Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RevertToSelf, RegEnumValueA, OpenProcessToken, GetTokenInformation, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, SetTokenInformation, LookupPrivilegeValueA, DuplicateTokenEx, ImpersonateLoggedOnUser, GetLengthSid, AdjustTokenPrivileges, RegOpenCurrentUser, RegOpenUserClassesRoot, RegCloseKey, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, RegDeleteValueA, RegQueryInfoKeyA, RegEnumKeyExA
comctl32.dll
InitCommonControlsEx
comdlg32.dll
GetOpenFileNameA
gdi32.dll
SetBkColor
kernel32.dll
DllMain
ole32.dll
OleUninitialize, CoInitializeSecurity, OleInitialize, CoCreateGuid, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CoInitialize, CoUninitialize, CoTaskMemAlloc, CoInitializeEx
psapi.dll
GetModuleFileNameExA, EnumProcesses
shell32.dll
Shell_NotifyIconA, ShellExecuteExA, SHGetSpecialFolderPathA
shlwapi.dll
UrlEscapeA, SHDeleteEmptyKeyA, PathRenameExtensionA, PathCombineA, PathStripPathA, PathRemoveFileSpecA, PathIsDirectoryEmptyA, PathFindExtensionA
urlmon.dll
IsValidURL
user32.dll
EnumWindows, IsWindowEnabled, GetWindowThreadProcessId, FindWindowExA, GetClassNameA, EnumChildWindows, GetSystemMetrics, SystemParametersInfoA, GetShellWindow, FindWindowA, GetDesktopWindow, LoadCursorA, CreateWindowExA, GetClassInfoExA, RegisterClassExA, GetMessageA, TranslateAcceleratorA, TranslateMessage, DispatchMessageA, CallWindowProcA, DefWindowProcA, SetCursor, LoadStringA, GetKeyboardState, CreatePopupMenu, DestroyMenu, AppendMenuA, TrackPopupMenu, SendMessageA, SetDlgItemTextA, AdjustWindowRectEx, OffsetRect, SetClassLongA, GetDC, DrawIcon, ReleaseDC, GetMessagePos, ScreenToClient, DialogBoxParamA, ClientToScreen, SetWindowPos, SetTimer, KillTimer, CreateDialogParamA, EndDialog, GetDlgItem, SendMessageW, GetDlgCtrlID, ShowWindow, EnableWindow, SetForegroundWindow, UpdateWindow, GetSysColor, GetSysColorBrush, GetCursorPos, PostQuitMessage, LoadIconA, IsIconic, GetFocus, SetFocus, IsWindowVisible, InvalidateRgn, InvalidateRect, MessageBoxExA, MessageBoxA, IsWindow, SetWindowTextA, GetWindowTextA, GetWindowTextLengthA, SetWindowLongA, GetWindowLongA, DestroyWindow, LoadAcceleratorsA, WaitForInputIdle, ReleaseCapture, MoveWindow, GetClientRect, GetWindowRect, PostMessageA
userenv.dll
ExpandEnvironmentStringsForUserA
version.dll
VerQueryValueA, GetFileVersionInfoA, GetFileVersionInfoSizeA
wininet.dll
InternetCloseHandle, InternetReadFileExA, InternetErrorDlg, HttpQueryInfoA, HttpSendRequestA, HttpAddRequestHeadersA, HttpOpenRequestA, InternetConnectA, InternetSetOptionA, InternetSetStatusCallback, InternetCrackUrlA, InternetCanonicalizeUrlA, InternetCombineUrlA, InternetGetCookieA, InternetSetCookieA, InternetOpenA

intunemp3.exe

InstallIQ Installation Utility by W3i (Signed)

Remove intunemp3.exe
Version:   2.117.0.0
MD5:   f3bc5ec5df3ffb67aeaa0db8d7073528
SHA1:   4566f5529d2f07026f0f50b49598feddd3885757
SHA256:   2a90a2a7203e82bc8c618e452e6dad2f0f87bea0df37a9fd0b47fe6d5c39fa7b
Warning 8 antivirus scanners has detected malware.

What is intunemp3.exe?

InstallIQ Installation Utility downloads and bundles additional software, typically adware or unwanted programs.

About intunemp3.exe (from W3i)

InstallIQ is an install manager that will manage the installation of your selected software. In addition to managing the installation of your selected software, InstallIQ™ will make recommendations

Overview

intunemp3.exe is malware that executes as a process with the local user's privileges typically within the context of its parent fdm.exe (Free Download Manager by FreeDownloadManager.ORG). The file is digitally signed by W3i. This particular version is usually found on Microsoft Windows XP (5.1.2600.131072).

DetailsDetails

File name:intunemp3.exe
Publisher:W3i, LLC
Product name:InstallIQ Installation Utility
Typical file path:C:\downloads\software\intunemp3.exe
Original name:InstallIQ.exe
File version:2.117.0.0
Size:1.58 MB (1,654,464 bytes)
Certificate
Issued to:W3i
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details
Network connections
  • [TCP] 66.77.96.107:80
  • [UDP] listens on port 2006

  • MalwareMalware detections

    Based on 40+ industry antivirus scanners, 8 of them detected the following malware.
    Antivirus engineEngine versionDetection
    Avira AntiVir 7.11.44.24 APPL/InstallIQ.Gen5
    AVG 2014.0.3629 AdInstaller.InstallQ
    Dr.Web 7.0.3.07130 Adware.W3i.9
    Emsisoft Anti-Malware 5.1.0.11 Win32.AdWare!IK
    ESET NOD32 7.7512 a variant of Win32/InstallIQ
    Fortinet 5.0.26.0 Riskware/InstallIQ
    Ikarus T3.1.1.122.0 Win32.AdWare
    Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.RCBH1HR

    ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00893688%
    0.028634%
    Kernel CPU:0.00035045%
    0.013761%
    User CPU:0.00858643%
    0.014873%
    Kernel CPU time:1,507 ms/min
    100,923,805ms/min
    Context switches:131/sec
    284/sec
    Memory
    Private memory:13.76 MB
    21.59 MB
    Private (maximum):288 KB
    Private (minimum):232 KB
    Non-paged memory:13.76 MB
    21.59 MB
    Virtual memory:83.06 MB
    140.96 MB
    Virtual memory (peak):95.54 MB
    169.69 MB
    Working set:278 KB
    18.61 MB
    Working set (peak):21.5 MB
    37.95 MB
    Resource allocations
    Threads:6
    12
    Handles:326
    600
    GUI GDI count:78
    103
    GUI USER count:19
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command lines:
    • "C:\downloads\software\intunemp3.exe"
    • "C:\downloads\software\intunemp3.exe" /wrapper /dir="C:\DOCUME~1\user\Locals~1\temp\pkg_12253012d0" /pproc="fdm.exe"
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    intunemp3.exe (main module)
    Total CPU:1.14962056%
    0.272967%
    Kernel CPU:0.06271071%
    0.107585%
    User CPU:1.08690984%
    0.165382%
    Context switches:33/sec
    79/sec
    Memory:1.68 MB
    1.16 MB
    mshtml.dll (Microsoft HTML Viewer by Microsoft)
    Total CPU:0.00298606%
    Kernel CPU:0.00199071%
    User CPU:0.00099535%
    Context switches:59/sec
    Memory:2.93 MB

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 100.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE