84,488,480 programs installed

Should I remove Remarkit?

What percent of users and experts removed it?
81% remove it19% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Global Rank #35,522
United States Rank #32,932
Reach 0.0033%
Lifespan of installation (until removal)
< 4.61 days
136.04 days >
Average installed length: 71.48 days

Remarkit

What is Remarkit?

This adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of search-related ads, banner and video ads, and text-links and some popup/popunder ads. These ads are typically injected in the header of footer are of the web page. It will also convert words on pages you view into hyperlinks that are linked to advertisements. This application is classified as adware and/or a PUP based on its behavior. The software is distributed through third party installers that may include it as an additional or sponsored offer.

Overview

During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a background controller service that is set to automatically run. Delaying the start of this service is possible through the service manager. It adds a Browser Helper Object (BHO) to Internet Explorer. A scheduled task is added to Windows Task Scheduler in order to launch the program at various scheduled times (the schedule varies depending on the version). In the Mozilla Firefox browser, it will add an add-on. The main program executable is RemarkitW34.exe. Typically most users end up uninstalling this just after a few days. The software installer includes 80 files and is usually about 1.73 MB (1,814,140 bytes).
  • Possible malware installed by this program
  • Starts automatically
  • Loads into the web browser
  • Adds a background Windows Service
  • Installed as part of a co-bundle
  • Injects advertisements unassociated with the underlying web page
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Remarkit.
RemarkitW34.exe (934fd396ec54ac901d13984934855775) has been flagged by the following 6 scanners:
Anti-Virus softwareVersionDetection
Antiy-AVL 0.1.0.1 Trojan/Win32.SGeneric
avast! 2014.9-140530 Win32:Adware-BQB [PUP]
Baidu-International 4.0.3.14530 Adware.Win32.AddLyrics.BAF
ESET-NOD32 8.9812 a variant of Win32/AdWare.AddLyrics.AF
Malwarebytes v2014.05.30.07 PUP.Optional.AdLyrics.A
Sophos 4.98 AddLyrics
Re-markitWFpIsw.exe (a6c65011f9187919af4b83563929b756) has been flagged by the following 36 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Variant.Adware.AddLyrics.10
AegisLab 1.5 AdWare.MSIL.DomaIQ
Agnitum Outpost 5.5.1.3 PUA.Agent!
AhnLab-V3 2014.10.17.00 Adware/Win32.Gen
Antiy-AVL 1.0.0.1 GrayWare[AdWare:not-a-virus]/Win32.Agent
avast! 8.0.1489.320 Win32:Malware-gen
AVG 14.0.0.4040 Generic5.AVAW
Avira 7.11.179.12 Adware/AddLyrics.10.48
AVware 1.5.0.21 Trojan.Win32.Generic!BT
Baidu-International 3.5.1.41473 Adware.Win32.AddLyrics.bAO
Bitdefender 7.2 Gen:Variant.Adware.AddLyrics.10
CAT-QuickHeal 14.00 AdWare.Agent.r5 (Not a Virus)
Comodo Security 19818 Application.Win32.Adware.WDUnlocker.A
Emsisoft Anti-Malware 3.0.0.600 Gen:Variant.Adware.AddLyrics.10 (B)
ESET-NOD32 10576 a variant of Win32/AdWare.AddLyrics.AO
Fortinet FortiGate 5.1.152.0 Riskware/AddLyrics
F-Prot 4.7.1.166 W32/AddLyrics.A.gen!Eldorado
