rlservice.exe

RelevantKnowledge

TMRG, Inc.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The application rlservice.exe by TMRG has been detected as adware by 22 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “RelevantKnowledge”. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
TMRG, Inc.  (signed and verified)

Product:
RelevantKnowledge

Version:
1.0.13.138 (Build 13.138)

MD5:
97ef64bd7ddf9c6865e0e46d15acd800

SHA-1:
7eac255e70338dec2374c258badaeedc5677b8f9

SHA-256:
9232ac09c30ab3fefe857083984ce11d63115766fb59740e76faf1eafdae7e5f

Scanner detections:
22 / 68

Status:
Adware

Analysis date:
4/24/2024 4:07:38 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.RK
7.1.1

avast!
Win32:Relevant-G [PUP]
2014.9-131225

AVG
RelevantKnowledge
2014.0.3614

Bitdefender
Adware.Generic.113759
1.0.20.1795

Boost by Reason
Optional.Service.TMRG.J
188838

Comodo Security
UnclassifiedMalware
16289

Emsisoft Anti-Malware
Adware.Win32.FileSubmit
8.13.12.25.06

ESET NOD32
Win32/Adware.RK (variant)
7.8353

Fortinet FortiGate
Riskware/OSS
12/25/2013

F-Prot
W32/RK.B
v6.4.7.1.166

G Data
Adware.Generic.113759
13.12.22

K7 AntiVirus
Adware
13.167.8711

Malwarebytes
PUP.Adware.RelevantKnowledge
v2013.12.25.06

McAfee
Artemis!97EF64BD7DDF
5600.7270

MicroWorld eScan
Adware.Generic.113759
14.0.0.1077

NANO AntiVirus
Riskware.Win32.RelKnow.indvb
0.24.0.52214

Norman
Adware.A!genr
11.20131225

Reason Heuristics
PUP.Service.TMRG.J
14.8.7.22

Sophos
Generic Proxy-OSS Application
4.89

SUPERAntiSpyware
Spyware.RelevantKnowledge
10885

Vba32 AntiVirus
Trojan.Genome.ac
3.12.22.0

VIPRE Antivirus
Adware.Win32.RelevantKnowledge.a
17934

File size:
48.6 KB (49,792 bytes)

Product version:
1.0.13.138 (Build 13.138)

Copyright:
Copyright © 2001-2004

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\relevantknowledge\rlservice.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
7/17/2007 2:00:00 AM

Valid to:
9/28/2009 1:59:59 AM

Subject:
CN="TMRG, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="TMRG, Inc.", L=Reston, S=Virginia, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
02491544000D8C9D63F061B1EBAE8466

File PE Metadata
Compilation timestamp:
5/21/2009 11:18:33 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

CTPH (ssdeep):
768:l+hTCk+GEvSfgmq0lIHUUX/G2qb6iUi1iLQta+D2L5:8h+eq0+H//CoWicta+D21

Entry address:
0x42A0

Entry point:
6A, 28, 68, 48, 76, 40, 00, E8, 9C, FF, FF, FF, 33, FF, 57, FF, 15, 44, 51, 40, 00, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 01, FF, 15, 78, 51, 40, 00, 59, 83, 0D, 8C, 9B, 40, 00, FF, 83, 0D, 90, 9B, 40, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
16 KB (16,384 bytes)

Service
Display name:
RelevantKnowledge

Type:
Win32OwnProcess


Remove rlservice.exe - Powered by Reason Core Security