Agent

Syncro Agent Installer (MSI) Incorrectly Flagged by Antivirus Software

解決済み

We’ve successfully partnered with third party vendors to alleviate false positives related to installation of the Syncro agent. Here are some important details:

Microsoft Defender & Sophos Resolution

  • Microsoft Defender / AV Resolution: Microsoft has officially cleared the false positive flag. The necessary changes are reflected in Security Intelligence Version 1.441.59.0 & above.
  • This security intelligence update will be available to users who subscribe to the automatic security intelligence update mechanism, as well as users who choose to manually update security intelligence update.
  • Sophos Confirmation: Sophos has also confirmed that they have lifted their threat detection as a false positive and should be reflected in the latest definition update.

Google/Chrome Browser Downloads

  • We are continuing to engage with Google to fully resolve the browser download warnings, but we are unable to provide any timeline expectations at this time.
  • Users are currently able to bypass this warning when downloading in Chrome.

Mitigation for Remaining AV False Positive Detections (Action Required)

  • For users still experiencing issues with other AVs, please ensure your antivirus solutions are fully updated.
  • We have conducted an exhaustive review of the source code and build processes to confirm that the binary files are clean and fully intact, containing no malicious or unwanted components. Please report any further detections as false positive to your AV vendor.
  • Please consult and apply the following documentation for manual exceptions and allowlisting: https://docs.syncromsp.com/agents-alerts-automations/syncro-exceptions-and-allowlists
原因確定

We are continuing to engage third party vendors to prevent them from falsely flagging the Syncro Agent as malicious. We expect to be able to provide another update next week.

検証中

We are currently investigating reports that the Syncro Agent Installer (MSI) is being incorrectly flagged as malware by Antivirus. This appears to be a false positive due to a recent update to signature definitions.

We want to assure you that Syncro Agents are safe and contain no malicious code.

We understand that this alert is flagging the successful download and deployment of new Agents via MSI deployment. Our team is treating this as an urgent priority and is currently working towards ensuring that the Syncro MSI file is properly allow listed and the false positive removed.