 风尚云起文化传媒(北京)有限公司
Original Filename About.exe
Product Name About.exe
Product Version 1.0.3.230511

Digital Signatures

Signer Root Status
Fashion Cloud Culture Media (Beijing) Co., Ltd. WoTrus Code Signing 2021 CA Self Signed
Fashion Cloud Culture Media (Beijing) Co., Ltd. WoTrus Code Signing 2021 CA Self Signed

Block Information

Total Blocks: 4,483
Potentially Malicious Blocks: 272
Whitelisted Blocks: 4,177
Unknown Blocks: 34

Visual Map

0 0 0 0 0 0 0 0 x x ? ? x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 x x x 0 x x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x 0 x 0 0 x 0 ? 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 x x 0 x 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 x 0 0 x 0 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x x x x x x x x x x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 x x 0 x ? 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 x 0 0 0 0 x 0 x 0 x 0 0 x x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x x x 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserName

Related Posts

Trending

Most Viewed

Loading...