Should I block it?

90%
90% of PCs block this file from running.
Possible reason:
Multiple malware detections

VersionsAdditional versions

569d3 15.38%
61d3b 7.69%
9469c 7.69%
48131 7.69%
97b52 46.15%
80164 7.69%
a5f8c 7.69%
(Note, IObit Information Technology publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptAcquireContextA, CryptCreateHash, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptReleaseContext
kernel32.dll
DeleteCriticalSection, EnterCriticalSection, ExpandEnvironmentStringsA, FormatMessageA, FreeLibrary, GetACP, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetFileType, GetLastError, GetModuleHandleA, GetProcAddress, GetStdHandle, GetSystemTimeAsFileTime, GetTickCount, InitializeCriticalSection, LeaveCriticalSection, LoadLibraryA, PeekNamedPipe, QueryPerformanceCounter, ReadFile, SetFilePointer, SetLastError, SetUnhandledExceptionFilter, Sleep, SleepEx, TerminateProcess, TlsGetValue, UnhandledExceptionFilter, VirtualProtect, VirtualQuery, WaitForMultipleObjects, CloseHandle, CreateEventA, CreateMutexA, DuplicateHandle, GetExitCodeThread, ReleaseMutex, SetEvent, TerminateThread, WaitForSingleObject, GetVersionExA
libidn-11.dll
idn_free, idna_strerror, idna_to_ascii_lz, idna_to_unicode_lzlz, stringprep_check_version, stringprep_locale_charset, tld_check_lz, tld_strerror
libnspr4.dll
PR_Close, PR_CloseDir, PR_DestroyLock, PR_ExplodeTime, PR_FormatTime, PR_Free, PR_GMTParameters, PR_GetError, PR_GetOpenFileInfo, PR_ImportTCPSocket, PR_Init, PR_Lock, PR_MillisecondsToInterval, PR_NewLock, PR_NewTCPSocket, PR_Now, PR_Open, PR_OpenDir, PR_Read, PR_ReadDir, PR_Recv, PR_SecondsToInterval, PR_Send, PR_SetError, PR_SetSocketOption, PR_Unlock, PR_smprintf, PR_smprintf_free
libssh2-1.dll
libssh2_channel_free, libssh2_channel_read_ex, libssh2_channel_send_eof, libssh2_channel_wait_closed, libssh2_channel_wait_eof, libssh2_channel_write_ex, libssh2_hostkey_hash, libssh2_knownhost_add, libssh2_knownhost_check, libssh2_knownhost_free, libssh2_knownhost_init, libssh2_knownhost_readfile, libssh2_knownhost_writefile, libssh2_scp_recv, libssh2_scp_send_ex, libssh2_session_block_directions, libssh2_session_disconnect_ex, libssh2_session_free, libssh2_session_hostkey, libssh2_session_init_ex, libssh2_session_last_errno, libssh2_session_last_error, libssh2_session_set_blocking, libssh2_session_startup, libssh2_sftp_close_handle, libssh2_sftp_init, libssh2_sftp_last_error, libssh2_sftp_mkdir_ex, libssh2_sftp_open_ex, libssh2_sftp_read, libssh2_sftp_readdir_ex, libssh2_sftp_rename_ex, libssh2_sftp_rmdir_ex, libssh2_sftp_seek64, libssh2_sftp_shutdown, libssh2_sftp_stat_ex, libssh2_sftp_symlink_ex, libssh2_sftp_unlink_ex, libssh2_sftp_write, libssh2_userauth_keyboard_interactive_ex, libssh2_userauth_list, libssh2_userauth_password_ex, libssh2_userauth_publickey_fromfile_ex
mgwz.dll
inflate, inflateEnd, inflateInit2_, inflateInit_, zlibVersion
msvcr71.dll
DllMain
msvcrt.dll
DllMain
nss3.dll
ATOB_ConvertAsciiToItem, CERT_CacheCRL, CERT_DestroyCertificate, CERT_FindCertIssuer, CERT_GetCertTimes, CERT_GetCommonName, CERT_GetDefaultCertDB, CERT_NameToAscii, NSS_Initialize, NSS_IsInitialized, NSS_NoDB_Init, NSS_Shutdown, NSS_VersionCheck, PK11_Authenticate, PK11_CreateGenericObject, PK11_DestroyGenericObject, PK11_FindCertFromNickname, PK11_FindPrivateKeyFromCert, PK11_FindSlotByName, PK11_FreeSlot, PK11_IsPresent, PK11_SetPasswordFunc, PORT_Strdup, SECITEM_AllocItem, SECITEM_CompareItem, SECITEM_FreeItem, SECMOD_DestroyModule, SECMOD_LoadUserModule, SECMOD_UnloadUserModule, SECMOD_WaitForAnyTokenEvent, SEC_DestroyCrl, SEC_FindCrlByDERCert
ssl3.dll
NSS_GetClientAuthData, NSS_SetDomesticPolicy, SSL_BadCertHook, SSL_CipherPolicyGet, SSL_CipherPrefSet, SSL_ClearSessionCache, SSL_ForceHandshakeWithTimeout, SSL_GetChannelInfo, SSL_GetCipherSuiteInfo, SSL_GetClientAuthDataHook, SSL_HandshakeCallback, SSL_ImplementedCiphers, SSL_ImportFD, SSL_NumImplementedCiphers, SSL_OptionSet, SSL_PeerCertificate, SSL_ResetHandshake, SSL_RevealPinArg, SSL_SetPKCS11PinArg, SSL_SetURL
wldap32.dll
ber_free, ldap_err2string, ldap_first_attribute, ldap_first_entry, ldap_get_dn, ldap_get_values_len, ldap_init, ldap_memfree, ldap_msgfree, ldap_next_attribute, ldap_next_entry, ldap_search_s, ldap_set_option, ldap_simple_bind_s, ldap_sslinit, ldap_unbind_s, ldap_value_free_len, ldap_err2stringA, ldap_first_attributeA, ldap_get_dnA, ldap_get_values_lenA, ldap_initA, ldap_memfreeA, ldap_next_attributeA, ldap_search_sA, ldap_set_optionA, ldap_simple_bind_sA
ws2_32.dll
WSACleanup, WSAGetLastError, WSASetLastError, WSAStartup, __WSAFDIsSet, accept, bind, closesocket, connect, freeaddrinfo, getaddrinfo, gethostname, getpeername, getsockname, getsockopt, htons, ioctlsocket, listen, ntohs, recv, recvfrom, select, send, sendto, setsockopt, socket, gethostbyname, WSAIoctl
zlib1.dll
inflate, inflateEnd, inflateInit2_, inflateInit_, zlibVersion
Export table
curl_easy_cleanup
curl_easy_duphandle
curl_easy_escape
curl_easy_getinfo
curl_easy_init
curl_easy_pause
curl_easy_perform
curl_easy_recv
curl_easy_reset
curl_easy_send
curl_easy_setopt
curl_easy_strerror
curl_easy_unescape
curl_escape
curl_formadd
curl_formfree
curl_formget
curl_free
curl_getdate
curl_getenv
curl_global_cleanup
curl_global_init
curl_global_init_mem
curl_maprintf
curl_mfprintf
curl_mprintf
curl_msnprintf
curl_msprintf
curl_multi_add_handle
curl_multi_assign
curl_multi_cleanup
curl_multi_fdset
curl_multi_info_read
curl_multi_init
curl_multi_perform
curl_multi_remove_handle
curl_multi_setopt
curl_multi_socket
curl_multi_socket_action
curl_multi_socket_all
curl_multi_strerror
curl_multi_timeout
curl_multi_wait
curl_mvaprintf
curl_mvfprintf
curl_mvprintf
curl_mvsnprintf
curl_mvsprintf
curl_share_cleanup
curl_share_init
curl_share_setopt
curl_share_strerror
curl_slist_append
curl_slist_free_all
curl_strequal
curl_strnequal
curl_unescape
curl_version
curl_version_info

