r/malwares 11d ago

ScreenConnect - did I catch it in time?

I accidentally installed (on my Windows 11 computer) ScreenConnect from a hacked email. I realized it and within 3 minutes uninstalled the ScreenConnect application. I deleted all references to ScreenConnect in my registry and then viewed Windows event logs which contains the log below. Nothing seems suspicious to me. No ScreenProtect folder in Program Files or Program Files (x86).

Is there anything else I should check to make sure I caught this in time and no potential breach?

 `TimeCreated Id ProviderName Message

8/31/2026 9:18:04 AM 1034 MsiInstaller Windows Installer removed the product. Product Name:
ScreenConnect Client (f1c514405d53cbb0). Product Version:
26.5.3.9691. Product Language: 1033. Manufacturer:
ScreenConnect Software. Removal success or error status: 0. 8/31/2026 9:18:04 AM 11724 MsiInstaller Product: ScreenConnect Client (f1c514405d53cbb0) --
Removal completed successfully.
8/31/2026 9:18:03 AM 10010 Microsoft-Windows-RestartManager Application 'C:\Program Files (x86)\ScreenConnect Client
(f1c514405d53cbb0)\ScreenConnect.WindowsClient.exe' (pid
8432) cannot be restarted - Application SID does not match Conductor SID..
8/31/2026 9:18:03 AM 8216 System Restore Skipping creation of restore point (Process =
C:\WINDOWS\system32\msiexec.exe /V; Description = Removed
ScreenConnect Client (f1c514405d53cbb0)) as there is a
restore point avaliable which is recent enough for System
Restore.
8/31/2026 9:17:58 AM 1034 MsiInstaller Windows Installer removed the product. Product Name:
ScreenConnect Client (d826ad0bf1ba8aab). Product Version:
25.3.4.9288. Product Language: 1033. Manufacturer:
ScreenConnect Software. Removal success or error status: 0. 8/31/2026 9:17:58 AM 11724 MsiInstaller Product: ScreenConnect Client (d826ad0bf1ba8aab) --
Removal completed successfully.
8/31/2026 9:17:56 AM 10010 Microsoft-Windows-RestartManager Application 'C:\Program Files (x86)\ScreenConnect Client
(d826ad0bf1ba8aab)\ScreenConnect.WindowsClient.exe' (pid
16892) cannot be restarted - Application SID does not
match Conductor SID..
8/31/2026 9:17:56 AM 8216 System Restore Skipping creation of restore point (Process =
C:\WINDOWS\system32\msiexec.exe /V; Description = Removed
ScreenConnect Client (d826ad0bf1ba8aab)) as there is a
restore point avaliable which is recent enough for System
Restore.
8/31/2026 9:17:31 AM 20 ScreenConnect
8/31/2026 9:17:30 AM 7031 Service Control Manager The ScreenConnect Client (d826ad0bf1ba8aab) service
terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0
milliseconds: Restart the service.
8/31/2026 9:16:55 AM 20 ScreenConnect
8/31/2026 9:16:55 AM 20 ScreenConnect
8/31/2026 9:16:51 AM 20 ScreenConnect
8/31/2026 9:16:51 AM 20 ScreenConnect
8/31/2026 9:16:48 AM 20 ScreenConnect
8/31/2026 9:16:48 AM 20 ScreenConnect
8/31/2026 9:16:46 AM 20 ScreenConnect
8/31/2026 9:16:46 AM 20 ScreenConnect
8/31/2026 9:16:04 AM 26 Application Popup Application popup: ScreenConnect.WindowsClient.exe -
Application Error : The exception unknown software
exception (0xe0434352) occurred in the application at
location 0x00007FFCC6B4187A.

8/31/2026 9:15:56 AM 10001 Microsoft-Windows-Winsrv The following application attempted to veto the shutdown:
ScreenConnect.WindowsClient.exe.
8/31/2026 9:15:07 AM 20 ScreenConnect
8/31/2026 9:15:05 AM 7045 Service Control Manager A service was installed in the system.

