Risk

About “RiskTool.Win32.KuaiZip” infection

Malware Removal

The RiskTool.Win32.KuaiZip is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.KuaiZip virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify browser security settings

Related domains:

tj.kpzip.com
news.7654.com

How to determine RiskTool.Win32.KuaiZip?


File Info:

crc32: 88CE4183
md5: aefbc1200245f2893a3b0eb280fc056e
name: mininewsplus-1.exe
sha1: a0d2c4fbd0a1b41e022019a953d30b526fce8b92
sha256: 196aed2ac72c2bfd38bfc8af75957be389e3bc38d2b4a7986e92e0a44079cf34
sha512: 7701d2d80fb1b6ce7854eb1e85fafa2211af49d6d62bb3592e74f3a69ceccc5e965bf6c243e6789d62ad0e572420042050759591fc2d66c86731d61fc9f093ee
ssdeep: 6144:UePIjw/BNu3NaZlT38l+ozFezIcmbMdxz8TKVj5QiNH8lnn3coS4b2coskF:RQyBNFlTe+rccmYry3iN8n3coS41op
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: MiniNewsPlus
FileVersion: 3.0.261.79
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 3.0.261.79
FileDescription: MiniNewsPlus
Translation: 0x0804 0x04e4

RiskTool.Win32.KuaiZip also known as:

BkavW32.HfsAdware.C51A
DrWebProgram.Kuaizip.1
MicroWorld-eScanGen:Variant.Strictor.202171
FireEyeGeneric.mg.aefbc1200245f289
CAT-QuickHealTrojan.Kuaizip
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Strictor.202171
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
CyrenW32/Adware.TMNG-5348
APEXMalicious
AvastWin32:PUP-gen [PUP]
GDataGen:Variant.Strictor.202171
Kasperskynot-a-virus:HEUR:RiskTool.Win32.KuaiZip.gen
AlibabaBackdoor:Win32/KZip.9c4939bb
NANO-AntivirusRiskware.Win32.KuaiZip.gjrdhv
TencentMalware.Win32.Gencirc.10b888f6
SophosKuaiZip (PUA)
F-SecureAdware.ADWARE/Kuaizip.hwuxh
ZillyaAdware.KuaiZip.Win32.434
TrendMicroTROJ_GEN.R015C0PIH19
McAfee-GW-EditionPUP-XHW-XZ
EmsisoftGen:Variant.Strictor.202171 (B)
IkarusTrojan-Dropper.Delf
JiangminRiskTool.KuaiZip.gj
MaxSecureTrojan.Malware.74069765.susgen
AviraADWARE/Kuaizip.hwuxh
Antiy-AVLRiskWare[RiskTool]/Win32.KuaiZip
Endgamemalicious (moderate confidence)
SUPERAntiSpywarePUP.KuaiZip/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.KuaiZip.gen
MicrosoftPUA:Win32/KuaiZip
AhnLab-V3PUP/Win32.RL_Generic.R292163
McAfeeGenericRXAA-AA!AEFBC1200245
MAXmalware (ai score=99)
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesAdware.Kuaiba
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/KuaiZip.W potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R015C0PIH19
RisingPUA.KuaiZip!8.2F40 (RDMK:cmRtazolptwBSlbTowym4fc3pDnM)
YandexPUA.KuaiZip!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/KuaiZip
WebrootW32.Adware.Gen
AVGFileRepMalware [PUP]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove RiskTool.Win32.KuaiZip?

RiskTool.Win32.KuaiZip removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment