pmls64.dll

PremierOpinion

VoiceFive Networks, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The module pmls64.dll by VoiceFive Networks has been detected as adware by 30 anti-malware scanners. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
VoiceFive, Inc.  (signed by VoiceFive Networks, Inc.)

Product:
PremierOpinion

Version:
4.0.20.54 (Build 20.54)

MD5:
5e1adf18c67c719dee32145b980969e6

SHA-1:
31ce8ea3497f0538ee4c9d2a25e837db7512b09c

SHA-256:
bc029fdfbe78c6866c246d2e6ee28c47b6736f2cade6bed85ca486a4c9a65639

Scanner detections:
30 / 68

Status:
Adware

Analysis date:
4/20/2024 4:42:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.OFD
390

Agnitum Outpost
PUA.Agent
7.1.1

avast!
Win32:Relevant-W [PUP]
2014.9-160110

AVG
MalSign.Relevant Knowledge
2017.0.2868

Baidu Antivirus
Adware.Win32.RK
4.0.3.16110

Bitdefender
Adware.Generic.1296541
1.0.20.50

Bkav FE
W64.HfsAdware
1.3.0.7062

Clam AntiVirus
Win.Adware.1296193
0.98/21511

Comodo Security
ApplicUnwnt
21877

Dr.Web
Adware.Relevant.114
9.0.1.010

Emsisoft Anti-Malware
Adware.Agent.OFD
8.16.01.10.08

ESET NOD32
Win32/AdWare.RK.AR (variant)
10.12066

F-Secure
Adware.Agent.OFD
11.2016-10-01_1

G Data
Adware.Agent.OFD
16.1.24

IKARUS anti.virus
PUA.RK
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.207.16831

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.836

Malwarebytes
PUP.Optional.RelevantKnowledge
v2016.01.10.08

McAfee
Artemis!B1018629DE94
5600.6524

MicroWorld eScan
Adware.Generic.1296541
17.0.0.30

Norman
RelevantKnowledge.EAA
11.20160110

Panda Antivirus
PUP/RelevantKnowledge
16.01.10.08

Qihoo 360 Security
Win32/Trojan.Adware.d37
1.0.0.1015

Reason Heuristics
PUP.TMRG.VoiceFiveNetworks (M)
16.1.10.20

Rising Antivirus
PE:PUF.Injector!1.9F0F
23.00.65.16108

Sophos
RelevantKnowledge
4.96

SUPERAntiSpyware
PUP.RelevantKnowledge
9393

Trend Micro House Call
Suspicious_GEN.F47V0309
7.2.10

VIPRE Antivirus
Marketscore.RelevantKnowledge
39634

Zillya! Antivirus
Adware.Agent.Win32.68090
2.0.0.2341

File size:
1 MB (1,084,728 bytes)

Product version:
4.0.20.54 (Build 20.54)

Copyright:
Copyright © 2001-2004

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\premieropinion\pmls64.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/12/2012 2:00:00 AM

Valid to:
10/9/2015 1:59:59 AM

Subject:
CN="VoiceFive Networks, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="VoiceFive Networks, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7DF0080A576090E4868BAC6B0E459122

File PE Metadata
Compilation timestamp:
7/21/2015 6:16:02 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:eNUrY9EZ1AvfCOdGLD4vRHBQFyRxIa9Bqsy08GGE977b6//d2pjD2wGTsSXa6t6C:eNUQEXAiOoL8pmFyxsgP63d2BD2BTB3

Entry address:
0x906F4

Entry point:
23, A2, 3E, FE, EB, 24, F6, BF, BD, FE, 71, 4F, 6F, 6C, C7, DB, 3F, 2E, C7, 9C, 77, FC, 91, 40, 24, 67, 67, FE, 2E, E7, B4, FB, D8, 8B, 11, 4C, 39, DF, C4, 52, 45, 04, 50, 45, F9, 7F, 79, FE, 6E, F2, 23, D5, 23, 63, DE, F8, F3, 6F, CE, 31, 15, D0, 7C, 2F, FD, F7, CA, 77, DD, D3, 3E, DC, 8F, E7, F9, FD, ED, AF, 49, 57, 3F, 57, DB, 48, E3, 3D, 9C, 04, AF, C8, DC, 53, 8E, F1, 5B, CC, F4, 91, 5B, 79, DD, A5, B6, 79, BF, E3, 7F, EF, 86, D9, FF, FE, 0D, 9F, CF, 1F, E4, 57, DB, 3F, F1, 1B, 67, DF, 21, F6, 7F, BF...
 
[+]

Code size:
739.5 KB (757,248 bytes)

Remove pmls64.dll - Powered by Reason Core Security