Riskware/XYNTService

description-logoAnalysis

Riskware/XYNTService is a detection for a Riskware tool that was based on the XYNTService.exe, an open source program that can allow programs/service to have an auto start and persistency. Malicious programs may utilize this XYNTService.exe to make the malwares start even before the user has logged on and stay running/executing even after the user has logged off.

recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2024-04-24 92.03667
2024-04-17 92.03457
2024-04-15 92.03397
2024-04-09 92.03220
2024-04-08 92.03191
2024-04-08 92.03180
2024-04-01 92.02981
2024-03-27 92.02821
2024-03-25 92.02774
2024-03-18 92.02560