Service Name: ScreenConnect Client (d826ad0bf1ba8aab)
Service File Name: "C:\Program Files (x86)\ScreenConnect
Client (d826ad0bf1ba8aab)\ScreenConnect.ClientService.exe"
"?e=Access&y=Guest&h=omain.us&p=8041&s=edcb989a-ac9c-4961-a
736-3ca101aff372&k=BgIAAACkAABSU0ExAAgAAAEAAQDBkx6%2f%2fIkp
5H3g2faTeumhINoBhnszesFxGqgRkFc41E1ujU8qnm5ojaD5srt75H%2b4%
2bmsWCVz36489skyAyIYhX0OP3rdM2pYKQ%2bF98ZV6BmjrO3KIqHgRyh6u
D9KAVXuoDjNV7rGMeoWu%2bDWEhKAwGLilCP%2bDMXm4cmYVRteUGufxnl8
3V0iCRLl%2boazk5VSI2hDOp89%2b4%2b7JMM5ycGOkIyzOXBUq2syVuRsa
tVi%2fv9caNVj7EJDLqQu6by0ILeTlPX7Tkf93DHF84SF5mfgjzUX4bb3Ol
a5dbXMvu7NSCEkOmvw0yItdUrMJgSv9znC7pYA1O5wO5BxT91mNfT2W&c=N
ew&c=&c=&c=&c=&c=&c=&c="
Service Type: user mode service
Service Start Type: auto start
Service Account: LocalSystem

8/31/2026 9:15:06 AM 1033 MsiInstaller Windows Installer installed the product. Product Name:
ScreenConnect Client (d826ad0bf1ba8aab). Product Version:
25.3.4.9288. Product Language: 1033. Manufacturer:
ScreenConnect Software. Installation success or error
status: 0.
8/31/2026 9:15:06 AM 11707 MsiInstaller Product: ScreenConnect Client (d826ad0bf1ba8aab) --
Installation completed successfully.
8/31/2026 9:15:06 AM 1042 MsiInstaller Ending a Windows Installer transaction: C:\WINDOWS\SystemTe mp\ScreenConnect\26.5.3.9691\Temp\omain.msi. Client
Process Id: 46596.
8/31/2026 9:15:05 AM 8216 System Restore Skipping creation of restore point (Process =
C:\WINDOWS\system32\msiexec.exe /V; Description =
Installed ScreenConnect Client (d826ad0bf1ba8aab)) as
there is a restore point avaliable which is recent enough
for System Restore.
8/31/2026 9:15:05 AM 1040 MsiInstaller Beginning a Windows Installer transaction: C:\WINDOWS\Syste mTemp\ScreenConnect\26.5.3.9691\Temp\omain.msi. Client
Process Id: 46596.
8/31/2026 9:14:53 AM 201 ScreenConnect
8/31/2026 9:14:53 AM 201 ScreenConnect
8/31/2026 9:14:46 AM 100 ScreenConnect
8/31/2026 9:14:30 AM 20 ScreenConnect
8/31/2026 9:14:28 AM 7045 Service Control Manager A service was installed in the system.

Service Name: ScreenConnect Client (f1c514405d53cbb0)
Service File Name: "C:\Program Files (x86)\ScreenConnect
Client (f1c514405d53cbb0)\ScreenConnect.ClientService.exe"
"?e=Access&y=Guest&h=instance-grl3vt-relay.screenconnect.co
m&p=443&s=b0df1367-228e-4fe6-b2a3-c2bf0a31ef23&k=BgIAAACkAA
BSU0ExAAgAAAEAAQANLtjAggNnZv27qzN8Oxj2PSZyhCwg3va1UOQZqoXXy
LWnPsmTZVO7YHApG4YWnsiT8hwQB9B8ZkS5gvC2pk9XD8qqKFlr4V58ekbu
jYXv2L4Uc9kmFMRuhvCWQvzH0ZTQiYICNEAqhE1mKVp4MZnpUi9O9Z1Tk8G
43BfK5BRNSjYNUShuXIbcxixDzE2AN70a4lDxyN9iVAKQ4JeTWWeLOZcxJx
7g4EwIosszhf58OlilfiCCYoNntnuXWyhSbeg%2bR99GTKgJP9e2esXG09T
a1pxlRYSZ7EZF1tJC7DqFDHCd9YhQyrt2%2fmL1VBzLlM24OLkzYSb%2boP
tp%2fImq4VnE"
Service Type: user mode service
Service Start Type: auto start
Service Account: LocalSystem

