This article explains why some customers are seeing Microsoft Defender and other endpoint security products detect ConnectWise ScreenConnect as Trojan:Win32/Pomal!rfnon (or similar), how to validate the detection, and the actions we recommend taking.
Tes uses ConnectWise ScreenConnect to provide authorised remote support access to customer environments. Based on information currently available, the reported detections may be consistent with a false positive affecting legitimate ScreenConnect installations. This article provides guidance to assist customers in assessing the detection within the broader security context of their environment.
Based on information currently available, Tes believes the reported detections may be consistent with a false positive affecting legitimate ScreenConnect installations.
At this time, Tes has not identified evidence that the reported detections are associated with unauthorised access to or compromise of customer data.
Investigations remain ongoing and this article will be updated should additional information become available.
This article applies only to environments using the Tes-managed ConnectWise ScreenConnect remote support agent. Administrative access to the affected host and security management tools may be required to perform the validation steps described below.
On this page
- What is ScreenConnect?
- What are customers seeing?
- Why is Defender detecting it?
- How to verify the detection
- Recommended actions
- Known Impact of the Detection
- References
- Frequently Asked Questions
What is ScreenConnect?
ConnectWise ScreenConnect is the remote support tool used by Tes Technical Services to provide authorised access to customer environments for troubleshooting, maintenance and support activities.
The ScreenConnect client typically installs a Windows service named:
ScreenConnect.ClientService.exewithin a directory similar to:
C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\What are customers seeing?
Affected customers have reported detections similar to:
Trojan:Win32/Pomal!rfnonTrojan:Win32/Wacatac.C!ml
against:
ScreenConnect.ClientService.exeCommon characteristics include:
- Detection by Microsoft Defender or another endpoint security product.
- The file is located within the expected ScreenConnect installation directory.
- The file is digitally signed by ConnectWise, LLC.
- The ScreenConnect service has been quarantined, blocked or removed.
- Remote support connectivity has been interrupted.
Based on observations and information available to date, the reported detections appear consistent with a false positive. Customers should assess the detection within the broader security context of their environment.
Why is Defender detecting it?
Remote Monitoring and Management (RMM) tools such as ScreenConnect are widely used by support providers and IT teams. Because these tools provide remote access capabilities, they are frequently monitored by endpoint security products using behavioural and reputation-based detection techniques.
Legitimate remote access tools may also be misused by threat actors and should be assessed within the broader security context of the environment.
The detection name alone does not prove a system compromise. File location, source, digital signature and observed behaviour should all be considered when assessing the detection.
Customers should also consider other alerts, security events and indicators of compromise when evaluating the affected host.
How to verify the detection
1. Verify the file location
Confirm the detected file is located in the expected ScreenConnect installation directory:
C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\2. Verify the digital signature
Confirm the executable is signed by:
ConnectWise, LLCYou can validate the signature using PowerShell:
Get-AuthenticodeSignature "C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\ScreenConnect.ClientService.exe"3. Verify the file hash
If requested by Tes Support, calculate the SHA256 hash:
Get-FileHash "C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\ScreenConnect.ClientService.exe" -Algorithm SHA2564. Gather information for Tes Support
Please provide:
- Server name
- Detection timestamp
- SHA256 hash
- Security product reporting the detection
- Whether the file was quarantined, blocked or deleted
These checks assist with validation but should not be considered conclusive evidence that a system has not been compromised.
Customers should review the detection alongside other available security telemetry, endpoint monitoring information and security alerts.
Recommended actions
- Confirm the file is located within the expected ScreenConnect installation directory.
- Confirm the file is digitally signed by ConnectWise, LLC.
- Review the detection alongside other available security telemetry.
- Contact Tes Technical Services if assistance is required.
- Review restoration options in line with your organisation's security policies.
- Follow your organisation's security and incident response procedures where additional suspicious activity is identified.
If your organisation believes the detection relates to a legitimate ScreenConnect installation, you may wish to submit a false positive report to Microsoft for review.
As Microsoft Defender and the affected endpoint are managed within your organisation's environment, Tes is generally unable to submit false positive cases directly on behalf of customers.
Tes can, however, assist with validating the ScreenConnect installation and gathering supporting information such as:
- File hashes
- Digital signatures
- Installation paths
- Detection details
The presence of this detection does not exclude the possibility of unrelated security events within the environment.
Known Impact of the Detection
Based on investigations completed to date, Tes has not identified evidence that the reported detections have resulted in unauthorised modification of application data or database integrity.
The primary observed impact is loss of ScreenConnect connectivity due to the service being quarantined, blocked or removed.
Investigations remain ongoing and this article will be updated should additional information become available.
References
- ConnectWise – False positive from antivirus software
- ConnectWise Trust Centre Advisories
- Microsoft Security Intelligence
Frequently Asked Questions
Has my server been compromised?
Tes has not identified evidence that this detection alone indicates compromise of the affected server.
Customers should assess the detection alongside other available alerts, security events and indicators of compromise.
Can I restore the file?
Only after confirming the file location, source and digital signature, and in accordance with your organisation's security procedures and change management processes.
Should I re-enable the ScreenConnect service?
Where the file has been validated as the legitimate Tes-managed ScreenConnect installation and no other indicators of compromise have been identified, customers may choose to restore and re-enable the service in accordance with their organisation's security policies and change management processes.
Will Tes continue monitoring this issue?
Yes. Tes continues to monitor information published by Microsoft, ConnectWise and the wider security community. This article will be updated if additional information becomes available.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article