How to remove $R9ICUGP.exe

$R9ICUGP.exe

The module $R9ICUGP.exe has been detected as PUP.Downloader

$R9ICUGP.exe
Product Name:

Zona installer

Company Name:

4th generation

MD5: b3137441005cb0baa84c938aff05062c
Size: 42 MB
First Published: 2017-11-25 11:06:39 (7 years ago)
Latest Published: 2023-05-16 23:28:10 (2 years ago)
Status: PUP.Downloader (on last analysis)
Analysis Date: 2023-05-16 23:28:10 (2 years ago)
Signed By: Chetvertoe pokolenie, OOO
Status: Valid
%sysdrive%\$recycle.bin\s-1-5-21-2239565601-3286185508-3447279859-1000
%profile%\downloads
%temp%\scoped_dir2240_22876
%profile%\documents
%localappdata%\packages\microsoft.microsoftedge_8wekyb3d8bbwe\tempstate\downloads
%temp%\scoped_dir6008_24883
%temp%\scoped_dir3980_16095
%profile%
%sysdrive%
%desktop%
$RQAQKCK.exe
$R9ICUGP.exe
$ROR12SW.exe
ZonaSetup[E8SN9].exe
ZonaSetup[E81QY].exe
ZonaSetup[EMNh_].exe
ZonaSetup[EMO2p].exe
ZonaSetup[EML84].exe
ZonaSetup[Egcbi].exe
ZonaSetup[EmMWc].exe
ZonaSetup[EmMh9].exe
ZonaSetup[EMpNQ].exe
ZonaSetup[EEPTG].exe
ZonaSetup[EMn3k].exe
ZonaSetup[E6yAy].exe
ZonaSetup[E6YIT].exe
ZonaSetup[Em_1N].exe
ZonaSetup[EmA7n].exe
ZonaSetup.exe
ZonaSetup[E62wH].exe
ZonaSetup[EmOA0].exe
ZonaSetup[EmGNt].exe
ZonaSetup[EM_Nn].exe
ZonaSetup[E66Xo].exe
ZonaSetup[EM5ZB].exe
ZonaSetup[EEb6r].exe
ZonaSetup[EE6EJ].exe
ZonaSetup[EmQEQ].exe
ZonaSetup[8l06a].exe
ZonaSetup[EEUcg].exe
ZonaSetup[E6EbI].exe
ZonaSetup[EED9_].exe
ZonaSetup[Em5Uc].exe
ZonaSetup[8hN8K].exe
ZonaSetup[EgDFF].exe
zona-windows-64-0-0-0-1.exe
ZonaSetup[Eg4LN].exe
ZonaSetup[EMtYM].exe
ZonaSetup[EM2xB].exe
ZonaSetup[EMG0g].exe
ZonaSetup[E2BKk].exe
ZonaSetup[EgD8w].exe
ZonaSetup[EMnBQ].exe
ZonaSetup[EmHBL].exe
ZonaSetup[EExlP].exe
zona-windows-64-0-0-0-1_ms.exe
ZonaSetup[EgPSY].exe
zona-windows-64-0-0-0-1_ss.exe
d5dc9b9bc6e9ee5a0fda.exe
ZonaSetup[E6AO_].exe
69.2%
15.4%
7.7%
2.9%
2.9%
1.0%
1.0%
Windows 10 47.1%
Windows 7 46.2%
Windows 8.1 6.7%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0005c0fa

PE Sections:

Name Size of data MD5
.text 516608 88a48b55780915b19bdd6667a22744ab
.rdata 120832 dff2e58dd3c59d5361c27a0edc936e6b
.data 20992 7d4a364aa1ed3ec80b4ea50ce482095c
.rsrc 44055040 665548841b846fd4ab117ce12e7cccd5
.reloc 141824 ed97b68e837ec876ec211775ee8e8c5c

More information:

Download GridinSoft Anti-Malware - Removal tool for $R9ICUGP.exe