F-Secure 11.0.19100.45 Gen:Variant.Adware.AddLyrics.10
G Data 24 Gen:Variant.Adware.AddLyrics.10
K7 AntiVirus 9.184.13704 Unwanted-Program ( 004a8e8a1 )
K7GW 9.184.13704 Unwanted-Program ( 004a8e8a1 )
Kaspersky 12.0.0.1225 not-a-virus:AdWare.Win32.Agent.alrl
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Agent.al.(kcloud)
McAfee 6.0.5.614 RDN/Generic PUP.x!clh
McAfee-GW-Edition v2014.2 RDN/Generic PUP.x!clh
MicroWorld-eScan 12.0.250.0 Gen:Variant.Adware.AddLyrics.10
NANO AntiVirus 0.28.2.62671 Riskware.Win32.Agent.damffm
Qihoo-360 1.0.0.1015 Win32/Virus.Adware.960
Sophos 4.98.0 AddLyrics
Symantec 20141.1.0.330 Trojan.Gen.2
Tencent 1.0.0.1 Win32.Risk.Adware.Lohq
Trend Micro 9.740.0.1012 TROJ_GEN.R0CBC0EFN14
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R0CBC0EFN14
Vba32 AntiVirus 3.12.26.3 AdWare.Agent
VIPRE Antivirus 33986 Trojan.Win32.Generic!BT
Zillya 2.0.0.1958 Adware.Agent.Win32.9495
Re-markitWFp.exe (f88f36b16fc7763bb799bfa001b7928a) has been flagged by the following 32 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Adware.Generic.941587
AhnLab-V3 2014.08.05.00 Adware/Win32.AddLyrics
Avira AntiVir 7.11.165.50 Adware/Agent.286720.8
Antiy-AVL 1.0.0.1 GrayWare[AdWare:not-a-virus]/Win32.Agent
avast! 8.0.1489.320 Win32:Malware-gen
AVG 14.0.0.3986 Generic5.AWZA
AVware 1.5.0.16 Trojan.Win32.Generic!BT
Baidu-International 3.5.1.41473 Adware.Win32.AddLyrics.BAM
Bitdefender 7.2 Adware.Generic.941587
CAT-QuickHeal 14.00 AdWare.Agent.r5 (Not a Virus)
Comodo Security 19086 ApplicUnwnt
Dr.Web 7.0.9.4080 Trojan.Lyrics.60
Emsisoft Anti-Malware 3.0.0.600 Adware.Generic.941587 (B)
ESET-NOD32 10204 a variant of Win32/AdWare.AddLyrics.AS
Fortinet FortiGate 5.1.152.0 Adware/Agent
F-Secure 11.0.19100.45 Adware.Generic.941587
G Data 24 Adware.Generic.941587
K7 AntiVirus 9.182.12945 Riskware ( 0040f01a1 )
K7GW 9.182.12945 Riskware ( 0040f01a1 )
Kaspersky 12.0.0.1225 not-a-virus:AdWare.Win32.Agent.akws
McAfee 6.0.4.564 RDN/Generic PUP.x!cgl
McAfee-GW-Edition 2013.2 RDN/Generic PUP.x!cgl
MicroWorld-eScan 12.0.250.0 Adware.Generic.941587
NANO AntiVirus 0.28.2.61349 Riskware.Win32.Agent.czjuez
Panda Antivirus 10.0.3.5 Trj/CI.A
Rising Antivirus 25.0.0.11 PE:Trojan.Win32.Generic.16EBD23E!384553534
Sophos 4.98.0 Generic PUA BL
Symantec 20131.1.5.61 Trojan.Gen.2
Tencent 1.0.0.1 Win32.Risk.Adw.Eehj
TrendMicro-HouseCall 9.700.0.1001 TROJ_SPNR.15GA14
Vba32 AntiVirus 3.12.26.3 AdWare.Agent
VIPRE Antivirus 31926 Trojan.Win32.Generic!BT
Re-markitWFp161.exe (11f5a05cf5cbb0e7f308f06135e338f5) has been flagged by the following 4 scanners:
Anti-Virus softwareSoftware versionDetection
avast! 8.0.1489.320 Win32:Adware-BNS [PUP]
Baidu-International 3.5.1.41473 Adware.Win32.AddLyrics.AK
ESET-NOD32 9754 a variant of Win32/AdWare.AddLyrics.AK
Symantec 20131.1.5.61 WS.Reputation.1
173.dll (c040435bd93a23b3adc0dfdd76b6e7a2) has been flagged by the following 2 scanners:
Anti-Virus softwareSoftware versionDetection
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0621
       View all 80 all detections
Remarkit has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Displayed publisher: remarkit soft
Installation folder: C:\Program Files\re_markit
Uninstaller: C:\Program Files\Re_markit\Uninstall.exe
Estimated size: 1.73 MB

