{"id":3930,"date":"2015-01-15T21:06:18","date_gmt":"2015-01-15T21:06:18","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=3930"},"modified":"2018-05-29T12:01:03","modified_gmt":"2018-05-29T12:01:03","slug":"rational-thought-solutions-18-detection-rate-msil-adware-pullupdate","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/rational-thought-solutions-18-detection-rate-msil-adware-pullupdate\/","title":{"rendered":"Rational Thought Solutions &#8211; 18% Detection Rate &#8211; MSIL.Adware.PullUpdate"},"content":{"rendered":"<p>Found another publisher that appears to be signing adware related files while checking out the new files added to FreeFixer&#8217;s database. The publisher is called\u00a0<strong>Rational Thought Solutions<\/strong>.<\/p>\n<p>When I uploaded the Rational Thought Solutions file to <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>, it came up with a 18% detection rate. The file is detected as <strong>Downloader.CBD<\/strong> by AVG, <strong>a variant of MSIL\/Adware.PullUpdate.G.gen<\/strong> by ESET-NOD32, <strong>PUP.Optional.StormAlert.A<\/strong> by Malwarebytes, <strong>Artemis!707FECAF8B22<\/strong> by McAfee and <strong>MSIL.Adware.PullUpdate<\/strong> by VIPRE.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Rational-Thought-Solutions-virustotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3931\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Rational-Thought-Solutions-virustotal.png\" alt=\"Rational Thought Solutions virustotal\" width=\"720\" height=\"436\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Rational-Thought-Solutions-virustotal.png 720w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Rational-Thought-Solutions-virustotal-300x181.png 300w\" sizes=\"(max-width: 720px) 100vw, 720px\" \/><\/a><\/p>\n<p>From what I can tell from the\u00a0Rational Thought Solutions files added to the FreeFixer database, the file names seems to be randomly generated. The files are located at\u00a0C:\\ProgramData\\%random%\\%random%.exe.<\/p>\n<p>Did you also stumble upon a download that was signed by Rational Thought Solutions? What kind of download was it and was it reported by the anti-virus scanners at <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>? Please share in posting comments below.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Found another publisher that appears to be signing adware related files while checking out the new files added to FreeFixer&#8217;s database. The publisher is called\u00a0Rational Thought Solutions. When I uploaded the Rational Thought Solutions file to VirusTotal, it came up with a 18% detection rate. The file is detected as Downloader.CBD by AVG, a variant &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/rational-thought-solutions-18-detection-rate-msil-adware-pullupdate\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Rational Thought Solutions &#8211; 18% Detection Rate &#8211; MSIL.Adware.PullUpdate<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[362],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/3930"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=3930"}],"version-history":[{"count":3,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/3930\/revisions"}],"predecessor-version":[{"id":3934,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/3930\/revisions\/3934"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=3930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=3930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=3930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}