libcurl-4.dll

By IObit Information Technology (Signed)

Remove libcurl-4.dll
MD5:   61d3bf18b15ea237b98f2de0f9590384
SHA1:   d3d303bd78297b95b765b038e46c8cd8fccaf90f
SHA256:   38b07edc48ab6254e6eb611c02bd6c3a2c4dda2bb7e91b5f67c228a776e523ba
Warning 3 antivirus scanners has detected malware.

Overview

libcurl-4.dll is malware that is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by IObit Information Technology which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:libcurl-4.dll
Typical file path:C:\Program Files\intunemp3\runtime\win32\libcurl-4.dll
Size:222.5 KB (227,840 bytes)
Certificate
Issued to:IObit Information Technology
Authority (CA):VeriSign
Expiration date:Sunday, February 14, 2016
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

MalwareMalware detections

Based on 40+ industry antivirus scanners, 3 of them detected the following malware.
Antivirus engineEngine versionDetection
Emsisoft Anti-Malware None Trojan.Win32.Agent.AMN (A)
Kaspersky 9.0.0.837 UDS:DangerousObject.Multi.Generic
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V1231

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 30.77%
Windows 7 Ultimate 30.77%
Windows 8.1 Pro 7.69%
Windows 8 Enterprise N 7.69%
Windows 8.1 7.69%
Microsoft Windows XP 7.69%
Windows 7 Ultimate N 7.69%

Distribution by countryDistribution by country

United States installs about 30.77% of libcurl-4.dll.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 20.00%
Intel 20.00%
Sony 20.00%
Acer 20.00%
Alienware 10.00%
GIGABYTE 10.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE