pmropn64.exe

PremierOpinion

VoiceFive, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The application pmropn64.exe by VoiceFive has been detected as adware by 23 anti-malware scanners. This file is typically installed with the program PremierOpinion by VoiceFive, Inc. which is a potentially unwanted software program. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
VoiceFive, Inc.  (signed and verified)

Product:
PremierOpinion

Version:
1.0.9.4 (Build 9.4)

MD5:
e6f7d72cf43003eee70c390cfd659805

SHA-1:
dfe98ffcc44df4bdbcfefafeae674d8e9cc88ac3

SHA-256:
109590d4a0b45985f1c161f34930c79b59f041e00a787fd7169f9aa64651294e

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
4/26/2024 11:28:20 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Relevant.BS.1
7.11.64.16

avast!
Win32:Relevant-AB [PUP]
2014.9-151127

AVG
MalSign.Relevant Knowledge
2016.0.2913

Bitdefender
Adware.Relevant.BS
1.0.20.1655

Bkav FE
W32.Clodd64.Trojan
1.3.0.4959

Clam AntiVirus
Win.Adware.Relevant-5
0.98/18155

Comodo Security
UnclassifiedMalware
15495

Emsisoft Anti-Malware
Riskware.Win32.RelevantKnowledge.AMN
8.15.11.27.01

ESET NOD32
Win32/Adware.RK
9.8093

Fortinet FortiGate
Riskware/RK
11/27/2015

F-Prot
W64/Relevant.A2.gen
v6.4.7.1.166

F-Secure
Adware.Relevant.BS
11.2015-27-11_6

G Data
Adware.Relevant.BS
15.11.22

K7 AntiVirus
Riskware
13.174.10588

Malwarebytes
Adware.PremierOpinion
v2015.11.27.01

McAfee
Artemis!B6440AA25ED0
5600.6569

MicroWorld eScan
Adware.Relevant.BS
16.0.0.993

nProtect
Adware.Relevant.BS
13.03.08.01

Reason Heuristics
PUP.TMRG.VoiceFive (M)
15.11.27.1

Sophos
RelevantKnowledge
4.98

SUPERAntiSpyware
PUP.RelevantKnowledge
9483

Trend Micro House Call
TROJ_GEN.F47V0822
7.2.331

VIPRE Antivirus
Trojan.Win32.Generic
15918

File size:
200 KB (204,792 bytes)

Product version:
1.0.9.4 (Build 9.4)

Copyright:
Copyright © 2001-2004

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\premieropinion\pmropn64.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/27/2011 5:00:00 PM

Valid to:
9/27/2013 4:59:59 PM

Subject:
CN="VoiceFive, Inc.", O="VoiceFive, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3EDFC5EA7AAD2A20B9C31AE68DC1005C

File PE Metadata
Compilation timestamp:
3/26/2013 3:24:55 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
3072:i8Uq2LUqdKtkETTnK/LZHwZs8/EF+YQs8IbgKb+MEk5ok7F2:QqoQtksGFwZs8a+YQs585+52

Entry address:
0xCB7C

Entry point:
48, 83, EC, 28, E8, DF, 7B, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83, F8, 40, 72, 1E, 48, F7, D9, 83, E1, 07, 74, 06, 4C, 2B, C1, 48, 89, 10, 48, 03, C8, 4D, 8B, C8, 49, 83, E0, 3F, 49, C1, E9, 06, 75, 39, 4D, 8B, C8, 49, 83, E0, 07, 49, C1, E9, 03, 74, 11, 66, 66, 66, 90, 90, 48, 89, 11, 48, 83, C1, 08, 49, FF, C9, 75, F4...
 
[+]

Entropy:
6.1766

Code size:
129 KB (132,096 bytes)

The file pmropn64.exe has been discovered within the following program.

PremierOpinion  by VoiceFive, Inc.
Publisher's description - “VoiceFive, a comScore, Inc. company, is a leading global market research company that studies and reports on Internet trends and behavior.”
73% remove it
 
Powered by Should I Remove It?

Remove pmropn64.exe - Powered by Reason Core Security