rlls.dll

Relevant-Knowledge

TMRG, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The module rlls.dll by TMRG has been detected as adware by 23 anti-malware scanners. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
TMRG, Inc.  (signed by TMRG, Inc.)

Product:
Relevant-Knowledge

Version:
4.0.14.22 (Build 14.22)

MD5:
ee0ee47ac70c20529ee8d908a6b4b580

SHA-1:
fe9924793cc76f207e5bc38a3fd3f3ad94329bb1

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
4/20/2024 12:51:04 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Adware
7.1.1

Avira AntiVirus
Adware/RK.T
7.11.152.214

avast!
Win32:PUP-gen [PUP]
2014.9-160215

AVG
RelevantKnowledge
2017.0.2833

Baidu Antivirus
Adware.Win32.RK
4.0.3.16215

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
UnclassifiedMalware
15235

Dr.Web
Adware.Relevant.84
9.0.1.046

Emsisoft Anti-Malware
Riskware.Win32.RelevantKnowledge.AMN
8.16.02.15.08

ESET NOD32
Win32/Adware.RK.AM (variant)
10.7999

Fortinet FortiGate
Riskware/RK
2/15/2016

F-Prot
W32/Relevant.B.gen
v6.4.6.5.141

K7 AntiVirus
Adware
13.160.8207

Malwarebytes
PUP.Adware.RelevantKnowledge
v2016.02.15.08

NANO AntiVirus
Riskware.Win32.Relevant.cygwmp
0.28.6.62995

Norman
RelevantKnowledge.A
11.20160215

Qihoo 360 Security
Win32/Virus.Adware.e7b
1.0.0.1015

Reason Heuristics
PUP.TMRG (M)
16.2.15.8

Rising Antivirus
PE:Trojan.Win32.Generic.12F070E7!317747431
23.00.65.16213

SUPERAntiSpyware
PUP.RelevantKnowledge
9322

Trend Micro House Call
TROJ_GEN.RCBH1BA
7.2.46

VIPRE Antivirus
Adware.Win32.RelevantKnowledge.a
15500

Zillya! Antivirus
Adware.RK.Win32.167
2.0.0.1976

File size:
549 KB (562,192 bytes)

Product version:
4.0.14.22 (Build 14.22)

Copyright:
Copyright © 2001-2004

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\relevantknowledge\rlls.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/21/2011 2:00:00 AM

Valid to:
1/12/2013 12:59:59 AM

Subject:
CN="TMRG, Inc.", O="TMRG, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3E610C00C4D725B9689279CC88EEA594

File PE Metadata
Compilation timestamp:
10/12/2011 12:06:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:cBKcfn5Pxdmz+8P7eX2CAu/x/xaUGpalUVoId05tbTik+YFmpz:ck8nHsz162CAxUGpDogKJtFez

Entry address:
0x4B17B

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, 0C, B1, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 55, 8B, EC, 56, 57, 8B, 7D, 10, 8B, C7, 83, E8, 00, 0F, 84, E5, 15, 00, 00, 48, 0F, 84, CD, 15, 00, 00, 48, 0F, 84, 98, 15, 00, 00, 48, 0F, 84, 49, 15, 00, 00, 48, 0F, 84, B9, 14, 00, 00, 8B, 4D, 0C, 8B, 45, 08, 53, 6A, 20, 5A, E9, 72, 04, 00, 00, 8B, 30, 3B, 31, 74, 7C, 0F, B6, 30, 0F, B6, 19, 2B, F3, 74, 15, 33, DB, 85, F6, 0F, 9F, C3, 8D, 5C, 1B, FF, 8B, F3, 85, F6, 0F, 85...
 
[+]

Code size:
396 KB (405,504 bytes)

Startup Files Notify
Name:
RelevantKnowledge


Remove rlls.dll - Powered by Reason Core Security