Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

1.1.22.120 (Build 22.120) 33.33%
1.1.22.113 (Build 22.113) 33.33%
1.1.21.137 (Build 21.137) 33.33%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
SetSecurityDescriptorGroup, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, SetFileSecurityW, GetTokenInformation, LookupPrivilegeValueW, AdjustTokenPrivileges, GetLengthSid, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerExW, DuplicateTokenEx, OpenProcessToken, SetTokenInformation, CreateProcessAsUserW, GetNamedSecurityInfoW, SetNamedSecurityInfoW, SetServiceStatus, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegDeleteValueW, ControlService, DeleteService, CreateServiceW, OpenSCManagerW, OpenServiceW, CloseServiceHandle
kernel32.dll
FindNextFileW, DeleteFileW, FindFirstFileW, RemoveDirectoryW, WTSGetActiveConsoleSessionId, GetProcAddress, GetModuleHandleW, CopyFileW, GetFileAttributesW, GetCurrentProcess, Sleep, OpenEventW, OpenProcess, FindClose, HeapFree, GetProcessHeap, InterlockedIncrement, HeapAlloc, CreateEventW, lstrcmpiW, GetCommandLineW, GetVersionExW, GetStringTypeA, GetLocaleInfoA, GetModuleHandleA, InterlockedDecrement, lstrlenA, WideCharToMultiByte, SetEvent, WaitForMultipleObjects, FormatMessageW, LocalAlloc, GetLocalTime, CreateFileW, SetFilePointer, WriteFile, CloseHandle, GetModuleFileNameW, lstrcatW, LocalFree, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, GetLastError, RaiseException, lstrlenW, MultiByteToWideChar, CreateFileA, FlushFileBuffers, WaitForSingleObject, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, WriteConsoleW, QueryPerformanceCounter, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetStartupInfoA, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, InitializeCriticalSectionAndSpinCount, LoadLibraryA, GetModuleFileNameA, GetStdHandle, IsValidCodePage, GetOEMCP, GetLocaleInfoW, GetConsoleMode, GetConsoleCP, IsValidLocale, EnumSystemLocalesA, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, HeapDestroy, HeapReAlloc, HeapSize, InterlockedCompareExchange, InterlockedExchange, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlUnwind, ExitThread, GetCurrentThreadId, CreateThread, ExitProcess, LCMapStringA, LCMapStringW, GetCPInfo, GetStringTypeW, HeapCreate, VirtualFree, VirtualAlloc, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetACP, GetUserDefaultLCID
ole32.dll
CoUninitialize, StringFromGUID2, CoInitializeEx, CoCreateInstance, CoSetProxyBlanket
shell32.dll
CommandLineToArgvW, SHGetSpecialFolderPathW
user32.dll
MessageBoxW, wsprintfW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
wtsapi32.dll
WTSEnumerateSessionsW, WTSQueryUserToken, WTSFreeMemory, WTSQuerySessionInformationW

rlservice.exe

Relevant-Knowledge by TMRG Inc. (Signed)

Remove rlservice.exe
Version:   1.1.22.120 (Build 22.120)
MD5:   a739a2aec476678694ef38857808b3bd
SHA1:   00193431d0f9dc17ccd7d5c6a9d200a994abde05
SHA256:   509c922006b6cea75218991b1cd84f4b3d9d38ba676345d8cf2bfdb6dd97987c
Warning 9 antivirus scanners has detected malware.

Overview

rlservice.exe is malware that runs as a service under the name RelevantKnowledge within the local user context. This is typically installed with the program RelevantKnowledge published by TMRG, Inc. and is most likely removed by most users once installed (70% removed). The file is digitally signed by TMRG Inc. which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:rlservice.exe
Publisher:TMRG, Inc.
Product name:Relevant-Knowledge
Typical file path:C:\Program Files\relevantknowledge\rlservice.exe
File version:1.1.22.120 (Build 22.120)
Size:181.77 KB (186,136 bytes)
Build date:8/17/2013 5:47 AM
Certificate
Issued to:TMRG Inc.
Authority (CA):VeriSign
Effective date:Thursday, December 22, 2011
Expiration date:Sunday, December 22, 2013
Digital DNA
PE subsystem:Windows Console
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
TMRG, Inc.
  70% remove
Relevant-Knowledge maintains a group of users who have monitoring software (with brands including PermissionResearch, OpinionSquare and VoiceFive Networks) installed on their PCs in exchange for joining the Relevant-Knowledge research panels, users are presented with various benefits, including computer security software, Internet data storage, virus scanning and chances to win cash or prizes. The program is typically bundled by 3rd-...

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'RelevantKnowledge'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 9 of them detected the following malware.
Antivirus engineEngine versionDetection
Avira AntiVir 7.11.114.78 Adware/RK.AV.3
avast! 8.0.1489.320 Win32:Relevant-W [PUP]
Bkav Security 1.3.0.4562 W32.Clod3b0.Trojan.85aa
ESET NOD32 7.9064 a variant of Win32/Adware.RK
Kingsoft 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 1.75.0.1 PUP.Adware.RelevantKnowledge
SUPERAntiSpyware 5.6.0.1032 PUP.RelevantKnowledge
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V0828
VIPRE Antivirus 23496 Marketscore.RelevantKnowledge (fs)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 66.67%
Windows 8 33.33%

Distribution by countryDistribution by country

MA installs about 33.33% of Relevant-Knowledge.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE