Riskware/InstalleRex

description-logoAnalysis


Riskware/InstalleRex is a generic detection for a type of grayware that arrives as an application installation package and might download and install unwanted software.

  • The installation has no notification and cannot be cancelled once it has started.

  • It creates the following files. These files are components of the InstallMate istallation package:
    • undefinedAppDataundefined\InstallMate\{Random GUID}\TsuDll.dll
    • undefinedAppDataundefined\InstallMate\{Random GUID}\_Setup.dll
    • undefinedAppDataundefined\InstallMate\{Random GUID}\_Setupx.dll
    • undefinedAppDataundefined\InstallMate\{Random GUID}\Setup.exe
    • undefinedAppDataundefined\InstallMate\{Random GUID}\Setup.exe

  • It creates the following files:
    • undefinedAppDataundefined\BetterSoft\Agent\Agent.exe
    • undefinedAppDataundefined\BetterSoft\Agent\profile.ini : This is an encrypted configuration file. It contains the software information which is used by Agent.exe to download the update.


recommended-action-logoRecommended Action

FortiGate Systems

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.

FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2023-12-06 91.09476
2023-12-06 91.09474
2023-12-02 91.09351
2023-12-02 91.09342
2023-11-11 91.08713
2023-11-06 91.08560
2023-11-02 91.08441
2023-11-01 91.08415
2023-10-31 91.08386
2023-10-24 91.08167