Program filesFiles installed by Remarkit

Program executable:RemarkitW34.exe (Malware detected)
Path:C:\Program Files\re_markit\RemarkitW34.exe
MD5:934fd396ec54ac901d13984934855775
Additional files:
  • 161.xpi
  • 170.dll
  • 170.xpi
  • 171.dll
  • 173.dll
  • (Malware detected) Re-markitWFp.exe
  • Re-markitWFp161.dll
  • (Malware detected) Re-markitWFp161.exe
  • (Malware detected) Re-markitWFpIsw.exe
  • Uninstall.exe

Program behaviorsBehaviors exhibited

3 Internet Explorer BHOs
  • 171.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Remarkit' with the class of {2BB247D1-5D80-CBB0-5A9D-836901F491B1}.
  • 170.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Remarkit' with the class of {43A79AF0-A27F-5E95-8E80-FC00DE05CF11}.
  • 173.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Remarkit' with the class of {48AA8EED-56DD-3A7F-B3EE-2BF1E48E5D8E}.
2 Scheduled Tasks
  • Re-markitWFpIsw.exe is scheduled as a task named 'Remarkit_wd' (runs daily at 11:33 PM).
  • RemarkitW34.exe is scheduled as a task named 'Remarkit Update' (runs daily at 1:46 PM).
3 Scheduled Tasks (Boot/Login)
  • Re-markitWFpIsw.exe is automatically launched at startup through a scheduled task named Remarkit_wd.
  • Re-markitWFp.exe is automatically launched at startup through a scheduled task named Remarkit Update.
  • RemarkitW34.exe is automatically launched at startup through a scheduled task named Remarkit Update.
Service
  • Re-markitWFp161.exe runs as a service named 'Remarkit' (Re-markit) "Re-markit".

How do I remove Remarkit?

You can uninstall Remarkit from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Remarkit, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Remarkit.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Remarkit you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win 7 (SP1) 57%
Win 10 2%
 
HOW IT RUNS
Windows Service? Yes
(Installs a service)
 
USER ACTIONS
Uninstall it 81%
Keep it 19%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 60.00%
Windows 10 33.85%
Windows Vista 6.15%
Which OS releases does it run on?
Windows 7 Home Premium 32.31%
Windows 7 Ultimate 15.38%
Windows 8.1 13.85%
Windows 8 6.15%
Windows 7 Professional 6.15%
Windows 8.1 Pro 4.62%

Distribution by countryGeography

47.37% of installs come from the United States
Which countries install it?
  United States 47.37%
  Saudi Arabia 14.47%
  Italy 6.58%
  Belgium 5.26%
  France 2.63%
  Norway 2.63%
  Iran 2.63%
  Chile 1.32%
  Singapore 1.32%
  UA 1.32%
  RS 1.32%
  Australia 1.32%
  India 1.32%
  Mexico 1.32%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Dell 22.58%
Hewlett-Packard 20.97%
Acer 16.13%
Lenovo 11.29%
GIGABYTE 6.45%
ASUS 6.45%
Samsung 6.45%
Toshiba 4.84%
Sony 1.61%
MSI 1.61%
American Megatrends 1.61%
Common models
HP Pavilion dv6 Notebook ... 4.69%
Acer Aspire V5-571PG 3.13%
Acer Aspire V5-571P 1.56%
Acer Aspire V3-471 1.56%
Acer Aspire E1-522 1.56%
TOSHIBA SATELLITE PRO C85... 1.56%

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.