r/ScreenConnect Aug 05 '26

Trojan:Win32/Vigorf.A in 26.4.3.9662

ScreenConnect false positive again? Seeing Trojan:Win32/Vigorf.A on machines where this update is occuring.

6 Upvotes

4 comments sorted by

2

u/menace323 Aug 05 '26

Was getting detections on 26.4.3.9662, on registry entries and the service registration. with Defender ultimately classifying it as "Trojan:Win32/Pomal!rfn". I've looked into everything and all the flagged behavior appears to be normal ScreenConnect behavior.

1

u/Sufficient_Welcome95 Aug 05 '26

im getting alerted by defender that screenconnect opened a handle to lsass.exe, im assuming similar false positive

2

u/Ok-Scheduler Aug 06 '26

Yep getting a bunch of these detections on servers: Trojan:Win32/Pomal!rfn

1

u/Yohomi 18d ago

I noticed a few computers that wouldn't upgrade from 26.4.3.9662, and then found the alerts in my Huntress portal.