rlph.dll

Relevant-Knowledge

TMRG, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The module rlph.dll by TMRG has been detected as adware by 14 anti-malware scanners. This file is typically installed with the program RelevantKnowledge by TMRG, Inc. which is a potentially unwanted software program. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
TMRG, Inc.  (signed by TMRG, Inc.)

Product:
Relevant-Knowledge

Version:
1.0.1.8

MD5:
3b0a7580945187c0dd64bbf2e03101fe

SHA-1:
bc60b8e5363126808d1ab89abfe30e947be256bf

Scanner detections:
14 / 68

Status:
Adware

Analysis date:
5/8/2024 8:42:09 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:PUP-gen [PUP]
2014.9-160213

AVG
MalSign.Relevant Knowledge
2017.0.2835

Bkav FE
W32.Clodb36.Trojan
1.3.0.4613

Clam AntiVirus
PUA.RelevantKnowledge-1
0.98/18155

F-Prot
W32/Relevant.B.gen
v6.4.7.1.166

K7 AntiVirus
Adware
13.170.9164

Malwarebytes
PUP.Optional.RelevantKnowledge
v2016.02.13.02

Norman
W32/RelevantKnowledge.AYV
11.20160213

Reason Heuristics
PUP.TMRG (M)
16.2.13.2

Rising Antivirus
PE:Trojan.Win32.Generic.131A3412!320484370
23.00.65.16211

Sophos
Generic Proxy-OSS Application
4.96

SUPERAntiSpyware
PUP.RelevantKnowledge
9327

Trend Micro House Call
TROJ_GEN.F47V0826
7.2.44

VIPRE Antivirus
Marketscore.RelevantKnowledge
25390

File size:
801 KB (820,240 bytes)

Product version:
1.0.1.8

Copyright:
Copyright (C) 2007-2011

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\relevantknowledge\rlph.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/21/2011 7:00:00 AM

Valid to:
1/12/2013 6:59:59 AM

Subject:
CN="TMRG, Inc.", O="TMRG, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3E610C00C4D725B9689279CC88EEA594

File PE Metadata
Compilation timestamp:
9/13/2011 4:41:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:i9VZRG3DDOEM3/auz7iMpAxHeoHVMSe60zxeE6:EVZRODGhZa1eoHVMS9E6

Entry address:
0x5C23C

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, DE, E0, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, 8B, 44, 24, 04, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, F6, B5, FF, FF, 59, C3, 55, 8B, EC, 83, EC, 14, A1, C0, 7D, 0B, 10, 33, C5, 89, 45, FC, 53, 56, 33, DB, 39, 1D, 3C, 9D, 0B, 10, 57, 8B, F1, 75, 38, 53, 53, 33, FF, 47, 57, 68, AC, 7C, 08, 10, 68, 00, 01, 00, 00, 53, FF, 15, 8C, B0, 07, 10, 85, C0, 74, 08, 89, 3D, 3C, 9D, 0B, 10, EB, 15, FF, 15...
 
[+]

Entropy:
6.4036

Code size:
488 KB (499,712 bytes)

The file rlph.dll has been discovered within the following program.

RelevantKnowledge  by TMRG, Inc.
Relevant-Knowledge maintains a group of users who have monitoring software (with brands including PermissionResearch, OpinionSquare and VoiceFive Networks) installed on their PCs in exchange for joining the Relevant-Knowledge research panels, users are presented with various benefits, including computer security software, Internet data storage, virus scanning and chances to win cash or prizes.
www.relevantknowledge.com
70% remove it
 
Powered by Should I Remove It?

Remove rlph.dll - Powered by Reason Core Security