Microsoft Defender Detecting ScreenConnect as Trojan

Modified on Mon, 21 Sep at 4:45 AM

This article explains why some customers are seeing Microsoft Defender and other endpoint security products detect ConnectWise ScreenConnect as Trojan:Win32/Pomal!rfnon (or similar), how to validate the detection, and the actions we recommend taking.

Tes uses ConnectWise ScreenConnect to provide authorised remote support access to customer environments. Based on information currently available, the reported detections may be consistent with a false positive affecting legitimate ScreenConnect installations. This article provides guidance to assist customers in assessing the detection within the broader security context of their environment.

Current Status

Based on information currently available, Tes believes the reported detections may be consistent with a false positive affecting legitimate ScreenConnect installations.

At this time, Tes has not identified evidence that the reported detections are associated with unauthorised access to or compromise of customer data.

Investigations remain ongoing and this article will be updated should additional information become available.
Before you begin
This article applies only to environments using the Tes-managed ConnectWise ScreenConnect remote support agent. Administrative access to the affected host and security management tools may be required to perform the validation steps described below.

On this page


What is ScreenConnect?

ConnectWise ScreenConnect is the remote support tool used by Tes Technical Services to provide authorised access to customer environments for troubleshooting, maintenance and support activities.

The ScreenConnect client typically installs a Windows service named:

ScreenConnect.ClientService.exe

within a directory similar to:

C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\

What are customers seeing?

Affected customers have reported detections similar to:

Trojan:Win32/Pomal!rfnon
Trojan:Win32/Wacatac.C!ml 

against:

ScreenConnect.ClientService.exe

Common characteristics include:

  • Detection by Microsoft Defender or another endpoint security product.
  • The file is located within the expected ScreenConnect installation directory.
  • The file is digitally signed by ConnectWise, LLC.
  • The ScreenConnect service has been quarantined, blocked or removed.
  • Remote support connectivity has been interrupted.
Current Assessment

Based on observations and information available to date, the reported detections appear consistent with a false positive. Customers should assess the detection within the broader security context of their environment.

Why is Defender detecting it?

Remote Monitoring and Management (RMM) tools such as ScreenConnect are widely used by support providers and IT teams. Because these tools provide remote access capabilities, they are frequently monitored by endpoint security products using behavioural and reputation-based detection techniques.

Legitimate remote access tools may also be misused by threat actors and should be assessed within the broader security context of the environment.

Important

The detection name alone does not prove a system compromise. File location, source, digital signature and observed behaviour should all be considered when assessing the detection.

Customers should also consider other alerts, security events and indicators of compromise when evaluating the affected host.

How to verify the detection

1. Verify the file location

Confirm the detected file is located in the expected ScreenConnect installation directory:

C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\

2. Verify the digital signature

Confirm the executable is signed by:

ConnectWise, LLC

You can validate the signature using PowerShell:

Get-AuthenticodeSignature "C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\ScreenConnect.ClientService.exe"

3. Verify the file hash

If requested by Tes Support, calculate the SHA256 hash:

Get-FileHash "C:\Program Files (x86)\ScreenConnect Client (<instance-id>)\ScreenConnect.ClientService.exe" -Algorithm SHA256

4. Gather information for Tes Support

Please provide:

  • Server name
  • Detection timestamp
  • SHA256 hash
  • Security product reporting the detection
  • Whether the file was quarantined, blocked or deleted
Validation guidance

These checks assist with validation but should not be considered conclusive evidence that a system has not been compromised.

Customers should review the detection alongside other available security telemetry, endpoint monitoring information and security alerts.
  1. Confirm the file is located within the expected ScreenConnect installation directory.
  2. Confirm the file is digitally signed by ConnectWise, LLC.
  3. Review the detection alongside other available security telemetry.
  4. Contact Tes Technical Services if assistance is required.
  5. Review restoration options in line with your organisation's security policies.
  6. Follow your organisation's security and incident response procedures where additional suspicious activity is identified.
Reporting a false positive to Microsoft

If your organisation believes the detection relates to a legitimate ScreenConnect installation, you may wish to submit a false positive report to Microsoft for review.

As Microsoft Defender and the affected endpoint are managed within your organisation's environment, Tes is generally unable to submit false positive cases directly on behalf of customers.

Tes can, however, assist with validating the ScreenConnect installation and gathering supporting information such as:
  • File hashes
  • Digital signatures
  • Installation paths
  • Detection details
This information may assist your IT or security team when engaging with Microsoft.
Important

The presence of this detection does not exclude the possibility of unrelated security events within the environment.

Known Impact of the Detection

Based on investigations completed to date, Tes has not identified evidence that the reported detections have resulted in unauthorised modification of application data or database integrity.

The primary observed impact is loss of ScreenConnect connectivity due to the service being quarantined, blocked or removed.

Investigations remain ongoing and this article will be updated should additional information become available.

References

Frequently Asked Questions

Has my server been compromised?

Tes has not identified evidence that this detection alone indicates compromise of the affected server.

Customers should assess the detection alongside other available alerts, security events and indicators of compromise.

Can I restore the file?

Only after confirming the file location, source and digital signature, and in accordance with your organisation's security procedures and change management processes.

Should I re-enable the ScreenConnect service?

Where the file has been validated as the legitimate Tes-managed ScreenConnect installation and no other indicators of compromise have been identified, customers may choose to restore and re-enable the service in accordance with their organisation's security policies and change management processes.

Will Tes continue monitoring this issue?

Yes. Tes continues to monitor information published by Microsoft, ConnectWise and the wider security community. This article will be updated if additional information becomes available.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article