Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
Relationships
Parent process
Child process
Related files
rlservice.exe
Relevant-Knowledge by TMRG Inc. (Signed)
Version: | 1.1.22.113 (Build 22.113) |
MD5: | 2b9583e9d0dec51739c669409c1f86f7 |
SHA1: | 88d09799685b429ccb50bf8832e01d4122eeeb5c |
SHA256: | afe8929fe13a2b1e5dbf61121ae343dc791be7de96d7f76d381e11d4256a1019 |
Warning 6 antivirus scanners has detected malware.
Overview
rlservice.exe is malware that runs as a service under the name RelevantKnowledge with extensive SYSTEM privileges (full administrator access). The file is digitally signed by TMRG Inc. which was issued by the VeriSign certificate authority (CA).
Details
File name: | rlservice.exe |
Publisher: | TMRG, Inc. |
Product name: | Relevant-Knowledge |
Typical file path: | C:\Program Files\relevantknowledge\rlservice.exe |
File version: | 1.1.22.113 (Build 22.113) |
Size: | 181.77 KB (186,136 bytes) |
Certificate |
Issued to: | TMRG Inc. |
Authority (CA): | VeriSign |
Effective date: | Thursday, December 22, 2011 |
Expiration date: | Sunday, December 22, 2013 |
Digital DNA |
PE subsystem: | Windows Console |
File packed: | No |
.NET CLR: | No |
More details
Behaviors
Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
Malware detections
Based on 40+ industry antivirus scanners, 6 of them detected the following malware.
Antivirus engine | Engine version | Detection |
avast! |
8.0.1489.320 |
Win32:Relevant-W [PUP] |
Comodo Internet Security |
16603 |
ApplicUnwnt |
ESET NOD32 |
7.8576 |
a variant of Win32/Adware.RK |
Kingsoft |
2013.4.9.267 |
Win32.Troj.Generic.a.(kcloud) |
Malwarebytes |
1.75.0.1 |
PUP.Adware.RelevantKnowledge |
SUPERAntiSpyware |
5.6.0.1008 |
PUP.RelevantKnowledge |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00005291% | |
Kernel CPU: | 0.00005291% | |
Kernel CPU time: | 47 ms/min | |
CPU cycles: | 2,004/sec | |
Memory |
Private memory: | 2.28 MB | |
Private (maximum): | 4.59 MB | |
Private (minimum): | 144 KB | |
Non-paged memory: | 2.28 MB | |
Virtual memory: | 40.43 MB | |
Virtual memory (peak): | 42.83 MB | |
Working set: | 192 KB | |
Working set (peak): | 4.61 MB | |
Page faults: | 6,535/min | |
I/O |
I/O other transfer: | 3 Bytes/sec | |
I/O other operations: | 1/sec | |
Resource allocations |
Threads: | 4 | |
Handles: | 108 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
66.67% |
|
Windows 8 |
33.33% |
|
Distribution by country
MA installs about 33.33% of Relevant-Knowledge.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Acer |
66.67% |
|
Hewlett-Packard |
33.33% |
|