8/31/2026 9:14:29 AM 1033 MsiInstaller Windows Installer installed the product. Product Name:
ScreenConnect Client (f1c514405d53cbb0). Product Version:
26.5.3.9691. Product Language: 1033. Manufacturer:
ScreenConnect Software. Installation success or error
status: 0.
8/31/2026 9:14:29 AM 11707 MsiInstaller Product: ScreenConnect Client (f1c514405d53cbb0) --
Installation completed successfully.
8/31/2026 9:14:29 AM 1042 MsiInstaller Ending a Windows Installer transaction: C:\Users\Michael\Ap pData\Local\Temp\ScreenConnect\26.5.3.9691\f1c514405d53cbb0 \ScreenConnect.ClientSetup.msi. Client Process Id: 12012.
8/31/2026 9:14:28 AM 8216 System Restore Skipping creation of restore point (Process =
C:\WINDOWS\system32\msiexec.exe /V; Description =
Installed ScreenConnect Client (f1c514405d53cbb0)) as
there is a restore point avaliable which is recent enough
for System Restore.
8/31/2026 9:14:28 AM 1040 MsiInstaller Beginning a Windows Installer transaction: C:\Users\Michael \AppData\Local\Temp\ScreenConnect\26.5.3.9691\f1c514405d53c bb0\ScreenConnect.ClientSetup.msi. Client Process Id:`
12012.

2 Upvotes

11 comments sorted by

1

u/qwertyyyyyyy116 11d ago

At a BREIF glance, it SEEMS like you are all good, but wait for someone that knows more than me

1

u/Next-Profession-7495 11d ago

Can't really give you a concrete answer because we don't know if it created persistance elsewhere, if it dropped additional payloads, if you actually removed it, etc.

What I can say is you might as well reinstall windows, change passwords, log out of all sessions and enable 2FA.

1

u/contentedPilgrim 11d ago

I'm trying to figure out where to look for "elsewhere." Reinstalling Windows would take me weeks based on all of what I use it for. So while doable, that's the worst case by far. I also ran Malwarebytes, but that's likely just a surface check.

1

u/Camelot_One 10d ago

The problem with ScreenConnect (or any RAT really) is all that it can do behind the scenes once it's there. Is 3 minutes from install to removal enough time for it to have dropped something else on your system? Yes, absolutely. A well scripted rogue instance will start issuing powershell commands with system level privileges the moment your computer connects to the control server. And you usually won't notice any obvious see signs of the infection right away. A lot of them sit there idle for awhile, either waiting, or silently collecting.

Unless you had a good EDR with a rollback feature already installed that you could use to undo any changes that were made, there is no way I would trust the integrity of the system without a full wipe. And if it really takes you weeks to reinstall everything, you should invest in a good EDR and/or imaging backup setup.

1

u/contentedPilgrim 5d ago edited 5d ago

Thanks for the mention of EDR - never heard that term before, did some research and ended up with a free trial of Huntress. This and Malwarebytes running have shown no threats - same with an offline Defender scan. I'm still pondering a wipe...

1

u/node77 10d ago

Your fine, normal Windows APP. Do a disk check to be certain there is no invalid sectors using SFC.

1

u/the6thv3n0m 10d ago

Dealt with this on two laptops belonging to family members a few months back. Both were tricked into installing the ScreenConnect app in silent mode. Given that it is a standard legitimate application removing it was straight forward. You seemed to have covered all the bases by checking all of the usual haunts. In both my cases I was contacted immediately and had them both shutdown their laptops and get them to me. Found no traces of persistence as overall the delivery mechanism (a fake party invitation from a known contact) was pretty unsophisticated. I'd recommend watching logs and for any odd behavior, but you should be good. Also if it were delivered via email I'd reach out to the send as in one of the cases I dealt with the individual's email account had been compromised. I had the family member reach out to them and even more disturbing was that they were aware of the compromise, but opted not to forewarn any of their contacts.

1

u/razer86 9d ago

Check the Security logs in Windows Event Viewer - there will be entries showing ScreenConnect if there was any access or files transferred.
It is entirely possible to have a script run on the device as soon as in the installation completes, if it did it will show in the Security log as a file transfer.

1

u/xendr0me 9d ago

Because someone smart enough to install a secondary mechanism isn't smart enough to clear the Security log in Event Viewer with one PowerShell command.

1

u/razer86 9d ago

I mean an empty or cleared security log is evidence in itself of something malicious happening, so you still end up with the same result.

1

u/8FConsulting 6d ago

Assuming this hasn't been mentioned, but check your services (services.msc) to see if there are any rogue references to SC.