January Quicken update killed by Anti Virus
Eric-CO
Quicken Windows Subscription Member
My anti-virus software is killing the January update and latest download of Quicken
It is Sentinel One next generation behavioral AV.
It seems to detect a keylogger installation, here are more details:
Infostealer
Keylogger Installation.
MITRE : Credential Access [T1056.001]
MITRE : Collection [T1056.001]
Injection
Code injection to other process memory space via Reflection.
MITRE : Defense Evasion [T1055][T1055.002]
MITRE : Privilege Escalation [T1055][T1055.002]
Suspicious library loaded into the process memory.
Evasion
Code injection to other process memory space during the target process' initialization
MITRE : Defense Evasion [T1055.012]
MITRE : Privilege Escalation [T1055.012]
Suspicious registry key was created.
MITRE : Defense Evasion [T1112]
Persistence
Application overwrote an existing com object with a new one.
MITRE : Persistence [T1546.015]
MITRE : Privilege Escalation [T1546.015]
Application registered itself to become persistent via COM object.
MITRE : Persistence [T1546.015]
MITRE : Privilege Escalation [T1546.015]
It is Sentinel One next generation behavioral AV.
It seems to detect a keylogger installation, here are more details:
Infostealer
Keylogger Installation.
MITRE : Credential Access [T1056.001]
MITRE : Collection [T1056.001]
Injection
Code injection to other process memory space via Reflection.
MITRE : Defense Evasion [T1055][T1055.002]
MITRE : Privilege Escalation [T1055][T1055.002]
Suspicious library loaded into the process memory.
Evasion
Code injection to other process memory space during the target process' initialization
MITRE : Defense Evasion [T1055.012]
MITRE : Privilege Escalation [T1055.012]
Suspicious registry key was created.
MITRE : Defense Evasion [T1112]
Persistence
Application overwrote an existing com object with a new one.
MITRE : Persistence [T1546.015]
MITRE : Privilege Escalation [T1546.015]
Application registered itself to become persistent via COM object.
MITRE : Persistence [T1546.015]
MITRE : Privilege Escalation [T1546.015]
1
Answers
-
Happened to me too! thank you for posting, this explains why my Quicken software vanished from my PC when I updated it, and I am unable to replace it by downloading the Quicken software from the Quicken website.
I hope that Sentinel and Quicken will figure this out. I have 25 years of data at stake.0 -
Have you considered the fact that your AV software might be at fault?
Signature:
This is my website: http://www.quicknperlwiz.com/1 -
[Removed - Speculation]0
This discussion has been closed.