Help - Search - Members - Calendar
Full Version: Mpcmdrun.exe
BleepingComputer.com > Security > Windows Defender
   
apached
Would really like to understand what causes applications to try to access the internet. What happens if access is denied.?
How can this be stopped? Do they maintain a log of every attempt ? Can the log be found and deleted?
Particularly annoying is every attempt to read a pdf file or opening an Excel file. and Windows Defender.
The destination IP's : 127.001 Port 1074, 64.4.52.57 HTTP, and 209.87.209.52DNS respectively.
I have been denying every request, but have not been able to work out what is the trigger for the Windows Defender application MpCmdRun.exe to startup.
Thanks,
apached
quietman7
MpCmdRun.exe is related to Defender's Command Line Utility and real-time monitoring component which is required for updating the program's signature definitions. MpCmdRun.exe scans for the availability of new signatures from the Microsoft site and then initiates the updating process as new ones become available. During the process MpCmdRun.exe will perform DNS queries to determine the exact IP address before connecting. In order to accomplish this task, the component must have frequent access to the Internet and thus, you may get an alert from your firewall.
apached
Hi,
I was concerned that the access requests were due to spyware activity. Have now allowed access. to mpcmdrun.exe. Should I also allow every attempt made by Adobe and Excel when pdf or excel files are opened? Why is it that the attempts are only detected by the firewall instead of the application directly communicating to the user the reason for getting connected.
apached
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.